{"_id":"@axon-protocol/env-vault-server","name":"@axon-protocol/env-vault-server","dist-tags":{"latest":"0.1.0"},"versions":{"0.1.0":{"name":"@axon-protocol/env-vault-server","version":"0.1.0","description":"AXON ENV/Secrets Vault Server — Manage .env files across projects with secret detection and masking","type":"module","main":"dist/index.js","types":"dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"bin":{"axon-env-vault":"src/mcp-stdio.ts"},"scripts":{"build":"tsc","prepublishOnly":"npm run build","start":"npx tsx src/index.ts","mcp":"npx tsx src/mcp-stdio.ts","dev":"npx tsx --watch src/index.ts"},"keywords":["axon","env","secrets","vault","dotenv","security","mcp","ai-agent","tools"],"repository":{"type":"git","url":"git+https://github.com/hchihoub/axon-protocol.git","directory":"servers/env-vault"},"homepage":"https://github.com/hchihoub/axon-protocol#readme","author":{"name":"AXON Protocol Contributors"},"license":"MIT","dependencies":{},"peerDependencies":{"@axon-protocol/sdk":"^0.1.0"},"devDependencies":{"typescript":"^5.4.0","tsx":"^4.7.0"},"gitHead":"7f39259c0dec0b320371c8ab84ea3d2b1e3bdd58","_id":"@axon-protocol/env-vault-server@0.1.0","bugs":{"url":"https://github.com/hchihoub/axon-protocol/issues"},"_nodeVersion":"25.8.0","_npmVersion":"11.11.0","dist":{"integrity":"sha512-qHNYxR1HlowT8NRe9Vr+pULNzlTdf7DKT5Srw2s/e1C1S0ynjqGdSKJbQ++gEapJGH5XLr6cGsS4aV6YPgsMig==","shasum":"ff9d35c58f89efdfcc3c9896dd03a48e316ae10a","tarball":"https://registry.npmjs.org/@axon-protocol/env-vault-server/-/env-vault-server-0.1.0.tgz","fileCount":22,"unpackedSize":118067,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQDv7kzV63IF57OnloTBzQsEOBAJRc9ivVNYSRdpDKOJ0AIhAP1BoENAtrOXj4lwLadEafAAlaP9YhbFNzQ5bG+8qxiK"}]},"_npmUser":{"name":"hec-28","email":"chihoub.houssem@gmail.com"},"directories":{},"maintainers":[{"name":"hec-28","email":"chihoub.houssem@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/env-vault-server_0.1.0_1773680553740_0.7061264042329789"},"_hasShrinkwrap":false}},"time":{"created":"2026-03-16T17:02:33.667Z","0.1.0":"2026-03-16T17:02:33.894Z","modified":"2026-03-16T17:02:34.109Z"},"maintainers":[{"name":"hec-28","email":"chihoub.houssem@gmail.com"}],"description":"AXON ENV/Secrets Vault Server — Manage .env files across projects with secret detection and masking","homepage":"https://github.com/hchihoub/axon-protocol#readme","keywords":["axon","env","secrets","vault","dotenv","security","mcp","ai-agent","tools"],"repository":{"type":"git","url":"git+https://github.com/hchihoub/axon-protocol.git","directory":"servers/env-vault"},"author":{"name":"AXON Protocol Contributors"},"bugs":{"url":"https://github.com/hchihoub/axon-protocol/issues"},"license":"MIT","readme":"# @axon-protocol/env-vault-server\n\nAXON ENV/Secrets Vault Server — Manage `.env` files across projects with secret detection and value masking.\n\n## Overview\n\nThis server provides 7 tools for managing environment files across projects. It scans directories for `.env*` files, parses them, detects potential leaked secrets using known API key patterns, and compares env files across environments.\n\n## Security\n\n- **Values are MASKED by default** in all listings (shown as `****`)\n- Only `get_env_value` returns actual values, stored in OCRS only\n- Secret detection uses regex patterns for known API key formats (AWS, GitHub, Stripe, Google, Slack, JWT, database URLs)\n- Summarizers NEVER include secret values\n- Comparison results show masked values only\n\n## Tools\n\n| Tool | Description | Capabilities |\n|------|-------------|-------------|\n| `scan_env_files` | Scan a directory tree for all .env files | read |\n| `read_env` | Read an .env file (values masked by default) | read |\n| `get_env_value` | Get a specific env variable value | read |\n| `set_env_value` | Set/update a variable in an .env file | write |\n| `delete_env_value` | Remove a variable from an .env file | write |\n| `detect_secrets` | Scan files for potential secrets | read |\n| `compare_envs` | Compare two .env files | read |\n\n## Usage\n\n### As MCP Server (Claude Desktop, Cursor, etc.)\n\n```json\n{\n  \"mcpServers\": {\n    \"env-vault\": {\n      \"command\": \"npx\",\n      \"args\": [\"tsx\", \"/path/to/servers/env-vault/src/mcp-stdio.ts\"],\n      \"env\": {\n        \"AXON_VAULT_ROOT\": \"/path/to/projects\"\n      }\n    }\n  }\n}\n```\n\n### Programmatic\n\n```typescript\nimport { launchEnvVaultServer } from \"@axon-protocol/env-vault-server\";\n\nconst { server, manager } = await launchEnvVaultServer({ rootDir: \"/projects\" });\nconsole.log(`${server.toolCount} tools ready`);\n```\n\n## Secret Detection Patterns\n\nThe `detect_secrets` tool recognizes:\n\n- **AWS**: Access keys (`AKIA...`), secret keys\n- **GitHub**: Personal access tokens (`ghp_`, `gho_`, `ghu_`, `ghs_`, `ghr_`)\n- **Stripe**: Secret keys (`sk_live_`, `sk_test_`), publishable keys (`pk_live_`)\n- **Google**: API keys (`AIza...`)\n- **Slack**: Tokens (`xox[bpors]-...`), webhooks\n- **JWT**: JSON Web Tokens (`eyJ...`)\n- **Database URLs**: PostgreSQL, MySQL, MongoDB, Redis connection strings\n- **Generic**: API keys, secrets, passwords, tokens\n\n## Environment Variables\n\n| Variable | Description | Default |\n|----------|-------------|---------|\n| `AXON_VAULT_ROOT` | Root directory for scanning | `cwd` |\n\n## Development\n\n```bash\nnpm run dev    # Watch mode\nnpm run build  # Compile TypeScript\nnpm run mcp    # Start MCP stdio server\n```\n","readmeFilename":"README.md","_rev":"1-50c8e2da1088df96cce1cf5bcd03436f"}