{"_id":"@elraian/mcpvault","_rev":"4-8bf1073ef03d4127126e684712f1d387","name":"@elraian/mcpvault","dist-tags":{"latest":"0.2.0"},"versions":{"0.1.0":{"name":"@elraian/mcpvault","version":"0.1.0","keywords":["mcp","model-context-protocol","claude","claude-code","credentials","vault","supabase","github","vercel","stripe","ai-agent"],"license":"MIT","_id":"@elraian/mcpvault@0.1.0","maintainers":[{"name":"elraian","email":"raian.riisna24@gmail.com"}],"homepage":"https://github.com/Elraian/mcpvault#readme","bugs":{"url":"https://github.com/Elraian/mcpvault/issues"},"bin":{"mvault":"dist/index.js","mcpvault":"dist/index.js","mcp-vault":"dist/index.js"},"dist":{"shasum":"52c5b8cd31979505b49c782729e18a45910454e1","tarball":"https://registry.npmjs.org/@elraian/mcpvault/-/mcpvault-0.1.0.tgz","fileCount":88,"integrity":"sha512-xJZCtPlNeqqNDm+y2ojwgPDaraksnJHuWMT8llS4Pu6FZGvAWAEyfY9VQQTEXDIfHoKPm3bNhooLsOOcsaSlsQ==","signatures":[{"sig":"MEUCIEeWELFzotNEDlI4J3Xpa/D5205xVWMzpWpGqn7hxA5FAiEA2Znj4+3qGA8Ldr2qBsnnZ5hQU7oLenNc3FtOsDn0y5g=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":257037},"main":"dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=20"},"gitHead":"aa5a4174930e2644aabe5181f28003700b00537b","scripts":{"dev":"tsx src/index.ts","test":"vitest run","build":"tsc","start":"node dist/index.js","typecheck":"tsc --noEmit","test:watch":"vitest","prepublishOnly":"npm run build && npm test"},"_npmUser":{"name":"elraian","email":"raian.riisna24@gmail.com"},"repository":{"url":"git+https://github.com/Elraian/mcpvault.git","type":"git"},"_npmVersion":"11.5.2","description":"Local MCP credential vault — multi-account credentials for AI agents (Claude, Cursor, Codex, custom MCP clients).","directories":{},"_nodeVersion":"22.15.0","dependencies":{"zod":"^3.23.8","open":"^11.0.0","commander":"^12.1.0","picocolors":"^1.1.1","@noble/hashes":"^1.5.0","@clack/prompts":"^1.4.0","@napi-rs/keyring":"^1.1.6","@modelcontextprotocol/sdk":"^1.18.0"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","vitest":"^2.1.5","typescript":"^5.6.3","@types/node":"^22.9.0"},"_npmOperationalInternal":{"tmp":"tmp/mcpvault_0.1.0_1778794994405_0.7061172362969146","host":"s3://npm-registry-packages-npm-production"}},"0.1.2":{"name":"@elraian/mcpvault","version":"0.1.2","keywords":["mcp","model-context-protocol","claude","claude-code","credentials","vault","supabase","github","vercel","stripe","ai-agent"],"license":"MIT","_id":"@elraian/mcpvault@0.1.2","maintainers":[{"name":"elraian","email":"raian.riisna24@gmail.com"}],"homepage":"https://github.com/Elraian/mcpvault#readme","bugs":{"url":"https://github.com/Elraian/mcpvault/issues"},"bin":{"mvault":"dist/index.js","mcpvault":"dist/index.js","mcp-vault":"dist/index.js"},"dist":{"shasum":"e1879b38c94b33062882b45aab2e3f8f9fdd6350","tarball":"https://registry.npmjs.org/@elraian/mcpvault/-/mcpvault-0.1.2.tgz","fileCount":88,"integrity":"sha512-JNBBJ7q0YRPXaaDQmBj8rpSsnq2/3BMLPkK11s6opQRoz02gpovdQaW6Nb+tzd6hDPt/Nx6dhN/9sn8o6srOZQ==","signatures":[{"sig":"MEQCIEoxq3/IR+mG7V66yASZexX2Nps1t3Qulq7VDX5NAdywAiBQx/qTVi6TaJ01wrElyGMhE38q2o22YFGmGZUfj/gX0A==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":268284},"main":"dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=20"},"gitHead":"5e1e901ee458d26fc1dc870e145f8df36cd63c70","scripts":{"dev":"tsx src/index.ts","test":"vitest run","build":"tsc","start":"node dist/index.js","typecheck":"tsc --noEmit","test:watch":"vitest","prepublishOnly":"npm run build && npm test"},"_npmUser":{"name":"elraian","email":"raian.riisna24@gmail.com"},"repository":{"url":"git+https://github.com/Elraian/mcpvault.git","type":"git"},"_npmVersion":"11.5.2","description":"Local MCP credential vault — multi-account credentials for AI agents (Claude, Cursor, Codex, custom MCP clients).","directories":{},"_nodeVersion":"22.15.0","dependencies":{"zod":"^3.23.8","open":"^11.0.0","commander":"^12.1.0","smol-toml":"^1.6.1","picocolors":"^1.1.1","@noble/hashes":"^1.5.0","@clack/prompts":"^1.4.0","@napi-rs/keyring":"^1.1.6","@modelcontextprotocol/sdk":"^1.18.0"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","vitest":"^2.1.5","typescript":"^5.6.3","@types/node":"^22.9.0"},"_npmOperationalInternal":{"tmp":"tmp/mcpvault_0.1.2_1778825811644_0.15423782188134583","host":"s3://npm-registry-packages-npm-production"}},"0.1.3":{"name":"@elraian/mcpvault","version":"0.1.3","keywords":["mcp","model-context-protocol","claude","claude-code","credentials","vault","supabase","github","vercel","stripe","ai-agent"],"license":"MIT","_id":"@elraian/mcpvault@0.1.3","maintainers":[{"name":"elraian","email":"raian.riisna24@gmail.com"}],"homepage":"https://github.com/Elraian/mcpvault#readme","bugs":{"url":"https://github.com/Elraian/mcpvault/issues"},"bin":{"mvault":"dist/index.js","mcpvault":"dist/index.js","mcp-vault":"dist/index.js"},"dist":{"shasum":"0964b7b80612e0298e775f28418e4d32da94df03","tarball":"https://registry.npmjs.org/@elraian/mcpvault/-/mcpvault-0.1.3.tgz","fileCount":94,"integrity":"sha512-Ih3is2yKBK0Z6m5Tkt4sYh0KPmvFtemnAZfSWEsqeMtSUvvODJGMjHBw86/o5SeRD5ebRtf89V8Yk4P5ImL9qQ==","signatures":[{"sig":"MEUCIQD7xIN7Og2kxqk7Ye6ugFuKhttVPE53g6+MJpbNRaUMSwIgFnShy7K+BiaoOdAlXlFEmDCkrcMmylU/gVenzBCi5EE=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":274720},"main":"dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=20"},"gitHead":"b672c94e61cb96b574e25cfccb3fc9bf3cc1549b","scripts":{"dev":"tsx src/index.ts","test":"vitest run","build":"tsc","start":"node dist/index.js","typecheck":"tsc --noEmit","test:watch":"vitest","prepublishOnly":"npm run build && npm test"},"_npmUser":{"name":"elraian","email":"raian.riisna24@gmail.com"},"repository":{"url":"git+https://github.com/Elraian/mcpvault.git","type":"git"},"_npmVersion":"11.5.2","description":"Local MCP credential vault — multi-account credentials for AI agents (Claude, Cursor, Codex, custom MCP clients).","directories":{},"_nodeVersion":"22.15.0","dependencies":{"zod":"^3.23.8","open":"^11.0.0","commander":"^12.1.0","smol-toml":"^1.6.1","picocolors":"^1.1.1","@noble/hashes":"^1.5.0","@clack/prompts":"^1.4.0","@napi-rs/keyring":"^1.1.6","@modelcontextprotocol/sdk":"^1.18.0"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","vitest":"^2.1.5","typescript":"^5.6.3","@types/node":"^22.9.0"},"_npmOperationalInternal":{"tmp":"tmp/mcpvault_0.1.3_1778826734945_0.75705690604008","host":"s3://npm-registry-packages-npm-production"}},"0.2.0":{"name":"@elraian/mcpvault","version":"0.2.0","description":"Local MCP credential vault — multi-account credentials for AI agents (Claude, Cursor, Codex, custom MCP clients).","type":"module","bin":{"mcpvault":"dist/index.js","mvault":"dist/index.js","mcp-vault":"dist/index.js"},"main":"dist/index.js","license":"MIT","repository":{"type":"git","url":"git+https://github.com/Elraian/mcpvault.git"},"homepage":"https://github.com/Elraian/mcpvault#readme","bugs":{"url":"https://github.com/Elraian/mcpvault/issues"},"keywords":["mcp","model-context-protocol","claude","claude-code","credentials","vault","supabase","github","vercel","stripe","ai-agent"],"scripts":{"build":"tsc","dev":"tsx src/index.ts","start":"node dist/index.js","test":"vitest run","test:watch":"vitest","typecheck":"tsc --noEmit","prepublishOnly":"npm run build && npm test"},"engines":{"node":">=20"},"dependencies":{"@clack/prompts":"^1.4.0","@modelcontextprotocol/sdk":"^1.18.0","@napi-rs/keyring":"^1.1.6","@noble/hashes":"^1.5.0","commander":"^12.1.0","open":"^11.0.0","picocolors":"^1.1.1","smol-toml":"^1.6.1","zod":"^3.23.8"},"devDependencies":{"@types/node":"^22.9.0","tsx":"^4.19.2","typescript":"^5.6.3","vitest":"^2.1.5"},"_id":"@elraian/mcpvault@0.2.0","gitHead":"a42d87beac33576d7bfda2c7c60061252f1a7d26","types":"./dist/index.d.ts","_nodeVersion":"22.15.0","_npmVersion":"11.5.2","dist":{"integrity":"sha512-Gka19TJpjGOjUfkObRjHoBmTDoj3QNXb/o0c6M7B+Dj4suUt3XBXRV7bKYJbh5bhwPa/2LD0phfmeoAGf5LF3Q==","shasum":"d8fd95b9cc3cd19fadad0aae82a12824c78bed91","tarball":"https://registry.npmjs.org/@elraian/mcpvault/-/mcpvault-0.2.0.tgz","fileCount":160,"unpackedSize":383440,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIF+2dxUcx5I/b1l83cl7/W8e1cmCJIyHl/wKkcTG7I4OAiEAgSqJ61vxDeBpcxcD8bDpNMAViXdk5pN9YatNgBhRCQ0="}]},"_npmUser":{"name":"elraian","email":"raian.riisna24@gmail.com"},"directories":{},"maintainers":[{"name":"elraian","email":"raian.riisna24@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/mcpvault_0.2.0_1778845808008_0.05282932309052524"},"_hasShrinkwrap":false}},"time":{"created":"2026-05-14T21:43:14.291Z","modified":"2026-05-15T11:50:08.262Z","0.1.0":"2026-05-14T21:43:14.555Z","0.1.2":"2026-05-15T06:16:51.792Z","0.1.3":"2026-05-15T06:32:15.297Z","0.2.0":"2026-05-15T11:50:08.154Z"},"bugs":{"url":"https://github.com/Elraian/mcpvault/issues"},"license":"MIT","homepage":"https://github.com/Elraian/mcpvault#readme","keywords":["mcp","model-context-protocol","claude","claude-code","credentials","vault","supabase","github","vercel","stripe","ai-agent"],"repository":{"type":"git","url":"git+https://github.com/Elraian/mcpvault.git"},"description":"Local MCP credential vault — multi-account credentials for AI agents (Claude, Cursor, Codex, custom MCP clients).","maintainers":[{"name":"elraian","email":"raian.riisna24@gmail.com"}],"readme":"# mcpvault\n\nLocal, encrypted credential vault for AI agents. Keep many accounts per service (Supabase, GitHub, Vercel, Stripe), and let Claude / Cursor / Codex pick the right one mid-conversation.\n\n> *\"I'm working on the Acme project today — switch me to that Supabase account and list the projects.\"*\n\nThe agent calls a vault tool, the right credentials are loaded, the request executes against the real API. No restart, no manual token-swapping.\n\n## Install\n\n```sh\nnpm i -g @elraian/mcpvault\n```\n\n> Requires Node 20+. Works on Windows, macOS, Linux.\n> The CLI command after install is just `mcpvault` (also aliased as `mvault` and `mcp-vault`).\n\n## Setup in 3 commands\n\n```sh\nmcpvault init                 # create vault, set master password\nmcpvault add supabase         # paste a PAT — validated immediately against the API\nmcpvault setup                # auto-wire into Claude Code / Desktop / Cursor\n```\n\nThen restart your chat client. That's it.\n\n## Day-to-day\n\n| Command | What it does |\n|---|---|\n| `mcpvault add <service>` | Add an account. Validates the token live, suggests a label. |\n| `mcpvault list` | See all accounts. The currently active one is marked ● per service. |\n| `mcpvault update <svc> <label>` | Rotate a token, edit description/tags. |\n| `mcpvault remove <svc> <label>` | Delete an account (with type-the-label confirmation). |\n| `mcpvault activate <svc> <label>` | Set the active account. Wrappers pick it up on next call. |\n| `mcpvault active` | Show what's active per service. |\n| `mcpvault status` / `lock` / `unlock` | Vault lock state. |\n| `mcpvault doctor` | Diagnose vault / keyring / file issues. |\n| `mcpvault setup` | Re-run to wire additional clients later. |\n\n`mcpvault`, `mvault`, and `mcp-vault` all work — they're aliases.\n\n## What you can ask the agent\n\nAfter `mcpvault setup` + restart, your agent has these tools available:\n\n**vault** (control plane)\n`unlock_vault`, `lock_vault`, `vault_status`, `list_accounts`, `find_account`, `get_active`, `activate_account`, `add_account`, `update_account`, `delete_account`, `export_redacted`\n\n**vault-supabase**\n`supabase_list_projects`, `supabase_list_organizations`, `supabase_run_sql`, `supabase_list_tables`, `supabase_get_logs`\n\n**vault-github**\n`github_list_repos`, `github_get_repo`, `github_list_issues`, `github_create_issue`, `github_list_pulls`, `github_get_file`, `github_search_code`\n\n**vault-vercel**\n`vercel_list_projects`, `vercel_list_deployments`, `vercel_get_deployment`, `vercel_list_domains`\n\n**vault-stripe** *(read-only by design — no writes)*\n`stripe_list_customers`, `stripe_retrieve_customer`, `stripe_list_charges`, `stripe_list_subscriptions`, `stripe_retrieve`\n\n## Example flow\n\n```text\nYou:    Switch to the Acme Supabase account and list its projects.\n\nAgent:  [find_account \"Acme\"] → matched \"client-acme\"\n        [activate_account supabase client-acme]\n        [supabase_list_projects]\n        Active is now client-acme. 3 projects: acme-prod, acme-staging, acme-internal.\n\nYou:    Now switch to my personal one and show me its orgs.\n\nAgent:  [activate_account supabase personal]\n        [supabase_list_organizations]\n        Personal account has 1 org: my-projects.\n```\n\nSame wrapper process. Zero restart between switches.\n\n## Security model\n\n| Layer | Mechanism |\n|---|---|\n| Vault file on disk | AES-256-GCM, Argon2id KDF (m=64 MiB, t=3, p=1) |\n| Master password | Never written to disk; held in memory after `unlock` |\n| Session key (after unlock) | OS keyring (Windows Credential Manager / macOS Keychain / libsecret on Linux). Survives reboots so you don't re-type your password daily. |\n| Wrapper MCP processes | Read decrypted creds from keyring per request. Credentials never returned through MCP — only the API result is. |\n| Stripe wrapper | Read-only by design. No `create_charge`, no `refund`. |\n| Audit log | `~/.mcpvault/vault.log` records which account was used per request, never the credential. |\n\nIf you want stricter behavior (re-enter master password every boot), run `mcpvault lock` before shutdown, or call `lock_vault` through your agent.\n\n## Files on disk\n\n```\n~/.mcpvault/\n├── vault.enc         # AES-256-GCM, Argon2id-derived key\n├── active.json       # plain JSON, only labels — no secrets\n└── vault.log         # append-only audit log\n```\n\n> The legacy paths `~/.mcp-vault/` and `~/.mvault/` are also recognized for existing users — auto-detected from disk.\n\n## Architecture\n\n```\nChat client (Claude Code / Desktop / Cursor)\n   │\n   ├── spawns: mcpvault server          ← control plane (list/find/activate/add)\n   ├── spawns: mcpvault wrap supabase   ← per-service wrapper\n   ├── spawns: mcpvault wrap github\n   ├── spawns: mcpvault wrap vercel\n   └── spawns: mcpvault wrap stripe\n                    │\n                    ├── reads: ~/.mcpvault/active.json    (which label per service)\n                    └── reads: ~/.mcpvault/vault.enc      (encrypted creds)\n                                │\n                         decrypted with key from\n                         OS keyring (cached at unlock)\n```\n\nEach wrapper re-reads the active label on every tool call, so switching accounts is instant — no process restart.\n\n## Development\n\n```sh\ngit clone https://github.com/Elraian/mcpvault.git\ncd mcpvault\nnpm install\nnpm run build\nnpm test           # ~22 unit + e2e tests\nnpm link           # exposes `mcpvault` globally for local testing\n```\n\n## Why this exists\n\nMost MCP servers are locked to one account at startup. If you have 10 Supabase projects across 4 clients, you either register the Supabase MCP 10 times or constantly swap tokens by hand. `mcpvault` lets the agent search and switch accounts naturally during a conversation. Same idea applies to any service Anthropic / Cursor / etc. don't natively multi-account.\n\n## Roadmap\n\n- v2: OAuth-based services (Gmail, Drive, Slack — needs refresh logic)\n- v3: 1Password / Bitwarden CLI integration\n- v3: Account \"contexts\" — switch Supabase + GitHub + Vercel + Stripe atomically per project\n- v4: Web UI (Tauri / system tray)\n\n## Credits\n\nBuilt by **[AISIDE](https://aiside.ee)** — [@Elraian](https://github.com/Elraian).\n\n- **Site:** <https://mcpvault.online>\n- **Source:** <https://github.com/Elraian/mcpvault>\n- **npm:** <https://www.npmjs.com/package/@elraian/mcpvault>\n\nIf this saves you time, a star on the repo costs you nothing and helps a lot.\n\n## License\n\nMIT — see [LICENSE](LICENSE).\n","readmeFilename":"README.md"}