mcp server
seekrit — secrets for agents
Encrypted store for API keys and database URLs your code needs. Use them without reading them.
Description as published by the maintainer. Source
- version 0.1.0
- archived
- security
archived — The linked repository returns 404. It was deleted, renamed or made private. Dashed tags are derived by ZBS Index from the published description, not stated by the maintainer.
What this server can do
40 functions, named and described by the server itself. Parameter names are shown because they say more about what a function does than its name usually does.
audit(org, limit, action)- Read the organization's audit trail (most recent first).
billing(org)- Show the org's plan, effective entitlements, current usage, and which upgrade actions are available. Read this if a create action was refused with a plan limit.
compose_group(app, env, org, group, position)- Compose a group into an application environment (higher position wins on name clashes). Keyless. Required: app, env, group.
create_app(org, name, slug)- Create an application in an organization. Keyless — then create its environments on the local crypto plane (create_env mints the data key locally). Required: name, slug.
create_group(org, name, slug)- Create a shared group (reusable secret bag) in an organization. Keyless. Required: name, slug.
delete_app(app, org)- Delete an application and all its environments/secrets. Removes ciphertext — keyless — but irreversible. Confirm intent before calling. Required: app.
delete_branch(app, org, branch)- Tear down an ephemeral branch config and every value it overrode. Keyless (it removes ciphertext, never reads it), and the parent environment is untouched. Creating a branch mints a data key, so that stays on the local crypto plane. Required: app, branch.
delete_env(app, env, org)- Delete an application environment and its secrets. Removes ciphertext — keyless — but irreversible. Confirm intent before calling. Required: app, env.
delete_group(org, group)- Delete a group and its environments/secrets. Removes ciphertext — keyless — but irreversible. Confirm intent before calling. Required: group.
delete_secret(app, env, org, name)- Delete a secret from an environment. Removes ciphertext — no key needed. Irreversible except by re-setting it (locally). Required: app, env, name.
get_started- The recommended first-project recipe: what to provision here vs. encrypt locally, end to end. Call this before provisioning.
invite_member(org, role, email)- Invite someone to the organization by email (admin only). They join at the given role once they sign in. Required: email.
kms_disable_key(org, keyId)- Disable a managed KMS key (blocks new operations; existing ciphertexts stay decryptable locally by grantees). Keyless. Required: keyId.
kms_list_keys(org)- List managed KMS keys the caller can see (metadata only — key material is fetched + used locally).
kms_revoke_grant(org, keyId, principalId, principalType)- Revoke a principal's grant on a managed KMS key (all versions). Keyless — the caller needs no key material to remove a grant. Required: keyId, principalType, principalId.
list_apps(org)- List applications in an organization.
list_branches(app, env, org)- List ephemeral branch configs (per-PR / preview environments) in an application, or of one environment. Names, parents, and expiry only — never values. Required: app.
list_env_groups(app, env, org)- List the groups composed into an application environment (precedence order). Required: app, env.
list_envs(app, org)- List environments of an application (names + slugs only, never values). Required: app.
list_group_envs(org, group)- List a group's environments (per-slug value sets). Required: group.
list_groups(org)- List shared groups (reusable secret bags) in an organization.
list_invites(org)- List pending invitations to join the organization.
list_lease_targets(org)- List registered temporary-access provisioning targets (Postgres, MySQL, …).
list_leases(org)- List temporary-access leases (the ledger — never secret material).
list_members(org)- List organization members and their public keys (used when granting access locally).
list_orgs- List organizations the caller can access.
list_secret_versions(app, env, org, name, limit)- List a secret's version history: who wrote each version, when, and which ones were restores. Metadata only — never values. Pair with restore_secret to undo a bad write. Required: app, env, name.
list_secrets(app, env, org)- List secret names + versions in an environment. NEVER returns values — reading a value happens on the local crypto plane (see setup_local_crypto). Required: app, env.
list_tokens(org)- List an organization's service tokens (metadata only — never the token strings).
local_tool_for(operation)- Given a crypto-plane operation this hosted server can't do (e.g. set_secret, create_env, run_command), return exactly how to do it locally. Use when a tool you expected is missing here. Required: operation.
rename_app(app, org, name)- Rename an application's display name (the slug is immutable). Keyless. Required: app, name.
rename_group(org, name, group)- Rename a group's display name (the slug is immutable). Keyless. Required: group, name.
restore_secret(app, env, org, name, version)- Roll a secret back to an earlier version (see list_secret_versions). The stored ciphertext is replayed as a NEW version — history is append-only, nothing is overwritten. Keyless: no decryption happens, so this works here on the metadata plane. Required: app, env, name, version.
revoke_invite(org, inviteId)- Revoke a pending organization invitation. Required: inviteId.
revoke_lease(org, leaseId)- Revoke a temporary-access lease now (drops the credential immediately). Required: leaseId.
revoke_token(org, tokenId)- Revoke a service token by id. Future DEK fetches stop immediately. Rotate the environment (locally) if the holder may have cached the key. Required: tokenId.
setup_local_crypto- How to run the local crypto plane (the `@seekrit/mcp` npm server, the CLI, or seekrit-run) so you can set and use secret values — with a copy-paste .mcp.json. Call this the moment you need a secret's value.
signup(orgName, orgSlug, clientName)- Create a seekrit workspace and your own machine credential — one call, no human, no browser. Binds the credential to this session, so every other tool works on your next call with no config change and no reconnect. Save the returned clientId + clientSecret: the secret is shown once and is how you reconnect later. Call this if a tool says you have no credential. Required: orgName, orgSlug.
uncompose_group(app, env, org, group)- Remove a composed group from an application environment. Keyless. Required: app, env, group.
whoami- Show the authenticated machine client and the org it can access. Call this first.
Last successful function declaration observed on . Source: https://mcp.seekrit.dev/mcp. We list what the server declared; we do not call any of these functions.
Endpoint status observed on . Source: https://mcp.seekrit.dev/mcp.
Signals
These are separate measurements of different things. They are deliberately not combined into one score, because a popularity number that mixes website traffic with saves and stars cannot be checked or acted on.
| Signal | Value | What it measures | Window | Observed | Source |
|---|---|---|---|---|---|
| Latest published version | 0.1.0 | Latest version string the maintainer published to the registry. | as of fetch | Model Context Protocol | |
| Registry record last updated | 2026-07-30 | When the registry record was last updated by its maintainer. | point in time | Model Context Protocol | |
| First listed in the MCP Registry | 2026-07-30 | Date this server was first published to the official MCP Registry. Not a usage or quality measure. | point in time | Model Context Protocol | |
| repository status | not_found | GitHub returned 404 for the repository the maintainer listed. The project was deleted, renamed or made private, so the listing points at nothing. | as of fetch | GitHub | |
| mcp tools declared | 40 tools | Number of functions the server itself declared when asked to list them. This is what the server offers an agent, not a measure of how well any of them work. | as of probe | mcp.seekrit.dev | |
| mcp endpoint status | ok | The server listed 40 functions when asked. | as of probe | mcp.seekrit.dev |
Where to get it
Also from mileszim
-
seekrit (local crypto plane)
— repository gone
Zero-knowledge secrets manager — local crypto-plane MCP server: decrypts and injects secrets.
This record as data
Every field on this page, with its source and observation date, is in the catalog JSON. Fetch the whole kind at once instead of parsing this HTML.
GET /api/v1/entries/mcp_server.json