Complete AI Training

MCP server · Security

secretctl MCP server

by forest6511

Lets your AI run commands that need passwords or keys, without ever seeing the secret values.

Flow diagram: you ask your AI “Run aws s3 ls with my aws secrets and show me the buckets”, on your own computer the secretctl MCP server works with your own computer, and you get back the command output, secrets hidden.

secretctl is a small program that keeps your passwords, API keys and tokens locked in an encrypted vault on your own computer. It also comes with a helper for AI assistants, so your AI can run commands that need those secrets without ever seeing them. It is handy for anyone who has ever pasted a key into a chat to debug something.

What is an MCP server? The 30-second version

On its own, your AI can only chat. An MCP server is a small helper program that gives your AI a new skill or a connection to something else. This one connects your AI to your secretctl vault on your machine. When your AI needs to run a command that requires a key, it asks this helper, the helper quietly adds the key behind the scenes, and your AI only sees the result.

What this MCP server does

You ask your AI to do something that needs a secret, like list your cloud storage buckets. Your AI asks the secretctl helper to run that command. The helper looks up the right secret in your vault, adds it to the command as a hidden setting, and runs the command for you. The command's output comes back with any secret values replaced by [REDACTED]. Your AI reads the result and answers you, but never sees the actual key.

Flow diagram: you ask your AI “Run aws s3 ls with my aws secrets and show me the buckets”, on your own computer the secretctl MCP server works with your own computer, and you get back the command output, secrets hidden. Click to zoom

What you can do with it

  • List the names of the secrets in your vault, without their values
  • Check whether a particular secret exists
  • See a masked version of a secret, like ****WXYZ
  • Run a command with one or more secrets quietly added
  • Run commands using a set of pre-approved bindings
  • List the field names inside a multi-field secret
  • Read the non-sensitive fields of a secret

Try asking your AI

  • “Run aws s3 ls with my aws secrets and show me the buckets”
  • “Do I have an OPENAI_API_KEY saved in my vault?”
  • “Run kubectl get pods with my k8s credentials”
  • “Show me a masked version of my DB_PASSWORD”

What it gives back to you

You get back the normal output of the command, like a list of buckets or pods, or a short answer like yes or no. Any secret value that appears in that output is replaced with [REDACTED] plus the secret's name. For listing or checking secrets, you get names and small details, never the actual values. Everything shows up right in your chat.

Before you start

What you need

  • The secretctl program installed on your computer
  • A vault you have created with a master password
  • The SECRETCTL_PASSWORD setting so the helper can open your vault
  • An AI assistant that supports MCP, like Claude Code

Good to know

It can run commands on your computer, so only allow the commands you trust in the policy file, and remember that output hiding uses exact matching, so encoded or partial secrets may slip through.

Install it with your AI

Add secretctl MCP server to your AI, no technical skills needed

You don't install anything by hand. You copy one prompt, paste it into an AI that can work on your computer, and it checks, installs and connects the server for you, asking you when it needs something.

Sign in to get the install prompt

Members get a ready-made prompt that lets the Claude desktop app check secretctl MCP server, install it and connect it for them, step by step. You don't need any technical skills: you copy, paste and answer a few questions. Your connected AI can also find and install any of the 4,066 MCP servers here for you.

Sign in Become a member

Who it's for

Developers and anyone who uses an AI assistant for work that involves API keys, cloud accounts or passwords.