MCP server · Security
secretctl MCP server
by forest6511
Lets your AI run commands that need passwords or keys, without ever seeing the secret values.

secretctl is a small program that keeps your passwords, API keys and tokens locked in an encrypted vault on your own computer. It also comes with a helper for AI assistants, so your AI can run commands that need those secrets without ever seeing them. It is handy for anyone who has ever pasted a key into a chat to debug something.
What is an MCP server? The 30-second version
On its own, your AI can only chat. An MCP server is a small helper program that gives your AI a new skill or a connection to something else. This one connects your AI to your secretctl vault on your machine. When your AI needs to run a command that requires a key, it asks this helper, the helper quietly adds the key behind the scenes, and your AI only sees the result.
What this MCP server does
You ask your AI to do something that needs a secret, like list your cloud storage buckets. Your AI asks the secretctl helper to run that command. The helper looks up the right secret in your vault, adds it to the command as a hidden setting, and runs the command for you. The command's output comes back with any secret values replaced by [REDACTED]. Your AI reads the result and answers you, but never sees the actual key.
Click to zoomWhat you can do with it
- List the names of the secrets in your vault, without their values
- Check whether a particular secret exists
- See a masked version of a secret, like ****WXYZ
- Run a command with one or more secrets quietly added
- Run commands using a set of pre-approved bindings
- List the field names inside a multi-field secret
- Read the non-sensitive fields of a secret
Try asking your AI
- “Run aws s3 ls with my aws secrets and show me the buckets”
- “Do I have an OPENAI_API_KEY saved in my vault?”
- “Run kubectl get pods with my k8s credentials”
- “Show me a masked version of my DB_PASSWORD”
What it gives back to you
You get back the normal output of the command, like a list of buckets or pods, or a short answer like yes or no. Any secret value that appears in that output is replaced with [REDACTED] plus the secret's name. For listing or checking secrets, you get names and small details, never the actual values. Everything shows up right in your chat.
Before you start
What you need
- The secretctl program installed on your computer
- A vault you have created with a master password
- The SECRETCTL_PASSWORD setting so the helper can open your vault
- An AI assistant that supports MCP, like Claude Code
Good to know
It can run commands on your computer, so only allow the commands you trust in the policy file, and remember that output hiding uses exact matching, so encoded or partial secrets may slip through.
Install it with your AI
Add secretctl MCP server to your AI, no technical skills needed
You don't install anything by hand. You copy one prompt, paste it into an AI that can work on your computer, and it checks, installs and connects the server for you, asking you when it needs something.
Sign in to get the install prompt
Members get a ready-made prompt that lets the Claude desktop app check secretctl MCP server, install it and connect it for them, step by step. You don't need any technical skills: you copy, paste and answer a few questions. Your connected AI can also find and install any of the 4,066 MCP servers here for you.
Who it's for
Developers and anyone who uses an AI assistant for work that involves API keys, cloud accounts or passwords.





