seekrit — secrets for agents
What this MCP does
Manages encrypted application secrets, shared secret groups, environments, access grants, service tokens, leases, KMS metadata, and audit trails.
Tools
Input schema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'properties': {'org': {'type': 'string', 'description': 'Organization slug or id. Omit it when the credential can reach exactly one org â\x80\x94 that org is used automatically. With several, the error names every slug you may pass; list them yourself with list_orgs.'}, 'limit': {'type': 'integer', 'maximum': 200, 'minimum': 1, 'description': 'How many entries to return, newest first. 1â\x80\x93200, default 50.'}, 'action': {'type': 'string', 'description': 'Exact action name to filter by, e.g. "secret.updated" or "app.deleted". Omit for every action. Read the values off an unfiltered call rather than guessing.'}}}
Input schema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'properties': {'org': {'type': 'string', 'description': 'Organization slug or id. Omit it when the credential can reach exactly one org â\x80\x94 that org is used automatically. With several, the error names every slug you may pass; list them yourself with list_orgs.'}}}
Input schema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['app', 'env', 'group'], 'properties': {'app': {'type': 'string', 'description': 'Application slug or id, as returned by list_apps (e.g. "storefront").'}, 'env': {'type': 'string', 'description': 'Environment slug or id within that application, as returned by list_envs (e.g. "production").'}, 'org': {'type': 'string', 'description': 'Organization slug or id. Omit it when the credential can reach exactly one org â\x80\x94 that org is used automatically. With several, the error names every slug you may pass; list them yourself with list_orgs.'}, 'group': {'type': 'string', 'description': 'Shared-group slug or id, as returned by list_groups (e.g. "shared-datastores").'}, 'position': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': 0, 'description': "Precedence among the environment's composed groups: on a name clash the HIGHER position wins, and the environment's own secrets beat every group. Omit to append at the end. Read the current order from list_env_groups first."}}}
Input schema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['name', 'slug'], 'properties': {'org': {'type': 'string', 'description': 'Organization slug or id. Omit it when the credential can reach exactly one org â\x80\x94 that org is used automatically. With several, the error names every slug you may pass; list them yourself with list_orgs.'}, 'name': {'type': 'string', 'description': 'Human-readable display name, e.g. "Acme Storefront". Can be renamed later.'}, 'slug': {'type': 'string', 'description': 'URL-safe identifier used by every other tool to refer to this app: lowercase letters, numbers, hyphens (e.g. "acme-storefront"). Immutable once created â\x80\x94 choose it carefully.'}}}
Input schema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['name', 'slug'], 'properties': {'org': {'type': 'string', 'description': 'Organization slug or id. Omit it when the credential can reach exactly one org â\x80\x94 that org is used automatically. With several, the error names every slug you may pass; list them yourself with list_orgs.'}, 'name': {'type': 'string', 'description': 'Human-readable display name, e.g. "Shared Datastores". Can be renamed later.'}, 'slug': {'type': 'string', 'description': 'URL-safe identifier the other tools refer to this group by: lowercase letters, numbers, hyphens (e.g. "shared-datastores"). Immutable once created.'}}}
Input schema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['app'], 'properties': {'app': {'type': 'string', 'description': 'Application slug or id, as returned by list_apps (e.g. "storefront").'}, 'org': {'type': 'string', 'description': 'Organization slug or id. Omit it when the credential can reach exactly one org â\x80\x94 that org is used automatically. With several, the error names every slug you may pass; list them yourself with list_orgs.'}}}
Input schema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['app', 'branch'], 'properties': {'app': {'type': 'string', 'description': 'Application slug or id, as returned by list_apps (e.g. "storefront").'}, 'org': {'type': 'string', 'description': 'Organization slug or id. Omit it when the credential can reach exactly one org â\x80\x94 that org is used automatically. With several, the error names every slug you may pass; list them yourself with list_orgs.'}, 'branch': {'type': 'string', 'description': 'Branch slug or id within the application, as returned by list_branches.'}}}
Input schema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['app', 'env'], 'properties': {'app': {'type': 'string', 'description': 'Application slug or id, as returned by list_apps (e.g. "storefront").'}, 'env': {'type': 'string', 'description': 'Environment slug or id within that application, as returned by list_envs (e.g. "production").'}, 'org': {'type': 'string', 'description': 'Organization slug or id. Omit it when the credential can reach exactly one org â\x80\x94 that org is used automatically. With several, the error names every slug you may pass; list them yourself with list_orgs.'}}}
Input schema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['group'], 'properties': {'org': {'type': 'string', 'description': 'Organization slug or id. Omit it when the credential can reach exactly one org â\x80\x94 that org is used automatically. With several, the error names every slug you may pass; list them yourself with list_orgs.'}, 'group': {'type': 'string', 'description': 'Shared-group slug or id, as returned by list_groups (e.g. "shared-datastores").'}}}
Input schema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['app', 'env', 'name'], 'properties': {'app': {'type': 'string', 'description': 'Application slug or id, as returned by list_apps (e.g. "storefront").'}, 'env': {'type': 'string', 'description': 'Environment slug or id within that application, as returned by list_envs (e.g. "production").'}, 'org': {'type': 'string', 'description': 'Organization slug or id. Omit it when the credential can reach exactly one org â\x80\x94 that org is used automatically. With several, the error names every slug you may pass; list them yourself with list_orgs.'}, 'name': {'type': 'string', 'description': 'The secret\'s name â\x80\x94 the variable name it is injected as, e.g. "DATABASE_URL". Names come from list_secrets; this is never a value.'}}}
Input schema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'properties': {}}
Input schema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['email'], 'properties': {'org': {'type': 'string', 'description': 'Organization slug or id. Omit it when the credential can reach exactly one org â\x80\x94 that org is used automatically. With several, the error names every slug you may pass; list them yourself with list_orgs.'}, 'role': {'enum': ['member', 'admin'], 'type': 'string', 'description': 'Role granted on join. "member" (the default) can use the org; "admin" can also invite others and delete resources.'}, 'email': {'type': 'string', 'format': 'email', 'pattern': "^(?:[A-Za-z0-9_'+\\-]+\\.)*[A-Za-z0-9_'+\\-]*[A-Za-z0-9_+-]@(?:[A-Za-z0-9][A-Za-z0-9\\-]*\\.)+[A-Za-z]{2,}$", 'description': 'Email address to invite. They receive an invitation and become a member on first sign-in; until then they appear in list_invites, not list_members.'}}}
Input schema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['keyId'], 'properties': {'org': {'type': 'string', 'description': 'Organization slug or id. Omit it when the credential can reach exactly one org â\x80\x94 that org is used automatically. With several, the error names every slug you may pass; list them yourself with list_orgs.'}, 'keyId': {'type': 'string', 'description': "The managed key's id, from kms_list_keys (the `id` field â\x80\x94 `name` is a display label and is not accepted here)."}}}
Input schema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'properties': {'org': {'type': 'string', 'description': 'Organization slug or id. Omit it when the credential can reach exactly one org â\x80\x94 that org is used automatically. With several, the error names every slug you may pass; list them yourself with list_orgs.'}}}
Input schema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['keyId', 'principalType', 'principalId'], 'properties': {'org': {'type': 'string', 'description': 'Organization slug or id. Omit it when the credential can reach exactly one org â\x80\x94 that org is used automatically. With several, the error names every slug you may pass; list them yourself with list_orgs.'}, 'keyId': {'type': 'string', 'description': "The managed key's id, from kms_list_keys (the `id` field â\x80\x94 `name` is a display label and is not accepted here)."}, 'principalId': {'type': 'string', 'description': "The principal's id â\x80\x94 a `userId` from list_members, or a token `id` from list_tokens, matching principalType."}, 'principalType': {'enum': ['user', 'service_token'], 'type': 'string', 'description': 'What kind of principal to revoke: "user" for a human member (list_members) or "service_token" for a machine credential (list_tokens).'}}}
Input schema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'properties': {'org': {'type': 'string', 'description': 'Organization slug or id. Omit it when the credential can reach exactly one org â\x80\x94 that org is used automatically. With several, the error names every slug you may pass; list them yourself with list_orgs.'}}}
Input schema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['app'], 'properties': {'app': {'type': 'string', 'description': 'Application slug or id, as returned by list_apps (e.g. "storefront").'}, 'env': {'type': 'string', 'description': 'Optional environment slug or id to narrow to branches forked from that one environment. Omit to list every branch in the application.'}, 'org': {'type': 'string', 'description': 'Organization slug or id. Omit it when the credential can reach exactly one org â\x80\x94 that org is used automatically. With several, the error names every slug you may pass; list them yourself with list_orgs.'}}}
Input schema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['app', 'env'], 'properties': {'app': {'type': 'string', 'description': 'Application slug or id, as returned by list_apps (e.g. "storefront").'}, 'env': {'type': 'string', 'description': 'Environment slug or id within that application, as returned by list_envs (e.g. "production").'}, 'org': {'type': 'string', 'description': 'Organization slug or id. Omit it when the credential can reach exactly one org â\x80\x94 that org is used automatically. With several, the error names every slug you may pass; list them yourself with list_orgs.'}}}
Input schema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['app'], 'properties': {'app': {'type': 'string', 'description': 'Application slug or id, as returned by list_apps (e.g. "storefront").'}, 'org': {'type': 'string', 'description': 'Organization slug or id. Omit it when the credential can reach exactly one org â\x80\x94 that org is used automatically. With several, the error names every slug you may pass; list them yourself with list_orgs.'}}}
Input schema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['group'], 'properties': {'org': {'type': 'string', 'description': 'Organization slug or id. Omit it when the credential can reach exactly one org â\x80\x94 that org is used automatically. With several, the error names every slug you may pass; list them yourself with list_orgs.'}, 'group': {'type': 'string', 'description': 'Shared-group slug or id, as returned by list_groups (e.g. "shared-datastores").'}}}
Input schema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'properties': {'org': {'type': 'string', 'description': 'Organization slug or id. Omit it when the credential can reach exactly one org â\x80\x94 that org is used automatically. With several, the error names every slug you may pass; list them yourself with list_orgs.'}}}
Input schema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'properties': {'org': {'type': 'string', 'description': 'Organization slug or id. Omit it when the credential can reach exactly one org â\x80\x94 that org is used automatically. With several, the error names every slug you may pass; list them yourself with list_orgs.'}}}
Input schema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'properties': {'org': {'type': 'string', 'description': 'Organization slug or id. Omit it when the credential can reach exactly one org â\x80\x94 that org is used automatically. With several, the error names every slug you may pass; list them yourself with list_orgs.'}}}
Input schema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'properties': {'org': {'type': 'string', 'description': 'Organization slug or id. Omit it when the credential can reach exactly one org â\x80\x94 that org is used automatically. With several, the error names every slug you may pass; list them yourself with list_orgs.'}}}
Input schema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'properties': {'org': {'type': 'string', 'description': 'Organization slug or id. Omit it when the credential can reach exactly one org â\x80\x94 that org is used automatically. With several, the error names every slug you may pass; list them yourself with list_orgs.'}}}
Input schema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'properties': {}}
Input schema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['app', 'env'], 'properties': {'app': {'type': 'string', 'description': 'Application slug or id, as returned by list_apps (e.g. "storefront").'}, 'env': {'type': 'string', 'description': 'Environment slug or id within that application, as returned by list_envs (e.g. "production").'}, 'org': {'type': 'string', 'description': 'Organization slug or id. Omit it when the credential can reach exactly one org â\x80\x94 that org is used automatically. With several, the error names every slug you may pass; list them yourself with list_orgs.'}}}
Input schema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['app', 'env', 'name'], 'properties': {'app': {'type': 'string', 'description': 'Application slug or id, as returned by list_apps (e.g. "storefront").'}, 'env': {'type': 'string', 'description': 'Environment slug or id within that application, as returned by list_envs (e.g. "production").'}, 'org': {'type': 'string', 'description': 'Organization slug or id. Omit it when the credential can reach exactly one org â\x80\x94 that org is used automatically. With several, the error names every slug you may pass; list them yourself with list_orgs.'}, 'name': {'type': 'string', 'description': 'The secret\'s name â\x80\x94 the variable name it is injected as, e.g. "DATABASE_URL". Names come from list_secrets; this is never a value.'}, 'limit': {'type': 'integer', 'maximum': 200, 'minimum': 1, 'description': 'How many versions to return, newest first. 1â\x80\x93200, default 20.'}}}
Input schema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'properties': {'org': {'type': 'string', 'description': 'Organization slug or id. Omit it when the credential can reach exactly one org â\x80\x94 that org is used automatically. With several, the error names every slug you may pass; list them yourself with list_orgs.'}}}
Input schema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['operation'], 'properties': {'operation': {'type': 'string', 'description': 'The tool name you were looking for, in snake_case as it appears on the local plane â\x80\x94 e.g. "set_secret", "get_secret", "create_env", "create_token", "grant_env", "run_command". Unknown names return the general boundary rule rather than an error.'}}}
Input schema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['app', 'name'], 'properties': {'app': {'type': 'string', 'description': 'Application slug or id, as returned by list_apps (e.g. "storefront").'}, 'org': {'type': 'string', 'description': 'Organization slug or id. Omit it when the credential can reach exactly one org â\x80\x94 that org is used automatically. With several, the error names every slug you may pass; list them yourself with list_orgs.'}, 'name': {'type': 'string', 'description': 'The new display name, e.g. "Acme Storefront (EU)".'}}}
Input schema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['group', 'name'], 'properties': {'org': {'type': 'string', 'description': 'Organization slug or id. Omit it when the credential can reach exactly one org â\x80\x94 that org is used automatically. With several, the error names every slug you may pass; list them yourself with list_orgs.'}, 'name': {'type': 'string', 'description': 'The new display name, e.g. "Shared Datastores (EU)".'}, 'group': {'type': 'string', 'description': 'Shared-group slug or id, as returned by list_groups (e.g. "shared-datastores").'}}}
Input schema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['app', 'env', 'name', 'version'], 'properties': {'app': {'type': 'string', 'description': 'Application slug or id, as returned by list_apps (e.g. "storefront").'}, 'env': {'type': 'string', 'description': 'Environment slug or id within that application, as returned by list_envs (e.g. "production").'}, 'org': {'type': 'string', 'description': 'Organization slug or id. Omit it when the credential can reach exactly one org â\x80\x94 that org is used automatically. With several, the error names every slug you may pass; list them yourself with list_orgs.'}, 'name': {'type': 'string', 'description': 'The secret\'s name â\x80\x94 the variable name it is injected as, e.g. "DATABASE_URL". Names come from list_secrets; this is never a value.'}, 'version': {'type': 'integer', 'maximum': 9007199254740991, 'description': 'The version number to restore, taken from list_secret_versions. Its ciphertext becomes a new version on top of history â\x80\x94 the old version is not removed.', 'exclusiveMinimum': 0}}}
Input schema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['inviteId'], 'properties': {'org': {'type': 'string', 'description': 'Organization slug or id. Omit it when the credential can reach exactly one org â\x80\x94 that org is used automatically. With several, the error names every slug you may pass; list them yourself with list_orgs.'}, 'inviteId': {'type': 'string', 'description': "The pending invitation's id, from list_invites."}}}
Input schema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['leaseId'], 'properties': {'org': {'type': 'string', 'description': 'Organization slug or id. Omit it when the credential can reach exactly one org â\x80\x94 that org is used automatically. With several, the error names every slug you may pass; list them yourself with list_orgs.'}, 'leaseId': {'type': 'string', 'description': "The lease's id from list_leases (not the target's id â\x80\x94 see list_lease_targets)."}}}
Input schema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['tokenId'], 'properties': {'org': {'type': 'string', 'description': 'Organization slug or id. Omit it when the credential can reach exactly one org â\x80\x94 that org is used automatically. With several, the error names every slug you may pass; list them yourself with list_orgs.'}, 'tokenId': {'type': 'string', 'description': "The token's id from list_tokens â\x80\x94 not the token string, which is never stored."}}}
Input schema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'properties': {}}
Input schema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['orgName', 'orgSlug'], 'properties': {'orgName': {'type': 'string', 'maxLength': 120, 'minLength': 1, 'description': 'The real project, product, or company this workspace is for (e.g. "Acme Storefront") â\x80\x94 NOT a placeholder like "test" or "agent". A human will later claim the org by this name.'}, 'orgSlug': {'type': 'string', 'minLength': 1, 'description': 'URL-safe identifier derived from the project, lowercase letters/numbers/hyphens (e.g. "acme-storefront"). Throwaway slugs make the org unmanageable.'}, 'clientName': {'type': 'string', 'description': 'Optional label for this machine credential (defaults to <slug>-agent).'}}}
Input schema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['app', 'env', 'group'], 'properties': {'app': {'type': 'string', 'description': 'Application slug or id, as returned by list_apps (e.g. "storefront").'}, 'env': {'type': 'string', 'description': 'Environment slug or id within that application, as returned by list_envs (e.g. "production").'}, 'org': {'type': 'string', 'description': 'Organization slug or id. Omit it when the credential can reach exactly one org â\x80\x94 that org is used automatically. With several, the error names every slug you may pass; list them yourself with list_orgs.'}, 'group': {'type': 'string', 'description': 'Shared-group slug or id, as returned by list_groups (e.g. "shared-datastores").'}}}
Input schema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'properties': {}}
Recent tool changes
Similar MCP servers
BorealHost
Provides web hosting and infrastructure management, including site deployment, DNS, domains, containers, compute, backups, cachin…
BlackVeil DNS & Email Security Scanner
Audits domain, DNS, email, certificate, HTTP, brand-impersonation, and agent-discovery security controls.
Hackertarget
Performs passive DNS, ASN, IP geolocation, HTTP header, ping, link, and network-path reconnaissance and diagnostics.
Busymate DevTools
Captures, inspects, exports, and debugs HTTPS traffic from devices and applications, with request and response inspection, proxy …
Ripe Stat
Provides RIPE registry and routing data for IP addresses, prefixes, ASNs, BGP state and neighbors, network ownership, geolocation…
Cloudflare Radar
Provides Cloudflare Radar internet observatory data on DDoS attacks, BGP leaks, domain popularity, internet quality, and traffic …
Domains
Checks domain registration status and availability and searches certificate-transparency records for certificates and subdomains.
Rdap
Looks up authoritative RDAP registration records for domains, IP addresses, autonomous systems, entities, and nameservers.