mcpbeat Sign in

Secret Safe Env MCP Server

by irrenwill Your server? Claim it
local only

Secret Safe Env runs on your own machine — the client starts it, so there is no endpoint to ping. 31 installs a week from npm. Last commit 7 Jun 2026.

Write secrets into .env without the agent ever seeing the value - Windows masked dialog (繁中 UI)

Installs per day peak 23 · avg 7 · -56% w/w
a month agotoday
31
Installs / week
npm · secret-safe-env
0
Stars
0 open issues
7 Jun 2026
Last commit
0 releases in 90 days
MIT
License
PowerShell

What the code does

We read the source, 8 h ago · rules 3dff92dd89df

Capabilities

What this server is able to do. For an MCP server this is often the job itself — a terminal server runs commands because that is what it is for. Listed so you know what you are plugging in, not as an accusation.

    const child = spawn(resolvePowershell(), buildSpawnArgs(dialogScriptPath(), key, envPath), buildSpawnOptions());

Is this your server and something here is wrong? Tell us — corrections are free and do not require a plan.

This code can reach further than it looks

We found places where it runs commands, builds paths or queries from values it is given. None of that is a flaw by itself — it becomes one when the code changes, and code changes quietly between releases. We re-read it on every one.

Three servers free · no card

Connect this server

This server runs on your own machine — install it with the package manager and the client starts it for you. Package name taken from the official registry entry.

run in your terminal
claude mcp add secret-safe-env -- npx -y secret-safe-env
~/Library/Application Support/Claude/claude_desktop_config.json
{
  "mcpServers": {
    "secret-safe-env": {
      "args": [
        "-y",
        "secret-safe-env"
      ],
      "command": "npx"
    }
  }
}
~/.codex/config.toml
[mcp_servers.secret-safe-env]
command = "npx"
args = ["-y", "secret-safe-env"]
.cursor/mcp.json
{
  "mcpServers": {
    "secret-safe-env": {
      "args": [
        "-y",
        "secret-safe-env"
      ],
      "command": "npx"
    }
  }
}
.vscode/mcp.json
{
  "mcpServers": {
    "secret-safe-env": {
      "args": [
        "-y",
        "secret-safe-env"
      ],
      "command": "npx"
    }
  }
}

Alternatives to Secret Safe Env

same job, measured the same way
Stashbase
by stashbase

Secrets for developers and agents—secure context and workflows without exposing secret values.

answering
Secrets-LE
by nolindnaidoo

Detect hardcoded secrets in source and config. Reports masked previews, never the values.

38 installs/wk local only
seekrit — secrets for agents
by seekrit

Encrypted store for API keys and database URLs your code needs. Use them without reading them.

40 tools answering
Onepassword Agent MCP
by gambadio

Local MCP access to approved 1Password fields without exposing plaintext secrets to AI agents.

59 installs/wk local only
Wundervault MCP
by wundervault

Zero-knowledge MCP secrets vault for AI agents: secrets injected at runtime, never seen by the model

217 installs/wk local only
hush
by royashbrook

A secret store for AI agents: the agent never sees the plaintext.

1 tools answering
Envault
by dinanathdash

Secure secret management with a Human-In-The-Loop (HITL) interceptor for agent mutations.

35 installs/wk local only
MCP Secret Scrub
by sudo-ai-git

Deterministic no-LLM MCP server that scrubs secrets before they reach an agent. Never leaks values.

91 installs/wk local only

Secret Safe Env — questions

Answers built from our own checks of this server.

Why is there no uptime for Secret Safe Env?
Secret Safe Env runs on your own machine over stdio — there is no network address to reach, so uptime cannot be measured for it by anyone. What can be measured is adoption: the npm package secret-safe-env was installed 31 times last week.
How do I connect Secret Safe Env?
Copy the ready config from this page — we generate it for Claude Code, Claude Desktop, Codex, Cursor and VS Code, each with the file path that client actually reads. It runs locally, so the command pulls secret-safe-env straight from npm; nothing to host, nothing to sign up for.
How many people use Secret Safe Env?
The npm package secret-safe-env was installed 31 times in the last week. Week over week that is -56%. We show installs rather than GitHub stars on purpose: a star is a bookmark, an install is someone actually running it.
Is Secret Safe Env open source?
Yes — it is published under the MIT licence, written in PowerShell and 0 stars on GitHub. The source link is on this page, so you can read exactly what it does with your data before you connect it.