Secretcarousel is listed as active in the registry but did not answer our last check. 132 installs a week from npm. Last commit 24 Jul 2026.
Agent-first secrets vault. Store, rotate, and share credentials from chat. 20 tools.
We read the source, 23 h ago · rules 3dff92dd89df
What this server is able to do. For an MCP server this is often the job itself — a terminal server runs commands because that is what it is for. Listed so you know what you are plugging in, not as an accusation.
этот файл ставится пользователю, но в репозитории его нет
Is this your server and something here is wrong? Tell us — corrections are free and do not require a plan.
We found places where it runs commands, builds paths or queries from values it is given. None of that is a flaw by itself — it becomes one when the code changes, and code changes quietly between releases. We re-read it on every one.
Endpoint below is the one we actually reach during checks — not the one copied from a README. Last verified 8 min ago.
claude mcp add secretcarousel --transport http https://mcp.secretcarousel.com/sse
{
"mcpServers": {
"secretcarousel": {
"url": "https://mcp.secretcarousel.com/sse"
}
}
}
[mcp_servers.secretcarousel]
url = "https://mcp.secretcarousel.com/sse"
{
"mcpServers": {
"secretcarousel": {
"url": "https://mcp.secretcarousel.com/sse"
}
}
}
{
"mcpServers": {
"secretcarousel": {
"url": "https://mcp.secretcarousel.com/sse"
}
}
}
This one needs environment variables set before it will start:
SC_API_KEY (SecretCarousel API key (sc_...). Optional: without a key the server starts in onboarding mode and can self-signup via the sc_signup tool.).
The author declared them in the registry entry; get the values from the project itself.
| URL | Transport | State | Latency | Checked |
|---|---|---|---|---|
| https://mcp.secretcarousel.com/sse | sse | answering | 191 ms | 8 min ago |
Local-first secret scanning, rotation, vault, and audit-log tools for AI agents.
Secret and credential management MCP — securely store, retrieve, manage API keys and tokens
Encrypted secrets and credential management for agents
Secret scanner preventing leaks of corporate keys and credentials.
Check text for leaked credentials before an agent writes or commits it. Runs locally.
Local-first persistent memory MCP: shared SQLite key/value store, searchable, TTL-aware, secret-safe
Identity, secrets, and passwordless SSH provisioning for AI agents — Keycloak, vault, MCP tools.
Secure secrets proxy for AI agents — manages API keys so agents never see raw credentials.
Answers built from our own checks of this server.