vault-kv-mcp logo

vault-kv-mcp

elisjetmax/mcp-vault-hashicorp
0 starsUpdated 2026-06-24Community

Is this your server?

Add your score badge to your README and get your server in front of 45k+ builders a month.

Works with

Claude CodeClaude DesktopCursorVS CodeClineCodex CLIOpenClaw+ any MCP client

Install to Claude Code

This server doesn't publish a one-line install command. Follow the setup in the source repository.

Summary

A read-only MCP server that provides tools to read, list, and inspect secrets from HashiCorp Vault's KV secrets engine (versions 1 and 2) using a Vault token.

README.md

vault-kv-mcp

A read-only MCP (Model Context Protocol) server that exposes the HashiCorp Vault KV secrets engine (versions 1 and 2) as tools. Every tool performs only non-destructive reads — there are no write, delete, or destroy operations. It authenticates with a Vault token and speaks MCP over stdio, so it works with local MCP clients such as Claude Desktop.

Tools (all read-only)

| Tool | Description | |------|-------------| | vault_kv_read | Read a secret (latest or a specific KV v2 version). | | vault_kv_list | List keys / sub-folders under a path. | | vault_kv_read_metadata | KV v2: read version history and metadata. | | vault_list_kv_mounts | Discover available secret mounts and their KV versions. | | vault_health | Check Vault server health / connectivity. |

KV v1 vs v2 is auto-detected per mount when kv_version is not supplied (falling back to v2).

For defense in depth, pair this with a Vault token whose policies grant only read/list capabilities on the relevant paths.

Configuration

Set these environment variables (see .env.example):

  • VAULT_ADDR — Vault base URL (default http://127.0.0.1:8200)
  • VAULT_TOKENrequired Vault token, sent as the X-Vault-Token header
  • VAULT_NAMESPACE — optional, for Vault Enterprise / HCP Vault
  • VAULT_SKIP_VERIFY — optional, set true to skip TLS verification (dev only)

The token only needs policies granting access to the KV paths you intend to use.

Build

npm install
npm run build

Run / test with the MCP Inspector

VAULT_ADDR=http://127.0.0.1:8200 VAULT_TOKEN=hvs.xxxx npm run inspector

Use with Claude Desktop

Add to your claude_desktop_config.json:

{
  "mcpServers": {
    "vault-kv": {
      "command": "node",
      "args": ["/absolute/path/to/vault-mcp/dist/index.js"],
      "env": {
        "VAULT_ADDR": "http://127.0.0.1:8200",
        "VAULT_TOKEN": "hvs.your-token-here"
      }
    }
  }
}

Quick local Vault for testing

vault server -dev          # prints a Root Token and unseal info
export VAULT_ADDR=http://127.0.0.1:8200
export VAULT_TOKEN=<root-token-from-output>
vault kv put secret/demo username=app password=s3cr3t

Then ask your MCP client to read secret/demo.

Security notes

  • The server only ever reads from Vault; it never writes, deletes, or destroys secrets.
  • The token is read only from the environment and never logged.
  • Prefer a short-lived, least-privilege token (read/list only) over a root token.

See related servers & alternatives →

Related MCP servers

Browse all →

Related guides

Hand-picked reading to help you choose and use Other servers.