auth-mcp
A secure MCP server that stores and retrieves API keys and credentials, featuring encrypted storage, masked retrieval, and AI-powered recommendation via MCP sampling.
README
auth-mcp
A secure MCP server that stores all your API keys and auth credentials in one place, retrievable by any MCP client (Goose, Claude Code, Cursor, Codex, Gemini CLI...). Built with FastMCP so it can be hosted on Prefect Horizon and reached over HTTP at a URL like https://<name>.fastmcp.app/mcp.
Features
| Tool | Description |
|---|---|
auth_set(name, value, description) |
Store or update a credential |
auth_get(name, mask=True) |
Retrieve a credential (masked by default; mask=False for full value) |
auth_list() |
List names + metadata only — never values |
auth_search(query) |
Search by name/description — metadata only |
auth_recommend(task) |
MCP sampling — asks goose's AI to pick the best credential for a task |
auth_delete(name) |
Delete a credential |
auth_health() |
Health check |
Security model
- Encrypted at rest — the
filebackend encrypts every value with Fernet (AES-128-CBC + HMAC), key derived fromAUTH_MCP_MASTER_KEYvia PBKDF2-HMAC-SHA256 (600k iterations). The vault file never contains a plaintext secret. - List/search never leak values — only names, descriptions and timestamps.
- Masked by default —
auth_getreturns********last4unless you explicitly passmask=False. - Remote access is authenticated by the hosting platform (FastMCP/Prefect Horizon).
- Optional
prefectbackend stores secrets as Prefect CloudSecretblocks (durable, encrypted at rest by Prefect, RBAC-scoped) — ideal for the hosted deployment.
MCP sampling
auth_recommend(task) uses MCP sampling: the server sends the task plus a list of available credentials (names + descriptions only — values never leave the vault) back to goose's LLM, which returns the single best match and its reasoning. This turns the vault into a smart credential router:
auth_recommend(task="call OpenAI to summarize this email thread")
# -> {"ok": true, "recommendation": "openai",
# "reasoning": "Task mentions OpenAI summarization.", "available": [...]}
# then: auth_get(name="openai", mask=False)
Sampling is automatically available in goose (no configuration needed) and gracefully degrades — if the client doesn't support sampling, the tool returns the full list instead.
⚠️ Never commit
.env, the vault file, or real keys. Everything sensitive is git-ignored.
Project layout
auth-mcp/
├── pyproject.toml # deps + entry point (also used as Horizon "requirements")
├── README.md
├── .env.example # copy to .env and fill in
├── src/auth_mcp/
│ ├── config.py # env config (backend, master key, vault path)
│ ├── storage.py # EncryptedFileStore + PrefectSecretStore backends
│ └── server.py # FastMCP server + tools (Horizon server path)
└── tests/test_storage.py
Run locally
cd auth-mcp
python -m venv .venv
.venv\Scripts\activate # Windows (macOS/Linux: source .venv/bin/activate)
pip install -e ".[test]"
# generate a master key and run the server
set AUTH_MCP_MASTER_KEY=CHANGE-ME-strong-passphrase
python -m auth_mcp.server
Test it:
pytest -q
The server speaks MCP over stdio. Add it to your local Goose/Claude Code/Cursor config, then try:
auth_set(name="openai", value="sk-...", description="OpenAI API key")
auth_list()
auth_get(name="openai") # -> ********1234
auth_get(name="openai", mask=False)
Deploy to Prefect Horizon
Prefect Horizon hosts FastMCP servers directly from a GitHub repo. Steps:
-
Push this project to GitHub
cd auth-mcp git init && git add . && git commit -m "Initial auth-mcp" # create a repo on github.com and: git remote add origin git@github.com:<you>/auth-mcp.git git push -u origin main -
Sign in to horizon.prefect.io (create an account if needed).
-
Create a new server and point it at your repo:
- Repository:
<you>/auth-mcp - Server path:
src/auth_mcp/server.py - Requirements:
pyproject.toml
- Repository:
-
Set environment variables in the Horizon UI:
Variable Value AUTH_MCP_MASTER_KEYA strong passphrase (see below) AUTH_MCP_BACKENDprefect(recommended for hosted: secrets live in Prefect Cloud)PREFECT_API_URLhttps://api.prefect.cloud/api/accounts/<ACCOUNT_ID>/workspaces/<WORKSPACE_ID>PREFECT_API_KEYA Prefect Cloud API key that can read/write SecretblocksGenerate a master key:
python -c "import secrets; print(secrets.token_urlsafe(32))" -
Deploy, then copy your server URL, e.g.
https://auth-mcp-xxxx.fastmcp.app/mcp. -
Point your MCP client at the URL (HTTP transport):
- Goose:
goose mcp add auth-mcp --transport http https://auth-mcp-xxxx.fastmcp.app/mcp - Claude Code:
claude mcp add auth-mcp --transport http https://auth-mcp-xxxx.fastmcp.app/mcp - Cursor: add to
.cursor/mcp.jsonwith"url": "https://auth-mcp-xxxx.fastmcp.app/mcp"
Any client on your team can now read/write shared credentials through one hosted endpoint.
- Goose:
Backends
file(default): encrypted vault on disk (AUTH_MCP_VAULT_PATH, default.auth_vault.json). Zero external services; good for local use and simple self-hosting.prefect: each credential is a PrefectSecretblock. Install withpip install "auth-mcp[prefect]". RequiresPREFECT_API_URL+PREFECT_API_KEY. Best for the Horizon deployment since secrets survive restarts and are managed by Prefect Cloud.
Security checklist
- [ ] Use a long, unique
AUTH_MCP_MASTER_KEYand store it in a password manager - [ ] Never commit
.envor*.jsonvault files - [ ] Grant the Horizon/Prefect API key only the permissions it needs (Secret blocks)
- [ ] Rotate keys regularly (
auth_setoverwrites in place) - [ ] Keep
mask=Trueunless a full value is genuinely required
Recommended Servers
playwright-mcp
A Model Context Protocol server that enables LLMs to interact with web pages through structured accessibility snapshots without requiring vision models or screenshots.
Audiense Insights MCP Server
Enables interaction with Audiense Insights accounts via the Model Context Protocol, facilitating the extraction and analysis of marketing insights and audience data including demographics, behavior, and influencer engagement.
Magic Component Platform (MCP)
An AI-powered tool that generates modern UI components from natural language descriptions, integrating with popular IDEs to streamline UI development workflow.
VeyraX MCP
Single MCP tool to connect all your favorite tools: Gmail, Calendar and 40 more.
Kagi MCP Server
An MCP server that integrates Kagi search capabilities with Claude AI, enabling Claude to perform real-time web searches when answering questions that require up-to-date information.
graphlit-mcp-server
The Model Context Protocol (MCP) Server enables integration between MCP clients and the Graphlit service. Ingest anything from Slack to Gmail to podcast feeds, in addition to web crawling, into a Graphlit project - and then retrieve relevant contents from the MCP client.
Neon Database
MCP server for interacting with Neon Management API and databases
Exa Search
A Model Context Protocol (MCP) server lets AI assistants like Claude use the Exa AI Search API for web searches. This setup allows AI models to get real-time web information in a safe and controlled way.
Qdrant Server
This repository is an example of how to create a MCP server for Qdrant, a vector search engine.
E2B
Using MCP to run code via e2b.