Envault provides secret management with a human-in-the-loop approval layer for AI agents making mutations. It connects to the hosted Envault service (or your local instance) and exposes operations for reading, writing, and managing environment variables organized into projects. The HITL interceptor means Claude can pull secrets freely but any creates, updates, or deletes require your explicit approval before they're committed. Useful when you want AI to reference production credentials during development without accidentally overwriting or deleting them. Works alongside the envault CLI and native Vercel integration, giving you programmatic access to the same AES-256-GCM encrypted vault your team uses for secret storage and project-based collaboration.
claude mcp add --transport stdio dinanathdash-envault uvx envault