
Built for scenarios where you need an LLM agent to authenticate or call APIs without exposing secrets in its context window. Offers three main patterns: vault_add opens a localhost form where you enter credentials that get AES-256-GCM encrypted to disk, vault_login decrypts and autofills them via Chrome DevTools Protocol, and vault_api_request proxies HTTP calls by injecting API keys into headers server-side. The agent only sees success/failure responses, never the actual passwords or tokens. Useful when building autonomous workflows that touch authenticated services like Jira, Stripe, or GitHub without leaking credentials into conversation history or session logs.
MCP server for ZeroCreds — collect credentials from users without exposing them to the LLM.
Claude ZeroCreds Server User
│ │ │
├─zerocreds_create_session──►│ │
│◄─{ token, url }────────────┤ │
│ │ │
│ "Please fill: <url>"──────────────────────────────►│
│ │◄──── form submit ───────┤
│ │ (credentials saved) │
│ │ │
├─zerocreds_check_status─────►│ │
│◄─{ status: "done" }────────┤ │
│ │ │
│ (proceeds — never saw the credentials)
npm install -g zerocreds-mcp
Add to ~/.claude/mcp.json (Claude Code) or Claude Desktop config:
{
"mcpServers": {
"zerocreds": {
"command": "zerocreds-mcp",
"env": {
"ZEROCREDS_URL": "https://zerocreds.ru",
"ZEROCREDS_TOKEN": "your-admin-or-integrator-token",
"ZEROCREDS_DEFAULT_DESTINATION": "local-dev",
"ZEROCREDS_TG_BOT_TOKEN": "optional — sends link via Telegram",
"ZEROCREDS_TG_CHAT_ID": "optional"
}
}
}
}
| Variable | Required | Description |
|---|---|---|
ZEROCREDS_URL | no | Server URL (default: https://zerocreds.ru) |
ZEROCREDS_TOKEN | yes | Admin or integrator token |
ZEROCREDS_DEFAULT_DESTINATION | no | Default destination name (default: local-dev) |
ZEROCREDS_TG_BOT_TOKEN | no | Telegram bot token — auto-sends the link |
ZEROCREDS_TG_CHAT_ID | no | Telegram chat ID |
zerocreds_create_sessionCreates a one-time form session. Returns { token, url, expires_at }.
Claude shows url to the user, then polls zerocreds_check_status every 5–10 seconds.
Parameters:
title (required) — form headingfields (required) — array of { name, label, type?, placeholder?, required?, level? }description — optional subtextdestination — named destination from server config; overrides env defaultttl_minutes — link expiry (default: 30)Field types: text, password, email, tel, number, textarea, url
Field levels (optional, shown to user as privacy indicator):
secret · pii · attribute · credential
zerocreds_check_statusPolls session status. Returns { status: "pending" | "done" | "expired" }.
User: "Log me into GitHub"
Claude: [zerocreds_create_session]
title: "Connect GitHub"
fields: [
{ name: "token", label: "Personal Access Token", type: "password" }
]
→ { token: "abc123", url: "https://zerocreds.ru/f/abc123" }
Claude: "Please fill in your token here: https://zerocreds.ru/f/abc123"
[polls zerocreds_check_status every 5s]
→ { status: "done" }
Claude: "GitHub connected! Proceeding..."
[reads token from secret store via configured destination]
See zerocreds-server to run your own instance.
MIT