
Gives Claude secure access to credentials without hardcoding them in your config. Exposes three tools: get_credentials to retrieve valid tokens, list_services to see what's stored, and check_credential_status to verify expiry. Handles the annoying stuff like OAuth token refresh automatically and logs every credential access for security auditing. Uses AES-256 encryption for the vault and includes distributed rate limiting to prevent API quota burns. Reach for this when you're building agents that need to authenticate with external services but you don't want API keys sitting in plaintext or tokens expiring mid-conversation.
Secure credential management for Claude Desktop and MCP servers.
npx @clavisagent/mcp-server
Or install globally:
npm install -g @clavisagent/mcp-server
Add the following to your Claude Desktop configuration file (claude_desktop_config.json):
{
"mcpServers": {
"clavis": {
"command": "npx",
"args": ["-y", "@clavisagent/mcp-server"],
"env": {
"CLAVIS_API_KEY": "eyJ..."
}
}
}
}
claude mcp add clavis -- npx -y @clavisagent/mcp-server
| Variable | Required | Default | Description |
|---|---|---|---|
CLAVIS_API_KEY | yes | — | Your Clavis JWT, from POST /v1/auth/login. Not the cla_… key shown at sign-up. |
CLAVIS_API_URL | no | https://clavisagent.com | Base URL of your Clavis instance. Set this for self-hosted deployments. |
| Tool | Description |
|---|---|
call_service | Recommended. Make an API call with server-side credential injection — the credential is injected into the upstream request server-side, so the raw key never enters the conversation. |
get_credentials | Legacy. Returns the raw access token or API key for a named service. Prefer call_service. |
list_services | List all services with stored credentials |
check_credential_status | Check the status and expiry of credentials for a service |
Prefer call_service over get_credentials. call_service keeps the secret
server-side, so a prompt injection has no credential in context to exfiltrate.
get_credentials places the raw key in the conversation and exists only for
callers that must hold the token themselves.
MIT