Endpoints: 28,729MCP servers: 18,413Payout addresses: 2,070Paid calls: 1,521Letters: 13Defects: 1,321counted 2 min ago
teppi

MCP serverdev.seekrit/remote-mcp

Encrypted store for API keys and database URLs your code needs.
Read moreEncrypted store for API keys and database URLs your code needs. Use them without reading them.
UNRATEDActivestreamable-httpmcp.seekrit.dev

Overview

Score?
UNRATED 0.672
of what a free look can see, on 30 looks
Looks
36
last 25 min ago
Tools
40
changed 12 days ago

More info

URL
mcp.seekrit.dev/mcp
streamable-http
Says it is
seekrit 0.0.1
protocol 2025-06-18
In the record since
32 days ago

Among servers18,413 with a card

0median 0.606 · this server 0.672 · highest on record 0.8561

Toolsfrom sha256:724b457344…4b8307 · +0 −0 12 days ago

The tools this server lists, read out of the definition it returned
ToolSchema
audit
Read the organization's append-only audit trail, most recent first — every mutation across apps, environments, secrets, members, and tokens. Use it to answer "what changed and who
input · no output
billing
Show the org's plan, effective entitlements, current usage, and which upgrade actions are available. Read this if a create action was refused with a plan limit — it names the limit
input · no output
compose_group
Compose a shared group into an application environment, so that environment resolves the group's secrets as well as its own. Safe to repeat — composing an already-composed group ju
input · no output
create_app
Create an application — the container that will own environments and secrets. This step needs no key material, so it runs here. Creating its environments does NOT: create_env mints
input · no output
create_group
Create a shared group — a reusable bag of secrets (a shared datastore, a vendor account) that many application environments compose in rather than each keeping a copy. Use create_a
input · no output
delete_app
Delete an application together with all of its environments and their secrets, discarding the ciphertext. Irreversible — there is no undo and no export. This is the widest-blast-ra
input · no output
delete_branch
Tear down an ephemeral branch config and every value it overrode. The parent environment is untouched — only the branch's own overrides go — which makes this the routine cleanup wh
input · no output
delete_env
Delete one application environment and the secrets it owns, discarding the ciphertext. Irreversible, and the environment's data key goes with it — recreating the environment means
input · no output
delete_group
Delete a shared group together with its environments and their secrets, discarding the ciphertext. Irreversible. Every application environment that composed this group loses those
input · no output
delete_secret
Delete a secret from an environment, discarding its ciphertext and every version. Irreversible — restore_secret CANNOT bring it back (that only rolls back within a surviving secret
input · no output
get_started
Read the recommended first-project recipe end to end: which steps run here and which need the local crypto plane. Takes no arguments and returns a prose walkthrough. Call this befo
input · no output
invite_member
Invite a human to the organization by email (admin only). They join at the given role once they sign in. Use this to hand a project off to a person — then grant them decryption wit
input · no output
kms_disable_key
Disable a managed KMS key: new encrypt/sign operations are blocked, while data already encrypted under it stays decryptable locally by existing grantees. Reversible only by an oper
input · no output
kms_list_keys
List the managed KMS keys the caller can see — symmetric and signing keys seekrit stores wrapped, for encrypting data outside the secret store. Metadata only: key material is fetch
input · no output
kms_revoke_grant
Revoke one principal's grant on a managed KMS key, across all its versions — that user or service token can no longer use the key, while everyone else keeps working. Use kms_disabl
input · no output
list_apps
List the applications in an organization — an application is the top-level container that owns environments, which in turn own secrets. Start here when you know the org but not the
input · no output
list_branches
List ephemeral branch configs (per-PR / preview environments) across an application, or just those forked from one environment. Names, parents, and expiry only — never values. Use
input · no output
list_env_groups
List the shared groups composed INTO one application environment, in precedence order (higher position wins a name clash). Read this to explain where a secret name actually comes f
input · no output
list_envs
List the environments an application owns (production, staging, …). Names and slugs only — never values. Use this to find the `env` slug that list_secrets and the delete/restore to
input · no output
list_group_envs
List the environments belonging to one shared GROUP — a group holds a separate value set per slug, so its `production` differs from its `staging`. Use this when you already have a
input · no output
list_groups
List the shared groups in an organization — a group is a reusable bag of secrets (a shared datastore, a vendor account) that many application environments can compose in rather tha
input · no output
list_invites
List invitations to the organization that have been sent but not yet accepted. Use it to confirm an invite_member call landed, or to find an `inviteId` for revoke_invite. Accepted
input · no output
list_lease_targets
List the registered temporary-access targets — the databases (Postgres, MySQL, …) against which short-lived credentials can be minted on demand instead of storing a standing passwo
input · no output
list_leases
List temporary-access leases that have been issued — the ledger of who got a short-lived credential against which target and until when. Never includes the credential itself. Use i
input · no output
list_members
List organization members with their public keys. The public keys are what you pass to `grant_env` on the LOCAL crypto plane to give a human the ability to decrypt — so call this w
input · no output
list_orgs
List the organizations this credential can access. Use it to find the `org` slug every other tool takes; prefer whoami if you also want to confirm which client you are. Returns [{
input · no output
list_secret_versions
List one secret's version history: who wrote each version, when, and which ones were restores. Metadata only — never values. Pair with restore_secret to undo a bad write: read the
input · no output
list_secrets
List the secret NAMES and versions in an environment. NEVER returns values: this server cannot decrypt. Use it to discover which names exist before referencing them; to read a valu
input · no output
list_tokens
List an organization's service tokens — the long-lived credentials that let a deployed workload fetch secrets. Metadata only: the token strings are shown once at creation (on the l
input · no output
local_tool_for
Look up how to perform one crypto-plane operation locally — the targeted answer for "the tool I expected is not on this server". Returns { operation, where, how } for a known opera
input · no output
rename_app
Change an application's display name. The slug is immutable — every other tool refers to the app by slug, so a rename breaks nothing. Use delete_app + create_app only if the slug i
input · no output
rename_group
Change a shared group's display name. The slug is immutable — references from composed environments are by slug, so a rename breaks nothing. Returns the updated { id, orgId, name,
input · no output
restore_secret
Roll a secret back to an earlier version — the undo for a bad write. The stored ciphertext is replayed as a NEW version, so history is append-only and nothing is overwritten. Read
input · no output
revoke_invite
Cancel a pending organization invitation before it is accepted. Use this for an invite sent in error; once someone has accepted, they are a member and this no longer applies. Find
input · no output
revoke_lease
Revoke a temporary-access lease now instead of waiting for it to expire — the leased database credential is dropped at the target immediately, so anything still holding it fails on
input · no output
revoke_token
Revoke a service token by id. Future key fetches by that token stop immediately, so any workload still using it loses access on its next read. If the holder may have cached the key
input · no output
setup_local_crypto
Get the exact commands for running the local crypto plane (the `@seekrit/mcp` npm server, the `@seekrit/cli` CLI, seekrit-run, seekrit-proxy), including a copy-paste .mcp.json that
input · no output
signup
Create a seekrit workspace and your own machine credential — one call, no human, no browser. Binds the credential to this session, so every other tool works on your next call with
input · no output
uncompose_group
Remove a composed group from an application environment. The group and its secrets are untouched — only the link is dropped — but the environment stops resolving every name it inhe
input · no output
whoami
Show the authenticated machine client and the org it can access. Call this first: it confirms the credential works and tells you which org slug to pass (or that you can omit `org`
input · no output
Verify it yourselfnpx teppi-check https://mcp.seekrit.dev/mcpcurl -s https://api.teppi.xyz/v1/trust/mcp/mcs_01M1FZ2AF59XN98NH5ZGJ2JJEJ