Sign In

@clavisagent/mcp-server

Package Overview
Dependencies
Maintainers
1
Versions
4
Alerts
File Explorer

Advanced tools

Socket logo

Install Socket

Detect and block malicious and high-risk dependencies

Install

@clavisagent/mcp-server

MCP server for secure credential management. Handles encrypted storage, auto token refresh, and rate limiting for Claude Desktop and AI agents.

latest
Source
npmnpm
Version
0.1.3
Version published
Weekly downloads
86
-3.37%
Maintainers
1
Weekly downloads
 
Created
Source

Clavis MCP Server

Secure credential management for Claude Desktop and MCP servers.

Features

  • 🔐 Encrypted credential storage (AES-128-CBC + HMAC-SHA256, via Fernet)
  • 🛡️ Server-side credential injection — the raw key never enters the conversation
  • 🔄 Automatic OAuth token refresh
  • ⚡ Distributed rate limiting
  • 📊 Audit logging on every credential access

Installation

npx @clavisagent/mcp-server

Or install globally:

npm install -g @clavisagent/mcp-server

Usage with Claude Desktop

Add the following to your Claude Desktop configuration file (claude_desktop_config.json):

{
  "mcpServers": {
    "clavis": {
      "command": "npx",
      "args": ["-y", "@clavisagent/mcp-server"],
      "env": {
        "CLAVIS_API_KEY": "eyJ..."
      }
    }
  }
}

Usage with Claude Code

claude mcp add clavis -- npx -y @clavisagent/mcp-server

Configuration

VariableRequiredDefaultDescription
CLAVIS_API_KEYyesYour Clavis JWT, from POST /v1/auth/login. Not the cla_… key shown at sign-up.
CLAVIS_API_URLnohttps://clavisagent.comBase URL of your Clavis instance. Set this for self-hosted deployments.

Available Tools

ToolDescription
call_serviceRecommended. Make an API call with server-side credential injection — the credential is injected into the upstream request server-side, so the raw key never enters the conversation.
get_credentialsLegacy. Returns the raw access token or API key for a named service. Prefer call_service.
list_servicesList all services with stored credentials
check_credential_statusCheck the status and expiry of credentials for a service

Security note

Prefer call_service over get_credentials. call_service keeps the secret server-side, so a prompt injection has no credential in context to exfiltrate. get_credentials places the raw key in the conversation and exists only for callers that must hold the token themselves.

License

MIT

Keywords

mcp

FAQs

Package last updated on 26 Jul 2026

Did you know?

Socket

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Install

Related posts