
Company News
AWS Security Hub Adds Socket for Supply Chain Security
Socket is now in the AWS Security Hub Extended plan. Adopt it through AWS, apply committed spend, and block malicious open source packages.
@securecode/mcp-server
Advanced tools
SecureCodeHQ MCP Server - Let Claude Code access your secrets securely
MCP Server for SecureCodeHQ. Lets Claude Code access your secrets securely — without ever seeing them.
By default, secret values are never shown to the AI. When Claude reads a secret, the value is written to a local file on your machine. The AI gets the file path but never sees the actual value.
You: "Get my Stripe API key"
Claude: ✓ STRIPE_KEY injected → ~/.securecode/.session/a1b2c3d4.env
The value is NOT in this conversation.
This is inject mode — the default. If you explicitly need the AI to see the value, use reveal: true.
1. Get your API key from securecodehq.com > Settings > API Keys
2. Add to your Claude Code config:
Edit ~/.claude.json:
{
"mcpServers": {
"securecode": {
"command": "npx",
"args": ["@securecode/mcp-server"],
"env": {
"SECURECODE_API_KEY": "sc_your_key_here"
}
}
}
}
3. Restart Claude Code. That's it.
Once connected, Claude Code can:
"Get my Stripe API key" -> injects to local file (AI never sees value)
"Get my DB_URL with reveal" -> reveals value to AI (audited)
"List my production secrets" -> shows names and tags, never values
"Save this API key as OPENAI_KEY" -> creates a new secret
"Import my .env.production file" -> bulk import with auto-tagging
"Lock my session" -> blocks all access until you wake it
"byebye" -> locks session + cleans secrets from disk
| Tool | Description |
|---|---|
get-secret | Get a secret — inject to file by default, reveal: true to show to AI, cleanup: true to remove files |
list-secrets | List all secrets with tags, expiry status, and descriptions |
create-secret | Create a new secret with tags, TTL, and domain |
update-secret | Update value, description, tags, or domain |
delete-secret | Soft-delete a secret |
renew-secret | Renew expired secrets or change TTL |
import-env | Import from .env or CSV content (with preview mode) |
export-env | Export secrets as .env or CSV format |
get-status | Check plan, usage limits, secrets count, and MCP server version |
wake-session | Unlock session with optional tag scope and auto-sleep timer |
sleep-session | Lock session immediately, block all access, clean injected files |
session-status | Check session status, scope, and time remaining |
byebye | End session: lock + clean all injected secrets from disk + goodbye |
get-active-rules | List active MCP access rules (read-only) |
Control how AI agents access your secrets with tag-based policies. Rules are created from the dashboard and enforced server-side.
| Action | Effect |
|---|---|
| Block Always | Secret is only accessible from the dashboard |
| Require Confirmation | Agent must acknowledge before accessing |
| Require Session | Requires an active session (wake-session) |
| Block Models | Only allows specific AI models |
| Notify | Sends email notification on access (non-blocking) |
You: "Read my STRIPE_LIVE_KEY"
Claude: [MCP Rule: "Block production secrets"]
Access blocked. This secret is only accessible from the dashboard.
Rules are evaluated by priority: Block Always > Require Session > Block Models > Require Confirmation > Notify.
The MCP server checks for updates on first use. If your version is outdated, you'll see a warning with every tool response:
⚠ Your SecureCode MCP server is outdated (v0.5.1 → v0.6.0).
To update, restart Claude Code — it will fetch the latest version automatically if you use npx.
The MCP server includes an adaptive Tip Engine that educates developers about security best practices:
Tips are throttled (max 3 per session, 1-week cooldown per secret) so they inform without annoying.
Control access to your secrets per session:
You: "Wake my session for the acme project staging"
Claude: [calls wake-session with scope [{project:"acme", env:"staging"}]]
-> Session unlocked. Only acme/staging secrets accessible.
You: "Lock my session"
Claude: [calls sleep-session]
-> Session locked. All access blocked. Injected files cleaned.
You: "byebye"
Claude: -> Session locked & secrets cleaned from disk. See you next time!
Sessions auto-sleep after configurable inactivity (default: 2 hours).
reveal: true returns value to AI (audited as conscious action)sc_ prefixMIT
FAQs
SecureCodeHQ MCP Server - Let Claude Code access your secrets securely
The npm package @securecode/mcp-server receives a total of 19 weekly downloads. As such, @securecode/mcp-server popularity was classified as not popular.
We found that @securecode/mcp-server demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Company News
Socket is now in the AWS Security Hub Extended plan. Adopt it through AWS, apply committed spend, and block malicious open source packages.

Research
/Security News
Popular npm packages keyv and cacheable compromised.

Security News
A misconfiguration gave three Anthropic models internet access, and one, believing it was in a simulation, shipped a credential-stealing package to PyPI.