New:Microsoft Teams Notifications Are Now Available in Socket.Learn more
Get Started

apilocker-mcp

Package Overview
Dependencies
Maintainers
1
Versions
2
Alerts
File Explorer

Advanced tools

Socket logo

Install Socket

Detect and block malicious and high-risk dependencies

Install

apilocker-mcp

MCP server for API key security guidance and management — powered by API Locker

latest
npmnpm
Version
1.1.0
Version published
Maintainers
1
Created
Source

API Locker MCP Server

API key security guidance, exposure risk assessment, and key management recommendations — powered by API Locker.

What It Does

This MCP server gives AI assistants (Claude, ChatGPT, Cursor, etc.) the ability to:

  • ✅ Give security best practices for storing API keys
  • 🔍 Identify which provider an API key belongs to (from its prefix)
  • ⚠️ Assess exposure risk based on how a key is currently stored
  • 🛠️ Recommend the right key manager for any use case

Tools

get_security_tips

Get actionable API key security tips, filterable by topic:

  • storage — vault, .env, encryption
  • rotation — key lifecycle, expiry
  • exposure — handling leaked keys
  • environment — CI/CD, Docker, production
  • browser — browser extension security

identify_api_key

Identify which provider an API key belongs to based on its prefix. Supports 20+ providers including OpenAI (sk-), Anthropic (sk-ant-), AWS (AKIA), GitHub (ghp_), Stripe (sk_live_), and more.

recommend_key_manager

Get tool recommendations for managing API keys based on use case:

  • browser — local development
  • team — shared access
  • cli — terminal/CLI usage
  • cloud — production/infrastructure

check_key_exposure_risk

Evaluate exposure risk for different storage methods: hardcoded in code, .env file, git committed, clipboard, chat message, Notion/Docs, password manager, encrypted vault, localStorage.

Installation

Claude Desktop

Add to your claude_desktop_config.json:

{
  "mcpServers": {
    "apilocker": {
      "command": "npx",
      "args": ["-y", "apilocker-mcp"]
    }
  }
}

Cursor

Add to your Cursor MCP settings:

{
  "mcpServers": {
    "apilocker": {
      "command": "npx",
      "args": ["-y", "apilocker-mcp"]
    }
  }
}

Manual / Local

git clone https://github.com/farukkolip/apilocker-mcp
cd apilocker-mcp
npm install
node index.js

Example Usage

Once installed, you can ask your AI assistant:

  • "How should I store my OpenAI API key?"
  • "I accidentally committed my API key to GitHub, what do I do?"
  • "What provider is this key from: sk-ant-..."
  • "What's the best API key manager for browser use?"
  • "Is it safe to store API keys in Notion?"

About API Locker

API Locker is a free Chrome extension that stores all your API keys in an AES-256-GCM encrypted vault. Keys never leave your device unencrypted. Optional zero-knowledge cloud sync available on Pro plan.

Install API Locker →

License

MIT

Keywords

mcp

FAQs

Package last updated on 13 Apr 2026

Related posts