MCP server registry
Security & governancePublic source

Credentials Vault MCP Server

Scoped, auditable credential access for ADK-Rust Enterprise agents. Provides 8 MCP tools over 5 pluggable vault backends — never exposes raw secrets to LLM context.

What it gives an agent

A purpose-built capability behind one MCP connection.

The server owns its domain logic and publishes a tool contract an MCP client can discover. ADK-Rust can load that contract into an agent, normalize each schema for the chosen model provider, and keep the connection lifecycle outside the agent’s business logic.

01

Zero secret exposure — raw secrets never reach LLM context. Tools return handles and short-lived tokens only.

02

Scoped access — credentials declare which agents, skills, and MCP servers can use them.

03

Full audit trail — every access, denial, rotation, and revocation is logged.

04

Pluggable backends — use one or many vault backends simultaneously.

05

Registry-ready — ships with mcp-server.toml for automatic ADK-Rust Enterprise onboarding.

Architecture

How Credentials Vault MCP Server fits into an agent system.

The model never needs the implementation details or credentials of the system behind the server. It sees reviewed tool definitions. The MCP client handles discovery and calls, while the server keeps ownership of validation, policy, and communication with its domain system.

01

ADK-Rust agent

Chooses a capability from the reviewed tool catalog.

02

MCP client

Discovers schemas, sends calls, and receives typed content.

03

Credentials Vault MCP Server

Validates the request and owns 8 documented tool contracts.

04

Domain system

Keeps the API, data, credentials, and business rules behind the server.

Connection: stdio · streamable HTTP · Server framework: ADK MCP SDK + rmcp

From the project documentation

The server’s published architecture

Open the source diagram ↗
Credentials Vault MCP Server architecture diagram from its official repository

Tool catalog

What can an agent ask Credentials Vault MCP Server to do?

Each tool has a stable name, a human-readable purpose, and a JSON input contract discovered during MCP initialization. Risk classes come from the project’s registry manifest when one is available.

8 named tools

list_credentials

List credential metadata — never exposes raw secret values

read only
get_credential_metadata

Inspect owner, scope, expiry, rotation policy, and risk level

read only
request_runtime_secret

Issue a scoped runtime handle after policy checks — returns handle, not raw secret

identity security action
request_workload_token

Mint a short-lived OIDC or workload identity token

identity security action
rotate_credential

Rotate a secret through the approved workflow

identity security action
revoke_credential

Disable a compromised or expired credential

identity security action
audit_credential_access

Retrieve access, denial, and rotation audit events

read only
validate_secret_scope

Check whether an agent, skill, or MCP server can use a credential

read only

Governance

Understand the effect of every tool.

A server connection inherits the authority of its credentials and deployment environment. The declarations below come from this project’s README and MCP registry manifest; your application still decides which tools an agent receives and where approval is required.

4 read only4 identity security action
  • Zero secret exposure — raw secrets never reach LLM context. Tools return handles and short-lived tokens only.
  • Full audit trail — every access, denial, rotation, and revocation is logged.

MCP surface

What the current documentation declares.

MCP can carry tools, resources, prompts, structured results, progress, cancellation, and long-running work. This record highlights the modern protocol features explicitly mentioned by this repository.

The current README concentrates on its tool surface. Check the source and release notes before relying on optional MCP capabilities beyond tool discovery and invocation.
ADK MCP SDKrmcpRegistry manifest

Install and connect

Follow the project’s documented starting point.

Install the server in the environment that owns its credentials and domain access. Add it to your MCP host, verify the discovered tools, and narrow the toolset before giving it to a production agent.

Install
cargo install mcp-credentials-vault
MCP client configuration
{
  "mcpServers": {
    "credentials-vault": {
      "command": "/path/to/mcp-credentials-vault",
      "args": [],
      "env": {
        "RUST_LOG": "info"
      }
    }
  }
}

Commands and configuration are extracted from the public README. Confirm prerequisites, environment variables, and release-specific options in the official documentation before deployment.

Official documentation

Continue with the project maintainers’ source of truth.

This page provides an approachable map of the server. The repository remains authoritative for exact schemas, prerequisites, configuration, examples, tests, releases, and security updates.

Source record

Release and repository metadata for this catalog entry.

View public repository ↗
Version
1.1.0
License
Apache-2.0
Tools
8
Revision
81305f1ce016
Updated
May 26, 2026
Transportsstdiostreamable HTTP