Encrypted store for API keys and database URLs your code needs. Use them without reading them.
healthy
status
40
tools exposed
1867ms
connect latency
70bee0299834
schema fingerprint
Tools (40)
signup
Create a seekrit workspace and your own machine credential — one call, no human, no browser. Binds the credential to this session, so every other tool works on your next call with no config change and no reconnect. Save the returned clientId + clientSecret: the secret is shown once and is how you re
get_started
The recommended first-project recipe: what to provision here vs. encrypt locally, end to end. Call this before provisioning.
setup_local_crypto
How to run the local crypto plane (the `@seekrit/mcp` npm server, the CLI, or seekrit-run) so you can set and use secret values — with a copy-paste .mcp.json. Call this the moment you need a secret's value.
local_tool_for
Given a crypto-plane operation this hosted server can't do (e.g. set_secret, create_env, run_command), return exactly how to do it locally. Use when a tool you expected is missing here.
whoami
Show the authenticated machine client and the org it can access. Call this first.
list_orgs
List organizations the caller can access.
list_apps
List applications in an organization.
list_envs
List environments of an application (names + slugs only, never values).
list_branches
List ephemeral branch configs (per-PR / preview environments) in an application, or of one environment. Names, parents, and expiry only — never values.
list_groups
List shared groups (reusable secret bags) in an organization.
list_group_envs
List a group's environments (per-slug value sets).
list_env_groups
List the groups composed into an application environment (precedence order).
list_members
List organization members and their public keys (used when granting access locally).
list_secrets
List secret names + versions in an environment. NEVER returns values — reading a value happens on the local crypto plane (see setup_local_crypto).
list_secret_versions
List a secret's version history: who wrote each version, when, and which ones were restores. Metadata only — never values. Pair with restore_secret to undo a bad write.
list_tokens
List an organization's service tokens (metadata only — never the token strings).
list_invites
List pending invitations to join the organization.
kms_list_keys
List managed KMS keys the caller can see (metadata only — key material is fetched + used locally).
list_lease_targets
List registered temporary-access provisioning targets (Postgres, MySQL, …).
list_leases
List temporary-access leases (the ledger — never secret material).
audit
Read the organization's audit trail (most recent first).
billing
Show the org's plan, effective entitlements, current usage, and which upgrade actions are available. Read this if a create action was refused with a plan limit.
create_app
Create an application in an organization. Keyless — then create its environments on the local crypto plane (create_env mints the data key locally).
create_group
Create a shared group (reusable secret bag) in an organization. Keyless.
compose_group
Compose a group into an application environment (higher position wins on name clashes). Keyless.
uncompose_group
Remove a composed group from an application environment. Keyless.
invite_member
Invite someone to the organization by email (admin only). They join at the given role once they sign in.
rename_app
Rename an application's display name (the slug is immutable). Keyless.
rename_group
Rename a group's display name (the slug is immutable). Keyless.
restore_secret
Roll a secret back to an earlier version (see list_secret_versions). The stored ciphertext is replayed as a NEW version — history is append-only, nothing is overwritten. Keyless: no decryption happens, so this works here on the metadata plane.
delete_secret
Delete a secret from an environment. Removes ciphertext — no key needed. Irreversible except by re-setting it (locally).
revoke_token
Revoke a service token by id. Future DEK fetches stop immediately. Rotate the environment (locally) if the holder may have cached the key.
revoke_invite
Revoke a pending organization invitation.
revoke_lease
Revoke a temporary-access lease now (drops the credential immediately).
kms_disable_key
Disable a managed KMS key (blocks new operations; existing ciphertexts stay decryptable locally by grantees). Keyless.
kms_revoke_grant
Revoke a principal's grant on a managed KMS key (all versions). Keyless — the caller needs no key material to remove a grant.
delete_app
Delete an application and all its environments/secrets. Removes ciphertext — keyless — but irreversible. Confirm intent before calling.
delete_group
Delete a group and its environments/secrets. Removes ciphertext — keyless — but irreversible. Confirm intent before calling.
delete_env
Delete an application environment and its secrets. Removes ciphertext — keyless — but irreversible. Confirm intent before calling.
delete_branch
Tear down an ephemeral branch config and every value it overrode. Keyless (it removes ciphertext, never reads it), and the parent environment is untouched. Creating a branch mints a data key, so that stays on the local crypto plane.
Endpoint
https://mcp.seekrit.dev/mcp Category: Payments · Last checked: 2026-08-15T09:22:30Z
Monitor your own MCP server
Get alerted the moment yours goes down, a tool schema drifts, or an upstream silently breaks.
What this means. This server responded to the MCP handshake and listed its tools without authentication. The schema fingerprint lets us flag if tool signatures silently change (schema drift) between checks.