HashiCorp Vault MCP Server
Official HashiCorp. AI-assisted secret management — ask about over-privileged tokens instead of manual CLI queries.
Official HashiCorp MCP server for Vault secret management. Query secrets, manage policies, and audit access through natural language.
- Ask about over-privileged access tokens in your Vault
- Audit secret access policies through conversation
- Check which services have access to specific secrets
Official HashiCorp. AI-assisted secret management — ask about over-privileged tokens instead of manual CLI queries.
Security teams using HashiCorp Vault who want conversational secret management and policy auditing.
https://github.com/hashicorp/vault-mcp-server
By HashiCorp
How to Get It
docker run -i --rm -e VAULT_ADDR=<vault-addr> -e VAULT_TOKEN=<vault-token> hashicorp/vault-mcp-server
Tip: Paste this into a Claude Code conversation. Verify command matches your Claude Code version.
Once it’s connected, paste this into Claude:
Help me ask about over-privileged access tokens in my Vault
Trust Signals Auto-scanned
Data & Access
Community Pulse Growing
Discussed on Reddit
- obsidian-web-mcp: a sync-safe MCP server that lets Claude reach your vault from — Reddit · 41 pts
- MCP server that treats your vault as a graph, not a folder — Reddit · 25 pts
- Vault MCP Server – Enables interaction with HashiCorp Vault to read, write, list — Reddit · 2 pts
3 mentions across 1 sources
Reviewer notes
Auto-scanned review. These are observations, not a security certification.
catalog_hygiene stale-eval refresh: Scored from trust signals (evidence-eval-v1): 52 GitHub stars; 14 contributors; last commit 14d ago; license MPL-2.0.
Things to check
- HashiCorp states the server is intended for local use only at this stage. Depending on the query it may expose Vault data — including secrets — to the MCP client and LLM, so do not use it with untrusted clients or models. If using the StreamableHTTP transport, set MCP_ALLOWED_ORIGINS to trusted origins to prevent DNS-rebinding attacks.
How to evaluate tools before deploying →
Data shown here comes from public APIs and automated scanning. Reviewer notes reflect one person's experience. This is not a security certification or legal recommendation. Always evaluate tools according to your own organization's policies.
Evaluation
catalog_hygiene stale-eval refresh: Scored from trust signals (evidence-eval-v1): 52 GitHub stars; 14 contributors; last commit 14d ago; license MPL-2.0.