BrowseFull catalogOutcomesSolve a specific problemRolesStack by teamTrustFilter by risk tier
← Back to the Claude Observatory

HashiCorp Vault MCP Server

Connector Security Usable
Works inClaude Code Claude Cowork Claude Chat
Usable Scanned — metadata only

Official HashiCorp. AI-assisted secret management — ask about over-privileged tokens instead of manual CLI queries.

Official HashiCorp MCP server for Vault secret management. Query secrets, manage policies, and audit access through natural language.

57 starsMPL-2.0 (commercial OK)FreeNo code needed
Official tool maintained by HashiCorp.
Usable rating — This tool is functional but has notable gaps. Review the evaluation notes below before deploying.

Official HashiCorp. AI-assisted secret management — ask about over-privileged tokens instead of manual CLI queries.

Security teams using HashiCorp Vault who want conversational secret management and policy auditing.

Claude Code Claude Cowork Claude Chat

https://github.com/hashicorp/vault-mcp-server

By HashiCorp

How to Get It

Option 1: Claude Desktop AppOpen the Customize panel in the sidebar → browse connectors → search and add. Works in Claude Code, Claude Cowork, and Claude Chat.
Option 2: Paste into Claude CodeCopy the command below and paste it into a Claude Code conversation. Claude will run it for you.
Command
docker run -i --rm -e VAULT_ADDR=<vault-addr> -e VAULT_TOKEN=<vault-token> hashicorp/vault-mcp-server

Tip: Paste this into a Claude Code conversation. Verify command matches your Claude Code version.

First thing to try

Once it’s connected, paste this into Claude:

Help me ask about over-privileged access tokens in my Vault
PrerequisitesA running HashiCorp Vault server (local or remote) and a valid Vault token with appropriate permissions; Docker, or Go 1.24+ to build from sourceCostFree

Trust Signals Auto-scanned

Stars57Contributors16Last updated2026-08-11LicenseMPL-2.0 (OK for commercial use)Known CVEsNone foundSources: GitHub Advisory Database + OSV.dev · Scanned 2026-08-15 · scanner vattempted-no-data

Data & Access

Data processingPrompts sent to Anthropic API. Enterprise/Team plans exclude training.Connects toHashiCorp servers (official integration)

Community Pulse Growing

Discussed on Reddit

3 mentions across 1 sources

Reviewer notes

Auto-scanned review. These are observations, not a security certification.

catalog_hygiene stale-eval refresh: Scored from trust signals (evidence-eval-v1): 52 GitHub stars; 14 contributors; last commit 14d ago; license MPL-2.0.

Things to check

  • HashiCorp states the server is intended for local use only at this stage. Depending on the query it may expose Vault data — including secrets — to the MCP client and LLM, so do not use it with untrusted clients or models. If using the StreamableHTTP transport, set MCP_ALLOWED_ORIGINS to trusted origins to prevent DNS-rebinding attacks.

How to evaluate tools before deploying →

Data shown here comes from public APIs and automated scanning. Reviewer notes reflect one person's experience. This is not a security certification or legal recommendation. Always evaluate tools according to your own organization's policies.

Evaluation

Ease of Use
3/5
Versatility
3/5
Reliability
4/5
Security
3/5
Overall score3.25 / 5.00 UsableEvaluatedJul 2026
catalog_hygiene stale-eval refresh: Scored from trust signals (evidence-eval-v1): 52 GitHub stars; 14 contributors; last commit 14d ago; license MPL-2.0.

← Back to the Claude Observatory

Rolling Claude out in your org? Let's talk.

Start a conversation →