MCP Advanced Setup & Reference
Manual MCP configuration and runtime controls for advanced Envault agent workflows.
Use this page if you need manual MCP wiring or an explicit reference for tools and operational controls.
For the direct local setup flow (envault mcp install) and the delegated envault_agt_ + HITL walkthrough, use Local AI Agents (Claude & Cursor).
Hybrid model: proprietary core, open execution layer
Envault's cloud platform is proprietary. The runtime surfaces that execute agent actions are intentionally open:
mcp-server/is fully open source under MIT.src/lib/sdk/is fully open source under MIT.
This gives engineering teams a concrete control surface to verify:
- The HITL interceptor path for mutation requests.
- The delegated short-lived token architecture (
envault_agt_JWT lifecycle). - The approval-first sequencing that prevents agents from bypassing human approval.
This page is intentionally advanced. It complements the quickstart guide and avoids duplicating it.
Design partner invite: we are onboarding 5-10 startup/agencies for free to stress-test CLI behavior, GitHub JIT access provisioning, and HITL fencing.
1. Manual Configuration (Standalone MCP Tokens)
Use manual token wiring only when CLI-managed install is not possible (for example isolated DevContainers or custom remote IDE setups).
Generate an MCP Token
Log in to your Envault web dashboard. Navigate to Account Settings -> Security -> MCP Token.
Click Generate Token. Copy this securely, as it will only be shown once.
You can only have one active MCP token at a time. Generating a new one instantly revokes the previous token.
Configure your AI Client
Install the server into your AI client of choice.
Edit your Claude Desktop configuration file:
- macOS:
~/Library/Application Support/Claude/claude_desktop_config.json - Windows:
%APPDATA%\Claude\claude_desktop_config.json
{
"mcpServers": {
"envault": {
"command": "npx",
"args": ["-y", "@dinanathdash/envault-mcp-server@latest"],
"env": {
"ENVAULT_TOKEN": "<YOUR_ENVAULT_TOKEN>",
"ENVAULT_BASE_URL": "https://www.envault.tech"
}
}
}
}Open Settings -> Features -> MCP and add a new MCP Server:
- Name:
envault - Type:
command - Command:
npx -y @dinanathdash/envault-mcp-server@latest
Then add the exact Environment Variables:
ENVAULT_TOKEN=<YOUR_ENVAULT_TOKEN>ENVAULT_BASE_URL=https://www.envault.tech
Edit your workspace or global .vscode/mcp.json:
{
"servers": {
"envault": {
"command": "npx",
"args": ["-y", "@dinanathdash/envault-mcp-server@latest"],
"env": {
"ENVAULT_TOKEN": "<YOUR_ENVAULT_TOKEN>",
"ENVAULT_BASE_URL": "https://www.envault.tech"
}
}
}
}Windows Users: If npx fails to start within GUI apps (like Claude Desktop), change the command from "npx" to "npx.cmd".
Restart your Client
After modifying the configuration, fully restart your AI application (or reload the VS Code window) to initialize the Envault MCP Server.
2. HITL Runtime Behavior (Reference)
When an agent requests a mutation, Envault executes the same approval sequence below:
-
Agent Request: The agent uses its MCP
envault_pushtool to request the mutation. -
Envault Intercepts: Instead of updating the database, Envault creates a
pending_approvalsrecord and returns a202 Acceptedresponse. -
Agent Pauses: The agent receives an
approval_idand anapproval_url. It will pause execution or inform you that an approval is required. -
Human Verification: You click the
approval_urlto view the requested changes in the Envault Web Dashboard, or approve it via your terminal:envault approve <approval_id>Note: The
approvecommand now provides a cryptographic visual diff directly in your terminal, outlining Additions (+), Deletions (-), and Modifications (~). You must be in an interactive terminal to approve the change, otherwise it fails to prevent blind execution. -
Execution: Once approved, the mutation is securely executed, and the agent proceeds with its task.
The delegated token path is also verifiable in source: agent runtime calls only proceed with scoped, short-lived envault_agt_ credentials, and mutation execution remains gated behind explicit HITL approval.
All agent requests, approvals, and rejections are recorded in your Project Audit Logs for traceability and debugging.
3. MCP Tools Reference
Once connected, your AI Agent gains access to the following tools:
- Read-Only Tools:
envault_status,envault_context,envault_diff,envault_pull - Mutation Tools (Requires HITL):
envault_push,envault_deploy,envault_set_local_key,envault_remove_local_key - Execution Tools:
envault_run(Injects secrets dynamically into a local command)
Security Kill Switches
If an agent behaves unexpectedly or an MCP token is compromised, you do not need to delete the project.
Envault provides instant Kill Switches:
- User Level: Navigate to Settings -> Security and disable "Agent Access". This instantly stops all agents using your tokens across all projects.
- Project Level: Workspace Owners can navigate to Project Settings -> Access Control to disable "Agent Workflows", immediately protecting that specific project from all automated AI modifications.