Security

Secure Your AI with Security MCP Servers

Connect HashiCorp Vault MCP, 1Password MCP, and OAuth MCP to Claude. Secure secrets management, authentication, and vulnerability scanning for enterprise AI workflows.

regex-safety-audit-mcp logo - MCP server integration

regex-safety-audit-mcp

PREMIUM

Parses a regex into a real AST to catch catastrophic-backtracking (ReDoS) risk — nested unbounded quantifiers, ambiguous alternation inside a repeated group, and backreferences — without ever executing the pattern itself. Generates proof-of-concept attack strings and JS-safe rewrites (JS has no atomic groups or possessive quantifiers, so the usual PCRE/.NET fixes don't transfer).

New
redos
regex
security-audit
+1
GuardRail Security logo - MCP server integration

GuardRail Security

PREMIUM

Enterprise multi-language security MCP for AI coding agents. Features hybrid scanning (secrets + Python AST/taint + tree-sitter), repo/PR diff scanning, OSV CVEs, SARIF/SBOM, Docker/K8s checks, policy packs, RBAC, audit logs, and fix drafts.

3
4.5 (2)
security
sast
secrets
+6

vault-dna

by VibeDNA

FREE

Encrypted local credential vault for Claude. Every API key, token, seed phrase encrypted with Fernet + scrypt. Master password stored in your OS keyring. 16 tools: get, list, search, add, edit, delete, scan_for_leaks, backup, add_with_template (22 service templates), export_env, usage_log. Claude checks before asking for keys, scans codebases for leaks before deploy, auto-stores any new credential dropped in conversation. All local, all offline, free.

security
credentials
vault
+2
SaaS Health & Security Auditor logo - MCP server integration

SaaS Health & Security Auditor

PREMIUM

Know if your site is down, your cert is expiring, or Stripe is having issues before your users do.

1
security
monitoring
audit
+7
AegisOps MCP logo - MCP server integration

AegisOps MCP

PREMIUM

AegisOps MCP is an enterprise AI runtime governance and autonomous operations security platform for Model Context Protocol (MCP) agents. It secures AI tool execution with adaptive policy enforcement, risk analysis, approval workflows, autonomous remediation, audit logging, compliance controls, and real-time operational intelligence.

1
ai governance
mcp server
ai security
+7
FakeSpotter logo - MCP server integration

FakeSpotter

PREMIUM
Pay-per-call

AI-Powered Forensic Suite for digital evidence authentication, deepfake detection, and document integrity verification.

1
forensics
security
deepfake-detection
+2
Code Security Scanner logo - MCP server integration

Code Security Scanner

PREMIUM

Scan local codebases for hardcoded secrets, vulnerable dependencies, and insecure code patterns. Supports 24+ secret patterns, 45+ CVEs, and 20+ insecure code patterns across Python, JavaScript, TypeScript, Go, Rust, Java, and more.

security
secrets
vulnerability-scanning
+3
CyberSentry logo - MCP server integration

CyberSentry

PREMIUM
Pay-per-call

Real-time AI security posture analysis for coding agents. Seven expert tools: secret scanning, supply chain CVE checking, SBOM generation, compliance mapping across 8 frameworks, OWASP LLM Top-10 auditing, Ghost Secret scanning, and AI attack surface mapping. Built by Carlos A. Russell, CISSP · CISM · CISA · CGEIT.

security
ai-security
supply-chain
+2

Featured Security MCP Servers

Enterprise-grade security integrations for AI workflows

HashiCorp Vault MCP

Official

Securely access secrets, tokens, and credentials from HashiCorp Vault

Official
Secrets
Tokens
Enterprise
View Server

1Password MCP Server

Secure your MCP configurations with 1Password CLI integration

Vaults
Items
CLI
View Server

OAuth MCP Server

Handle OAuth 2.0 flows and token management for API authentication

OAuth 2.0
PKCE
Tokens
Refresh
View Server

AWS Secrets Manager MCP

Retrieve secrets from AWS Secrets Manager for secure credential access

AWS
Secrets
Rotation
IAM
View Server

Authentication & Identity

Handle OAuth flows, manage sessions, and integrate with identity providers

OAuth MCP Server

OAuth 2.0
PKCE
Tokens

Auth0 MCP

Identity
SSO
MFA

Okta MCP Server

Enterprise
SAML
SSO

Clerk MCP

User Management
Sessions

Firebase Auth MCP

Google
Social Login

Supabase Auth MCP

JWT
Row Level Security

Secrets Management

Securely access API keys, credentials, and tokens from enterprise vaults

HashiCorp Vault MCP

Enterprise
Dynamic Secrets

1Password MCP

Official
Vaults

AWS Secrets Manager MCP

AWS
Rotation

Google Secret Manager MCP

GCP
Versioning

Azure Key Vault MCP

Azure
Keys
Certs

Doppler MCP Server

Sync
Environments

Security Scanning

Scan code, dependencies, and containers for vulnerabilities

Snyk MCP Server

Dependencies
Code

SonarQube MCP

Code Quality
Bugs

Semgrep MCP

SAST
Rules

Trivy MCP Server

Containers
IaC

What Can Security MCP Servers Do?

Retrieve Secrets

Access API keys, tokens, and credentials from secure vaults.

Handle OAuth

Manage OAuth flows, token exchange, and refresh cycles.

Scan Vulnerabilities

Detect security issues in code, dependencies, and containers.

Manage Identity

Integrate with Auth0, Okta, and other identity providers.

Security Best Practices

  • Least privilege: Grant only the permissions needed for the task
  • Short-lived tokens: Use tokens with expiration rather than long-lived credentials
  • Audit logging: Enable logging on both the MCP server and secrets manager
  • Separate environments: Use different credentials for dev, staging, and production
  • Rotate regularly: Set up automatic credential rotation where possible
  • Review access: Regularly audit which MCP servers have access to what secrets

Compare Secrets Managers

Choose the right secrets management solution for your workflow

FeatureVault1PasswordAWS SMDoppler
Dynamic Secrets
Auto Rotation
Team SharingIAM
Multi-CloudAWS
CLI Tool
Official MCPCommunityCommunity

Frequently Asked Questions

How do I securely manage API keys with MCP?

Use a security MCP server like 1Password MCP or Vault MCP to store and retrieve API keys. Never hardcode credentials. MCP servers can fetch secrets at runtime from secure stores, keeping your configuration files clean.

Can Claude access secrets from Vault?

Yes! Install the Vault MCP server, configure your Vault address and authentication method, and add it to Claude Desktop. Claude can then securely retrieve secrets using natural language requests.

What is the best MCP server for authentication?

For secrets management, 1Password MCP and Vault MCP are top choices. For OAuth flows, use the OAuth MCP server. For enterprise SSO, consider Auth0 MCP or Okta MCP servers.

How do I connect 1Password to Claude Desktop?

Install 1Password MCP server from the official 1Password developer portal. Configure your 1Password account credentials and add the server to your Claude Desktop MCP configuration. Restart Claude to activate.

Is it safe to use MCP servers with sensitive data?

Yes, when properly configured. Use read-only access, limit scope to specific secrets, enable audit logging, and prefer short-lived tokens. Security MCP servers like Vault and 1Password have enterprise-grade security built-in.

How do OAuth MCP servers work?

OAuth MCP servers handle the complete OAuth 2.0 flow — authorization, token exchange, and refresh. They support PKCE for security and can manage tokens for multiple providers, letting Claude authenticate to APIs on your behalf.

Build a Custom Security MCP Server

Create custom security integrations. Build an MCP server, publish to the marketplace, and earn 80% of every sale.