Secure Your AI with Security MCP Servers
Connect HashiCorp Vault MCP, 1Password MCP, and OAuth MCP to Claude. Secure secrets management, authentication, and vulnerability scanning for enterprise AI workflows.
Moltline RegClock
by GARPHENGATE
Incident-reporting deadlines from the legal text — EU CRA, NIS2, DORA, GDPR, UK GDPR, HIPAA and SEC 8-K — with citations, business-day and bank-holiday rules, a statutory classifier and calendar export.
Moltline Agent Governance
by GARPHENGATE
Audit your agent fleet: MCP config audits, tool blast-radius scoring, skill-file injection scans, and governance inventories free; tailored policy generator and Auditor persona with a licence.
MCP Production Gate
Unified MCP security audit, tool-call firewall, output DLP, policy engine, and protocol integrity suite.
Tool Output Privacy Firewall
Redact secrets and PII and minimize MCP tool outputs before they reach an AI model.
Supabase Security Auditor
Find risky Supabase RLS policies, missing RLS protection, and dangerous PostgreSQL privileges — safely and read-only.
regex-safety-audit-mcp
Parses a regex into a real AST to catch catastrophic-backtracking (ReDoS) risk — nested unbounded quantifiers, ambiguous alternation inside a repeated group, and backreferences — without ever executing the pattern itself. Generates proof-of-concept attack strings and JS-safe rewrites (JS has no atomic groups or possessive quantifiers, so the usual PCRE/.NET fixes don't transfer).
GuardRail Security
Enterprise multi-language security MCP for AI coding agents. Features hybrid scanning (secrets + Python AST/taint + tree-sitter), repo/PR diff scanning, OSV CVEs, SARIF/SBOM, Docker/K8s checks, policy packs, RBAC, audit logs, and fix drafts.
vault-dna
by VibeDNA
Encrypted local credential vault for Claude. Every API key, token, seed phrase encrypted with Fernet + scrypt. Master password stored in your OS keyring. 16 tools: get, list, search, add, edit, delete, scan_for_leaks, backup, add_with_template (22 service templates), export_env, usage_log. Claude checks before asking for keys, scans codebases for leaks before deploy, auto-stores any new credential dropped in conversation. All local, all offline, free.
Featured Security MCP Servers
Enterprise-grade security integrations for AI workflows
HashiCorp Vault MCP
Securely access secrets, tokens, and credentials from HashiCorp Vault
1Password MCP Server
OAuth MCP Server
Handle OAuth 2.0 flows and token management for API authentication
AWS Secrets Manager MCP
Retrieve secrets from AWS Secrets Manager for secure credential access
Authentication & Identity
Handle OAuth flows, manage sessions, and integrate with identity providers
OAuth MCP Server
Auth0 MCP
Okta MCP Server
Clerk MCP
Firebase Auth MCP
Supabase Auth MCP
Secrets Management
Securely access API keys, credentials, and tokens from enterprise vaults
HashiCorp Vault MCP
1Password MCP
AWS Secrets Manager MCP
Google Secret Manager MCP
Azure Key Vault MCP
Doppler MCP Server
Security Scanning
Scan code, dependencies, and containers for vulnerabilities
Snyk MCP Server
SonarQube MCP
Semgrep MCP
Trivy MCP Server
What Can Security MCP Servers Do?
Retrieve Secrets
Access API keys, tokens, and credentials from secure vaults.
Handle OAuth
Manage OAuth flows, token exchange, and refresh cycles.
Scan Vulnerabilities
Detect security issues in code, dependencies, and containers.
Manage Identity
Integrate with Auth0, Okta, and other identity providers.
Security Best Practices
- • Least privilege: Grant only the permissions needed for the task
- • Short-lived tokens: Use tokens with expiration rather than long-lived credentials
- • Audit logging: Enable logging on both the MCP server and secrets manager
- • Separate environments: Use different credentials for dev, staging, and production
- • Rotate regularly: Set up automatic credential rotation where possible
- • Review access: Regularly audit which MCP servers have access to what secrets
Compare Secrets Managers
Choose the right secrets management solution for your workflow
| Feature | Vault | 1Password | AWS SM | Doppler |
|---|---|---|---|---|
| Dynamic Secrets | ✓ | — | ✓ | — |
| Auto Rotation | ✓ | — | ✓ | ✓ |
| Team Sharing | ✓ | ✓ | IAM | ✓ |
| Multi-Cloud | ✓ | ✓ | AWS | ✓ |
| CLI Tool | ✓ | ✓ | ✓ | ✓ |
| Official MCP | ✓ | ✓ | Community | Community |
Frequently Asked Questions
How do I securely manage API keys with MCP?
Use a security MCP server like 1Password MCP or Vault MCP to store and retrieve API keys. Never hardcode credentials. MCP servers can fetch secrets at runtime from secure stores, keeping your configuration files clean.
Can Claude access secrets from Vault?
Yes! Install the Vault MCP server, configure your Vault address and authentication method, and add it to Claude Desktop. Claude can then securely retrieve secrets using natural language requests.
What is the best MCP server for authentication?
For secrets management, 1Password MCP and Vault MCP are top choices. For OAuth flows, use the OAuth MCP server. For enterprise SSO, consider Auth0 MCP or Okta MCP servers.
How do I connect 1Password to Claude Desktop?
Install 1Password MCP server from the official 1Password developer portal. Configure your 1Password account credentials and add the server to your Claude Desktop MCP configuration. Restart Claude to activate.
Is it safe to use MCP servers with sensitive data?
Yes, when properly configured. Use read-only access, limit scope to specific secrets, enable audit logging, and prefer short-lived tokens. Security MCP servers like Vault and 1Password have enterprise-grade security built-in.
How do OAuth MCP servers work?
OAuth MCP servers handle the complete OAuth 2.0 flow — authorization, token exchange, and refresh. They support PKCE for security and can manage tokens for multiple providers, letting Claude authenticate to APIs on your behalf.
Build a Custom Security MCP Server
Create custom security integrations. Build an MCP server, publish to the marketplace, and earn 80% of every sale.