What is AgentSecrets?
The Zero-Knowledge Difference
How AgentSecrets Works
Installation
Quick Start
Migrating from .env Files
Migrating from Vault / AWS
Migrating from dotenv-vault
Production Checklist
Credential Exposure
What Zero-Knowledge Means
The Proxy Model
The Three-Layer Model
Environments
Agent Identity
Storage Modes
The No get() Principle
Secret-Level Policies
Cloud Overview & Architecture
The Dual-Engine Model
Cloud Resolver Data Plane
Workload & Agent Tokens
Egress Allowlists & Audit Streams
Cloud REST API Reference
Account (init / login)
Server & Self-Hosting (server)
Docs
Shell Autocompletion
Keychain Auth
Secrets
Environments
Credential Proxy
env Injection
Workspaces & Teams
Projects
Agent Identity
Audit & Governance
Integrations Overview
Claude Desktop
Cursor
OpenClaw
HTTP Proxy (Any)
LangChain (Soon)
CrewAI (Soon)
CI/CD Pipeline
SDK Overview
Python SDK
Python API Reference
Python SDK Manual Testing
JavaScript SDK (Soon)
Ecosystem Overview
Zero-Knowledge MCP Server
Server Overview
5-Layer Architecture
Self-Hosting Guide
Authentication & Keys
Workspaces & Teams
Projects & Scope
Environments
Secrets & Sync Protocol
Agent Identity Resolution
Telemetry & Metrics Engine
Audit Log Sync
API Endpoint Reference
Security Overview
Anti-Impersonation & Process Verification
Encryption Model
Zero-Knowledge Sync
Proxy Security Layers
Threat Model
OWASP Top 10 Mitigation
Security FAQ
Third-Party Audit
Reporting Vulnerabilities
Guides Overview
Building on the SDK
Stripe Integration
OpenAI Integration
Multi-Agent Setup
Onboarding Team
CI/CD Pipeline
Publishing ZK MCP
Rotating Credentials
Auditing Team Activity
Dev to Production
Kubernetes Deployment
Monorepo Setup
Production Proxy Hardening
vs .env Files
vs HashiCorp Vault
vs AWS Secrets Manager
vs dotenv-vault
vs Infisical
When Not to Use
Proxy Not Starting
Proxy Not Resolving
Domain Blocked
Sync Conflicts
MCP Not Connecting
Session Token Errors
Proxy Session Authorization
Keychain Storage & Backends
SSRF & Destination Rules
Installation Issues
Error Codes Reference
Frequently Asked Questions
v3.1.x
v3.0.0
v2.1.0
v2.0.0
v1.4.0
v1.3.x
v1.2.0
v1.1.x
v1.0.x
TroubleshootingMCP Not Connecting

Troubleshooting MCP Integration

AgentSecrets provides a native Model Context Protocol (MCP) server, enabling AI assistants like Claude Desktop and Cursor to make authenticated API calls securely without accessing raw credentials.

MCP Server Not Installing

When running agentsecrets mcp install, the CLI modifies your local MCP configuration file (e.g., claude_desktop_config.json). If this fails:

  1. Unsupported AI Assistant: Ensure you are using a supported AI assistant that reads standard MCP config paths.
  2. File Permissions: Check if the CLI has write access to your AI assistant's configuration directory.
  3. Manual Installation: You can manually add the AgentSecrets MCP server to your config file:
    "mcpServers": { "agentsecrets": { "command": "agentsecrets", "args": ["mcp", "serve"] } }

Agent Can't See the Tools

Once installed, the AgentSecrets MCP server exposes a rich suite of tools to the AI, including:

  • list_keys: Allows the agent to see which keys are available (names only, no values).
  • api_call: Routes requests through the zero-knowledge proxy engine.
  • get_status: Inspects session, workspace, project, and proxy status.

If the agent claims it doesn't have these tools:

  1. Completely restart your AI assistant (e.g., quit and reopen Claude Desktop).
  2. Ensure the agentsecrets binary is in your system's $PATH so the AI assistant can execute the "command": "agentsecrets" instruction.

"api_call" Tool Failing

If the agent uses api_call but receives an error:

  • Domain Blocked: The agent attempted to contact a domain not in your workspace allowlist. You must add it: agentsecrets workspace allowlist add <domain>.
  • Invalid Secret Name: The agent tried to inject a secret that doesn't exist. Tell the agent to use the list_keys tool to verify available key names first.

Every MCP call uses the exact same internal proxy engine as the HTTP proxy. You can debug MCP requests by viewing the proxy audit logs:

agentsecrets proxy logs --last 5

Look for entries where "agent_id": "mcp".

Redacted Responses

If an external API echoes back the injected credential in its response body, the AgentSecrets MCP server automatically replaces the value with [REDACTED_BY_AGENTSECRETS] before the response reaches the agent. This is a deliberate security feature to prevent secret leakage via adversarial API responses.

Was this helpful?
Thanks for your feedback!
Your feedback helps us improve the platform.