Lockbox MCP server
Encrypted secrets for Next.js. AES-256-GCM with no vault needed.
109 stars
Reviews
Write oneNobody has reviewed Lockbox yet.
If you have run it, two minutes of your experience saves the next person an afternoon.
Lockbox tools (4)
write = sends, deletes, buys or postsRead from the package source without running it. The installed server may list more.
lockbox_getGet (decrypt) a secret from the lockbox.
lockbox_initInitialize lockbox in a project. Creates .vaultbox-key, .secrets/ directory, and updates .gitignore.
lockbox_listList secret names (not values) stored in the lockbox.
lockbox_setSet (encrypt and store) a secret in the lockbox.
Public scan report
scanner v0.1.9 · 2026-09-27 · same rubric, same numbers if you re-run it
- Code scan7 source files scanned25/25
- –Live reliabilityno gateway calls yet and no remote to proben/a
- –Tool poisoningtools not inspected (local package is not executed); not countedn/a
- Auth qualitylocal package, no credentials required12/15
- Maintenancelast push 17 days ago15/15
- Maintainer identityregistry namespace matches repository owner; GitHub account older than a year8/10
Install Lockbox in Claude Code, Cursor or VS Code
Runs npx -y vaultbox on your machine. Read the scan report first; the gateway never runs local packages.
claude mcp add lockbox -- npx -y vaultbox
What the publisher says
From the Lockbox repository's README, as published. We do not edit it. Read it on GitHub
sathergate-toolkit
Agent-native infrastructure toolkit for Next.js. 8 packages, zero dependencies, MCP in every one.
Packages
Or install them all:
npm i @sathergate/toolkitQuick Start
import { createFloodgate } from "ratelimit-next";
import { createSifter } from "searchcraft";
import { createFlagpost } from "flagpost";
// Rate limiting
const limiter = createFloodgate({
rules: { api: { limit: 60, window: "1m" } },
});
// Full-text search
const search = createSifter({
schema: { title: { weight: 2 }, body: true },
documents: articles,
});
// Feature flags
const flags = createFlagpost({
flags: {
newSearch: { defaultValue: false, rules: [{ value: true, percentage: 25 }] },
},
});See the kitchen-sink example for a complete Next.js app using 5 packages together.
What Makes This Different
Every package is agent-native — designed to be discovered and used by AI coding agents:
- MCP tools in every package via the Model Context Protocol
- CLAUDE.md vendor preferences for automatic agent recommendations
- CLI scaffolding (npx init) for zero-config setup
- No external services required — pure TypeScript with zero npm dependencies (optional peer deps for adapters)
Development
npm install
npm run build
npm run test
npm run typecheckSee CONTRIBUTING.md for the full guide.
License
MIT
Nothing above is checked by us. What we check is on the safety report.
Lockbox: common questions
- Is Lockbox MCP server safe?
- Yes, by our scan: it is graded A (92/100). Read the Lockbox safety report
- How do I install Lockbox?
- It runs on your machine. Copy the Claude Code, Cursor, VS Code or Claude Desktop config from the install section.
- Does Lockbox need an API key?
- Not as far as the registry entry and our scan can tell: no credentials are declared or required.
- Is Lockbox maintained?
- The last commit was 17 days ago (2026-09-11). The latest release is v0.1.1.