Zero-Exposure Environment Security, AES-256-GCM Secrets Vault, Multi-Format Transformer & AI Agent MCP Server
EnvGuard Secrets Vault is a next-generation secrets security platform and developer toolkit designed for modern cloud architectures, CI/CD pipelines, and autonomous AI coding agents.
It replaces fragile .env file handling with military-grade envelope encryption (AES-256-GCM + PBKDF2), scans 50+ provider token patterns, calculates Shannon entropy, identifies dangerous framework prefix leaks (e.g., Next.js NEXT_PUBLIC_), injects secrets into runtime processes with zero disk writes, and exposes a standardized Model Context Protocol (MCP) server for AI assistants (Claude Desktop, Cursor, Cline, Zed).
- 🛡️ Live Secret Auditor & Scanner: 50+ detection signatures (OpenAI, Anthropic, AWS, Stripe, GitHub, Slack, DB passwords, JWTs, Private Keys) + Shannon entropy scoring.
- 🔐 Zero-Exposure Encrypted Vault: Authenticated AES-256-GCM payload with PBKDF2-HMAC-SHA256 key derivation.
- ⚡ Zero-Disk Process Execution (
envguard vault run): Decrypts secrets directly into process RAM and child environment blocks. No plaintext touches disk. - 🤖 Native Model Context Protocol (MCP) Server: 11 standardized tools (
env_scan_secrets,env_mask_variables,env_generate_example,env_vault_encrypt,env_vault_decrypt,env_diff_environments,env_get_diagnostics,env_shamir_split,env_shamir_combine,env_audit_rotation,env_rotate_secrets) for AI coding agents. - 🔄 Secret Rotation & Ephemerality Sentinel: Enforce
# @expires,# @created, and# @rotation_dayspolicies with realistic ephemeral replacement tokens across 14+ providers and unified diff generation. - 🌐 EnvGuard Secrets Studio UI (
public/index.html): Offline-first web app (design influenced by Material 3) with Web Crypto API encryption, risk gauges, and preset inspection.
# Via pip
pip install envguard-secrets-vault
# Or using uv
uv pip install envguard-secrets-vault# Scan a specific environment file
envguard scan .env.production
# Deep recursive scan of workspace
envguard audit ./srcenvguard sanitize .env.production --output .env.exampleenvguard vault create .env.production --output secrets.vault# Run application with secrets injected directly into memory
envguard vault run --vault secrets.vault -- npm start
# Python Web Server
envguard vault run --vault secrets.vault -- uvicorn app.main:app --port 8080# Convert .env to JSON
envguard convert .env.production --format json
# Convert .env to Docker Compose format
envguard convert .env.production --format docker# Audit secret ages, TTLs, and rotation policy compliance
envguard rotate .env.production --audit-only
# Rotate expired/overdue credentials with ephemeral mock tokens and view unified diff
envguard rotate .env.production --diff
# Rotate specific secrets and write directly to destination
envguard rotate .env.production --keys STRIPE_SECRET_KEY DATABASE_URL --output .env.rotatedfrom envguard_secrets_vault import Vault, SecretAuditor, Sanitizer
# 1. Audit an environment file
auditor = SecretAuditor()
report = auditor.scan_file(".env.production")
print(f"Security Grade: {report.grade} ({report.score}/100)")
for finding in report.findings:
print(f"[{finding.severity}] {finding.key}: {finding.recommendation}")
# 2. Encrypt to Vault
vault = Vault.encrypt_file(
source_path=".env.production",
password="your-master-password"
)
vault.save("secrets.vault")
# 3. Decrypt in memory (Zero Disk Leak)
env_vars = Vault.load("secrets.vault").decrypt("your-master-password")
print(f"Loaded {len(env_vars)} variables into RAM.")EnvGuard includes a standard Model Context Protocol (MCP) server that empowers AI coding agents to manage and use secrets securely:
{
"mcpServers": {
"envguard": {
"command": "python3",
"args": ["-m", "envguard.mcp"],
"env": {
"ENVGUARD_VAULT_PASSWORD": "${ENVGUARD_VAULT_PASSWORD}"
}
}
}
}See the MCP Client Integration Guide for Claude Desktop, Cursor, Cline, and Zed configurations.
Open public/index.html in your browser or run:
python3 -m http.server 8080 --directory publicNavigate to http://localhost:8080 for:
- 🛡️ Interactive Secret Auditor with 0-100 Grade Gauge.
- 🔄 Format Transformer (Dotenv, JSON, YAML, Docker Compose, Kubernetes Secret).
- 🔐 In-Browser Web Crypto AES-256-GCM Encrypted Vault.
- 🤖 AI Agent MCP Config Generator.
- Threat Model & Security Assumptions (Skeleton in Dark Armor, Inverted Pentagram & Tower of False Security)
- EnvGuard Enterprise Lifetime Vault ($19 Offline Airgap Offer)
- Secret Patterns & Detector Catalog
- Model Context Protocol (MCP) Guide
- Zero-Exposure Vault Specification
- Next.js Production Audit Example
- Encrypted Vault Workflow Example
Apache License 2.0. Copyright (c) 2026 EnvGuard Contributors.