A local MCP server that manages secrets and injects them into commands, HTTP requests, and OAuth flows with user approval and audit logging
nokey provides 8 well-named tools with strong descriptions and mostly complete schemas. Tool naming follows verb_noun convention (list_secrets, exec, mint_token, revoke_token, start_proxy, stop_proxy) with clear action semantics. Descriptions are detailed and explain WHAT each tool does, WHEN to use it, and consequences (e.g., exec output redaction, token approval workflows). However, schema completeness varies: some parameters lack explicit type definitions in visible code, and output schemas are not documented in the source provided. Error handling is minimal, no recovery guidance or categorization. Security is a strength: the server enforces secret redaction, supports token-based approval workflows, and uses environment variable injection. The tool set is cohesive (secret management + command execution + proxy) with good composition and idempotent operations. Cancellation is supported. Tool annotations (readOnlyHint, destructiveHint) are present. No prompts, resources, sampling, roots, or logging observed, correct omission for current spec. STDIO transport caps protocol readiness at 50 maximum.
Execute a command with secrets injected as environment variables. Output is automatically redacted — secret values are replaced with [REDACTED:KEY_NAME].
Execute a command with secret values resolved from placeholders. Use ${{NOKEY:SECRET_NAME}} in args to reference secrets by name. Only referenced secrets are fetched. Secrets are never placed in environment variables. Output is automatically redacted.
List all stored secret key names (not values)
List all active access lease tokens.
Mint a short-lived access lease token for one or more secrets. The token can be passed to exec or exec_with_secrets to skip per-call approval. Always requires user approval at mint time. Max TTL: 3600 seconds.
Revoke an access lease token by ID.
Output schemas not documented. Tools return structured data but schemas are not visible in source code. LLMs cannot know what fields to expect (list_secrets returns what structure? exec returns what format?). Required by pattern:tool and pattern:response-shaper.
Incomplete parameter type information visible in source. Parameters like 'args' (exec) and 'for' (mint_token) have descriptions but explicit JSON Schema type/items properties may not be fully visible or specified. Schema completeness cannot be fully verified.
Error handling lacks recovery guidance. Tools return errors but do not indicate whether errors are retryable, user-fixable, or fatal. No actionable error messages (e.g., 'Token invalid. Use mint_token() to create a new one.'). Required by pattern:recovery-guide and pattern:error-classification.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-23 | C | 68 | 2026-07-28+ | v2 |
Start a local HTTP/HTTPS proxy that injects secrets into request headers based on proxy rules in policies.yaml. Returns the proxy address. Set http_proxy and https_proxy to route requests through it.
Stop the running local HTTP/HTTPS proxy.
No pagination for list_secrets and list_tokens. If stored secrets/tokens grow large, unbounded results could exhaust context. Should accept limit/offset and return total_count. Required by pattern:paginated-result.
start_proxy parameter 'addr' allows non-loopback rejection but description is sparse on valid format. Does it accept IPv6? Port ranges? Required format not clearly specified in description.