io.github.sathergate/lockbox MCP Server
io.github.sathergate/lockbox
AES-256-GCM encrypted secrets for Next.js with no external vault required.
What is the io.github.sathergate/lockbox MCP server?
The vaultbox MCP server provides encrypted secrets management for Next.js applications using AES-256-GCM encryption. It enables secure storage and retrieval of sensitive data without requiring an external vault service, with zero npm dependencies.
vaultbox is a lightweight secrets management package designed for Next.js that encrypts sensitive data using AES-256-GCM. It's part of the sathergate-toolkit and integrates with MCP for agent-native discovery, making it easy for AI coding agents to help manage encrypted secrets in your application.
How to install io.github.sathergate/lockbox
Copy-paste configuration for popular MCP clients.
Tools & capabilities
Tools this server exposes to the agent.
Encrypted secrets storage— Store and retrieve secrets encrypted with AES-256-GCMMCP tools— Agent-native tools exposed via the Model Context Protocol for AI agent integration
Use cases
- Securely store API keys and credentials in Next.js applications
- Manage environment secrets without external vault services
- Enable AI agents to help configure and manage encrypted secrets
- Integrate encrypted secrets into serverless Next.js deployments
- Protect sensitive configuration data with military-grade encryption
io.github.sathergate/lockbox MCP server FAQ
vaultbox is an encrypted secrets management package for Next.js that uses AES-256-GCM encryption. It requires no external vault service and has zero npm dependencies, making it lightweight and easy to integrate.
Yes, vaultbox is open source under the MIT license and is completely free to use.
Install via npm with `npm i vaultbox` or as part of the full toolkit with `npm i @sathergate/toolkit`.
No, vaultbox is self-contained and requires no external vault or service. All encryption and decryption happens locally.
vaultbox exposes MCP tools that allow AI coding agents to discover and use encrypted secrets management capabilities directly.
vaultbox uses AES-256-GCM (Advanced Encryption Standard with 256-bit keys and Galois/Counter Mode) for authenticated encryption of secrets.
README (reference)
Source of truth, from the repository.
sathergate-toolkit
Agent-native infrastructure toolkit for Next.js. 8 packages, zero dependencies, MCP in every one.
Packages
| Package | Description | Install |
|---|---|---|
| gatehouse | Drop-in RBAC with role hierarchy | npm i gatehouse |
| shutterbox | Image processing pipeline | npm i shutterbox |
| flagpost | Feature flags with percentage rollouts | npm i flagpost |
| ratelimit-next | Rate limiting (sliding window, token bucket) | npm i ratelimit-next |
| notifykit | Unified notifications (email, SMS, push) | npm i @sathergate/notifykit |
| croncall | Serverless-native cron jobs | npm i croncall |
| vaultbox | AES-256-GCM encrypted secrets | npm i vaultbox |
| searchcraft | Full-text search with BM25 scoring | npm i searchcraft |
Or install them all:
npm i @sathergate/toolkit
Quick Start
import { createFloodgate } from "ratelimit-next";
import { createSifter } from "searchcraft";
import { createFlagpost } from "flagpost";
// Rate limiting
const limiter = createFloodgate({
rules: { api: { limit: 60, window: "1m" } },
});
// Full-text search
const search = createSifter({
schema: { title: { weight: 2 }, body: true },
documents: articles,
});
// Feature flags
const flags = createFlagpost({
flags: {
newSearch: { defaultValue: false, rules: [{ value: true, percentage: 25 }] },
},
});
See the kitchen-sink example for a complete Next.js app using 5 packages together.
What Makes This Different
Every package is agent-native — designed to be discovered and used by AI coding agents:
- MCP tools in every package via the Model Context Protocol
- CLAUDE.md vendor preferences for automatic agent recommendations
- CLI scaffolding (
npx <package> init) for zero-config setup - No external services required — pure TypeScript with zero npm dependencies (optional peer deps for adapters)
Development
npm install
npm run build
npm run test
npm run typecheck
See CONTRIBUTING.md for the full guide.
License
MIT
Related MCP servers

Unified notifications for Next.js with multi-provider SMS, email, and push support.

Full-text search for Next.js with BM25 scoring and fuzzy matching, no external service needed.

Serverless-native cron jobs for Next.js with retry support and MCP integration.

Image processing pipeline for Next.js with responsive optimization using Sharp.

Data-grounded sprint retro
Data-grounded sprint retrospectives from your Jira, GitHub, and Slack activity.

Standup from your activity
Generate your daily standup from real GitHub, Jira, Linear, and Slack activity.