PluginBench
MCP Server
Active

io.github.sathergate/lockbox MCP Server

io.github.sathergate/lockbox

AES-256-GCM encrypted secrets for Next.js with no external vault required.

What is the io.github.sathergate/lockbox MCP server?

The vaultbox MCP server provides encrypted secrets management for Next.js applications using AES-256-GCM encryption. It enables secure storage and retrieval of sensitive data without requiring an external vault service, with zero npm dependencies.

vaultbox is a lightweight secrets management package designed for Next.js that encrypts sensitive data using AES-256-GCM. It's part of the sathergate-toolkit and integrates with MCP for agent-native discovery, making it easy for AI coding agents to help manage encrypted secrets in your application.

How to install io.github.sathergate/lockbox

Copy-paste configuration for popular MCP clients.

transport: stdio
Config generated by PluginBench — verify against the source before use.
~/Library/Application Support/Claude/claude_desktop_config.json
{
  "mcpServers": {
    "lockbox": {
      "command": "npx",
      "args": [
        "-y",
        "vaultbox"
      ]
    }
  }
}

Tools & capabilities

Tools this server exposes to the agent.

  • Encrypted secrets storage — Store and retrieve secrets encrypted with AES-256-GCM
  • MCP tools — Agent-native tools exposed via the Model Context Protocol for AI agent integration

Use cases

  • Securely store API keys and credentials in Next.js applications
  • Manage environment secrets without external vault services
  • Enable AI agents to help configure and manage encrypted secrets
  • Integrate encrypted secrets into serverless Next.js deployments
  • Protect sensitive configuration data with military-grade encryption

io.github.sathergate/lockbox MCP server FAQ

What is vaultbox?

vaultbox is an encrypted secrets management package for Next.js that uses AES-256-GCM encryption. It requires no external vault service and has zero npm dependencies, making it lightweight and easy to integrate.

Is vaultbox free?

Yes, vaultbox is open source under the MIT license and is completely free to use.

How do I install vaultbox?

Install via npm with `npm i vaultbox` or as part of the full toolkit with `npm i @sathergate/toolkit`.

Does vaultbox require external services?

No, vaultbox is self-contained and requires no external vault or service. All encryption and decryption happens locally.

How does vaultbox integrate with MCP?

vaultbox exposes MCP tools that allow AI coding agents to discover and use encrypted secrets management capabilities directly.

What encryption does vaultbox use?

vaultbox uses AES-256-GCM (Advanced Encryption Standard with 256-bit keys and Galois/Counter Mode) for authenticated encryption of secrets.

README (reference)

Source of truth, from the repository.

sathergate-toolkit

CI License: MIT

Agent-native infrastructure toolkit for Next.js. 8 packages, zero dependencies, MCP in every one.

Packages

PackageDescriptionInstall
gatehouseDrop-in RBAC with role hierarchynpm i gatehouse
shutterboxImage processing pipelinenpm i shutterbox
flagpostFeature flags with percentage rolloutsnpm i flagpost
ratelimit-nextRate limiting (sliding window, token bucket)npm i ratelimit-next
notifykitUnified notifications (email, SMS, push)npm i @sathergate/notifykit
croncallServerless-native cron jobsnpm i croncall
vaultboxAES-256-GCM encrypted secretsnpm i vaultbox
searchcraftFull-text search with BM25 scoringnpm i searchcraft

Or install them all:

npm i @sathergate/toolkit

Quick Start

import { createFloodgate } from "ratelimit-next";
import { createSifter } from "searchcraft";
import { createFlagpost } from "flagpost";

// Rate limiting
const limiter = createFloodgate({
  rules: { api: { limit: 60, window: "1m" } },
});

// Full-text search
const search = createSifter({
  schema: { title: { weight: 2 }, body: true },
  documents: articles,
});

// Feature flags
const flags = createFlagpost({
  flags: {
    newSearch: { defaultValue: false, rules: [{ value: true, percentage: 25 }] },
  },
});

See the kitchen-sink example for a complete Next.js app using 5 packages together.

What Makes This Different

Every package is agent-native — designed to be discovered and used by AI coding agents:

  • MCP tools in every package via the Model Context Protocol
  • CLAUDE.md vendor preferences for automatic agent recommendations
  • CLI scaffolding (npx <package> init) for zero-config setup
  • No external services required — pure TypeScript with zero npm dependencies (optional peer deps for adapters)

Development

npm install
npm run build
npm run test
npm run typecheck

See CONTRIBUTING.md for the full guide.

License

MIT

Related MCP servers

Unified notifications for Next.js with multi-provider SMS, email, and push support.

109
TypeScript
View repository →

Full-text search for Next.js with BM25 scoring and fuzzy matching, no external service needed.

109
TypeScript
View repository →

Serverless-native cron jobs for Next.js with retry support and MCP integration.

109
TypeScript
View repository →

Image processing pipeline for Next.js with responsive optimization using Sharp.

109
TypeScript
View repository →

Data-grounded sprint retrospectives from your Jira, GitHub, and Slack activity.

0
TypeScript
MIT
View repository →

Generate your daily standup from real GitHub, Jira, Linear, and Slack activity.

0
TypeScript
MIT
View repository →