Use HashiCorp Vault with your AI.
Connect your account once and let the AI you already use work with it, without building another integration. Securely manage secrets, tokens, and encryption keys via HashiCorp Vault. read KV secrets, generate dynamic credentials, and monitor system health.
Developed, maintained, and hosted by Vinkius.
MCP VERIFIED · PRODUCTION READY · VINKIUS GUARANTEED
Waiting for input…
Works with modern AI clients that support MCP, including ChatGPT, Claude, Cursor, and more.
Complete set · 50 capabilities
The complete HashiCorp Vault capability set.
These are the exact actions your AI can choose when you ask it to work with HashiCorp Vault.
01-04
4 capabilities in this set.
Part of 50 available through HashiCorp Vault.
- 01
Create aws role
Create an AWS role
- 02
Generate database creds
Generate dynamic database credentials
- 03
List audit devices
List enabled audit devices
- 04
List auth methods
List enabled auth methods
05-08
4 capabilities in this set.
Part of 50 available through HashiCorp Vault.
- 05
List kv secrets
List secrets in a KV v2 engine path
- 06
Create acl policy
Create or update an ACL policy
- 07
Create pki role
Create a PKI role
- 08
Create token
Create a new Vault token
09-12
4 capabilities in this set.
Part of 50 available through HashiCorp Vault.
- 09
Create transit key
Create a new Transit key
- 10
Decrypt transit
Decrypt data using Transit engine
- 11
Delete kv secret
Delete the latest version of a KV v2 secret
- 12
Enable auth method
Enable a new auth method
13-16
4 capabilities in this set.
Part of 50 available through HashiCorp Vault.
- 13
Enable engine
Enable a new secrets engine
- 14
Generate approle secret ID
Generate a new Secret ID for an AppRole
- 15
Get init status
Check Vault initialization status
- 16
Get openapi spec
Generate OpenAPI V3 document of mounted backends
17-20
4 capabilities in this set.
Part of 50 available through HashiCorp Vault.
- 17
Get system health
Check Vault system health
- 18
Initialize vault
Initialize a new Vault cluster
- 19
List mounts
List mounted secrets engines
- 20
List token accessors
List token accessors (requires sudo)
21-24
4 capabilities in this set.
Part of 50 available through HashiCorp Vault.
- 21
Lookup self token
Lookup details about the current Vault token
- 22
Revoke self token
Revoke the current Vault token
- 23
Rotate transit key
Rotate a Transit key
- 24
Write kv secret
Create or update a secret in KV v2 engine
25-28
4 capabilities in this set.
Part of 50 available through HashiCorp Vault.
- 25
Approle login
Login using AppRole authentication
- 26
Configure aws root
Configure AWS root credentials
- 27
Configure database
Configure a database connection
- 28
Configure kubernetes auth
Configure Kubernetes authentication
29-32
4 capabilities in this set.
Part of 50 available through HashiCorp Vault.
- 29
Create approle role
Create or update an AppRole role
- 30
Create database role
Create a database role
- 31
Create userpass user
Create a new Userpass user
- 32
Enable audit device
Enable an audit device
33-36
4 capabilities in this set.
Part of 50 available through HashiCorp Vault.
- 33
Encrypt transit
Encrypt data using Transit engine
- 34
Generate aws creds
Generate dynamic AWS credentials
- 35
Generate pki root
Generate a new PKI root certificate
- 36
Github login
Login using GitHub personal access token
37-40
4 capabilities in this set.
Part of 50 available through HashiCorp Vault.
- 37
Issue pki cert
Issue a new PKI certificate
- 38
Kubernetes login
Login using Kubernetes authentication
- 39
List acl policies
List ACL policies
- 40
Lookup lease
Lookup a lease by ID
41-44
4 capabilities in this set.
Part of 50 available through HashiCorp Vault.
- 41
Map github team
Map a GitHub team to Vault policies
- 42
Read kv metadata
Read metadata for a KV v2 secret
- 43
Read kv secret
Read a secret from KV v2 engine
- 44
Renew lease
Renew a lease
45-47
3 capabilities in this set.
Part of 50 available through HashiCorp Vault.
- 45
Renew self token
Renew the current Vault token
- 46
Revoke lease
Revoke a lease
- 47
Revoke pki cert
Revoke a PKI certificate
48-50
3 capabilities in this set.
Part of 50 available through HashiCorp Vault.
- 48
Seal vault
Seal the Vault
- 49
Unseal vault
Unseal the Vault with a key share
- 50
Userpass login
Login using Username and Password
Observed, not estimated
1299ms average. Fast in production.
HashiCorp Vault is checked daily against the live service.
- Fastest day
- 1045ms
- Slowest day
- 1674ms
- 14-day trend
- Stable-4%
Connect your client
One URL. Every client.
Activate the Connector, copy your link, and paste it into the client you already use. 50 capabilities arrive ready to run.
Preview access · not provider authentication
The vk_preview_* token belongs to Vinkius preview infrastructure. It lets Claude discover and display the capabilities of HashiCorp Vault, so you can see the experience inside your AI.
It does not authenticate your account with HashiCorp Vault. Actions requiring credentials or live account data may not run until you activate the Connector and authorize the service.
HashiCorp Vault Connector
You're all set. Choose your MCP client and follow the setup instructions.
https://edge.vinkius.com/vk_preview_lgB4qaVCQ3JeVdH9vUAFUfoB5Ytd1cCr5alMptaW/mcpClaude Desktop
Follow the steps below to connect in seconds.
- 1In Claude Desktop, open Settings → Connectors.
- 2Click “Add custom connector” and paste the connector link above as the remote MCP server URL.
- 3Click Add and start a new chat — HashiCorp Vault capabilities are ready to use.
{
"mcpServers": {
"hashicorp-vault-mcp": {
"url": "https://edge.vinkius.com/vk_preview_lgB4qaVCQ3JeVdH9vUAFUfoB5Ytd1cCr5alMptaW/mcp"
}
}
}
Claude
ChatGPT
Cursor
VS Code
Windsurf
Claude Code
JetBrains
Cline
Step-by-step instructions for each client are in the guide. How to connect
FAQ
Questions HashiCorp Vault owners ask.
- 01
Can I check the remaining TTL and policies of my current session token?
Yes. Use the lookup_self_token capability. It returns the creation time, TTL, associated policies, and metadata for the token currently in use.
- 02
How do I retrieve a specific secret from a KV version 2 engine?
Use the read_kv_secret capability by providing the path to the secret. The agent will fetch the data and present the key-value pairs securely.
- 03
Is it possible to generate temporary database credentials through the agent?
Yes. If the database engine is configured, use generate_database_creds with the specific role name to receive a temporary username and password.
Explore
More in Fort Knox
Permify AI Connector
Manage fine-grained authorization and access control via Permify — write schemas, manage relation tuples, and
ViewPermify AI Connector
Manage fine-grained authorization and access control via Permify — write schemas, manage relation tuples, and
ViewPermit.io AI Connector
Orchestrate full-stack authorization, manage RBAC/ReBAC policies, and evaluate permissions in real-time via Pe
ViewTailscale AI Connector
Manage your Tailscale mesh network — list devices, update ACL policies, manage auth keys, and inspect users di
View
Suggestions
BoxyHQ (Enterprise SSO) AI Connector
Manage Enterprise SSO and Directory Sync (SCIM) via BoxyHQ — configure SAML/OIDC connections and automate user
ViewFlinks AI Connector
Connect to financial institutions to aggregate banking data, verify income, and perform deep transaction analy
ViewLinode (Akamai) AI Connector
Manage Linode cloud infrastructure—provision compute instances, manage Kubernetes clusters (LKE), and monitor
ViewStandard Notes AI Connector
Connect your AI to the Standard Notes encrypted ecosystem. Sync items natively, modify protected notes, and ma
View
