Skip to main content

MCP server for Ethereum keystore encryption, decryption, and management

Project description

Keystore MCP Server

PyPI MCP Registry

A Model Context Protocol (MCP) server for Ethereum keystore encryption, decryption, and management following the Web3 Secret Storage Definition Version 3 standard.

Features

Tools (9)

  • encrypt_keystore - Encrypt private key to Web3 Secret Storage V3 format
  • decrypt_keystore - Decrypt keystore to recover private key
  • save_keystore_file - Save keystore with standard Ethereum naming
  • load_keystore_file - Load and validate keystore files
  • get_keystore_info - Extract metadata without decryption
  • validate_keystore - Validate keystore structure
  • change_keystore_password - Change password and optionally upgrade KDF
  • batch_encrypt_keystores - Encrypt multiple wallets
  • keystore_to_private_key_file - Export decrypted private key (dangerous)

Resources (4)

  • keystore://specification - Web3 Secret Storage V3 specification
  • keystore://security-guide - Security best practices
  • keystore://kdf-comparison - Scrypt vs PBKDF2 comparison
  • keystore://examples/{type} - Example keystores

Prompts (4)

  • secure_wallet_backup - Guided backup creation
  • keystore_migration - Migration from legacy formats
  • keystore_recovery - Recovery assistance
  • keystore_security_audit - Security audit workflow

Installation

pip install -e .

# Or with dev dependencies
pip install -e ".[dev]"

Usage

Running the Server

keystore-mcp-server

Claude Desktop Configuration

{
  "mcpServers": {
    "keystore": {
      "command": "keystore-mcp-server"
    }
  }
}

Cryptographic Standards

Web3 Secret Storage V3

  • KDF: scrypt (recommended) or pbkdf2
  • Cipher: AES-128-CTR
  • MAC: Keccak-256
  • UUID: Version 4

Default Scrypt Parameters

Parameter Value Description
N 262144 (2^18) CPU/memory cost
r 8 Block size
p 1 Parallelization
dklen 32 Derived key length

Default PBKDF2 Parameters

Parameter Value Description
c 262144 Iterations
prf hmac-sha256 PRF
dklen 32 Derived key length

Security

⚠️ Important Security Notes:

  1. Never share keystore passwords - Treat like private keys
  2. Use strong passwords - Minimum 12 characters, mixed case, numbers, symbols
  3. Secure file storage - Files created with 0600 permissions
  4. Air-gapped operations - Use offline for high-value wallets
  5. Backup keystores - Store encrypted backups in multiple locations

Examples

Encrypt a Private Key

result = await encrypt_keystore(
    private_key="0x...",
    password="strong-password-123",
    kdf="scrypt"
)

Decrypt a Keystore

result = await decrypt_keystore(
    keystore=keystore_json,
    password="strong-password-123"
)

Save Keystore File

result = await save_keystore_file(
    keystore=keystore_json,
    directory="./keystores"
)
# Creates: UTC--2024-01-15T10-30-00.000Z--address.json

Testing

pytest tests/ -v

License

MIT License

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

keystore_mcp_server-1.0.0.tar.gz (41.6 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

keystore_mcp_server-1.0.0-py3-none-any.whl (46.6 kB view details)

Uploaded Python 3

File details

Details for the file keystore_mcp_server-1.0.0.tar.gz.

File metadata

  • Download URL: keystore_mcp_server-1.0.0.tar.gz
  • Upload date:
  • Size: 41.6 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.12.1

File hashes

Hashes for keystore_mcp_server-1.0.0.tar.gz
Algorithm Hash digest
SHA256 5560c9faa33e0e815a242165e95456bfa853d5cfdf3929de329cf005725a099a
MD5 1675a1bfef0f1d953a471c33bfb2720e
BLAKE2b-256 52d59f3e836998a628ad81a2b273e72d5090bed51303497814ab5f70fa67127d

See more details on using hashes here.

File details

Details for the file keystore_mcp_server-1.0.0-py3-none-any.whl.

File metadata

File hashes

Hashes for keystore_mcp_server-1.0.0-py3-none-any.whl
Algorithm Hash digest
SHA256 46e72acc1e11df78f0e32fbb5ec82efdbe5845dd284bd2168bb398a0480fbb3b
MD5 bb1a5ead3f74fd94a273c5c8d0fee867
BLAKE2b-256 c61596df52730aa709ae8105a973d99823444b45f73f61820a936a72ab0a0d1d

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page