Skip to main content

OpenBao Secrets Engine MCP Server for Agentic AI!

Project description

Openbao MCP

Status Version License

OpenBao Secrets and Encryption Key Vault orchestrator. Built with the highest architectural standards, incorporating dynamic facades, custom API routing, and FastMCP tool decoration.

Documentation — Installation, deployment, usage across the API, CLI, and MCP interfaces, and guidance for provisioning the OpenBao backend are maintained in the official documentation.

Table of Contents


Overview

Openbao MCP provides a high-performance, model-optimized interface to Openbao capabilities. It isolates the model from underlying API transport complexity, ensuring safe, idempotent, and highly traceable system interactions.


Features

  • Dynamic Facade Orchestration: Integrates multi-inheritance clients cleanly under a single facade.
  • Battle-Tested Resilience: Out-of-the-box credential authentication, connection polling, and request retry strategies.
  • FastMCP Declarative Tools: Fast, native schema registration with full inline validation.
  • Complete Test Intent Diversity: Deep, automated unit, integration, and mock tests ensuring high code coverage.

⚙️ Dynamic Tool Selection & Visibility

This MCP server supports dynamic toolset selection and visibility filtering at runtime. This allows you to restrict the set of exposed tools in order to prevent blowing up the LLM's context window.

You can configure tool filtering via multiple input channels:

  • CLI Arguments: Pass --tools or --toolsets (or their disabled counterparts --disabled-tools and --disabled-toolsets) during startup.
  • Environment Variables: Define standard environment variables:
    • MCP_ENABLED_TOOLS / MCP_DISABLED_TOOLS
    • MCP_ENABLED_TAGS / MCP_DISABLED_TAGS
  • HTTP SSE Request Headers: Pass custom headers during transport initialization:
    • x-mcp-enabled-tools / x-mcp-disabled-tools
    • x-mcp-enabled-tags / x-mcp-disabled-tags
  • HTTP SSE Request Query Parameters: Append query parameters directly to your transport connection URL:
    • ?tools=tool1,tool2
    • ?tags=tag1

When query strings or parameters are supplied, an LLM-free Knowledge Graph resolution layer (using DynamicToolOrchestrator) matches query intents against known tool tags, names, or descriptions, with safe fallback and automated 24-hour background cache refreshing.


Installation

Install in editable mode directly inside your active workspace:

pip install -e .[all]

Or via the uv tool:

uv pip install -e .

Usage

You can launch the FastMCP server in stdio mode via Python module execution:

import asyncio
from openbao_mcp.mcp_server import get_mcp_instance

async def main():
    mcp = get_mcp_instance()
    # Execute stdio loop or launch server
    print("MCP Server ready.")

if __name__ == "__main__":
    asyncio.run(main())

For direct shell launch, execute:

python -m openbao_mcp.mcp_server

Configuration

The package is fully configurable via the environment variables listed below:

Variable Description Default Required
OPENBAO_URL The primary URL of the OpenBao server. http://127.0.0.1:8200 Yes
OPENBAO_TOKEN Root or service account access token. bao_root_token Yes
BAO_ADDR Alias/fallback for the OpenBao server address. None No
VAULT_ADDR Alias/fallback for the OpenBao/Vault server address. None No
OPENBAO_MCP_BASE_URL Alternative fallback URL for user-level client endpoints. http://127.0.0.1:8200 No
OPENBAO_MCP_USERNAME Username for username/password authentication methods. None No
OPENBAO_MCP_PASSWORD Password for username/password authentication methods. None No
OPENBAO_MCP_SSL_VERIFY Enable/disable SSL/TLS certificate verification (True/False). True No
SECRETSTOOL Enable/disable Secrets Engine MCP tools namespace. True No
SYSTOOL Enable/disable System Administration MCP tools namespace. True No
AUTHTOOL Enable/disable Authentication Engine MCP tools namespace. True No
SSHTOOL Enable/disable SSH Management MCP tools namespace. True No

A local template is supplied inside .env.example. Copy this file as .env and fill out your specific service endpoint parameters before starting execution.


MCP Tools

The following declarative FastMCP tools are registered and available to upstream AI agents:

Tool Name Description Parameters
read_secret Retrieve secret from Vault KV engine path: str
write_secret Write secret to Vault KV engine path: str, data: dict
get_health Get OpenBao system health status None

See docs/overview.md or docs/concepts.md for deeper operational examples.


Architecture

This package uses the standardized Agent-Utilities dynamic facade architecture:

graph TD
    User([User Agent]) --> Server[FastMCP Server]
    Server --> Facade[Api Dynamic Facade]
    Facade --> ClientBase[ApiClientBase]
    Facade --> Auth[Credentials Auth Handler]
    ClientBase --> Service([External Service API])

Deployment

Bare-Metal (Standard pip)

  1. Set up your Python virtual environment (>= 3.10).
  2. Install the package: pip install .[all]
  3. Export credentials:
    export OPENBAO_URL="http://127.0.0.1:8200"
    
  4. Run: python -m openbao_mcp.mcp_server

Container (Docker Compose)

A standard compose structure is provided inside the docker/ folder. Build and deploy:

docker compose -f docker/compose.yml up --build -d

Documentation

The complete documentation is published as the official documentation site and is the recommended reference for installation, deployment, and day-to-day operation.

Page Contents
Installation pip, source, extras, prebuilt Docker image
Deployment run the MCP server, the agent server, Compose, Caddy + Technitium, env config
Usage the MCP tools, the Api client, example prompts
Backing Platform deploy OpenBao with Docker
Overview architecture and the dynamic facade
Concepts concept registry (CONCEPT:BAO-*)

AGENTS.md is the canonical contributor/agent guidance.

Contributing

Please audit all code changes against ecosystem guidelines in CONTRIBUTING.md if available, and run:

pre-commit run --all-files

License

This project is licensed under the MIT License. See the LICENSE file for complete details.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

openbao_mcp-0.30.1.tar.gz (28.5 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

openbao_mcp-0.30.1-py3-none-any.whl (31.9 kB view details)

Uploaded Python 3

File details

Details for the file openbao_mcp-0.30.1.tar.gz.

File metadata

  • Download URL: openbao_mcp-0.30.1.tar.gz
  • Upload date:
  • Size: 28.5 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.14.4

File hashes

Hashes for openbao_mcp-0.30.1.tar.gz
Algorithm Hash digest
SHA256 22dfaf2af0a535938e3efa74c1340be27651a52bac164427768f2d2f8cf5fb98
MD5 20b4d52c0fe14427e2c02baf076819af
BLAKE2b-256 4714254e8aa7ae5fc7e152ee168c47ab3b9b29553fa356e4372415062eadb6b6

See more details on using hashes here.

File details

Details for the file openbao_mcp-0.30.1-py3-none-any.whl.

File metadata

  • Download URL: openbao_mcp-0.30.1-py3-none-any.whl
  • Upload date:
  • Size: 31.9 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.14.4

File hashes

Hashes for openbao_mcp-0.30.1-py3-none-any.whl
Algorithm Hash digest
SHA256 1faa9094f5ec1be8d334942f8a37757f1de356346379bcd67fb461b6ba223f36
MD5 05ea73dd264245e97b23345586f9ab59
BLAKE2b-256 e0264f10261f36a903c384410464757a1dbc4c4bd51417d1039a0ccf04d1b40e

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page