HSM-backed vault for AI agent secrets with just-in-time credential fetching and prompt injection scanning.
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
process.env. You'll be asked to provide them before it can run.MCP_TRANSPORT— Set =httpStream and PORT=8080 to run in hosted mode.ONECLAW_AGENT_API_KEY— stdio (default) Local — Claude Desktop, Cursor Env: (recommended; auto-discovers agent + vault) or ONECLAW_AGENT_ID + key; or ONECLAW_AGENT_TOKEN + ONECLAW_VAULT_IDONECLAW_AGENT_ID— stdio (default) Local — Claude Desktop, Cursor Env: ONECLAW_AGENT_API_KEY (recommended; auto-discovers agent + vault) or + key; or ONECLAW_AGENT_TOKEN + ONECLAW_VAULT_IDONECLAW_AGENT_TOKEN— stdio (default) Local — Claude Desktop, Cursor Env: ONECLAW_AGENT_API_KEY (recommended; auto-discovers agent + vault) or ONECLAW_AGENT_ID + key; or + ONECLAW_VAULT_IDONECLAW_BASE_URLONECLAW_CONFIG_DIRONECLAW_DAEMON_SOCKET— No ~/.config/1claw/daemon.sock Path to the local daemon Unix socket (local daemon mode only).ONECLAW_DPOPONECLAW_LOCAL_ONLY— No false Set to true for security-only mode (no vault credentials needed).ONECLAW_LOCAL_VAULT— No false Set to true to use the local daemon instead of the cloud API.ONECLAW_MCP_EXFIL_PROTECTION— block block rejects tool inputs containing known secrets; warn logs but allows; off disables.ONECLAW_MCP_PII_DETECTION— true Detect PII patterns (emails, SSNs, credit cards, etc.) in inputs and outputs.ONECLAW_MCP_REDACT_SECRETS— true Redact known secret values from non-secret tool outputs. Requires security enabled.ONECLAW_MCP_SANITIZATION_MODE— block block rejects critical/high threats; surgical normalizes Unicode but allows; log_only only logs.ONECLAW_MCP_SECURITY_ENABLED— true Master switch. Set to false to disable all inspection.ONECLAW_SECRET_PREFIXONECLAW_VAULT_ID— stdio (default) Local — Claude Desktop, Cursor Env: ONECLAW_AGENT_API_KEY (recommended; auto-discovers agent + vault) or ONECLAW_AGENT_ID + key; or ONECLAW_AGENT_TOKEN +PORT— Set MCP_TRANSPORT=httpStream and =8080 to run in hosted mode.[](https://m8ven.ai/mcp/1claw-mcp-c3qlpa)