The full upstream README, mirrored here for reference. Install config, tool schemas, adoption signals, and an original overview live on the Clavis listing page.
Secure credential management for Claude Desktop and MCP servers.
Or install globally:
Add the following to your Claude Desktop configuration file (claude_desktop_config.json):
| Variable | Required | Default | Description |
|---|---|---|---|
CLAVIS_API_KEY | yes | — | Your Clavis JWT, from POST /v1/auth/login. Not the cla_… key shown at sign-up. |
CLAVIS_API_URL | no | https://clavisagent.com | Base URL of your Clavis instance. Set this for self-hosted deployments. |
| Tool | Description |
|---|---|
call_service | Recommended. Make an API call with server-side credential injection — the credential is injected into the upstream request server-side, so the raw key never enters the conversation. |
get_credentials | Legacy. Returns the raw access token or API key for a named service. Prefer call_service. |
list_services | List all services with stored credentials |
check_credential_status | Check the status and expiry of credentials for a service |
Prefer call_service over get_credentials. call_service keeps the secret
server-side, so a prompt injection has no credential in context to exfiltrate.
get_credentials places the raw key in the conversation and exists only for
callers that must hold the token themselves.
MIT