Skip to main content
AllMCPs
BrowseBestCategoriesStackCompareToolsGuidesBlog Log in Submit MCP

Stay in the loop

Get new MCP servers and top picks in your inbox.

AllMCPs

The open directory for discovering and installing Model Context Protocol servers.

Explore

  • Browse servers
  • Best MCP servers
  • Categories
  • MCP clients
  • Agent prompts
  • Stack Builder
  • Compare servers
  • Tags index
  • Submit a server
  • Pricing

Learn

  • Guides hub
  • What is MCP?
  • Install guide
  • Troubleshooting
  • Security
  • Blog
  • Blog RSS

Tools

  • All tools
  • Config generator
  • Config validator
  • MCP playground
  • OpenAPI β†’ MCP
  • Badge generator

For agents

  • API docs
  • Trust & traffic
  • llms.txt β†— (opens in a new tab)
  • Catalog JSON β†— (opens in a new tab)
  • Remote MCP β†— (opens in a new tab)

Company

  • About
  • Contact
  • X (@AllMCPs) β†— (opens in a new tab)
  • GitHub β†— (opens in a new tab)
  • Terms
  • Privacy
AllMCPs VerifiedAllMCPs VerifiedFeatured on Nick LaunchesFeatured on Nick LaunchesLaunch Llama NewsletterLaunch Llama NewsletterVerified DR - allmcps.comVerified DR - allmcps.comFeatured on SaaSGrowFeatured on SaaSGrowFeatured on Twelve ToolsFeatured on Twelve ToolsFeatured on Saaspa.geFeatured on Saaspa.geFeatured on Findly.toolsFeatured on Findly.toolsFeatured on Startup FameFeatured on Startup FameFeatured on LaunchKiwiFeatured on LaunchKiwiFeatured on ScrollLaunchFeatured on ScrollLaunchFeatured on DailyPingsFeatured on DailyPingsFazier badgeFazier badgeFeatured on NewTool.siteFeatured on NewTool.siteFeatured on saasfame.comFeatured on saasfame.comDR Checker - Domain RatingDR Checker - Domain RatingListed on Turbo0Listed on Turbo0Launched on LaunchBoard - Product Launch PlatformLaunched on LaunchBoard - Product Launch PlatformList on SimilarlabsList on Similarlabshttps://codetrendy.comhttps://codetrendy.comListed on DevTool.ioFeatured on BuildlistFeatured on BuildlistAllMCPs VerifiedAllMCPs VerifiedFeatured on Nick LaunchesFeatured on Nick LaunchesLaunch Llama NewsletterLaunch Llama NewsletterVerified DR - allmcps.comVerified DR - allmcps.comFeatured on SaaSGrowFeatured on SaaSGrowFeatured on Twelve ToolsFeatured on Twelve ToolsFeatured on Saaspa.geFeatured on Saaspa.geFeatured on Findly.toolsFeatured on Findly.toolsFeatured on Startup FameFeatured on Startup FameFeatured on LaunchKiwiFeatured on LaunchKiwiFeatured on ScrollLaunchFeatured on ScrollLaunchFeatured on DailyPingsFeatured on DailyPingsFazier badgeFazier badgeFeatured on NewTool.siteFeatured on NewTool.siteFeatured on saasfame.comFeatured on saasfame.comDR Checker - Domain RatingDR Checker - Domain RatingListed on Turbo0Listed on Turbo0Launched on LaunchBoard - Product Launch PlatformLaunched on LaunchBoard - Product Launch PlatformList on SimilarlabsList on Similarlabshttps://codetrendy.comhttps://codetrendy.comListed on DevTool.ioFeatured on BuildlistFeatured on Buildlist
Β© 2026 Jackalope Digital LLC. All rights reserved.
  1. Home
  2. πŸ’» Developer Tools
  3. Ocultar Pii
O
Health: ActiveRecent health check succeeded.Last checked 8/10/2026, 11:57:54 PM

Ocultar Pii

Enrichment pendingWe haven’t run our AI enrichment pass on this listing yet, so the overview, use cases, and FAQ below may be sparse or missing. We work through the catalog over time β€” check back soon.
View Repository

Zero-egress PII redaction for Claude. Runs locally β€” no data leaves your infrastructure.

Quick Install

Automated & IDE Setup

Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β€” or use 1-click editor setup below.

Add to CursorAdd to VS Code
Manual Client & Custom JSON ConfigExpand JSON β–Ύ

Install Config Generator

Choose your client
claude_desktop_config.json
{
  "mcpServers": {
    "ocultar-pii": {
      "command": "npx",
      "args": [
        "-y",
        "https://img.shields.io/badge/license-Apache%202.0-blue.svg)](LICENSE"
      ]
    }
  }
}

πŸ’‘ Paste into ~/Library/Application Support/Claude/claude_desktop_config.json (macOS) or %APPDATA%\Claude\claude_desktop_config.json (Windows)

Install Directory Badge Claim listing AlternativesπŸ’» More in Developer Tools

Documentation Overview

Ocultar

Apache 2.0 Go 1.24+ Docker Release

Ocultar is an open-source local PII/PHI masking engine for AI workflows.

It runs as a local HTTP sidecar. Send it text before it reaches a cloud LLM; it returns the same text with every piece of personal data replaced by a deterministic, reversible token ([EMAIL_9c8f7a1b], [PERSON_3a12b4cd], …). Originals are encrypted and stored in a local vault. Callers with the auditor token can restore them.

No PII ever reaches the upstream model.


Quick start β€” Docker

server.ts
export OCU_MASTER_KEY=$(openssl rand -hex 32)
export OCU_SALT=$(openssl rand -hex 16)
export OCU_AUDITOR_TOKEN=$(openssl rand -hex 24)

docker run --rm -p 4141:4141 \
  -e OCU_MASTER_KEY \
  -e OCU_SALT \
  -e OCU_AUDITOR_TOKEN \
  ghcr.io/ocultar-dev/ocultar:latest -serve 4141

Quick start β€” build from source

bash
CGO_ENABLED=1 go build -o ocultar ./services/refinery/cmd/

OCU_MASTER_KEY=$(openssl rand -hex 32) \
OCU_SALT=$(openssl rand -hex 16) \
OCU_AUDITOR_TOKEN=$(openssl rand -hex 24) \
./ocultar -serve 4141

API reference

GET /api/health

Returns engine status. No authentication required.

config.json
{
  "status": "healthy",
  "version": "1.14",
  "vault": { "status": "online" },
  "slm":   { "status": "online", "circuit": "closed" }
}

POST /api/refine

Mask PII in text or JSON. No authentication required.

Request body: raw text string or any JSON value.

Response:

config.json
{
  "refined": "{\"message\":\"Hello [PERSON_3a12b4cd], your order [EMAIL_9c8f7a1b] is ready.\"}",
  "report": {
    "hits": 2,
    "types": ["PERSON", "EMAIL"]
  }
}

refined is a JSON-encoded string β€” parse it once to get the masked payload.


POST /api/reveal

Restore vault tokens back to originals.

Authentication: Authorization: Bearer <OCU_AUDITOR_TOKEN> header required. Returns 403 if OCU_AUDITOR_TOKEN is not set on the server.

Request body:

config.json
{ "tokens": ["[PERSON_3a12b4cd]", "[EMAIL_9c8f7a1b]"] }

Response:

config.json
{
  "results": {
    "[PERSON_3a12b4cd]": "Alice Martin",
    "[EMAIL_9c8f7a1b]": "alice@example.com"
  }
}

GET /api/entities Β· POST /api/entities Β· POST /api/entities/seed

Manage the persistent entity registry (pre-seed canonical names so all variants map to the same token). Requires Authorization: Bearer <OCU_AUDITOR_TOKEN>.


Architecture

Ocultar runs two detection tiers before any text leaves the machine:

Tier 1 β€” Deterministic regex / heuristics (fast, zero-egress)

Sub-tierShieldWhat it catches
0DictionaryVIP names, org names from configs/protected_entities.json
0.5Pattern + EntropyHigh-entropy strings (API keys, secrets) via Shannon scoring
1Rule EngineEMAIL, SSN, IBAN, credit cards, 50+ national ID formats
1.1Phone Shieldlibphonenumber validation
1.2Address ShieldHeuristic street address parser (EN/FR/ES/DE)
1.5ContextualNames in greetings, signatures, interrogative sentences

Tier 2 β€” SLM-based NER (higher recall, configurable endpoint)

Sends text to a local AI sidecar for named-entity recognition. The scanner is always initialized but produces no results unless a compatible sidecar is running at SLM_SIDECAR_URL. Point it at a privacy-filter or llama.cpp instance to activate NER.

bash
SLM_SIDECAR_URL=http://localhost:8085 ./ocultar -serve 4141

Use SLM_ADAPTER=openai-chat for a llama.cpp / Qwen endpoint, or leave unset for the privacy-filter protocol (default).


Privacy model

  • Zero-egress design. Masked tokens ([EMAIL_9c8f7a1b], …) are the only data forwarded to the upstream model. Raw text is not transmitted.
  • Local vault only. The mapping of each token back to its original value is stored in an encrypted DuckDB vault (vault.db) on the local filesystem using AES-256-GCM with HKDF-SHA256. The vault file is never transmitted.
  • Raw prompt retention. The refinery logs each raw (unmasked) prompt locally to the vault to support the audit diff view. This data is encrypted at rest alongside the token mappings and is not sent anywhere. If prompt retention is not desired, do not configure OCU_AUDITOR_TOKEN β€” without an auditor token the reveal endpoint returns 403 and the diff view is inaccessible.
  • Fail-closed design. If the refinery encounters an error or is unavailable, the gateway returns a 5xx error and stops β€” it does not forward raw text as a fallback.

Configuration

VariableRequiredDefaultPurpose
OCU_MASTER_KEYYes (production)insecure dev key32+ byte AES key material for HKDF
OCU_SALTYes (production)built-in defaultPer-deployment HKDF salt
OCU_AUDITOR_TOKENYesβ€”Bearer token for /api/reveal and /api/entities
OCU_VAULT_PATHNovault.dbDuckDB vault file path
SLM_SIDECAR_URLNohttp://localhost:8085Tier 2 NER sidecar endpoint
SLM_ADAPTERNoprivacy-filterSidecar protocol: privacy-filter or openai-chat

Building from source

Requires Go 1.24+ with CGO enabled (DuckDB and libphonenumber need a C compiler).

bash
git clone https://github.com/ocultar-dev/ocultar.git
cd ocultar
make build

Run tests:

bash
CGO_ENABLED=1 go test ./...

License

Apache 2.0 β€” see LICENSE.

Related MCP Servers

View all in Developer Tools View all alternatives
  • Mcp Server logoMcp Server

    MCP Server for ThoughtSpot - provides OAuth authentication and tools for querying data

    πŸ’» Developer Tools0 views
    Compare vs Mcp Server β†’
  • A
    Ai Netcafe

    Compare LLM cost & latency on one prompt, translate PDF keeping layout, cited research, make PPTX

    πŸ’» Developer Tools0 views
    Compare vs Ai Netcafe β†’
  • Claude Task Master logoClaude Task Master

    AI-powered task management system for AI-driven development. Features PRD parsing, task expansion, multi-provider support (Claude, OpenAI, Gemini, Perplexity, xAI), and selective tool loading for optimized context usage.

    πŸ’» Developer Tools7 views
    Compare vs Claude Task Master β†’
  • Shadcn Ui Mcp Server logoShadcn Ui Mcp Server

    MCP server that gives AI assistants seamless access to shadcn/ui v4 components, blocks, demos, and metadata.

    πŸ’» Developer Tools2 views
    Compare vs Shadcn Ui Mcp Server β†’

Frequently Asked Questions about Ocultar Pii

Add the following block to your claude_desktop_config.json under mcpServers: "mcpServers": { "ocultar-pii": { "command": "npx", "args": ["-y", "ocultar-pii"] } }

AllMCPs Directory Badge

Full Badge Customizer

Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.

Badge Style:
Live Dynamic SVG PreviewOcultar Pii AllMCPs Directory Badge
Markdown (GitHub README)
[![AllMCPs](https://allmcps.com/api/badge/ocultar-pii?style=directory)](https://allmcps.com/mcp/ocultar-pii)
HTML Embed
<a href="https://allmcps.com/mcp/ocultar-pii"><img src="https://allmcps.com/api/badge/ocultar-pii?style=directory" alt="Ocultar Pii on AllMCPs" /></a>

Technical Specs & Signals

CategoryπŸ’»Developer Tools
More technical detailsExpand β–Ύ
TransportSSE (Remote)
RuntimeNode.js
5/5 checks healthy over the last 6h
Views0
Unique ViewsTotal visits recorded for this listing page on AllMCPs.
Installs0
Installs & Copy ActionsTotal times users copied install commands or configuration snippets for this server.
GitHub stars0
GitHub Star CountTotal stargazers on GitHub representing community popularity (0 stars).
Last commit14d ago
Last Repository CommitThe most recent commit or push recorded for this server's GitHub repository.Last commit on Jul 27, 2026
40Quality signal: Fair Β· 40/100How this signal is calculated β–Ύ
Server availabilityNot measured

Not scored for repo-hosted servers β€” we can't reach the running server, only its GitHub page. Hosted MCP endpoints are health-checked live.

Verified ownership10/20
Documentation & tools16/30
Adoption & activity4/15
Community engagement0/10

A guidance signal from public completeness & health data β€” not a user rating. New listings start lower and rise as they add docs, get verified, and grow adoption. Signals we can't observe for a listing are skipped, not counted against it.

β˜… FeaturedMoxie Docs MCP logo

Moxie Docs MCP

MCP & Agent Skills for Automated Documentation, and codebase conventions + context

Explore Server β†’

Own this project?

This directory is pre-filled from public sources. Claim via GitHub README, site badge, or DNS TXT to get the verified badge and attach your website.

Free dofollow backlink: after claiming, verify your product site and place a dofollow AllMCPs badge β€” we recheck it stays live.

Claim & get free dofollow

Share & Embed

Add our SVG badge (dark/light directory styles) or embeddable widget to your site.

Explore more

More in πŸ’» Developer Tools β†’Best MCP servers for Developers β†’Alternatives to Ocultar Pii β†’Install in Claude DesktopInstall in CursorInstall in VS Code