Stop AI coding agents from leaking API keys. Local proxy swaps real secrets for phm_ tokens.
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β or use 1-click editor setup below.
π‘ Paste the JSON block into your client's configuration file under mcpServers, then restart the application.
Delegate more to AI without putting real keys in agent context.
Phantom replaces project secrets with scoped phm_ placeholders. Applications use those placeholders through an authenticated local proxy, while agents use value-blind MCP tools for inventory, diagnostics, and governed requests.
Quick start Β· β Star Phantom Β· Delegate safely Β· Why Phantom? Β· MCP setup Β· Docs Β· Contribute Β· phm.dev
βΆ Historical v0.4 demo β current behavior differs Β Β·Β π‘ Security model Β Β·Β π Threat model Β Β·Β π¬ Discussions
[!IMPORTANT] Release-state snapshot (verified 2026-09-05): the immutable
v0.7.8GitHub release at source commitf065b13462f9eaf27e0443f8911f021575b7c409. Its 19-asset release set, checksums, archive-specific SPDX SBOMs, GitHub provenance and SBOM attestations, and all six native release rows are bound to that immutable release record by tag-bound workflow 33952398697. Exact public registry endpoints were requeried on 2026-09-05. Homebrew independently publishes reviewedv0.7.8; npmlatestremains0.6.0, and the npm0.7.4wrappers remain quarantined underrelease-candidateafter failed npm-channel acceptance. The GitHub receipt alone does not prove the separately verified Homebrew formula, an npm or crates.io package, MCP Registry entry, hosted-service commissioning, provider activation, signing/notarization, certification, or customer acceptance. See release readiness and platform support.
Choose the smallest path that answers your next question. The first path uses no credential, makes no network request, and does not install or configure Phantom.
| Goal | Start | What it establishes |
|---|---|---|
| See the delegation boundary with no secret or setup | Run node examples/first-five-minutes/run.mjs, then read the first-five-minutes walkthrough | A deterministic, read-only example contract; not vault, proxy, provider, or deployment acceptance. |
| Protect a real local project | Follow Quick Start with the reviewed v0.7.8 GitHub release | Local initialization and diagnostics on your machine. |
| Connect an AI coding client | Complete the first MCP task | Value-blind capability, status, and repository checks; no provider action. |
| Define a bounded task for an agent | Use the safe delegation quickstart | A reviewable task contract with explicit authority and acceptance boundaries. |
| Evaluate a team rollout | Use the enterprise adoption guide | A controlled evaluation plan; not a claim of commissioned cloud or enterprise service. |
| Audit the trust model first | Read the security model and threat model | Documented controls, assumptions, and residual risks. |
AI coding agents routinely work in repositories that also contain local credentials. Once a real API key enters an agent context, transcript, tool call, or generated file, you have lost control of where that value may persist.
Traditional secrets managers focus on keys at rest and in transit. Phantom adds a boundary for agent context:
phm_ mappings, MCP responses remain value-blind, and exact proxy routes inject their own configured authentication values. Unmanaged files, broader shell authority, and same-user processes remain in the threat model.v0.7.8 GitHub release, phantom init protects a project without requiring an account, DNS changes, or a custom CA.Phantom's implemented user-facing surfaces are the CLI, vault, authenticated local proxy, MCP server, and optional cloud/team workflows documented below. Cloud and team behavior additionally depends on the deployed service, account plan, and provider configuration; source code alone is not deployment or customer-acceptance evidence. The conversation facade is intentionally narrow:
phantom_do is proposal-only. It canonicalizes a closed Cargo action and reports its digest, effect, and activation blockers; execute is hard denied.phantom_setup_workspace can propose setup, create a bearerless request, and report authenticated status. Applying a request remains a separate trusted-terminal operation.phantom grant retains value-blind lifecycle metadata and design-source foundations, but 0.7.8 hard-denies every live provider issuance/renewal path before credential or network access. A provider grant is not an execution-kernel authority grant, broker lease, or permission for an agent to execute work.See the documentation map, architecture, security policy, and threat model for the evidence behind those boundaries.
Install both binaries from the reviewed v0.7.8 GitHub release.
The Homebrew formula separately publishes the reviewed v0.7.8 binaries:
For exact v0.7.8 on macOS, Linux, or Windows, use the matching release asset
in Installation. Then protect and verify the project:
For a task contract you can hand to Claude Code, Codex, Cursor, Windsurf, or Copilot, use the safe delegation quickstart and the copyable policy and task templates. Teams evaluating a controlled rollout can start with the enterprise adoption guide.
The same core command surface is implemented for native Windows, with remaining
native acceptance limits tracked in the platform matrix. Install the exact v0.7.8
Windows ZIP for your architecture from Installation, verify its
published .sha256 sidecar, and place both executables on PATH. WSL is a
separate Linux environment with its own filesystem and credential-store context.
Factual signals from GitHub, npm, and our automated checks β not a rating.
No reviews yet β be the first to share how this listing worked for you.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/phantom-secrets)<a href="https://allmcps.com/mcp/phantom-secrets"><img src="https://allmcps.com/api/badge/phantom-secrets?style=directory" alt="Phantom Secrets on AllMCPs" /></a>