Tidy your E2E-encrypted ShieldFive vault and local folders. Decrypts locally; revocable access.
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β or use 1-click editor setup below.
One-click editor setup isnβt available for this listing yet β we donβt have a confirmed install command, and weβd rather show nothing than point your editor at the wrong package or host. Follow the projectβs own setup instructions, linked above.
A Model Context Protocol server that lets Claude, ChatGPT, Cursor or a local model work with two things:
ShieldFive's servers never see a file name or a byte of content in the clear, and that holds with this server running too. Decryption happens inside this process, on your computer. What the assistant then does with what it reads is a separate question, answered under Security model.
Requires Node 20 or newer.
Add the server to your assistant. For Claude Desktop, add this to
claude_desktop_config.json (Cursor uses the same block in ~/.cursor/mcp.json):
For Claude Code: claude mcp add shieldfive -- npx -y @shieldfive/mcp
Restart the assistant and ask it to tidy up my ShieldFive vault. It calls
vault_connect, which opens ShieldFive in your browser.
In that tab, choose the folders, Read only or Read and organize, and an expiry (1 hour to 90 days), then click Authorize.
That is the whole setup: the connection is delivered straight to the server
running on your computer β over 127.0.0.1, never through ShieldFive β and
stored in your system keychain. Nothing is copied by hand.
To connect before you start a conversation, run npx -y @shieldfive/mcp login:
same browser page, same result. login --paste takes a connection string you
copied from Settings β AI assistants instead, for a machine with no browser.
npx @shieldfive/mcp status shows which connection is configured and whether
ShieldFive still accepts it. npx @shieldfive/mcp logout removes it from the
keychain. Revoking it in ShieldFive is what cuts off access everywhere.
For CI or a machine without a keychain, set SHIELDFIVE_GRANT to the connection
string instead. Anything that can read the server's environment can then read
the connection, so prefer the keychain wherever there is one. Setting
SHIELDFIVE_GRANT=none keeps one client local-only on a machine whose keychain
holds a connection for another.
http://127.0.0.1:<port>/callback itself. A crafted link cannot send your
connection anywhere but your own machine./callback, Host
exactly the loopback address (so a rebound DNS name is refused), no Origin
but ShieldFive's, and a 256-bit state compared in constant time. Then it
closes.In plain terms:
vault_trash moves items into a folder in your Bin
that belongs to the connection. There is no permanent-delete tool, and the
API a connection can reach has no delete route. Every rename, move and trash
appears in Settings β AI assistants β Activity with an Undo button.What this does not protect:
vault_trash at 50 items per call, requires a preview for
every change, and keeps every change undoable. A model can still be talked
into a reversible mistake inside the folders you granted.The full design, including the threat model and the reasoning behind each
decision, is in
docs/mcp-grants-design.md.
vault_connect is always available. The rest are registered once a connection
exists β connecting mid-conversation announces them with
notifications/tools/list_changed. Everything below names things by id; paths
are for people.
| Tool | Needs | What it does |
|---|---|---|
vault_connect | β | opens ShieldFive in the browser to authorize a connection, and stores it in the keychain |
vault_list_files | read | files and folders in scope, with decrypted names, paths, sizes, dates |
vault_search_files | read | by name, path, extension, size or date, run locally over decrypted names |
vault_storage_stats | read | totals, the biggest folders and files, a breakdown by type |
vault_find_duplicates | read | same-size files decrypted in memory and compared by SHA-256; budgeted, and says when a result is a lower bound |
vault_read_file | read | text files as fenced, untrusted content (up to 1 M characters); other types return details only |
vault_rename | organize | rename a file or folder |
vault_move | organize | move into another folder in scope |
vault_create_folder | organize | create a folder in scope |
vault_upload | write | encrypt a local file here and put it in the vault, then read it back and compare before you are told it is safe to remove the original |
vault_trash | organize | up to 50 items into the connection's folder in the Bin |
vault_move_in | write | free up space: up to 50 local files uploaded and verified one by one, each original moved to the local trash only after its copy reads back identical β one approval, nothing deleted |
Limits a user may meet:
readable: false until you next open ShieldFive on the web, which adds the key
the connection needs. Files uploaded in the web app are ready straight away.vault_move_in puts each
verified original in .shieldfive-mcp-trash, with a manifest naming its vault
copy; the space comes back when you empty that directory.Every path after the package name is a root. The local tools can read and write inside those directories and nowhere else, and make no network request.
In claude_desktop_config.json:
No reviews yet β be the first to share how this listing worked for you.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/shieldfive)<a href="https://allmcps.com/mcp/shieldfive"><img src="https://allmcps.com/api/badge/shieldfive?style=directory" alt="ShieldFive on AllMCPs" /></a>