Self-hosted remote MCP server for Bitwarden and Vaultwarden with OAuth 2.1; agents hold tokens only
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent — or use 1-click editor setup below.
One-click editor setup isn’t available for this listing yet — we don’t have a confirmed install command, and we’d rather show nothing than point your editor at the wrong package or host. Follow the project’s own setup instructions, linked above.
A self-hosted, remote MCP server that lets hosted AI agents such as Claude, Claude Cowork, Claude Code and Codex use your credentials without ever seeing them. The credentials stay in your Bitwarden (or Vaultwarden) vault. vaultgate uses them on the agent's behalf against systems you define (an HTTP API, Microsoft Graph, a SQL Server or PostgreSQL database, an SSH or WinRM host, a GitHub repository searched with Semble) under your policy, and hands back only the result. It is its own OAuth 2.1 authorization server, so the agent holds a short-lived, scoped, revocable token and nothing else.
Status: release candidate. Milestones M1 to M7 are merged: configuration, SQLite store, operator identity with TOTP, the OAuth 2.1 authorization server, the MCP tool surface, the managed
bw servebackend, the audit trail, packaging and the Azure template. M8 (hardening and compatibility evidence) is in progress. The actions layer, opt-in and off by default, has landed through M14: M9 the engine, the operator pages and thehttpconnector, M10 the Microsoft Graph credential adapter, M11sql, M12ssh, M13winrm, and M14 the policy-form validation messages, the call-history and unexpected-write views, grant management from the connected-clients list and the elicitation hardening. M16 adds thecodeconnector: Semble code search over private GitHub repositories, with its sidecar (guide).browseris M15; seedocs/PLAN.md.
A credential an agent can read ends up in the transcript. Once an agent reveals a password in order to use it, the value sits in the model's context, in the chat transcript, in the client's logs and on whatever command line the agent builds, and revoking the agent does not take it back. vaultgate is built so that the agent never needs the value:
ssh_run and
winrm_run run one command on one configured host under your allowlist (a target that accepts
any command needs both its own flag and the deployment's consent), and every operation executes
at its target.docker compose up is a complete installation.Hosted agents reach MCP servers over HTTPS and cannot run a process next to your vault, and the other Bitwarden MCP servers are built for exactly that local process:
| Server | Where it runs | Who holds the master password / API key | Client authorization | Consent and scopes | Revocation | Audit trail | Using a credential without seeing it |
|---|---|---|---|---|---|---|---|
Official bitwarden/mcp-server | Local, stdio; its README says it must never be hosted publicly | Your machine: the bw CLI session (BW_SESSION) in the client's configuration, or an OS password dialog | None; whoever launches the process | None; every tool is available to the launching client | Lock the vault or end the bw session | Not described | Not described |
| warden-mcp, remote mode | A long-running HTTP service you host | The client, which sends them as X-BW-Password, X-BW-ClientId and X-BW-ClientSecret headers on every call | None built in ("no built-in authentication layer in v1") | None; READONLY and NOREVEAL switches apply to every client alike | Rotate the Bitwarden credentials | Not described | Not described |
| Typical community servers, e.g. vaultwarden-mcp, bitwarden-mcp-server | Local stdio, or a plain HTTP port | The server process, from environment variables holding the e-mail address and master password | None | None | Rotate the Bitwarden credentials | Not described | Not described |
No reviews yet — be the first to share how this listing worked for you.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/vaultgate)<a href="https://allmcps.com/mcp/vaultgate"><img src="https://allmcps.com/api/badge/vaultgate?style=directory" alt="Vaultgate on AllMCPs" /></a>