{
  "name": "varsafe",
  "description": "Scoped, audited access to your team's secrets. List secrets without being able to read them, read one value at a time, resolve a whole environment for a command, or rotate a credential — each gated by an OAuth scope a human approved.",
  "version": "1.0.0",
  "documentation": "https://docs.varsafe.dev/guides/mcp",
  "websiteUrl": "https://varsafe.dev",
  "remotes": [
    {
      "type": "streamable-http",
      "url": "https://api.varsafe.dev/mcp",
      "authorization": {
        "type": "oauth2",
        "protectedResourceMetadata": "https://api.varsafe.dev/.well-known/oauth-protected-resource/mcp",
        "authorizationServerMetadata": "https://api.varsafe.dev/.well-known/oauth-authorization-server",
        "dynamicClientRegistration": true,
        "scopesSupported": [
          "secrets:read",
          "secrets:read_values",
          "secrets:write",
          "secrets:run",
          "projects:read",
          "audit:read",
          "identity:read",
          "offline_access"
        ]
      }
    }
  ],
  "packages": [
    {
      "type": "stdio",
      "description": "Local stdio server for editors that cannot speak Streamable HTTP. Installed with the CLI; see the MCP guide.",
      "documentation": "https://docs.varsafe.dev/guides/mcp"
    }
  ],
  "tools": [
    {
      "name": "varsafe_whoami",
      "scopes": ["identity:read"]
    },
    {
      "name": "varsafe_list_projects",
      "scopes": ["projects:read"]
    },
    {
      "name": "varsafe_list_environments",
      "scopes": ["projects:read"]
    },
    {
      "name": "varsafe_list_secrets",
      "scopes": ["secrets:read"]
    },
    {
      "name": "varsafe_diff_secrets",
      "scopes": ["secrets:read"]
    },
    {
      "name": "varsafe_get_secret_value",
      "scopes": ["secrets:read_values"]
    },
    {
      "name": "varsafe_get_secret_values",
      "scopes": ["secrets:read_values"]
    },
    {
      "name": "varsafe_export_secrets",
      "scopes": ["secrets:run"]
    },
    {
      "name": "varsafe_set_secret",
      "scopes": ["secrets:write"]
    },
    {
      "name": "varsafe_unset_secret",
      "scopes": ["secrets:write"]
    },
    {
      "name": "varsafe_generate_secret",
      "scopes": ["secrets:write"]
    }
  ],
  "notes": "https://varsafe.dev/mcp serves this same manifest; the protocol endpoint itself is https://api.varsafe.dev/mcp. An unauthenticated request there answers 401 with a WWW-Authenticate header naming the protected-resource metadata above. https://varsafe.dev/mcp/authorize is the human consent screen and is not an API."
}
