JFSecure

io.github.theone55v2.6.1Updated Oct 11, 2026

Let AI agents use secrets without seeing them: masked output, every use approved in JFSecure.

VerifiedSTDIODesktop onlyDeveloper ToolsSecurity & Monitoring

Overview

AI-generated overview

Lets an assistant use stored secrets as environment variables or template values without ever receiving the secret values.

What it does
JFSecure's jfs MCP server is a thin local client that talks over a local pipe to the running, unlocked JFSecure app. It exposes list_secrets (names only), run_with_secrets (runs a command with a secret's keys as environment variables, with output masked as [JFSecure: NAME]), and render_template (fills {{Secret:key}} placeholders into a file such as .env). There is deliberately no tool that returns a secret value; every use opens an approval window in the app showing the program, the exact command and the secret.
When to use it
Use it when an agent needs to authenticate or run commands that require credentials, but you do not want the values to appear in the model's context, transcripts or logs. It suits workflows such as calling an API with a token, rendering a .env file, or using a Git credential helper, with per-use approval in the desktop app.
Requirements
A local desktop install of the JFSecure app (macOS, Windows or Linux) with the vault open and unlocked; the jfs command must be on PATH (installed with the app, via Homebrew, .deb, or the app's Settings). The MCP server is added as a stdio server, for example with the command jfs and argument mcp. No environment variables, headers or separate authentication are declared.
Before you install
Approving a command lets it use the secret, and masking is described as a seatbelt rather than a wall: an approved command can still send a value away, so read the exact command before allowing it. Approvals can be granted once or for 15 minutes, scoped to that command and secret. The server itself never opens vault files or sees the vault password.

Installation

In SourceWeft

  1. Open JFSecure in the dashboard and add it to a workspace.
  2. Enable the server for the chats that should use its tools.

Desktop only via STDIO. STDIO servers start a local process, so they need the SourceWeft desktop host.

Other MCP clients

Follow the launch instructions in the repository.

README

jfs — secrets for AI agents that never see them

jfs is the command line and MCP server of JFSecure, an offline password and snippet manager. It lets Claude Code, Cursor or any MCP agent use a secret without ever getting it — and you approve every use in the app.

This repository is the source of jfs itself, so you can read exactly what an agent talks to. It is a thin client: it sends one JSON request over a local pipe to the running, unlocked JFSecure app and prints the answer. It never opens vault files, never sees the vault password and has no crypto. (The app is a separate download; jfs ships with it.)

[Claude Code asks, JFSecure shows the exact command, the agent gets the output with the token masked]

MCP tools

ToolWhat it doesWhat the agent gets back
list_secretsLists secret and key names, with the environment variable each key becomesNames only
run_with_secretsRuns a command with a secret's keys as environment variables (all, some, or one on stdin)Exit code and output, every value masked as [JFSecure: NAME]
render_templateFills {{Secret:key}} in a template and writes the file (e.g. .env)Which names were filled in

There is no "get" tool, on purpose. Every use opens an approval window in JFSecure that shows the program, the exact command and the secret: allow once, allow 15 minutes, or deny. For Claude Code a 15-minute approval covers only that command and that secret.

# the agent called run_with_secrets(secret: "github", command: …)exit code 0variables set: TOKEN--- stdout ---token is [JFSecure: TOKEN]{"login": "octocat", "plan": {"name": "pro"}}

Set up

  1. Install JFSecure and open your vault: brew install theone55/jfsecure/jfsecure (macOS), scoop bucket add jfsecure https://github.com/theone55/scoop-jfsecure; scoop install jfsecure/jfsecure (Windows), or the installer (Windows, macOS, Linux). jfs comes with it: on Windows the app puts it on PATH at its first start (open a new terminal afterwards); on macOS (.dmg) and the Linux AppImage use Settings → Install the jfs command; Homebrew and the .deb install it for you.
  2. Add the MCP server:
sh
claude mcp add --scope user jfsecure -- jfs mcp

Cursor (~/.cursor/mcp.json), Claude Desktop, Windsurf, VS Code — any stdio MCP client:

json
{ "mcpServers": { "jfsecure": { "command": "jfs", "args": ["mcp"] } } }

More: https://secure.jfolio.org/agents

Also as an MCP bundle (.mcpb, Windows / macOS / Linux) on the releases page, and in the official MCP Registry as io.github.theone55/jfs.

Command line

jfs status                       is the app running and unlockedjfs ls [secret|folder]           names only, no approval neededjfs get github/token             print a value (approved in the app)jfs copy github/token            to the clipboard, nothing printedjfs run github -- gh api user    run with the secret's keys as env vars ($token → TOKEN); output masked when pipedjfs render .env.tpl -o .env      fill {{Secret:key}} into a filegit config --global credential.helper "!jfs git-credential"

Full guide: https://secure.jfolio.org/cli

What it protects — and what it doesn't

  • The model never receives a value, so it can't end up in a transcript or a log.
  • A prompt-injected agent can only ask; you see the exact command.
  • The pipe is your OS user's only, and the app identifies the caller through the OS, not by what it says.
  • Masking is a seatbelt, not a wall: a command you approve can still send a value away. Read the command.

Build

sh
cargo build --release   # Rust stable; Windows, macOS, Linuxcargo test

The copy here follows each JFSecure release (version in Cargo.toml = the app's version it shipped with). Issues and questions are welcome here.

MIT License.

Source: README.md at commit 8f2cab3

Tools

0
Tool metadata has not been indexed yet.

Version history

2
  1. v2.6.1LatestOct 11, 2026
  2. v2.6.0Oct 11, 2026