
JFSecure
io.github.theone55v2.6.1Updated Oct 11, 2026
Let AI agents use secrets without seeing them: masked output, every use approved in JFSecure.
Overview
Lets an assistant use stored secrets as environment variables or template values without ever receiving the secret values.
- What it does
- JFSecure's jfs MCP server is a thin local client that talks over a local pipe to the running, unlocked JFSecure app. It exposes list_secrets (names only), run_with_secrets (runs a command with a secret's keys as environment variables, with output masked as [JFSecure: NAME]), and render_template (fills {{Secret:key}} placeholders into a file such as .env). There is deliberately no tool that returns a secret value; every use opens an approval window in the app showing the program, the exact command and the secret.
- When to use it
- Use it when an agent needs to authenticate or run commands that require credentials, but you do not want the values to appear in the model's context, transcripts or logs. It suits workflows such as calling an API with a token, rendering a .env file, or using a Git credential helper, with per-use approval in the desktop app.
- Requirements
- A local desktop install of the JFSecure app (macOS, Windows or Linux) with the vault open and unlocked; the jfs command must be on PATH (installed with the app, via Homebrew, .deb, or the app's Settings). The MCP server is added as a stdio server, for example with the command jfs and argument mcp. No environment variables, headers or separate authentication are declared.
Installation
In SourceWeft
- Open JFSecure in the dashboard and add it to a workspace.
- Enable the server for the chats that should use its tools.
Desktop only via STDIO. STDIO servers start a local process, so they need the SourceWeft desktop host.
Other MCP clients
Follow the launch instructions in the repository.
README
jfs — secrets for AI agents that never see them
jfs is the command line and MCP server of JFSecure, an offline password and
snippet manager. It lets Claude Code, Cursor or any MCP agent use a secret without ever getting it — and you
approve every use in the app.
This repository is the source of jfs itself, so you can read exactly what an agent talks to. It is a thin client:
it sends one JSON request over a local pipe to the running, unlocked JFSecure app and prints the answer. It never
opens vault files, never sees the vault password and has no crypto. (The app is a separate download; jfs ships with it.)
MCP tools
There is no "get" tool, on purpose. Every use opens an approval window in JFSecure that shows the program, the exact command and the secret: allow once, allow 15 minutes, or deny. For Claude Code a 15-minute approval covers only that command and that secret.
Set up
- Install JFSecure and open your vault:
brew install theone55/jfsecure/jfsecure(macOS),scoop bucket add jfsecure https://github.com/theone55/scoop-jfsecure; scoop install jfsecure/jfsecure(Windows), or the installer (Windows, macOS, Linux).jfscomes with it: on Windows the app puts it on PATH at its first start (open a new terminal afterwards); on macOS (.dmg) and the Linux AppImage use Settings → Install the jfs command; Homebrew and the .deb install it for you. - Add the MCP server:
Cursor (~/.cursor/mcp.json), Claude Desktop, Windsurf, VS Code — any stdio MCP client:
More: https://secure.jfolio.org/agents
Also as an MCP bundle (.mcpb, Windows / macOS / Linux) on the releases page, and in the official MCP Registry as io.github.theone55/jfs.
Command line
Full guide: https://secure.jfolio.org/cli
What it protects — and what it doesn't
- The model never receives a value, so it can't end up in a transcript or a log.
- A prompt-injected agent can only ask; you see the exact command.
- The pipe is your OS user's only, and the app identifies the caller through the OS, not by what it says.
- Masking is a seatbelt, not a wall: a command you approve can still send a value away. Read the command.
Build
The copy here follows each JFSecure release (version in Cargo.toml = the app's version it shipped with).
Issues and questions are welcome here.
MIT License.
Source: README.md at commit 8f2cab3
Tools
0Version history
2- v2.6.1LatestOct 11, 2026
- v2.6.0Oct 11, 2026

