Lockbox

run.lockboxv0.1.0Updated Oct 6, 2026

Send API keys and private files to someone else's agent, end-to-end encrypted.

VerifiedStreamable HTTPWeb executableDeveloper ToolsFiles & StorageSecurity & Monitoring

Overview

AI-generated overview

Lets an assistant move API keys and private files between agents and .env files with end-to-end encryption, without printing or pasting them into chat.

What it does
Lockbox provides an agent-facing skill and plugin that teaches a coding agent to use the lockbox CLI, so secrets travel from one .env file to another without being displayed in the conversation. It is distributed as a skill in Agent Skills format plus plugin bundles for Claude Code, Codex and Cursor, and can also be added as a remote connector at where a Lockbox panel opens in the chat. The README lists no individual tool names; the capability is secret transfer between agents.
When to use it
Use it when you need to hand an API key or a private file to another person's agent, or move credentials between environments, and do not want the value to appear in chat history or terminal output. It is aimed at coding-agent workflows where .env files are the usual place secrets live. It is not a general file-sharing or storage service.
Requirements
A remote MCP endpoint at added as a connector in Claude.ai or ChatGPT, or the agent-side skill/plugin installed for Claude Code, Codex or Cursor. The README also requires the separate CLI installed globally from npm (npm i -g @opslane/lockbox) and a sign-in with an email address (lockbox login [email protected]). Node.js is needed for the npm install and npx commands. No API keys or headers are declared in the manifest.
Before you install
The server exists to move secrets, so treat every transfer as sensitive: API keys and private files pass through it, and the README says the CLI and the Lockbox server are not in this repository, so the encryption implementation cannot be inspected here. Signing in with an email address (lockbox login [email protected]) ties the account to that identity. The README gives no details on retention, logging, or who can decrypt, so verify those in the vendor documentation before sending production keys

Installation

In SourceWeft

  1. Open Lockbox in the dashboard and add it to a workspace.
  2. Enable the server for the chats that should use its tools.

Web executable via Streamable HTTP. Remote servers run from the web runtime once configured in a workspace.

Other MCP clients

Add this to your client's mcpServers config.

{
  "mcpServers": {
    "lockbox": {
      "type": "http",
      "url": "https://lockbox.run/mcp"
    }
  }
}

README

Lockbox skills and plugin

Send API keys and private files to someone else's agent, end-to-end encrypted. lockbox.run

This repo holds the agent-facing parts of Lockbox: the lockbox skill and a plugin bundle for Claude Code, Codex and Cursor. The skill teaches your coding agent to use the lockbox CLI (npm i -g @opslane/lockbox) so keys go from one .env to another without being printed or pasted into chat.

Install

Any agent that reads skills (via skills.sh):

bash
npx skills add opslane/lockbox-skills

Claude Code:

bash
claude plugin marketplace add opslane/lockbox-skillsclaude plugin install lockbox@opslane

Claude.ai and ChatGPT: add https://lockbox.run/mcp as a connector. The Lockbox panel opens in the chat.

Then install the CLI and sign in:

bash
npm i -g @opslane/lockboxlockbox login [email protected]

What's here

PathWhat it is
skills/lockbox/The skill (Agent Skills format)
plugins/lockbox/The plugin bundle: the same skill, manifests for Claude Code, Codex and Cursor, and mcp.json
.claude-plugin/marketplace.jsonA Claude Code marketplace with this one plugin

The CLI and the Lockbox server are not in this repo. Docs: lockbox.run/docs. Security questions: [email protected].

License

MIT, for the files in this repo. See LICENSE.

Source: README.md at commit 7ffe01e

Tools

0
Tool metadata has not been indexed yet.

Version history

1
  1. v0.1.0LatestOct 6, 2026