Credential isolation for AI agents. Inject secrets at the network boundary.
io.github.getaegis/aegis
https://github.com/getaegis/aegis
STDIO
2 required env vars
Hosted endpoint — paste into any MCP client.
Configuration this server reads at startup.
Master encryption key for the credential vault
Hex-encoded 32-byte salt for key derivation (generated by aegis init)
Directory for vault databases and registry (default: .aegis/)
Gate proxy port (default: 3100)
Log verbosity: debug, info, warn, error (default: info)
Log output format: json or pretty (default: json)
Named vault to use (default: default)
Require agent authentication on every request (true/false, default: false)
Policy enforcement mode: enforce, dry-run, or off (default: enforce)
Directory containing YAML policy files
Enable Prometheus metrics endpoint (true/false, default: true)
Where to find authoritative docs and source for aegis.
Open MCP Agent Studio and connect this server to Claude, GPT, Gemini, DeepSeek and more — no install required.
Open Agent Studio