Sops MCP Server
by privacyplaybookio.github.privacyplaybook/sops-mcpv0.11.0
MCP server for creating and managing SOPS-encrypted secrets
context tax
queued
security
queued
cold start
queued
freshness
Active19d ago
Install Sops MCP server
Install in Claude Code
claude mcp add sops -e SOPS_MCP_AGE_PUBLIC_KEY='<sops-mcp-age-public-key>' -e SOPS_AGE_KEY='<sops-age-key>' -- uvx sops-mcpInstall in Cursor
{
"mcpServers": {
"sops": {
"command": "uvx",
"args": [
"sops-mcp"
],
"env": {
"SOPS_MCP_AGE_PUBLIC_KEY": "<sops-mcp-age-public-key>",
"SOPS_AGE_KEY": "<sops-age-key>"
}
}
}
}Add to ~/.cursor/mcp.json (global) or .cursor/mcp.json (project).
Install in Claude Desktop
{
"mcpServers": {
"sops": {
"command": "uvx",
"args": [
"sops-mcp"
],
"env": {
"SOPS_MCP_AGE_PUBLIC_KEY": "<sops-mcp-age-public-key>",
"SOPS_AGE_KEY": "<sops-age-key>"
}
}
}
}Settings → Developer → Edit Config (claude_desktop_config.json), then restart.
Install in VS Code
{
"servers": {
"sops": {
"type": "stdio",
"command": "uvx",
"args": [
"sops-mcp"
],
"env": {
"SOPS_MCP_AGE_PUBLIC_KEY": "<sops-mcp-age-public-key>",
"SOPS_AGE_KEY": "<sops-age-key>"
}
}
}
}Add to .vscode/mcp.json in your workspace.
Install in Windsurf
{
"mcpServers": {
"sops": {
"command": "uvx",
"args": [
"sops-mcp"
],
"env": {
"SOPS_MCP_AGE_PUBLIC_KEY": "<sops-mcp-age-public-key>",
"SOPS_AGE_KEY": "<sops-age-key>"
}
}
}
}Add to ~/.codeium/windsurf/mcp_config.json.
Configuration
| Variable | Required | Secret | Description |
|---|---|---|---|
| SOPS_MCP_AGE_PUBLIC_KEY | yes | — | Age recipient public key. Required at startup. |
| SOPS_AGE_KEY | — | yes | Age private key. Required at call time for any mutation tool (decrypt + re-encrypt). Read-only tools do not need it. |
Freshness
Active — last maintenance signal 19d ago. The newest of the signals below sets the band.
Last commit (default branch)
2026-09-21 · 19d ago · GitHub
Latest release
2026-09-10 · 30d ago · GitHub · v0.11.0
Package published
no data · npm/PyPI
Registry entry updated
2026-09-10 · 30d ago · official registry · v0.11.0
FAQ
›How do I install the Sops MCP server in Claude Code?
Run: claude mcp add sops -e SOPS_MCP_AGE_PUBLIC_KEY='<sops-mcp-age-public-key>' -e SOPS_AGE_KEY='<sops-age-key>' -- uvx sops-mcp. For Cursor, VS Code, Claude Desktop and Windsurf, use the install tabs above.
›Does Sops require an API key?
Yes. It expects SOPS_MCP_AGE_PUBLIC_KEY, SOPS_AGE_KEY, of which 1 is a secret.
›Can I use Sops as a remote (hosted) MCP server?
No hosted endpoint is published; it runs locally over stdio.
›Is Sops in the official MCP registry?
Yes, as io.github.privacyplaybook/sops-mcp.
Alternatives to Sops
Other security MCP servers.