smithery.ai

decrypt-secrets

Decrypt MCP tokens for remote sessions

First seen Mar 20, 2026

Installation

$ npx skills add https://smithery.ai

Also in this package

Other skills from smithery.ai · top by installs.

npx skills add https://smithery.ai

Browse all from smithery.ai

More details

Agent compatibility

Declared targets from SKILL.md / docs. Unmarked agents are not listed — the skill may still install via the CLI.

Claude Code Not declared
Cursor Not declared
Codex Not declared
GitHub Copilot Not declared
Windsurf Not declared
Gemini CLI Not declared
Cline Not declared
OpenCode Not declared

Package contents

Files included with this skill beyond the listing page.

  • skill md SKILL.md 1,728 B
  • docs SUMMARY.md 61 B

History

  1. First seen on skills.sh
  2. First recorded snapshot · 1 installs

SKILL.md

Decrypt Secrets

Decrypt your encrypted MCP tokens at the start of a remote session.

When NOT to Use

  • When the task doesn't match this skill's scope -- check related skills
  • When a more specialized skill exists for the specific task

When to Use

  • At the start of a remote/web session when MCP servers need tokens
  • When you see "Encrypted secrets found but not decrypted" in session startup
  • When MCP servers fail due to missing authentication

How It Works

  1. Your tokens are stored encrypted in .env.local.encrypted (safe to commit)
  2. Running this decrypts them to .env.local (gitignored)
  3. MCP servers then use the tokens automatically

Instructions

Run the decryption script and enter your passphrase:

node scripts/secrets/decrypt-secrets.js

You'll be prompted for the passphrase you set when encrypting.

First-Time Setup

If you haven't encrypted your secrets yet:

  1. Add your tokens to .env.local:

`` GITHUBTOKEN=ghpyourtoken SONARTOKEN=sqpyourtoken CONTEXT7APIKEY=your_key ``

  1. Encrypt them:

``bash node scripts/secrets/encrypt-secrets.js ``

  1. Commit .env.local.encrypted to your repo
  1. In future sessions, just run the decrypt script

Security Notes

  • .env.local is gitignored - your actual tokens are never committed
  • .env.local.encrypted uses AES-256-GCM encryption
  • Choose a strong passphrase (8+ characters)
  • Your passphrase is never stored anywhere

Version History

Version Date Description
1.0 2026-02-25 Initial implementation