</>MCP Agents Market
MCP Server

varlock

by dmno-dev4.3kTypeScriptUpdated 2026-09-03

AI-safe .env files: Schemas for agents, Secrets for humans.

Claude Desktop

Varlock is an MCP server that provides AI agents with safe access to environment configuration schemas without exposing sensitive secrets. It extends traditional .env files with a declarative schema format (.env.schema) that includes type validation, variable descriptions, and security metadata that AI agents can read, while keeping actual secret values hidden. The MCP server exposes Varlock's documentation through both HTTP and SSE transports, enabling AI assistants to help developers configure environment variables securely. This separation ensures agents have full context about configuration structure while maintaining zero-knowledge of production credentials.

Key Features

MCP server endpoints (HTTP and SSE) exposing Varlock documentation to AI agents
Schema-based .env files with JSDoc-style decorators for types, validation, and sensitivity flags
Proactive secret leak scanning via git hooks and runtime log redaction
Plugin system for declarative secret loading from 1Password, AWS Secrets, Azure Key Vault, HashiCorp Vault, and 15+ other backends
Multi-environment management with automatic .env.* file loading based on environment flags
CLI tools for validation, pretty-printing, and running processes with resolved environment variables
VSCode extension for .env.schema syntax highlighting and IntelliSense
Framework integrations for Next.js, Astro, Nuxt, Vite, Expo, and Cloudflare

Use Cases

  • 01Enabling AI coding assistants to understand project configuration requirements without exposing API keys
  • 02Validating environment variables across development, staging, and production environments with type safety
  • 03Centralizing secret management by pulling credentials from 1Password, Bitwarden, or cloud provider vaults
  • 04Preventing accidental secret leaks in AI-generated code through automated scanning
  • 05Documenting environment variable requirements for team collaboration without maintaining outdated .env.example files
  • 06Running Python, Node.js, or other scripts with validated and type-checked environment variables

Related MCP Servers

View more

varlock — FAQ

What is the Varlock MCP server?+

The Varlock MCP server exposes Varlock's documentation through Model Context Protocol endpoints (HTTP and SSE), allowing AI agents to understand environment configuration patterns and best practices. It helps AI assistants provide context-aware guidance on setting up .env.schema files without ever accessing actual secret values.

How do I install the Varlock MCP server?+

You can connect to the publicly hosted Varlock Docs MCP server at https://docs.mcp.varlock.dev/mcp (HTTP) or https://docs.mcp.varlock.dev/sse (SSE transport). For the core Varlock CLI, install via npx varlock init for JavaScript projects, brew install dmno-dev/tap/varlock for Homebrew, or use the Docker image ghcr.io/dmno-dev/varlock:latest.

Which AI clients work with Varlock MCP server?+

The Varlock MCP server works with any MCP-compatible client including Claude Desktop, and other tools that support the Model Context Protocol. The hosted endpoints use standard HTTP and SSE transports for broad compatibility.

Do I need API keys to use Varlock?+

The Varlock MCP documentation server requires no API keys to access. For using Varlock plugins to fetch secrets, you'll need credentials for your chosen backend (e.g., 1Password service account token, AWS credentials, or Azure Key Vault access).

Is Varlock free to use?+

Yes, Varlock is open source and published under an npm license. The core tool, CLI, plugins, and MCP server are all freely available.

What is a .env.schema file?+

A .env.schema file is an enhanced .env file that uses JSDoc-style comments to define types, validation rules, sensitivity flags, and descriptions for environment variables. Unlike .env.example files that quickly become outdated, .env.schema serves as a single source of truth that AI agents can safely read.

How do I install varlock?+

Open the source repository on GitHub and follow its README. varlock is a mcp server — MCP Agents Market links you directly to the official repo.

Is varlock free?+

varlock is an open-source project hosted on GitHub. Check the repository for its license and any usage requirements.

Related searches