Skip to main content
Feedback

HashiCorp Vault MCP connector

Updated 

HashiCorp Vault is a secrets management platform for securely storing, accessing, and controlling sensitive data such as credentials, tokens, and keys. The HashiCorp Vault MCP connector allows AI agents to create, read, update, and delete secrets, as well as manage secret versions and metadata. It also supports enabling, disabling, and listing secrets engines, giving agents broader control over how secrets are organized and secured across an instance.

Authentication type

  • API Key - Requires a static API key to be configured before the agent can connect to the service.

Uses

Use the HashiCorp Vault MCP connector to perform the following actions:

  • Retrieve encrypted secrets and credentials for automated workflows without exposing raw values
  • Rotate application passwords and access keys across environments on a schedule
  • Enforce least-privilege access with granular ACL policies for teams and services
  • Generate short-lived Vault tokens to authenticate automated workflow tasks securely
  • Audit which secrets engines and authentication methods are active across a tenant
  • Version and roll back secrets safely using the KV v2 secrets engine
  • Permanently remove obsolete secret versions to reduce security and compliance risk
  • Onboard new applications quickly by enabling and configuring secrets engines on demand

Example prompts

Use the following example prompts to invoke HashiCorp Vault MCP connector tools from your AI assistant or Boomi Connect workflow:

  • Show me the current database password stored in HashiCorp Vault.
  • Update the access key for our payment gateway in HashiCorp Vault.
  • List all the secrets engines enabled in HashiCorp Vault right now.
  • Create a new access token for our automation workflow in HashiCorp Vault.
  • What secrets are stored under the finance team's path in HashiCorp Vault?
  • Delete the old version of the Slack webhook secret in HashiCorp Vault.
  • Show me all the access policies configured in HashiCorp Vault.
  • Set up a new secrets engine for our marketing team in HashiCorp Vault.
  • Permanently remove the outdated AWS credentials from HashiCorp Vault.
  • List the authentication methods available for logging into HashiCorp Vault.

HashiCorp Vault MCP connector tools

The HashiCorp Vault MCP connector provides the following tools. Each tool maps to a specific action you can invoke from your AI agent or automation.

ToolDescription
hashicorpvault_hashicorpvaultreadkvv2secret_invokeRetrieve a secret from the KV v2 secrets engine by its path.
getSecretDataRead a secret
createOrUpdateSecretDataCreate or update a secret
patchSecretDataPatch an existing secret
deleteSecretDataDelete the latest version of a secret
getSecretMetadataRead secret metadata
destroySecretVersionsPermanently destroy secret versions
listMountsList all mounted secret engines
disableSecretsEngineDisable a secrets engine
enableSecretsEngineEnable a new secrets engine
listAuthMethodsList all auth methods
loginWithAuthMethodCreate a Vault token
listAclPoliciesList ACL policies
createOrUpdateAclPolicyCreate or update an ACL policy
On this Page