HashiCorp Vault MCP connector
HashiCorp Vault is a secrets management platform for securely storing, accessing, and controlling sensitive data such as credentials, tokens, and keys. The HashiCorp Vault MCP connector allows AI agents to create, read, update, and delete secrets, as well as manage secret versions and metadata. It also supports enabling, disabling, and listing secrets engines, giving agents broader control over how secrets are organized and secured across an instance.
Authentication type
- API Key - Requires a static API key to be configured before the agent can connect to the service.
Uses
Use the HashiCorp Vault MCP connector to perform the following actions:
- Retrieve encrypted secrets and credentials for automated workflows without exposing raw values
- Rotate application passwords and access keys across environments on a schedule
- Enforce least-privilege access with granular ACL policies for teams and services
- Generate short-lived Vault tokens to authenticate automated workflow tasks securely
- Audit which secrets engines and authentication methods are active across a tenant
- Version and roll back secrets safely using the KV v2 secrets engine
- Permanently remove obsolete secret versions to reduce security and compliance risk
- Onboard new applications quickly by enabling and configuring secrets engines on demand
Example prompts
Use the following example prompts to invoke HashiCorp Vault MCP connector tools from your AI assistant or Boomi Connect workflow:
Show me the current database password stored in HashiCorp Vault.Update the access key for our payment gateway in HashiCorp Vault.List all the secrets engines enabled in HashiCorp Vault right now.Create a new access token for our automation workflow in HashiCorp Vault.What secrets are stored under the finance team's path in HashiCorp Vault?Delete the old version of the Slack webhook secret in HashiCorp Vault.Show me all the access policies configured in HashiCorp Vault.Set up a new secrets engine for our marketing team in HashiCorp Vault.Permanently remove the outdated AWS credentials from HashiCorp Vault.List the authentication methods available for logging into HashiCorp Vault.
HashiCorp Vault MCP connector tools
The HashiCorp Vault MCP connector provides the following tools. Each tool maps to a specific action you can invoke from your AI agent or automation.
| Tool | Description |
|---|---|
| hashicorpvault_hashicorpvaultreadkvv2secret_invoke | Retrieve a secret from the KV v2 secrets engine by its path. |
| getSecretData | Read a secret |
| createOrUpdateSecretData | Create or update a secret |
| patchSecretData | Patch an existing secret |
| deleteSecretData | Delete the latest version of a secret |
| getSecretMetadata | Read secret metadata |
| destroySecretVersions | Permanently destroy secret versions |
| listMounts | List all mounted secret engines |
| disableSecretsEngine | Disable a secrets engine |
| enableSecretsEngine | Enable a new secrets engine |
| listAuthMethods | List all auth methods |
| loginWithAuthMethod | Create a Vault token |
| listAclPolicies | List ACL policies |
| createOrUpdateAclPolicy | Create or update an ACL policy |