Hermes Atlas
Security & sandboxing · works with Hermes Agent

Symaira Vault

danieljustus/symaira-vault

Go command-line password manager with age encryption and an MCP server for AI agents

In short

Symaira Vault is a command-line password manager, symvault, written in Go, with age encryption and a built-in MCP server so AI agents can use credentials under human control. Its MCP slash commands are surfaced in Hermes, Claude Code and OpenCode.

What Symaira Vault does

Symaira Vault is a command-line password manager, symvault, written in Go. It encrypts with age (X25519 and ChaCha20-Poly1305), caches the unlocked session in the OS keyring with a 15-minute TTL, and supports TOTP codes, clipboard auto-clear, autotype, git sync and multi-user vaults through age recipients. The README describes it as pre-1.0 and ships a built-in MCP server for AI agents.

The MCP server runs over stdio or HTTP with scoped token management and exposes guided slash commands such as add-credential, rotate-credential, find-and-use and share-credential in Claude Code, OpenCode and Hermes. Native secure-input dialogs collect credentials from agents without exposing them in chat, and review-gated intake stages loose credential files in an encrypted quarantine first. An opt-in egress broker attaches credentials to an agent's outbound requests server-side, and a paired phone can approve or deny agent write requests. It runs on macOS, Linux, Windows and FreeBSD.

Key features

  • age encryption with an OS keyring session cache
  • MCP server over stdio and HTTP with scoped token management
  • MCP slash commands for adding, rotating, finding and sharing credentials
  • Native secure-input dialogs that keep credentials out of agent chat
  • Egress credential broker that injects secrets into an agent's outbound requests
  • Approval devices for real-time human approval of agent write requests

When to use it

  • Let Hermes or Claude Code use API keys without pasting them into the conversation
  • Run a command with vault secrets injected as environment variables
  • Quarantine loose .env files for human review before they enter the vault

Who it is for: Terminal users who run AI agents and want an encrypted, local password manager that agents can reach through MCP.

How it fits with Hermes Agent

Symaira Vault is a general tool used with several agents, and its guided MCP slash commands appear in Hermes alongside Claude Code and OpenCode. The repository carries the hermes-agent and hermes-skill topics.

How to install Symaira Vault

These commands are copied from the project's README. Check the repository for the latest steps before you run them.

curl -sSfL https://raw.githubusercontent.com/danieljustus/symaira-vault/main/scripts/install.sh | sh

Note: The README marks it pre-1.0, with the CLI surface and vault format still stabilizing, and advises keeping tested backups.

FAQ

What is Symaira Vault?

Symaira Vault is a command-line password manager written in Go that encrypts with age. It includes an MCP server so AI agents can request and use credentials through scoped, approval-gated access.

Does Symaira Vault work with Hermes Agent?

Yes. The README lists Hermes among the agents that surface its MCP slash commands, next to Claude Code and OpenCode.

How do I install Symaira Vault?

On macOS or Linux, run the install.sh script with curl and sh, or use Homebrew with brew tap danieljustus/tap and brew install symvault. Windows has an install.ps1 script and a Scoop bucket, and a Nix flake is also provided.

Similar security for Hermes Agent

All security

Related guides: How to run Hermes Agent securely