Symaira Vault
danieljustus/symaira-vault
Go command-line password manager with age encryption and an MCP server for AI agents
Symaira Vault is a command-line password manager, symvault, written in Go, with age encryption and a built-in MCP server so AI agents can use credentials under human control. Its MCP slash commands are surfaced in Hermes, Claude Code and OpenCode.
What Symaira Vault does
Symaira Vault is a command-line password manager, symvault, written in Go. It encrypts with age (X25519 and ChaCha20-Poly1305), caches the unlocked session in the OS keyring with a 15-minute TTL, and supports TOTP codes, clipboard auto-clear, autotype, git sync and multi-user vaults through age recipients. The README describes it as pre-1.0 and ships a built-in MCP server for AI agents.
The MCP server runs over stdio or HTTP with scoped token management and exposes guided slash commands such as add-credential, rotate-credential, find-and-use and share-credential in Claude Code, OpenCode and Hermes. Native secure-input dialogs collect credentials from agents without exposing them in chat, and review-gated intake stages loose credential files in an encrypted quarantine first. An opt-in egress broker attaches credentials to an agent's outbound requests server-side, and a paired phone can approve or deny agent write requests. It runs on macOS, Linux, Windows and FreeBSD.
Key features
- age encryption with an OS keyring session cache
- MCP server over stdio and HTTP with scoped token management
- MCP slash commands for adding, rotating, finding and sharing credentials
- Native secure-input dialogs that keep credentials out of agent chat
- Egress credential broker that injects secrets into an agent's outbound requests
- Approval devices for real-time human approval of agent write requests
When to use it
- Let Hermes or Claude Code use API keys without pasting them into the conversation
- Run a command with vault secrets injected as environment variables
- Quarantine loose .env files for human review before they enter the vault
Who it is for: Terminal users who run AI agents and want an encrypted, local password manager that agents can reach through MCP.
How it fits with Hermes Agent
Symaira Vault is a general tool used with several agents, and its guided MCP slash commands appear in Hermes alongside Claude Code and OpenCode. The repository carries the hermes-agent and hermes-skill topics.
How to install Symaira Vault
These commands are copied from the project's README. Check the repository for the latest steps before you run them.
curl -sSfL https://raw.githubusercontent.com/danieljustus/symaira-vault/main/scripts/install.sh | shNote: The README marks it pre-1.0, with the CLI surface and vault format still stabilizing, and advises keeping tested backups.
FAQ
What is Symaira Vault?
Symaira Vault is a command-line password manager written in Go that encrypts with age. It includes an MCP server so AI agents can request and use credentials through scoped, approval-gated access.
Does Symaira Vault work with Hermes Agent?
Yes. The README lists Hermes among the agents that surface its MCP slash commands, next to Claude Code and OpenCode.
How do I install Symaira Vault?
On macOS or Linux, run the install.sh script with curl and sh, or use Homebrew with brew tap danieljustus/tap and brew install symvault. Windows has an install.ps1 script and a Scoop bucket, and a Nix flake is also provided.
Similar security for Hermes Agent
All securitySecurity layer for Hermes Agent with taint tracking, a policy engine and outbound secret scrubbing
swytchcodehq Agent Install MonitorLocal history of every package, Docker image and repository your Hermes Agent installs
Adolanium Hermes Plugin ShodanShodan host intel, search, DNS and CVE lookups for Hermes Agent, with credit budgeting
skalenetwork ReefRun Hermes, OpenClaw and your own agents in microsandbox microVMs with TOML-defined policy
aiconnai AgentShieldOffline Rust scanner for risky behavior in MCP servers and agent tools, with a Hermes Agent adapter
anpicasso Hermes Jev ApprovalsPlugin that serves TypeSafe's Jev model as the reviewer for Hermes Agent smart command approvals
Related guides: How to run Hermes Agent securely