EnigmAgent MCP

AES-256-GCM + Argon2id encrypted local vault that resolves {{PLACEHOLDER}} secrets for AI agent credentials.

Documentation

EnigmAgent

Local encrypted credential storage and operator-approved execution for AI agents. The integrated 3.0.0 release contains an authenticated vault, a Node administrator, a bounded MCP/REST gateway, a Python client and ten native framework integrations.

Start here

GoalEntry point
Understand what is released and testedIntegrated release v3
Download the versioned distributionsGitHub releases
Use a native agent frameworkPython SDK
Run the MCP/REST gatewayGateway
Manage a vault without writing application codeAdministrator
Run a source-pinned containerContainer
Check security boundariesThreat model and security policy
Inspect earlier source versionsPreserved versions
Review integration evidenceNative runtime evidence

Package registry versions and browser-store packages are separate publication channels. A GitHub source change does not silently update npm, PyPI, a browser extension or a user's existing installation. Use the versioned release artifacts and their checksums; inspect a registry's actual version before installing it.

Why a fixed-operation broker?

A tool that returns a decrypted credential also gives that credential to its caller. Placeholder syntax alone cannot keep it out of an agent's context. EnigmAgent therefore separates two modes:

  • Agent mode: the operator defines fixed GET/HEAD operations. The agent selects only an operation name. The broker attaches the credential to the configured destination and returns only {operation, status, ok}. Upstream response bodies and headers are discarded, including reflected or encoded credentials.
  • Explicit trusted-backend mode: raw resolution requires deliberate opt-in. It is incompatible with the operation-broker transport and is not a model-isolating interface.

Default MCP mode exposes metadata only. REST always requires authentication. The broker allows public IPv4 HTTPS destinations. Fixed 127.0.0.1 HTTP destinations require explicit operator enablement. Redirects, user-selected URLs/headers and private/reserved egress destinations are not accepted.

Native integrations

FrameworkFactory keyTested packageVersion
LangChainlangchainlangchain-core1.6.3
LangGraphlanggraphlanggraph1.2.11
LlamaIndexllamaindexllama-index-core0.14.24
CrewAIcrewaicrewai1.15.22
Haystackhaystackhaystack-ai3.1.1
Microsoft Agent Frameworkagent_frameworkagent-framework-core1.18.0
smolagentssmolagentssmolagents1.26.0
Agnoagnoagno3.0.10
PydanticAIpydantic_aipydantic-ai-slim2.44.0
AutoGen Coreautogenautogen-core0.7.5

These are third-party compatibility integrations maintained in this repository. Each is executed against a synthetic encrypted vault and a real authenticated local service. The tests check native results, available tracing/serialization surfaces and rejection of unknown operations. They are not claims of upstream endorsement, upstream merge, model quality or formal noninterference.

LangGraph includes checkpoint inspection. Haystack includes a serialized pipeline round trip with an explicit trusted-module allowlist. PydanticAI executes a local FunctionModel-driven agent loop; it does not call a paid model. MCP interoperability is also checked with the independently installed official Python MCP client.

Authenticated storage

New vaults use Argon2id and AES-256-GCM. Vault format v2 authenticates the complete entry set together, including names, domains and values. The envelope header is bound as associated data. Writes are revision-checked and atomically replace the current file after a flushed temporary write. A failed write does not update the session's committed in-memory state. Failed unlock attempts lock the old session.

Legacy format v1 is read-only until an explicit migration. Migration verifies all entry ciphertexts and preserves the original file as a permanent .v1-backup, as well as the rolling .bak. Legacy domain metadata was not authenticated by v1; its historical correctness cannot be recovered cryptographically by migration. Review old bindings and independently configure approved destinations.

A compromised broker process, administrator or operating system is outside this boundary. Hostile generated code needs an independently permissioned broker account/container; sharing an OS identity is not a sandbox. See the threat model for backup, rollback, Windows permissions and resource-limit qualifications.

Verify from source

Use Node.js 22 or newer. The full native integration matrix is tested with Python 3.12; the dependency-light client requires Python 3.10 or newer.

cd platforms/mcp-server
npm ci --ignore-scripts --no-audit --no-fund
npm test
node tests/verify-package.mjs

The integrated GitHub workflow additionally executes the Python integrations, installs built packages in clean environments, and starts the actual Docker image. Tagged release publication depends on those checks succeeding. No recurring maintenance task or mass outreach is configured.

Historical platform code

The browser extension, PWA, native GUI/IDE/mobile wrappers and older integration prototypes remain available as historical source. They are not certified by the Node/Python v3 release tests, and legacy v1 browser storage is not interchangeable with the new v2 Node vault. Their original files are also retained in the complete versioned source archives. Platform status distinguishes validated components from historical material instead of advertising every folder as a completed supported product.

Contributing and citation

See CONTRIBUTING.md, CITATION.cff and the integration plan. Contributions must solve a real integration need and include reproducible evidence. Do not mass-post issues, request artificial engagement or re-contact maintainers who declined a proposal.

MIT License. Copyright 2026 Francisco Angulo de Lafuente.