Skip to main content
Relic includes a built-in MCP server that lets AI assistants manage your secrets without ever seeing the actual values. Run relic mcp to start the server over stdio.

Setup

You must be authenticated before using the MCP server. Run relic login if you haven’t already.

Cursor

Add this to .cursor/mcp.json in your project root or global Cursor settings. This applies to both Cursor IDE and Cursor CLI.

Claude Code

This registers the server globally in ~/.claude.json. To scope it to the current project, add the --scope project flag:

Codex

Run the CLI command:
Or add it manually to ~/.codex/config.toml (global) or .codex/config.toml (project-scoped):

Zed

Add this to your Zed settings.json:
Zed supports MCP Tools and Prompts only — Resources and Sampling are not yet implemented.

OpenCode

Add this to your opencode.jsonc or opencode.json:

Claude Desktop

Add this to claude_desktop_config.json:

Available Tools

whoami

Returns the authenticated user’s name, email, and plan.

list-projects

Lists all projects (owned and shared) with their environments and folders.

list-secrets

Lists secret key names, and scopes for a given project environment.
This tool returns secret names only — never decrypted values. This is by design. Relic’s zero-knowledge model means secret values should never appear in an AI context window.

get-current-project

Reads relic.toml from the current directory and returns the project ID and config path. Useful for the AI to understand which project it’s working in.

run-with-secrets

Runs a command with decrypted secrets injected as environment variables. Returns the command’s stdout, stderr, and exit code.
Secret values are decrypted locally and injected into the child process environment. They are never included in the tool response — only the command output is returned to the AI.

Security Model

The MCP server inherits Relic’s client-side encryption. All decryption happens locally on your machine, and the server communicates with the AI assistant over stdio (no network exposure).

Example Usage

Once configured, you can ask your AI assistant things like:
  • “What secrets are in my production environment?”
  • “List all my Relic projects”
  • “Run my test suite with staging secrets”
  • “Which project is this directory linked to?”
The assistant will use the appropriate MCP tool and return the results without ever seeing your secret values.
Last modified on May 2, 2026