Tool

Pincer-MCP - Stop AI Agents From Reading Their Own Credentials

Pincer-MCP is a security-hardened Model Context Protocol gateway that implements proxy token architecture to prevent AI agents from seeing real API keys. Agents receive ephemeral proxy tokens (pxr_xxx) while Pincer stores encrypted credentials in the OS keychain (macOS Keychain, Windows Credential Manager, GNOME Keyring) and performs just-in-time decryption during API calls, immediately scrubbing keys from memory afterward. Includes tamper-evident audit logging with SHA-256 chain hashing and fine-grained per-agent, per-tool authorization.

Details

Type Tool
Fix Available No
#mcp #credentials #keychain #encryption #Audit

Related Resources