npm · policyvault-mcp
$npx -y policyvault-mcp@1.6.2 POLICYVAULT_MCP_SERVER_URL (required) — Bare origin of the PolicyVault server (e.g. https://app.policy-vault.org, or your self-hosted origin). Refused if it embeds credentials or a path.
POLICYVAULT_MCP_TOKEN (required) · secret — Machine-identity bearer credential (pvmk_...), minted by the vault operator in the PolicyVault app with exactly the scopes the agent should hold. Never logged; deleted from the process environment after being read.
POLICYVAULT_MCP_SCOPES — Optional comma-separated scope list to narrow which tools are advertised (display-side only; enforcement is always server-side).