FeaturesPricingFAQSecurityAffiliatesContact

MCP Server & API

ProphetKey runs a local Model Context Protocol (MCP) server inside the desktop app. Claude, Cursor, Windsurf and other AI agents connect over http://127.0.0.1:1421/mcp and go through the same proxy pipeline as your other tools — agents only ever see safe_key values, never your real provider keys.

Quick start

1. Open ProphetKey and start the local proxy (default port 1421).

2. Open the AI Access (MCP) tab and copy the generated configuration.

3. Paste it into Claude Desktop or Cursor under MCP settings:

{
  "mcpServers": {
    "prophetkey": {
      "url": "http://127.0.0.1:1421/mcp",
      "headers": {
        "Authorization": "Bearer <your-propagated-token>"
      }
    }
  }
}

The Bearer token is generated automatically on your device. Requests to /mcp without a valid token are rejected.

Option B — stdio via npm (Claude Code, Cursor CLI, agent SDKs)

For agents that expect a local stdio server, install the official bridge package prophetkey-mcp on npm. It forwards to the same local endpoint:

{
  "mcpServers": {
    "prophetkey": {
      "command": "npx",
      "args": ["-y", "prophetkey-mcp"],
      "env": { "PROPHETKEY_MCP_TOKEN": "<your-propagated-token>" }
    }
  }
}

Same tools, same proxy pipeline, same security model: the agent only ever sees safe_key values, and the token stays in your environment.

Handshake

Standard MCP sequence over JSON-RPC 2.0: initialize → notifications/initialized → tools/list → tools/call. Protocol version 2025-03-26.

Tools

ToolParametersDescription
prophetkey_list_keys—List keys in the current vault (name, provider, safe_key, health status).
prophetkey_get_key_infoname (string, required)Detail for a single key. Never returns the real key value.
prophetkey_proxy_status—Proxy status: running state, port, key count, request statistics.
prophetkey_health_check—Run a health check on all keys (expiry, usage, security score).
prophetkey_make_requestsafe_key, endpoint, method, bodyForward one request through the proxy pipeline with automatic key injection.

prophetkey_make_request

{
  "safe_key": "string (required)  // the key identifier to use",
  "endpoint": "string (required)  // e.g. "/v1/chat/completions"",
  "method":   "GET | POST | PUT | DELETE (required)",
  "body":     "object (optional)  // POST/PUT request body"
}

The request is forwarded through the same pipeline as the HTTP proxy: the real key is injected, usage and cost are recorded, and shadow-key honeypots plus time-window checks apply. When a time lock is active and outside the window, the request is blocked and returns isError: true.

Security model

  • safe_key only: agents never receive real key values. The proxy maps safe_key to the real provider credential on your device.
  • Local by default: everything runs on 127.0.0.1. No cloud round-trip for key material.
  • Fail-closed auth: unauthenticated /mcp requests are rejected with a constant-time check.
  • Rotation: regenerate safe_key mappings so compromised virtual keys stop working without reissuing your real provider key.
⚠ OpenAI-compatible only: the proxy forwards OpenAI-compatible endpoints. Fully custom, non-OpenAI-compatible APIs are not yet supported.

HTTP proxy alternative

Prefer not to use MCP? Point any OpenAI-compatible SDK or tool at http://127.0.0.1:1421 with Authorization: Bearer <safe_key> and it works identically. Status codes: 401 no/invalid auth, 403 invalid or revoked safe_key, 402 budget reached, 403 time-lock blocked.

← Getting Started

Streaming via MCP is available on Windows 10/11 today. macOS and Linux are on the roadmap for Q4 2026.