MCP credential storage

MCP credential storage, without keys in config files

Most MCP servers want an API key in a JSON config or an environment variable. MoltenRock Connect keeps the keys and speaks MCP itself.

The short answer

The problem with MCP credentials is where they sit: a plain-text key in each server’s config, readable by anything on the machine. MoltenRock Connect is a single local MCP server for 31 business platforms. You add each key once in the app (optionally in MoltenRock’s Secure Enclave vault); Claude Desktop, Claude Code and Cursor connect to Connect over MCP and never see a key.

The problem

Every MCP server brings its own secret

  • Keys in JSON
    claude_desktop_config.json and similar files hold keys in plain text, next to every other server’s.
  • Env vars leak
    Environment variables are inherited by child processes and show up in crash reports and logs.
  • One key per server
    Five MCP servers means five places to rotate a key, and five packages you have to trust with it.

How MoltenRock handles it

One local MCP server that holds the keys

  • One server, 31 platforms
    Stripe, Shopify, WooCommerce, ShipStation, AfterShip, Cloudflare and more, behind one MCP connection.
  • Keys in the app
    In your Mac’s Keychain, or in MoltenRock’s Secure Enclave vault with vault mode (MoltenRock Pro).
  • Answers, not keys
    Tools return data; customer names and addresses arrive as tokens.
  • Writes need you
    On Stripe, the write path is a proposal you approve with Touch ID.

How it works

Connect your MCP client

  1. 01
    Install MoltenRock Connect
    Free for Mac.
  2. 02
    Add your platforms
    Paste each key once in the app.
  3. 03
    Add Connect to your client
    Agent Setup in Connect shows the exact steps for Claude Desktop, Claude Code or Cursor.

Straight answer

What this replaces, and what it doesn’t

Stays on your Mac

  • Platform keys, in Connect or MoltenRock
  • Your MCP client’s config, with no keys in it
  • Decisions on any Stripe change

Leaves your Mac

  • Calls from your Mac to each platform
  • Tool results, to your MCP client
  • Connect covers its 31 platforms; other MCP servers still need their own keys

Questions

What people ask first

Which MCP clients work?

Claude Desktop, Claude Code and Cursor. Agent Setup in Connect walks through each one.

Is Connect a remote MCP server?

No. It runs on your Mac. There is no hosted endpoint and no account.

What about keys for other MCP servers?

For those, a vault still beats a config file. MoltenRock releases keys to OpenClaw and Hermes today; other apps’ keys are coming.

What does it cost?

Connect is free with two platforms. Connect Pro unlocks all 31 for $9.99, one time, on up to five Macs.

Take the keys out of your MCP config.

MoltenRock Connect is free for Mac.