Developer reference

MCP tools

Connect an MCP client to local encryption tools and hosted API operations.

MCP Server

Model Context Protocol (MCP) lets an AI application call tools. This server provides three local tools that need no API key and seven hosted API tools. Local means processing stays in the MCP server process, not necessarily outside the model's view: check what your MCP client sends to its model.

Local tools (no API key needed)

deny_local_encrypt      - Encrypt text locally
deny_local_decrypt      - Decrypt text locally
deny_local_create_decoy - Generate deniable control data locally

API tools (require API key)

deny_encrypt      - Encrypt via API
deny_decrypt      - Decrypt via API
deny_create_decoy - Create decoy via API
deny_vault_store  - Store to vault
deny_vault_list   - List vault items
deny_vault_get    - Get vault item
deny_usage        - Check API usage

Configuration

// Add to your MCP client config (e.g. claude_desktop_config.json)
{
  "mcpServers": {
    "deny-sh": {
      "command": "node",
      "args": ["path/to/deny-mcp-server.cjs"],
      "env": {
        "DENY_API_KEY": "dk_your_key_here"  // optional, only for API tools
      }
    }
  }
}

Full MCP docs: deny.sh/agents