# Password sharing for AI agents

QuarryPasswords lets AI agents create encrypted, one-time password and API-key shares. The local MCP tool uses free guest sharing: no account, login, API key or paid plan is required.

## Availability

Install @specscreen/quarry-passwords-mcp@0.1.0 from npm. The client runs locally; there is no hosted MCP endpoint.

Clients must support local MCP servers over stdio. A website URL alone cannot connect a client to this integration.

## What the tool does

create_share accepts 1–2 credential items. It encrypts them on the machine running the tool, uploads encrypted content to https://passwords.quarry.tools/api/shares, and returns the full one-time link.

It uses the same encryption format as the website. Credentials and the link decryption key are not sent to the service. Recipients reveal the share in their browser.

The tool cannot access accounts, paid features, dashboards or credential requests. It does not list, reveal, delete or send shares to other people. Normal guest rate limits apply.

## Connect your client

Install Node.js 22 or newer. Add the configuration below to a client that supports local stdio MCP servers. It downloads the pinned public package; no repository checkout is required.

The default destination is https://passwords.quarry.tools. The owner may set QUARRY_ORIGIN to an HTTPS staging origin or an HTTP loopback origin for local development. The production service must be deployed before that destination can accept shares.

```json
{
  "mcpServers": {
    "quarry-passwords": {
      "command": "npx",
      "args": [
        "--yes",
        "@specscreen/quarry-passwords-mcp@0.1.0"
      ]
    }
  }
}
```

## Tool inputs

Each item needs a label and exactly one of secret or secretEnv. Optional fields are service (defaults to other), username (defaults to empty), note and a web login url. This version supports passwords and API keys, not structured credit-card fields.

expiry accepts 2h, 1d, 7d, once; the default is 1d. “once” means up to 30 days if unused. Every expiry option allows only one successful reveal.

Optional passphrase or passphraseEnv adds protection. Use one, not both, with 8–128 characters. maxAttempts is only valid with protection (1–10, default 5). Without a passphrase, anyone with the full link can reveal the share.

The response contains url, expiresAt (UTC ISO timestamp), itemCount and passphraseProtected. It never returns the credentials or passphrase.

Example using an owner-provisioned environment variable:

```json
{
  "items": [
    {
      "service": "github",
      "label": "GitHub for Acme",
      "username": "ops@example.com",
      "secretEnv": "QUARRY_SHARE_GITHUB"
    }
  ],
  "expiry": "1d"
}
```

## Keep secrets out of the conversation

The owner can provision QUARRY_SHARE_* environment variables for the local process and pass their names through secretEnv or passphraseEnv. Only provision credentials the agent is allowed to share. The tool does not read arbitrary files, browser sessions or the website’s .dev.vars.

Environment references keep plaintext out of tool arguments. Inline credentials and returned links may still be retained in client history or by the agent provider. Anyone with the full link and any required passphrase can reveal the share, including the agent.

Treat links as secrets. Send a passphrase through a separate channel. Encryption cannot protect credentials after they are displayed on a compromised device or copied by the recipient.

## Rules for agents

Create a share only when the user asks. Do not send its link to another person unless instructed. Never press Reveal or call a reveal endpoint to test a newly created share: that consumes it.

Creation is not idempotent. A timeout or lost response can leave a share created without returning its link. Do not retry automatically. Unused shares expire normally.

Opening a share page alone does not consume it. A successful reveal deletes the encrypted contents from active storage; it does not erase recipient copies or infrastructure recovery history.

Do not include real share URLs, request URLs, credentials or personal account data in crawl indexes or public documentation. robots.txt is crawl guidance, not access control.

## Reference

- [Tool schema](https://passwords.quarry.tools/agents/mcp.json): Generated from the implemented MCP input schema; this JSON file is documentation, not a transport endpoint.
- [Security](https://passwords.quarry.tools/security)
- [Pricing](https://passwords.quarry.tools/pricing)
- [Privacy](https://passwords.quarry.tools/privacy)
- [Terms](https://passwords.quarry.tools/terms)
- Support: support@specscreen.com
