MCP Directory

MCPtrove interactive resource

MCP Config Redactor — Share mcpServers JSON Without Leaking Secrets

Create a share-safe MCP configuration for debugging while keeping commands and structure intact.

The reusable resource

A browser-only MCP config sanitizer with explicit redaction paths, copyable JSON, and a downloadable clean file.

MCP Config Redactor creates a share-safe copy of an mcpServers configuration in your browser, replacing likely credentials while preserving the structure needed for debugging.

On this page

What MCP Config Redactor does

MCP Config Redactor helps you prepare an MCP configuration for troubleshooting, documentation, or support. Paste JSON into the tool, and it produces a sanitized copy that preserves the configuration’s structure while replacing values that resemble credentials.

This is useful when a reviewer needs context such as server names, commands, arguments, URLs, nested options, or environment-variable paths. Removing the entire configuration can hide the details needed to diagnose a problem, while sharing the original may expose tokens, passwords, cookies, or private keys.

The tool accepts arbitrary JSON, although MCP configurations commonly contain an mcpServers object. It processes the text in your browser and never makes a network request.

For example:

{
  "mcpServers": {
    "github": {
      "command": "npx",
      "args": ["-y", "@modelcontextprotocol/server-github"],
      "env": {
        "GITHUB_TOKEN": "ghp_example_value"
      }
    }
  }
}

The redacted result keeps the server name, command, arguments, and environment-variable structure while replacing the credential-shaped value with <REDACTED>.

How to use it

Open MCP Config Redactor and paste the JSON you are considering sharing. Include enough surrounding configuration to preserve useful troubleshooting context, but review the scope before processing it.

As you paste valid JSON, the tool updates the redacted result instantly and reports:

  • The number of values scanned.
  • The number of values replaced.
  • The paths where redactions occurred.

You can copy the sanitized JSON or download it as mcp-config-redacted.json. Review the result before sending it to anyone.

A practical workflow is:

  1. Copy the configuration from its source.
  2. Paste it into the redactor.
  3. Let the browser update the result.
  4. Review the count and redaction paths.
  5. Inspect both redacted and unchanged values.
  6. Copy or download the sanitized JSON.
  7. Share only the reviewed copy.

If the input is invalid JSON, the tool shows an actionable parse error and produces no output. Correct the indicated syntax issue and the result will update. Common causes include missing commas, unmatched braces, unquoted property names, and trailing commas.

Keep the original configuration unchanged while you work. This makes it easier to compare the sanitized copy with the configuration that is actually used and prevents accidental edits to your working setup.

How the analysis works

The redactor uses heuristics. It does not determine whether a particular MCP server accepts a value or whether a credential is active. Instead, it examines object keys case-insensitively and checks string values for recognizable credential patterns.

Key-name checks include:

CategoryExample matching names
Tokens and secretstoken, secret, clientSecret
Passwordspassword, passphrase
API credentialsapiKey, api_key, accessKey, access_key
Authorizationauthorization, bearer
Sessions and cookiescookie, session
Private keysprivateKey, private_key

The analysis also recognizes several value shapes, including bearer and basic authorization strings, common prefixes such as sk-, ghp_, github_pat_, and xox, PEM-formatted private-key blocks, and URLs containing username-and-password credentials.

When a value matches a check, the value is replaced with <REDACTED>. Object nesting, array positions, server names, and property paths remain in place.

Commands, arguments, ordinary URLs, and other non-secret configuration values are normally preserved. Placeholder strings such as YOUR_TOKEN, ${ENV_VAR}, <token>, and changeme also remain visible because they commonly document expected inputs rather than active credentials. Their presence does not prove that the configuration is ready to use.

How to interpret the output

The scanned-value count shows how much of the JSON the tool examined. The redaction count shows how many values it replaced. These numbers help with review, but they are not a security score.

The path list identifies each replacement. For example:

mcpServers.github.env.GITHUB_TOKEN

Use these paths to compare the sanitized result with the original and confirm that expected credential locations were handled.

Review the complete output, including values that were not redacted. Check that:

  • Server names and nesting remain understandable.
  • Commands and arguments are still available for troubleshooting.
  • URLs do not contain credentials.
  • Remaining values are suitable for the intended audience.
  • Unrelated private configuration has been removed.
  • The JSON still represents the structure you need to discuss.

A zero-redaction result means only that the configured heuristics found no matching value. It does not prove that the file contains no sensitive information. Secrets with unusual names, encoded credentials, or values hidden in unexpected fields may not be detected.

A redaction also does not prove that the matched value was an active credential or that anything was compromised. Treat each match as a review signal.

Limitations and privacy

Detection is heuristic. The tool can miss uncommon secret formats and can redact harmless strings that resemble credentials. Manual review is required before sharing.

The redactor does not validate MCP behavior. It does not confirm that commands exist, environment variables are configured correctly, URLs point to the intended services, or servers will start successfully. It only creates a sanitized copy of the supplied JSON.

The tool processes the text in your browser and never makes a network request. Even so, handle the source configuration according to its sensitivity. Avoid placing the original in public issues, tickets, or chat threads. Share the sanitized copy only with the people and systems that need it.

If an actual credential has already been exposed, treat that as a separate credential-management issue. Redaction reduces exposure in a copy; it does not revoke or rotate the original value.

Practical next steps

If you want to confirm that the sanitized document remains structurally valid, use MCP Config Validator. This is especially useful after removing values or copying only part of a larger configuration.

If you need broader troubleshooting help, open MCP Config Doctor. A redacted configuration can provide safer context for reviewing the configuration stack and organizing likely issues.

If you need to inspect or replace a server, continue to MCPtrove Search. Search can help you find relevant MCP servers and compare available options.

Keep the sanitized file separate from your working configuration. Use a clear filename, document what was removed when that context matters, and perform one final review before sharing.

FAQ

Does MCP Config Redactor upload my configuration?

No. It processes the text in your browser and never makes a network request.

Does it redact every secret?

No. It uses key-name and value-pattern heuristics. It may miss unusually named or formatted secrets and may occasionally redact an innocent string. Review the full result before sharing it.

Will commands and arguments be removed?

Normally, no. Commands, arguments, non-credential URLs, and other non-secret structure remain visible so the result can still support debugging.

What happens if my JSON is invalid?

The tool displays an actionable parse error and produces no output. Correct the JSON syntax and run the analysis again.

Does successful redaction prove the file is safe?

No. The counts and path list are review aids, not a security guarantee. Inspect all remaining values and decide whether they are appropriate for the intended audience.

Related browser tools