Hand a secret to another agent as an encrypted, pay-per-read token, delivered exactly once. MCP server for Slidingbox.
- ✓Open-source license (ISC)
- ✓Actively maintained (<30d)
- ✓Clear description
- ✓Documented (README)
git clone https://github.com/slidingbox/hydrate-dehydrate-mcp{
"mcpServers": {
"hydrate-dehydrate-mcp": {
"command": "node",
"args": ["/path/to/hydrate-dehydrate-mcp/dist/index.js"]
}
}
}MCP Servers overview
# @slidingbox/hydrate-dehydrate-mcp
An MCP server for handing a secret from one agent, machine, or person to another
without leaving a copy behind.
`store_secret` encrypts on your machine and returns one token. Whoever holds the
token gets the secret exactly once — the first successful read delivers it and
destroys it, and a second read returns nothing. Slidingbox stores only
ciphertext: the key travels in the token and is never sent to the server.
```
store_secret("sk-live-...") -> sb_PApm-Ui...#0zgYgq2d...
^ pointer, on the server ^ key, never sent
retrieve_secret("sb_PApm-Ui...#0zgYgq2d...") -> sk-live-... (and it's gone)
```
## Install
```json
{
"mcpServers": {
"hydrate-dehydrate": {
"command": "npx",
"args": ["-y", "@slidingbox/hydrate-dehydrate-mcp"],
"env": { "SLIDINGBOX_API_KEY": "sbk_..." }
}
}
}
```
That block goes in your MCP client's config — `claude_desktop_config.json` for
Claude Desktop, or `claude mcp add` for Claude Code.
## Paying for reads
Storing is free. Reading costs $0.02, and there are two ways to cover it:
| Variable | What it does |
| --- | --- |
| `SLIDINGBOX_API_KEY` | An evaluation key (`sbk_<id>.<hmac>`). Covers a fixed number of reads for free. Get one instantly: `curl -X POST https://slidingbox.ai/v1/key` — no account, no email. |
| `SLIDINGBOX_PRIVATE_KEY` | A Base wallet holding USDC. Reads are paid per call over [x402](https://x402.org) — no account, no invoice, no subscription. |
| `SLIDINGBOX_URL` | Defaults to `https://slidingbox.ai`. |
| `SLIDINGBOX_NETWORK` | Defaults to `eip155:8453` (Base mainnet). |
With neither set, `store_secret` still works and `retrieve_secret` tells you
which one to configure. `SLIDINGBOX_PRIVATE_KEY` signs payments: give it a
wallet funded for this purpose and nothing else.
## What it is good for
- Passing a credential between two agents that share no store and no account.
- Sending a secret through a channel you would rather it not persist in — the
token in the chat log is inert the moment it is read.
- Proving a handoff happened once. A replayed token fails visibly instead of
quietly serving a second copy.
## What it is not
Not storage, backup, messaging, or key management. Secrets live 60–900 seconds
and then expire. Not for protected health information or payment-card data.
## How it works
Encryption is AES-256-GCM, done in this process before anything is sent. The
server receives `{ciphertext, iv}` and a time-to-live, and returns an opaque
pointer. That is the whole reason this is a local stdio server rather than a
route on the API: a remote MCP server would have to receive your plaintext in
order to encrypt it.
Payment, when a wallet is configured, is x402 — the read returns `402`, the
client signs an EIP-3009 authorization for $0.02 USDC, and retries. Paying
wallets are screened against the OFAC SDN list before settlement; see
<https://slidingbox.ai/compliance>.
- API: <https://slidingbox.ai/developers>
- Agent-readable: <https://slidingbox.ai/llms.txt>, <https://slidingbox.ai/.well-known/slidingbox.json>
## Development
```bash
npm install
npm test # offline: crypto round-trip and token parsing
node server.mjs # speaks MCP over stdio
```
## If this stops working
Slidingbox is a small product and may be retired. This server is built to say so
rather than fail opaquely: a retired service answers `410`, and a domain that no
longer resolves is reported as a retirement, not as a stack trace. Nothing you
store is ever held longer than 900 seconds, so a shutdown cannot strand data.
ISC © SLIDINGBOX LLC
What people ask about hydrate-dehydrate-mcp
What is slidingbox/hydrate-dehydrate-mcp?
+
slidingbox/hydrate-dehydrate-mcp is mcp servers for the Claude AI ecosystem. Hand a secret to another agent as an encrypted, pay-per-read token, delivered exactly once. MCP server for Slidingbox. It has 0 GitHub stars and its last recorded update is dated 2026-09-07.
How do I install hydrate-dehydrate-mcp?
+
You can install hydrate-dehydrate-mcp by cloning the repository (https://github.com/slidingbox/hydrate-dehydrate-mcp) or following the README instructions on GitHub. ClaudeWave also provides quick install blocks on this page.
Is slidingbox/hydrate-dehydrate-mcp safe to use?
+
Our security agent has analyzed slidingbox/hydrate-dehydrate-mcp and assigned a Trust Score of 87/100 (tier: Trusted). See the full breakdown of passed checks and flags on this page.
Who maintains slidingbox/hydrate-dehydrate-mcp?
+
slidingbox/hydrate-dehydrate-mcp is maintained by slidingbox. The last recorded GitHub activity is dated 2026-09-07, with 0 open issues.
Are there alternatives to hydrate-dehydrate-mcp?
+
Yes. On ClaudeWave you can browse similar mcp servers at /categories/mcp, sorted by popularity or recent activity.
Deploy hydrate-dehydrate-mcp to your cloud
Ship this repo to production in minutes. Each platform spins up its own environment with editable env vars.
Maintain this repo? Add a badge to your README
Drop the badge into your GitHub README to show it's tracked on ClaudeWave. Each badge links back to this page and reflects the live Trust Score.
[](https://claudewave.com/repo/slidingbox-hydrate-dehydrate-mcp)<a href="https://claudewave.com/repo/slidingbox-hydrate-dehydrate-mcp"><img src="https://claudewave.com/api/badge/slidingbox-hydrate-dehydrate-mcp" alt="Featured on ClaudeWave: slidingbox/hydrate-dehydrate-mcp" width="320" height="64" /></a>More MCP Servers
Fair-code workflow automation platform with native AI capabilities. Combine visual building with custom code, self-host or cloud, 400+ integrations.
User-friendly AI Interface (Supports Ollama, OpenAI API, ...)
An open-source AI agent that brings the power of Gemini directly into your terminal.
Real-time global intelligence dashboard. AI-powered news aggregation, geopolitical monitoring, and infrastructure tracking in a unified situational awareness interface
The fastest path to AI-powered full stack observability, even for lean teams.
🕷️ An adaptive Web Scraping framework that handles everything from a single request to a full-scale crawl!