proofable_context before create or revoke.
When signed in, omit
walletAddress. Secrets bind to your profile account from proofable_context.
Create (proofable_secret_create)
List (proofable_secret_list)
authRequired: true. It does not leak metadata.
Revoke (proofable_secret_revoke)
walletAddress when signed in.
Security
- Store secrets only through
proofable_secret_create. Confirm the stored name and proof ID. Never print the value in chat. - Prefer OAuth or Profile keys in MCP config only. Do not use them in app browser bundles.
- Rotate or revoke through
proofable_secret_revokeand re-create if a value is exposed.
Auth
How MCP sessions authenticate.
Current user
Profile lookup and refresh.