Skip to content

feat(kv): include KV v2 metadata (custom_metadata, version) in read_secret - #125

Open
artfaal wants to merge 1 commit into
hashicorp:mainfrom
artfaal:pr/read-secret-metadata
Open

feat(kv): include KV v2 metadata (custom_metadata, version) in read_secret#125
artfaal wants to merge 1 commit into
hashicorp:mainfrom
artfaal:pr/read-secret-metadata

Conversation

@artfaal

@artfaal artfaal commented Jul 10, 2026

Copy link
Copy Markdown

Problem

read_secret on a KV v2 mount returns only the data payload (secret.Data["data"]) and discards secret.Data["metadata"]. MCP clients therefore cannot see a secret's version, created/updated timestamps, or custom_metadata (e.g. description/usage) — even though Vault returns all of it in the same data-endpoint response.

Change

Return {"data": ..., "metadata": ...} for KV v2 reads, keeping the values while surfacing the metadata block. KV v1 behaviour is unchanged.

Why it matters

Teams often store human context (what a secret is for, where it's used) in custom_metadata. Without it an agent reading a secret has no idea what it is; this makes that context available.

The v2 read handler discarded secret.Data["metadata"] and returned only the
data payload, so clients could not see version, timestamps or custom_metadata
(e.g. description/usage). Return {data, metadata} instead, keeping the values
and surfacing the metadata block clients need to understand a secret.
@artfaal
artfaal requested a review from a team as a code owner July 10, 2026 11:49
@hashicorp-cla-app

Copy link
Copy Markdown

CLA assistant check

Thank you for your submission! We require that all contributors sign our Contributor License Agreement ("CLA") before we can accept the contribution. Read and sign the agreement

Learn more about why HashiCorp requires a CLA and what the CLA includes


Max Solovev seems not to be a GitHub user.
You need a GitHub account to be able to sign the CLA.
If you have already a GitHub account, please add the email address used for this commit to your account.

Have you signed the CLA already but the status is still pending? Recheck it.

artfaal pushed a commit to artfaal/vault-mcp-server that referenced this pull request Jul 21, 2026
Что в форке: два патча поверх upstream main (метаданные KV v2 в read_secret,
рабочий ENABLE_VAULT_OPERATIONS с read-only дефолтом), ссылки на upstream
PR hashicorp#125/hashicorp#126, сборка образа через release-default в Nexus (тег 0.2.0-jd-ro1)
и деплой на gvm25. В штатный README добавлен указатель на README-JD.
artfaal pushed a commit to artfaal/vault-mcp-server that referenced this pull request Aug 4, 2026
Контрибьютить в hashicorp дорого по бюрократии — решение принято, план
«примет upstream — свернём форк» больше не действует. Ветки pr/* остаются
как способ держать патч отдельно от JD-специфики, PR hashicorp#125 и hashicorp#126 висят
с прежнего захода.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant