Claude Code Internal MCP Servers: Connect Without Exposing Credentials
TL;DR
* Putting MCP server credentials in Claude Code's settings.json, .mcp.json, or environment files spreads secrets to every developer machine with no rotation path and no audit trail.
* Bifrost stores upstream MCP credentials on the gateway and gives each developer a scoped virtual key, so Claude