Skip to main content
Glama

Server Configuration

Describes the environment variables required to run the server.

NameRequiredDescriptionDefault
HOSTNoBind address (127.0.0.1 to restrict to localhost)0.0.0.0
PORTNoHTTP port8787
BASE_URLNoPublic URL (for OAuth callbacks when using a tunnel)http://localhost:PORT
DATA_DIRNoDirectory for persisted data (metadata index, auth tokens)~/.obsidian-mcp
LOG_LEVELNoSet to debug for verbose logging (tool calls, index sync)
READ_ONLYNoSet to true to disable all write tools (write_note, edit_note, delete_note, move_note, update_note_properties). Only read tools are exposed via MCP, and the vault backend rejects writes as well. Useful when sharing the server with multiple AI clients and write access should be opt-in. This protects the vault from MCP clients; it is not a storage-level guarantee. To make the bucket itself refuse writes, give the server read-only S3 keys.false
S3_BUCKETNoBucket Remotely Save syncs to. Setting it selects S3 mode (requires VAULT_PATH)
S3_PREFIXNoRemote base directory, if Remotely Save uses one
S3_REGIONNoRegion (auto for R2)auto
VAULT_NAMENoVault name (used for deep links and index storage)MyVault
VAULT_PATHNoPath to your Obsidian vault directory (in S3 mode, the local mirror folder; created if missing)
S3_ENDPOINTNoS3 endpoint, e.g. https://<account-id>.r2.cloudflarestorage.com. Omit for AWS S3
CF_ACCOUNT_IDNoCloudflare account ID; with the two settings below, enables the semantic_search tool
WRITE_FOLDERSNoComma-separated list of vault-relative folders where writes are allowed (e.g. MCP,Inbox). When set, the whole vault stays readable but write_note, edit_note, delete_note, move_note, and update_note_properties refuse paths outside these folders (move_note requires both source and destination to be writable). Enforced server-side, unlike MCP_INSTRUCTIONS. Matching is case-sensitive and folder-boundary-aware (MCP matches MCP/note.md but not MCP-private/note.md). Ignored when READ_ONLY=true; unset means the whole vault is writable.
MCP_AUTH_TOKENNoPassword for authentication
S3_POLL_SECONDSNoSeconds between bucket polls (minimum 5)30
INDEX_PASSPHRASENoEncrypts the persisted metadata index (note paths, tags, links) at rest with AES-256-GCM
MCP_INSTRUCTIONSNoExtra text appended to the server's MCP instructions (the string clients inject into the system prompt). Use this to bake vault-specific conventions into the server — e.g. folder structure, naming rules, folders to avoid — so they apply across every MCP client without per-client config. Best-effort: not all clients respect instructions.
MCP_REFRESH_DAYSNoDays before auth session expires14
S3_ACCESS_KEY_IDNoAccess key ID
MCP_ALLOWED_HOSTSNoComma-separated extra Host values accepted in no-auth mode (e.g. 192.168.1.5,mybox.local). No-auth mode rejects any other Host to block browser DNS-rebinding; localhost is always allowed. Ignored when MCP_AUTH_TOKEN is set.
CF_AI_SEARCH_TOKENNoCloudflare API token with AI Search Edit and Run permissions
S3_SECRET_ACCESS_KEYNoSecret access key
CF_AI_SEARCH_INSTANCENoName of the AI Search instance that indexes the bucket
MCP_INSTRUCTIONS_FILENoPath to a file (e.g. markdown) whose contents are appended to the MCP instructions. Easier than MCP_INSTRUCTIONS for multi-line conventions. If both are set, the file wins and MCP_INSTRUCTIONS is ignored (with a startup warning). Missing/unreadable file or files larger than 32 KB are fatal startup errors. Store this file somewhere only the service user can write (e.g. chmod 600) — its contents land in every MCP session's system prompt, so write access to it = prompt-injection access to every client.
CF_AI_SEARCH_NAMESPACENoNamespace the instance lives indefault
SEARCH_CONTENT_CACHE_MBNoNote content kept in memory for search_notes and list_tasks, in millions of characters (about MB); 0 disables32

Instructions

Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.

This server publishes no instructions, or was last inspected before Glama recorded them.

Capabilities

Server capabilities have not been inspected yet.

Tools

Functions exposed to the LLM to take actions

NameDescription

No tools

Prompts

Interactive templates invoked by user choice

NameDescription

No prompts

Resources

Contextual data attached and managed by the client

NameDescription

No resources