Obsidian CRUD MCP
by cdalton713
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| HOST | No | Bind address (127.0.0.1 to restrict to localhost) | 0.0.0.0 |
| PORT | No | HTTP port | 8787 |
| BASE_URL | No | Public URL (for OAuth callbacks when using a tunnel) | http://localhost:PORT |
| DATA_DIR | No | Directory for persisted data (metadata index, auth tokens) | ~/.obsidian-mcp |
| LOG_LEVEL | No | Set to debug for verbose logging (tool calls, index sync) | |
| READ_ONLY | No | Set to true to disable all write tools (write_note, edit_note, delete_note, move_note, update_note_properties). Only read tools are exposed via MCP, and the vault backend rejects writes as well. Useful when sharing the server with multiple AI clients and write access should be opt-in. This protects the vault from MCP clients; it is not a storage-level guarantee. To make the bucket itself refuse writes, give the server read-only S3 keys. | false |
| S3_BUCKET | No | Bucket Remotely Save syncs to. Setting it selects S3 mode (requires VAULT_PATH) | |
| S3_PREFIX | No | Remote base directory, if Remotely Save uses one | |
| S3_REGION | No | Region (auto for R2) | auto |
| VAULT_NAME | No | Vault name (used for deep links and index storage) | MyVault |
| VAULT_PATH | No | Path to your Obsidian vault directory (in S3 mode, the local mirror folder; created if missing) | |
| S3_ENDPOINT | No | S3 endpoint, e.g. https://<account-id>.r2.cloudflarestorage.com. Omit for AWS S3 | |
| CF_ACCOUNT_ID | No | Cloudflare account ID; with the two settings below, enables the semantic_search tool | |
| WRITE_FOLDERS | No | Comma-separated list of vault-relative folders where writes are allowed (e.g. MCP,Inbox). When set, the whole vault stays readable but write_note, edit_note, delete_note, move_note, and update_note_properties refuse paths outside these folders (move_note requires both source and destination to be writable). Enforced server-side, unlike MCP_INSTRUCTIONS. Matching is case-sensitive and folder-boundary-aware (MCP matches MCP/note.md but not MCP-private/note.md). Ignored when READ_ONLY=true; unset means the whole vault is writable. | |
| MCP_AUTH_TOKEN | No | Password for authentication | |
| S3_POLL_SECONDS | No | Seconds between bucket polls (minimum 5) | 30 |
| INDEX_PASSPHRASE | No | Encrypts the persisted metadata index (note paths, tags, links) at rest with AES-256-GCM | |
| MCP_INSTRUCTIONS | No | Extra text appended to the server's MCP instructions (the string clients inject into the system prompt). Use this to bake vault-specific conventions into the server — e.g. folder structure, naming rules, folders to avoid — so they apply across every MCP client without per-client config. Best-effort: not all clients respect instructions. | |
| MCP_REFRESH_DAYS | No | Days before auth session expires | 14 |
| S3_ACCESS_KEY_ID | No | Access key ID | |
| MCP_ALLOWED_HOSTS | No | Comma-separated extra Host values accepted in no-auth mode (e.g. 192.168.1.5,mybox.local). No-auth mode rejects any other Host to block browser DNS-rebinding; localhost is always allowed. Ignored when MCP_AUTH_TOKEN is set. | |
| CF_AI_SEARCH_TOKEN | No | Cloudflare API token with AI Search Edit and Run permissions | |
| S3_SECRET_ACCESS_KEY | No | Secret access key | |
| CF_AI_SEARCH_INSTANCE | No | Name of the AI Search instance that indexes the bucket | |
| MCP_INSTRUCTIONS_FILE | No | Path to a file (e.g. markdown) whose contents are appended to the MCP instructions. Easier than MCP_INSTRUCTIONS for multi-line conventions. If both are set, the file wins and MCP_INSTRUCTIONS is ignored (with a startup warning). Missing/unreadable file or files larger than 32 KB are fatal startup errors. Store this file somewhere only the service user can write (e.g. chmod 600) — its contents land in every MCP session's system prompt, so write access to it = prompt-injection access to every client. | |
| CF_AI_SEARCH_NAMESPACE | No | Namespace the instance lives in | default |
| SEARCH_CONTENT_CACHE_MB | No | Note content kept in memory for search_notes and list_tasks, in millions of characters (about MB); 0 disables | 32 |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Server capabilities have not been inspected yet.
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
No tools | |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
This server cannot be deployed
Maintenance
ActivityMaintained
ResponsivenessNo issues