Obsidian CLI MCP Server
This server wraps the official Obsidian CLI to give LLM agents local, secure control over Obsidian vaults through a single obsidian_exec tool. You can execute any of 80+ CLI commands like read, search, create, files, tasks, tags, properties, backlinks, bookmarks, and more. Specific capabilities include:
Manage notes: Read, create, and search notes within a vault.
Organize vaults: Target a specific vault using the optional
vaultparameter; otherwise uses the active vault.Retrieve metadata: Get backlinks, properties, bookmarks, task lists, tag counts, and other vault information.
Get help: Use
command="help"orcommand="help <subcommand>"to explore available commands.List blocked commands: Use
obsidian_blocked_commandsto see which dangerous commands (e.g.,eval,restart,devtools) are prevented.
Safety features: Dangerous commands are automatically blocked, and all commands run without a shell to prevent injection. Execution happens entirely locally with zero network dependencies (no API keys, no cloud services).
Execution modes: Works via direct process spawn in terminal environments or via an HTTP relay for Electron-based clients like Claude Desktop. On macOS, an optional launchd agent can auto-start the relay for seamless recovery.
The server provides a safe, flexible way for LLMs to interact with your vaults.
Provides access to an Obsidian vault through the official Obsidian CLI, enabling operations on notes, searches, tasks, tags, properties, backlinks, bookmarks, and more.
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@Obsidian CLI MCP Serverlist all notes in my daily folder"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
obsidian-cli-mcp-server
A local MCP server that wraps the official Obsidian CLI (v1.12+), giving LLM agents full access to 80+ vault operations through a single tool.
Zero network dependencies — no API keys, no cloud services; everything runs locally
Single-tool design — one
obsidian_exectool accepts any CLI command, so new Obsidian CLI features work instantly without updating the serverSafety-first — dangerous commands (
eval,devtools, etc.) are blocked at two layers; all execution usesspawnwithout shell interpretation, preventing command injectionDual execution mode — direct spawn for terminal environments + HTTP relay for Electron-hosted clients (Claude Desktop, Cowork)
Prerequisites
Obsidian v1.12.4+ with CLI enabled (Settings → General → Command line interface)
The
obsidianbinary in yourPATH(or setOBSIDIAN_CLI_PATH)Node.js ≥ 18
expect(pre-installed on macOS; needed forsearch/search:context)
Related MCP server: Obsidian MCP Server
Quick Start
# Clone and build
git clone https://github.com/cks850711/obsidian-cli-mcp-server.git
cd obsidian-cli-mcp-server
npm install
npm run buildConfiguration
Claude Code
Add to your Claude Code MCP settings:
{
"mcpServers": {
"obsidian-cli": {
"command": "node",
"args": ["/absolute/path/to/obsidian-cli-mcp-server/dist/index.js"]
}
}
}Claude Desktop
{
"mcpServers": {
"obsidian-cli": {
"command": "node",
"args": ["/absolute/path/to/obsidian-cli-mcp-server/dist/index.js"]
}
}
}Note: Claude Desktop is an Electron app, and spawning the Obsidian CLI (also Electron) from it causes a SingletonSocket IPC conflict. You must start the HTTP relay server from a terminal first — see HTTP Relay below.
Available Tools
obsidian_exec
Execute any Obsidian CLI sub-command and return its output.
Parameter | Type | Required | Description |
| string | ✅ | CLI sub-command and arguments (without the leading |
| string | — | Target a specific vault by name |
Examples:
command="help"
command="read file=MyNote"
command="search query=\"meeting notes\" limit=10"
command="create name=NewNote content=\"Hello world\""
command="files folder=Projects ext=md"
command="tasks todo"
command="tags counts sort=count"
command="properties file=MyNote"
command="backlinks file=MyNote"
command="bookmarks"For the full list of available CLI commands, run command="help".
obsidian_blocked_commands
Returns the list of CLI commands that are blocked by this server for safety reasons. Takes no parameters.
HTTP Relay
When the MCP server runs inside an Electron process tree (e.g., Claude Desktop), the Obsidian CLI binary hangs due to Electron's SingletonSocket IPC mechanism. The relay server solves this by running in a separate terminal.
# Start the relay (keep this terminal open)
npm run relay
# Default: http://127.0.0.1:27182The MCP server automatically tries the relay first, then falls back to direct spawn. No configuration needed — just start the relay before using the MCP server from Electron-based clients.
Environment variable | Default | Description |
|
| Relay server port |
|
| Path to the Obsidian CLI binary |
Auto-Start on Demand (macOS)
Keeping a terminal window open just to host the relay is inconvenient — especially for sandboxed clients (VMs, containers) that can reach the relay over HTTP but cannot start a process on the host.
The included launchd agent solves this: touching a trigger file starts the relay. Any client that can write to the repository directory can bring the relay up without a human opening a terminal.
Install
bash scripts/install-relay-agent.shThat is the whole setup — no paths to fill in, no config to edit. The script derives the repository location from its own position on disk, generates the .plist accordingly, and loads it with launchctl. Re-running it is safe (it reloads in place).
The generated agent lives at ~/Library/LaunchAgents/com.obsidian-cli-mcp-server.relay.plist and is not stored in the repository, so no absolute paths are ever committed.
To remove it:
bash scripts/install-relay-agent.sh --uninstallWhat it does
Touching the trigger file causes launchd to run scripts/start-relay.sh, which:
Exits immediately if the relay is already listening (repeated triggers are harmless)
Refuses to start if the port is occupied by something else, rather than fighting over it
Locates the
obsidianbinary — env var →PATH→ common install paths → Spotlight — since it lives inside the app bundle and is not on launchd's defaultPATHLaunches Obsidian if it is not already running (the CLI needs a live instance to talk to)
Starts the relay in the foreground, letting launchd own the process
The relay runs with no controlling terminal and no window; its output goes to logs/relay.log.
Client Host (macOS)
────── ────────────
relay not responding
│
▼
touch .relay-trigger ──────► launchd notices mtime change
│
▼
start-relay.sh
├─ ensure Obsidian is running
└─ start relay on :27182
│ │
▼ ▼
retry after ~5s ───────────► relay ──► Obsidian ──► vaultTriggering it
touch /path/to/obsidian-cli-mcp-server/.relay-triggerThen wait ~5 seconds and retry. Notes:
Use
touch. Creating or deleting the file is unnecessary, and some sandboxes permittouchwhile blockingunlink.launchd throttles a job to once per 10 seconds — spamming the trigger does nothing.
The agent is deliberately configured without
RunAtLoadandKeepAlive, so the relay starts only when triggered. Add both keys to the generated plist if you would rather have it start at login and restart automatically on crash.
Tell your agent about it
Installing the agent is only half of it. Unless the LLM client knows the trigger exists, it will still report "the relay is down" and wait for a human — which is exactly the problem this was meant to remove.
Put the recovery procedure somewhere the client loads on every session, not in a doc it has to go looking for: the failure needs to be self-healing at the moment it happens. For Claude Code that means CLAUDE.md; other clients have their own equivalent (system prompt, rules file, agent instructions).
Something like:
### If the Obsidian relay is not responding
Do not ask me to start it. Recover it yourself:
1. `touch <repo>/.relay-trigger`
2. Wait 5–10 seconds, then retry the command.
A launchd agent on the host watches that file and starts the relay
automatically. Use `touch` — do not create or delete the file. launchd
throttles to once per 10 seconds, so space out retries. Only report back
if two attempts fail, and include the command and error output.Replace <repo> with the absolute path to this repository as seen from the client — for sandboxed clients that is the path inside the sandbox, not on the host.
Troubleshooting
tail -20 logs/relay.log # what happened
launchctl list | grep obsidian-cli-mcp-server # is the agent loadedSymptom | Cause |
| Obsidian not installed, or in a non-standard location — set |
Relay starts but commands fail | Obsidian's CLI is disabled — enable it in Settings → General → Command line interface |
Nothing happens on touch | Agent not loaded; re-run the install script |
Security
Blocked Commands
The following commands are blocked by default to prevent unintended side effects:
Command | Reason |
| Arbitrary JavaScript execution inside Obsidian |
| Restarts the Obsidian app |
| Toggles Electron DevTools |
| Chrome DevTools Protocol — arbitrary method execution |
| CSS inspection |
| Debugger attach/detach |
| DOM query |
| Mobile emulation toggle |
The blocklist is enforced at two layers — both the MCP server (cli.ts) and the relay server (relay-server.ts) independently reject blocked commands. To customize, edit src/constants.ts.
Command Injection Prevention
All commands are executed via Node.js child_process.spawn without a shell (shell: false by default). User input is parsed into an argv array by a custom parser (parse-args.ts) — not by sh -c. This means:
Shell metacharacters (
;,|,$(),` `,&&) are not interpretedThe executable is always the fixed
obsidianbinary — it cannot be changed by user inputNo command substitution, variable expansion, or piping is possible
For search / search:context (which require a TTY), commands are wrapped with expect. Arguments are quoted using Tcl brace-quoting ({...}), which is fully literal with no substitution.
Architecture
LLM (Claude)
│
│ MCP (stdio)
▼
┌──────────────────────┐
│ MCP Server │
│ (index.ts) │
│ │
│ obsidian_exec tool │
│ ┌────────────────┐ │
│ │ isBlocked() │──│── Layer 1: block dangerous commands
│ │ parseArgs() │──│── Parse without shell
│ └───────┬────────┘ │
└──────────┼───────────┘
│
┌─────┴──────┐
▼ ▼
┌─────────┐ ┌───────────┐
│ Relay │ │ Direct │
│ Server │ │ Spawn │
│ (HTTP) │ │ │
│ :27182 │ │ │
└────┬────┘ └─────┬─────┘
│ │
▼ ▼
┌─────────────────┐
│ obsidian CLI │
│ (Electron) │
└─────────────────┘Development
npm run dev # Watch mode (tsx)
npm run build # Compile TypeScript
npm test # Run parse-args unit tests
npm run relay # Start HTTP relay serverLicense
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Servers
- Flicense-quality-maintenanceEnables AI assistants to read, write, search, and navigate Obsidian vault notes with support for CRUD operations, full-text search, graph navigation, daily notes, and frontmatter management.3,860
- AlicenseAqualityDmaintenanceEnables AI assistants to interact with Obsidian vaults for creating, reading, searching, and managing notes, daily notes, TODOs, session reports, and backlinks through both stdio and HTTP/SSE transports.103,8604MIT
- FlicenseCqualityFmaintenanceProvides LLM agents with comprehensive access to Obsidian vaults via the official Obsidian CLI bridge. It enables users to read, search, and modify notes, tasks, properties, and plugins while the Obsidian desktop app is running.5415
- AlicenseBqualityDmaintenanceEnables AI assistants to search, create, and manage notes in an Obsidian vault via 40+ local tools.5228MIT
Related MCP Connectors
Connect AI assistants to your GitHub-hosted Obsidian vault to seamlessly access, search, and analy…
Search your Obsidian vault to quickly find notes by title or keyword, summarize related content, a…
Search and reason over your Obsidian-style Markdown vault, right from ChatGPT.
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/cks850711/obsidian-cli-mcp-server'
If you have feedback or need assistance with the MCP directory API, please join our Discord server