PluginBench
MCP Server
Active
MIT

Vault Cortex MCP Server

io.github.aliasunder/vault-cortex

What is the Vault Cortex MCP server?

Standalone MCP server for Obsidian vaults — hybrid search, notes & files, memory, tasks, OAuth 2.1

How to install Vault Cortex

Copy-paste configuration for popular MCP clients.

transport: stdio
Config generated by PluginBench — verify against the source before use.
Environment / auth
  • MCP_AUTH_TOKEN
    required
    secret

    Bearer token for MCP client authentication. Must match the Authorization header sent by clients. Generate with: openssl rand -hex 32

  • PUBLIC_URL

    Public URL clients use to reach this server. Used as the OAuth issuer URL in discovery metadata. Override when exposing the server outside localhost or on a non-default port.

  • EMBEDDING_ENABLED

    Enable or disable the embedding pipeline. When false, no ONNX model is downloaded, no vector tables are created, and search uses FTS5 only.

  • RERANK_MODE

    Cross-encoder reranking mode: blended (position-aware score blending after RRF fusion) or none (skip reranking). Only takes effect when EMBEDDING_ENABLED is true.

  • WINDOWS_MODE

    Windows bind-mount mode: enables filesystem polling for the file watcher and rename-based moves across the Docker Desktop/WSL2 bridge. Set to true when the vault lives on a Windows drive.

  • MEMORY_ENABLED

    Enable or disable the structured memory layer. When false, memory tools are hidden, bootstrap is skipped, and server metadata omits memory references.

  • FILE_TOOLS_ENABLED

    Enable or disable file tools (vault_read_file, vault_list_files). When false, file tools are hidden and server metadata omits file tool references.

  • READONLY_MODE

    Run the server read-only: every vault-writing tool is hidden, the memory folder is not auto-created, and server metadata omits write references.

  • DISABLED_TOOLS

    Hide individual tools by name, comma-separated. Subtractive only — it cannot re-enable a tool another setting hides; an unknown tool name stops the server at startup.

  • MEMORY_DIR

    Vault folder for structured memory files (About Me-style notes). Memory tools are hidden when MEMORY_ENABLED is false, but this value still feeds the defaults for PROTECTED_PATHS and ORPHAN_EXCLUDE_FOLDERS.

  • DAILY_NOTES_FOLDER

    Vault folder for daily notes. Overrides the folder configured in Obsidian's daily-notes plugin. When unset, read from the vault's .obsidian/daily-notes.json, falling back to "Daily Notes".

  • DAILY_NOTES_FORMAT

    Filename date format for daily notes (Moment.js tokens). Overrides the format configured in Obsidian's daily-notes plugin. When unset, read from the vault's .obsidian/daily-notes.json, falling back to "YYYY-MM-DD".

  • TRUST_PROXY_HOPS

    Number of trusted reverse-proxy hops used to derive the client IP from X-Forwarded-For for OAuth rate limiting and request logs. With 0, injected forwarding headers are ignored.

  • TRUST_FORWARDED_HOPS

    How many entries from the end of the RFC 7239 Forwarded header's for= list to count to reach the client IP for OAuth rate limiting and request logs. 0 ignores the header; 1 when the proxy in front writes it (e.g. AWS API Gateway); 2 when a CDN fronts that proxy and is the only way to reach it.

  • TZ

    IANA timezone for timestamps and daily note resolution.

  • LOG_LEVEL

    Logging verbosity.

  • LOG_DIR

    Directory for log files that survive container re-creation. The container's own log is always written but discarded when the container is recreated; date-stamped files under LOG_DIR persist on the data volume. Default: /data/logs (remote image), $STORAGE_ROOT/data/logs (single-volume mode), none (local image). none keeps only the container log.

  • LOG_RETENTION_DAYS

    Days to keep log files before automatic cleanup on startup; only applies when LOG_DIR is a path.

  • PROTECTED_PATHS

    Comma-separated vault folder names blocked from vault_delete_note and vault_move_note. Default: MEMORY_DIR plus the daily notes folder, read from DAILY_NOTES_FOLDER or .obsidian/daily-notes.json (default Daily Notes). When set, overrides the default entirely.

  • ORPHAN_EXCLUDE_FOLDERS

    Comma-separated vault folder names excluded from vault_find_orphans. Default: DAILY_NOTES_FOLDER (else "Daily Notes"), "Templates", MEMORY_DIR.

  • SERVICE_DOCUMENTATION_URL

    Override the OAuth service documentation URL exposed via discovery metadata.

  • MAX_FILE_BYTES

    Largest file vault_read_file will read, in bytes. Reading a larger file returns an error instead of content.

  • MAX_IMAGE_OUTPUT_BYTES

    Byte budget for images returned by vault_read_file, in binary bytes before base64 encoding. Images exceeding the budget are downscaled/recompressed server-side to fit; raise for clients that accept larger tool responses.

  • MAX_PDF_RENDER_PAGES

    Maximum PDF pages to render as images when raw: true is set on vault_read_file. The per-page byte budget is MAX_IMAGE_OUTPUT_BYTES divided evenly across the rendered pages.

~/Library/Application Support/Claude/claude_desktop_config.json
{
  "mcpServers": {
    "vault-cortex": {
      "command": "docker",
      "args": [
        "run",
        "-i",
        "--rm",
        "ghcr.io/aliasunder/vault-cortex:0.54.6",
        "-p",
        "8000:8000",
        "-v",
        "{VAULT_PATH}:/vault:rw",
        "-v",
        "vault-cortex-data:/data"
      ],
      "env": {
        "MCP_AUTH_TOKEN": "<YOUR_MCP_AUTH_TOKEN>",
        "PUBLIC_URL": "<YOUR_PUBLIC_URL>",
        "EMBEDDING_ENABLED": "<YOUR_EMBEDDING_ENABLED>",
        "RERANK_MODE": "<YOUR_RERANK_MODE>",
        "WINDOWS_MODE": "<YOUR_WINDOWS_MODE>",
        "MEMORY_ENABLED": "<YOUR_MEMORY_ENABLED>",
        "FILE_TOOLS_ENABLED": "<YOUR_FILE_TOOLS_ENABLED>",
        "READONLY_MODE": "<YOUR_READONLY_MODE>",
        "DISABLED_TOOLS": "<YOUR_DISABLED_TOOLS>",
        "MEMORY_DIR": "<YOUR_MEMORY_DIR>",
        "DAILY_NOTES_FOLDER": "<YOUR_DAILY_NOTES_FOLDER>",
        "DAILY_NOTES_FORMAT": "<YOUR_DAILY_NOTES_FORMAT>",
        "TRUST_PROXY_HOPS": "<YOUR_TRUST_PROXY_HOPS>",
        "TRUST_FORWARDED_HOPS": "<YOUR_TRUST_FORWARDED_HOPS>",
        "TZ": "<YOUR_TZ>",
        "LOG_LEVEL": "<YOUR_LOG_LEVEL>",
        "LOG_DIR": "<YOUR_LOG_DIR>",
        "LOG_RETENTION_DAYS": "<YOUR_LOG_RETENTION_DAYS>",
        "PROTECTED_PATHS": "<YOUR_PROTECTED_PATHS>",
        "ORPHAN_EXCLUDE_FOLDERS": "<YOUR_ORPHAN_EXCLUDE_FOLDERS>",
        "SERVICE_DOCUMENTATION_URL": "<YOUR_SERVICE_DOCUMENTATION_URL>",
        "MAX_FILE_BYTES": "<YOUR_MAX_FILE_BYTES>",
        "MAX_IMAGE_OUTPUT_BYTES": "<YOUR_MAX_IMAGE_OUTPUT_BYTES>",
        "MAX_PDF_RENDER_PAGES": "<YOUR_MAX_PDF_RENDER_PAGES>"
      }
    }
  }
}

Related MCP servers

Lossless context compression: 2-8x fewer tokens, byte-exact recovery, search inside payloads

6
Python
MIT
View repository →

Long-term memory for AI agents: semantic facts, episodic events, and procedural workflows that evolve from failures

189
Python
Apache-2.0
View repository →
TRTripwire logo

Tripwire

Active

MCP for Roblox Studio and Open Cloud: drive Studio, run headless tests, and review game security.

2
Rust
MIT
View repository →

Find Lumi Studio iOS apps by task across all 50 Apple locales, with direct App Store links.

0
HTML
MIT
View repository →

Secure audio transcription meets AI. Connect Alice recordings to Claude, ChatGPT, Gemini, and more.

2
MIT
View repository →
MAMarketNow logo

MarketNow

Active

Verify AI agent credentials, translate 9 formats, check scam domains, search 68k+ MCP servers.

0
JavaScript
View repository →