PluginBench
MCP Server
Active
MIT

Markdown Vault MCP MCP Server

io.github.pvliesdonk/markdown-vault-mcp

Hybrid search and write operations for markdown vaults with semantic and keyword search, git integration, and OKF support.

What is the Markdown Vault MCP MCP server?

Markdown Vault MCP is a generic markdown vault server with hybrid search (keyword + semantic), write operations, git integration, and frontmatter-aware indexing. It exposes 34 LLM-visible tools for capturing, searching, editing, and managing markdown notes with automatic indexing and optional git-based version control.

This server lets you build a searchable, version-controlled markdown knowledge base accessible to Claude and other AI agents. It combines BM25 keyword search with semantic search (via FastEmbed, Ollama, OpenAI, or Voyage AI embeddings), supports read/write operations with overwrite protection, git auto-commit, and OKF (Open Knowledge Format) awareness. Use it to capture URLs as notes, research topics into interlinked notes, find missing links, and keep your vault synchronized across clients.

How to install Markdown Vault MCP

Copy-paste configuration for popular MCP clients.

transport: stdio
Config generated by PluginBench — verify against the source before use.
Environment / auth
  • MARKDOWN_VAULT_MCP_KV_STORE_URL

    Persistent-state backend URL shared by every pvl-core subsystem that needs state. `memory://` is in-process and lost on restart; `file:///path` persists on one server; `redis://`, `dynamodb://` and `mongodb://` each need their matching extra. When unset, defaults to `file:///data/state` (the volume family Docker images mount), or to `memory://` (with a warning) on a host where that directory is not usable.

  • MARKDOWN_VAULT_MCP_TOOLS_ALLOW

    Comma-separated explicit tool names this instance exposes; every other tool is hidden from listings and cannot be invoked. Names matching no registered tool are inert. Mutually exclusive with `tools_deny`. Takes effect through `apply_tool_visibility`.

  • MARKDOWN_VAULT_MCP_TOOLS_DENY

    Comma-separated explicit tool names hidden from this instance (absent from listings, cannot be invoked). Names matching no registered tool are inert. Mutually exclusive with `tools_allow`. Takes effect through `apply_tool_visibility`.

  • MARKDOWN_VAULT_MCP_SERVER_NAME

    Rename this server instance; defaults to the project name.

  • MARKDOWN_VAULT_MCP_INSTANCE_DESCRIPTION

    Concise routing context that distinguishes this deployment's material or responsibility.

  • MARKDOWN_VAULT_MCP_INSTRUCTIONS_EXTRA

    Deployment-specific behavioral policy added to the generated MCP instructions.

  • MARKDOWN_VAULT_MCP_INSTRUCTIONS

    Legacy: replaces all generated MCP instructions (deprecated; use _INSTANCE_DESCRIPTION for routing and _INSTRUCTIONS_EXTRA for policy).

  • MARKDOWN_VAULT_MCP_LOG_LEVEL

    Log level for every logger in the process, FastMCP's included (DEBUG / INFO / WARNING / ERROR / CRITICAL). The -v CLI flag overrides to DEBUG. The unprefixed FASTMCP_LOG_LEVEL still works for one major version and logs a deprecation warning.

  • MARKDOWN_VAULT_MCP_LOG_FORMAT

    Log rendering. rich is one colour event key=value line per record, for a terminal; json is one JSON object per record, for a collector. Unset picks rich when stderr is a terminal and json everywhere else, so a container or journald gets JSON with no configuration.

  • OLLAMA_HOST

    Ollama server URL for the ollama embedding provider. Bare (not MARKDOWN_VAULT_MCP_-prefixed), matching the Ollama ecosystem convention.

  • OPENAI_API_KEY
    secret

    OpenAI API key for the openai embedding provider, and the fallback key for the summarize tool when MARKDOWN_VAULT_MCP_SUMMARIZE_OPENAI_API_KEY is unset. Bare (not MARKDOWN_VAULT_MCP_-prefixed), matching the OpenAI ecosystem convention.

  • VOYAGE_API_KEY
    secret

    Voyage AI API key for the voyage embedding provider. Bare (not MARKDOWN_VAULT_MCP_-prefixed), matching the OPENAI_API_KEY / OLLAMA_HOST convention. Setting it never auto-selects the provider; choose it explicitly with MARKDOWN_VAULT_MCP_EMBEDDING_PROVIDER=voyage.

  • OPENAI_BASE_URL

    Bare fallback for MARKDOWN_VAULT_MCP_OPENAI_BASE_URL (embeddings). For the summarize tool it only routes traffic when an API key already enables the feature; it never enables summarize by itself.

  • OPENAI_EMBEDDING_MODEL

    Bare fallback for MARKDOWN_VAULT_MCP_OPENAI_EMBEDDING_MODEL.

  • MARKDOWN_VAULT_MCP_BUILD_TIMEOUT_S

    Maximum seconds an index-backed tool or resource waits for the FTS index to become queryable during a cold-start background build before raising IndexUnavailableError(reason="timeout"). Increase for large vaults.

  • MARKDOWN_VAULT_MCP_DRAIN_TIMEOUT_S

    Maximum seconds an index-querying read tool waits for the IndexWriter to drain when called with wait_for_pending_writes=true. On timeout the tool answers from the current index and reports index_stale=true in the response _meta.

  • MARKDOWN_VAULT_MCP_SOURCE_DIR

    Path to the markdown vault directory. When it does not exist, or the server cannot access it, the server starts but every tool fails with a message saying which until it is fixed (managed git mode clones into it). Symbolic links inside the vault are followed on Python 3.13+.

  • MARKDOWN_VAULT_MCP_READ_ONLY

    Set to true to hide the write tools (write, edit, append, delete, rename, move_folder, fetch, git_sync, the okf_* tools, create_upload_link) and serve a search-only vault.

  • MARKDOWN_VAULT_MCP_WRITE_PROTECT_EXISTING

    Refuse a write that would overwrite an existing file when no if_match etag is supplied. Deliberate replacement still works: read the file first, then pass if_match. Unaffected: edit, append, delete, rename. Set to false to allow blind overwrites.

  • MARKDOWN_VAULT_MCP_DISABLE_APPS_UI

    Hide the MCP Apps UI tools (browse_vault, show_context) from the tool listing for clients that do not render MCP Apps panels.

  • MARKDOWN_VAULT_MCP_INDEX_PATH

    Path to the SQLite FTS5 index file; unset keeps the index in memory. Set it for persistence across restarts.

  • MARKDOWN_VAULT_MCP_STATE_PATH

    Path to the change-tracking state file. Defaults to {SOURCE_DIR}/.markdown_vault_mcp/state.json.

  • MARKDOWN_VAULT_MCP_EMBEDDINGS_PATH

    Path to the numpy embeddings file; required to enable semantic search.

  • MARKDOWN_VAULT_MCP_INDEXED_FIELDS

    Comma-separated frontmatter fields promoted to the tag index for structured filtering. Changing it cold-rebuilds the index once on next startup; SEARCHABLE_FIELDS inherits this value when unset.

  • MARKDOWN_VAULT_MCP_REQUIRED_FIELDS

    Comma-separated frontmatter fields required on every document; documents missing any are excluded from the index.

  • MARKDOWN_VAULT_MCP_EXCLUDE

    Comma-separated glob patterns excluded from scanning, e.g. .obsidian/**,.trash/**.

  • MARKDOWN_VAULT_MCP_TITLE_FIELD

    Frontmatter field used as the document title (falls back to title, the first H1, then the filename). Changing it cold-rebuilds the index once on next startup.

  • MARKDOWN_VAULT_MCP_SEARCHABLE_FIELDS

    Comma-separated frontmatter fields whose text values become keyword-searchable and enrich first-chunk embeddings. Inherits INDEXED_FIELDS when unset; the sentinel none means filterable but not searchable. Changing it cold-rebuilds the index and re-embeds once on next startup.

  • MARKDOWN_VAULT_MCP_TEMPLATES_FOLDER

    Relative folder where note templates live (used by the create_from_template prompt).

  • MARKDOWN_VAULT_MCP_PROMPTS_FOLDER

    Directory of .md prompt files that extend or override built-in prompts; a relative path is resolved against SOURCE_DIR.

  • MARKDOWN_VAULT_MCP_CONVENTIONS_FILE

    Filename of the per-folder conventions files surfaced to clients at write time (bare .md filename without glob characters). Set to none to disable folder conventions.

  • MARKDOWN_VAULT_MCP_OKF_MODE

    OKF (Open Knowledge Format) read semantics. With auto (the default), read annotations switch on when the vault declares an OKF version in its root index.md. Use off to disable OKF semantics entirely, or on to force them for an undeclared vault. Annotations are read-only; write behavior is never affected.

  • MARKDOWN_VAULT_MCP_OKF_WRITE

    OKF (Open Knowledge Format) enforced write layer. When true on an OKF-active vault, the server stamps generated provenance on each write and clears any verified attestation when a note's content changes. It also keeps each written folder's log.md and index.md current, and exposes the okf_verify tool. Requires OKF_MODE to be auto or on (a true value with OKF_MODE=off is a config error). Off by default.

  • MARKDOWN_VAULT_MCP_OKF_VERIFY

    How the okf_verify tool attributes a human review. This applies only when OKF_WRITE is on, which gates the tool. With elicit (the default), okf_verify asks the human to confirm the review through an MCP elicitation, then records the attestation only on an affirmative reply. It fails closed when the client cannot elicit or the human declines, so a model holding the human's token cannot self-attest. Set trust-auth instead to attribute to a token's sub claim with no confirmation; it rejects static bearer credentials and other client-ID-only identities. This is safe only when the sole caller is a human-driven UI. Set off to hide the tool, leaving attestation to external tooling. A non-default value with OKF_WRITE off is a config error.

  • MARKDOWN_VAULT_MCP_ATTACHMENT_EXTENSIONS

    Comma-separated allowed attachment extensions (e.g. pdf,png,jpg); case and a leading dot are ignored, so PDF and .pdf name the same type. Use * to allow every non-markdown file. Unset selects the built-in allowlist. A link whose target has a listed extension is not part of the link graph; changing the list rebuilds the index once.

  • MARKDOWN_VAULT_MCP_MAX_ATTACHMENT_SIZE_MB

    Maximum attachment size in MB returned by read / accepted by write; 0 disables the limit.

  • MARKDOWN_VAULT_MCP_MAX_NOTE_READ_BYTES

    Maximum bytes returned by a full-document read of a note; use `read(path, section=…)` for partial reads. 0 disables the limit.

  • MARKDOWN_VAULT_MCP_DEFAULT_SEARCH_MODE

    Mode used when a search call omits 'mode': auto, keyword, semantic, or hybrid. The default 'auto' picks hybrid when embeddings are configured and keyword when they are not. Pin 'keyword' to keep unqualified searches off the embedding provider (each hybrid or semantic search embeds the query, which costs an API call on a metered provider). A configured semantic/hybrid default also degrades to keyword without embeddings, so no setting can make a vault unsearchable; an explicit mode= argument is never downgraded.

  • MARKDOWN_VAULT_MCP_CHUNKS_PER_FILE

    Maximum chunks returned per document in search results.

  • MARKDOWN_VAULT_MCP_SNIPPET_WORDS

    Width of the snippet window (words) in search results; 0 returns full chunk content.

  • MARKDOWN_VAULT_MCP_LENGTH_DOWNWEIGHT_ALPHA

    Down-weights longer chunks in ranking: score / (1 + alpha * log(chunk_count)).

  • MARKDOWN_VAULT_MCP_MAX_CHUNK_WORDS

    Word cap per chunk; the adaptive chunker splits at deeper heading levels, then paragraph/word boundaries, to respect it. Match it to the embedding model's context. A reindex applies a new value.

  • MARKDOWN_VAULT_MCP_MAX_CHUNK_CHARS

    Character cap enforced alongside MAX_CHUNK_WORDS to bound token-dense chunks. Unset derives min(1500, model context * 2.8). Set a positive value for an exact cap, or -1 to scale with the model's full context (can exhaust memory on long-context models). A reindex applies a new value.

  • MARKDOWN_VAULT_MCP_CHUNK_OVERLAP_WORDS

    Words of overlap between adjacent budget-split fragments of the same heading section (0 disables). A reindex applies a new value.

  • MARKDOWN_VAULT_MCP_FOLDER_WEIGHTS

    Folder-prefix score multipliers (`prefix:weight` pairs, comma-separated, weights > 0) applied to all search modes; the deepest matching prefix wins (sessions:0.5 demotes sessions/**).

  • MARKDOWN_VAULT_MCP_FTS_WEIGHTS

    Per-column BM25 weights (`column:weight` pairs, comma-separated, weights >= 0) for keyword ranking. Columns: path, title, folder, heading, content, summary.

  • MARKDOWN_VAULT_MCP_EMBEDDING_PROVIDER

    Embedding provider: openai, voyage, ollama, or fastembed. Unset auto-detects from the environment (never voyage). Any OpenAI-compatible endpoint works with openai plus OPENAI_BASE_URL; see the embeddings guide.

  • MARKDOWN_VAULT_MCP_OLLAMA_MODEL

    Ollama embedding model name.

  • MARKDOWN_VAULT_MCP_OLLAMA_CPU_ONLY

    Force Ollama to embed on CPU only.

  • MARKDOWN_VAULT_MCP_VOYAGE_MODEL

    Voyage AI embedding model name.

  • MARKDOWN_VAULT_MCP_OPENAI_BASE_URL

    OpenAI-compatible API base URL for embeddings; the bare OPENAI_BASE_URL is honoured as a fallback.

  • MARKDOWN_VAULT_MCP_OPENAI_EMBEDDING_MODEL

    OpenAI-compatible embedding model name; the bare OPENAI_EMBEDDING_MODEL is honoured as a fallback.

  • MARKDOWN_VAULT_MCP_FASTEMBED_MODEL

    FastEmbed model name.

  • MARKDOWN_VAULT_MCP_FASTEMBED_CACHE_DIR

    FastEmbed model cache directory (in Docker, stored under /data/state/fastembed).

  • MARKDOWN_VAULT_MCP_EMBED_CONTEXT

    Enrich embedding input with the note title, chunk heading, and (first chunk) searchable-field values. Flipping it re-embeds the whole vault once on next startup.

  • MARKDOWN_VAULT_MCP_EMBED_TIMEOUT_S

    Per-request wall-clock budget in seconds for a single embedding HTTP call (OpenAI/Ollama). The local FastEmbed backend runs in-process with no network call and ignores this. CPU-only or large-model workloads may need 60-120 s; raise this if batches time out.

  • MARKDOWN_VAULT_MCP_EMBEDDING_BATCH_SIZE

    Number of chunks sent per embedding request. Smaller batches shorten each request (useful under a tight timeout on slow models) at the cost of more round-trips.

  • MARKDOWN_VAULT_MCP_GIT_TOKEN
    secret

    Token/password for HTTPS git auth; remotes must be HTTPS when set.

  • MARKDOWN_VAULT_MCP_GIT_REPO_URL

    HTTPS remote URL for managed git mode: the server clones into an empty SOURCE_DIR on startup (or validates an existing origin) and enables the pull loop, auto-commit, and deferred push.

  • MARKDOWN_VAULT_MCP_GIT_USERNAME

    Username for HTTPS git auth prompts (x-access-token for GitHub, oauth2 for GitLab, the account name for Bitbucket).

  • MARKDOWN_VAULT_MCP_GIT_PULL_INTERVAL_S

    Seconds between git fetch + fast-forward update attempts; 0 disables periodic pull.

  • MARKDOWN_VAULT_MCP_GIT_PUSH_DELAY_S

    Seconds of write-idle time before pushing; 0 pushes only on shutdown.

  • MARKDOWN_VAULT_MCP_GIT_COMMIT_NAME

    Git committer name for auto-commits; set this in Docker where git config user.name is empty.

  • MARKDOWN_VAULT_MCP_GIT_COMMIT_EMAIL

    Git committer email for auto-commits.

  • MARKDOWN_VAULT_MCP_GIT_COMMIT_NAME_CLAIM

    OIDC claim key used as the commit author name (e.g. name); overrides GIT_COMMIT_NAME per request when an OIDC token is present. The claim is resolved when the tool call arrives and carried to the background commit, so it applies on every write. A configured claim the token does not carry is reported once at WARNING and the static identity is used.

  • MARKDOWN_VAULT_MCP_GIT_COMMIT_EMAIL_CLAIM

    OIDC claim key used as the commit author email (e.g. email); overrides GIT_COMMIT_EMAIL per request when an OIDC token is present. Resolved and carried the same way as the name claim.

  • MARKDOWN_VAULT_MCP_GIT_LFS

    Run git lfs pull on startup to fetch LFS-tracked attachments; set to false for repos without LFS.

  • MARKDOWN_VAULT_MCP_FILE_WATCHER

    Watch the vault for external filesystem changes; auto-disabled when git pull is active or a webhook can deliver (HTTP/SSE transports only). Requires the file-watcher extra.

  • MARKDOWN_VAULT_MCP_FILE_WATCHER_DEBOUNCE_S

    Seconds of quiet after the last filesystem event before reindexing.

  • MARKDOWN_VAULT_MCP_FILE_WATCHER_ROOT_FLOOR

    Keep the non-recursive watch on the vault root; set false to register zero source-dir-rooted FSEvents streams (avoids repeated macOS access prompts on a home-rooted vault) at the cost of root-level files relying on scans.

  • MARKDOWN_VAULT_MCP_BOOT_REINDEX

    Reconcile offline changes at startup by reindexing once the initial build completes. Set false on a large vault to start without paying a full filesystem scan per server start; changes made while no server was running are then invisible until a reindex runs (the reindex tool, or 'markdown-vault-mcp reindex'). Note that `index_stale` reports writer idleness, not agreement with disk, so it reads false while the index may still differ from the vault.

  • MARKDOWN_VAULT_MCP_GITHUB_WEBHOOK_SECRET
    secret

    Shared secret for the GitHub push-event webhook; when set, mounts POST /github-webhook on HTTP/SSE transports to trigger an immediate pull + reindex on push events.

  • MARKDOWN_VAULT_MCP_GITLAB_WEBHOOK_SIGNING_TOKEN
    secret

    Signing token for the GitLab push-event webhook (GitLab 19.0+); when set, mounts POST /gitlab-webhook on HTTP/SSE transports to trigger an immediate pull + reindex on push events. GitLab generates this value; copy the `whsec_` token it shows under Generate signing token rather than inventing one. Deliveries are authenticated by HMAC-SHA256 over the webhook id, timestamp and body, and a delivery older than 5 minutes is rejected.

  • MARKDOWN_VAULT_MCP_GITLAB_WEBHOOK_SECRET_TOKEN
    secret

    Secret token for the GitLab push-event webhook, GitLab's plain-text form and the only one below 19.0; also mounts POST /gitlab-webhook. It proves nothing about the body and cannot expire, so prefer the signing token where the GitLab version offers it. Setting both accepts either, which is how an existing webhook migrates.

  • MARKDOWN_VAULT_MCP_SUMMARIZE_PROVIDER

    Summarization backend (only openai is recognised). Unset auto-detects: the backend activates when credentials or an explicit endpoint are present.

  • MARKDOWN_VAULT_MCP_SUMMARIZE_OPENAI_API_KEY
    secret

    API key for the OpenAI-compatible summarize endpoint; the bare OPENAI_API_KEY is honoured as a fallback. Unset works for keyless local endpoints (Ollama).

  • MARKDOWN_VAULT_MCP_SUMMARIZE_OPENAI_BASE_URL

    OpenAI-compatible endpoint base URL for the summarize tool; setting it enables the tool even without an API key. The bare OPENAI_BASE_URL routes traffic only when a key already enables the feature.

  • MARKDOWN_VAULT_MCP_SUMMARIZE_OPENAI_MODEL

    Chat model id used for summaries.

  • MARKDOWN_VAULT_MCP_SUMMARIZE_MAX_TOKENS

    Upper bound on generated tokens per summarize call; on reasoning models this budget also covers internal reasoning tokens.

  • MARKDOWN_VAULT_MCP_SUMMARIZE_MAX_NOTES

    Cap on the number of notes summarised in one call (subtree expansion truncates to this many).

  • MARKDOWN_VAULT_MCP_SUMMARIZE_MAX_INPUT_CHARS

    Aggregate cap on note characters sent to the model in one call; excess is truncated with a flag on the result.

  • MARKDOWN_VAULT_MCP_SUMMARIZE_TIMEOUT

    Per-request wall-clock budget in seconds for a single summarize backend call; keep it below the MCP client's request timeout so the server-side error wins the race.

  • MARKDOWN_VAULT_MCP_TRANSFER_TTL_DEFAULT_S

    Link lifetime in seconds when the caller requests no explicit TTL.

  • MARKDOWN_VAULT_MCP_TRANSFER_TTL_MAX_S

    Ceiling in seconds a caller-requested link TTL is clamped to.

  • MARKDOWN_VAULT_MCP_TRANSFER_GRACE_TTL_S

    Post-success grace window in seconds: a served token's TTL shrinks to this so a stalled transfer can retry within it.

  • MARKDOWN_VAULT_MCP_TRANSFER_LEASE_S

    Crashed-handler reclaim window in seconds for an in-flight reservation.

  • MARKDOWN_VAULT_MCP_TRANSFER_MAX_UPLOAD_BYTES

    Maximum size in bytes of a single upload.

  • MARKDOWN_VAULT_MCP_JOBS_SOFT_DEADLINE_S

    Seconds a long-running tool call may run in the foreground before it is promoted to a background job and a job handle is returned instead.

  • MARKDOWN_VAULT_MCP_JOBS_RESULT_TTL_S

    Seconds a background-job record (working or finished) is retained for polling before it expires from the store.

  • MARKDOWN_VAULT_MCP_JOBS_MAX_PER_SUBJECT

    Maximum live background jobs per calling subject; further promotions are rejected until older records expire.

  • MARKDOWN_VAULT_MCP_SHUTDOWN_GRACE_S

    Seconds SIGTERM may spend draining in-flight requests before the HTTP server exits. Keep it at or below the termination grace period the orchestrator allows. `0` drops in-flight requests immediately.

  • MARKDOWN_VAULT_MCP_BASE_URL

    Public base URL of the deployed server, for example `https://mcp.example.com`. Required for OIDC. Also the fallback source of the MCP Apps domain when `app_domain` is unset.

  • MARKDOWN_VAULT_MCP_BEARER_TOKEN
    secret

    Single shared bearer token; enables bearer auth unless `bearer_tokens_file` is set, which takes precedence.

  • MARKDOWN_VAULT_MCP_OIDC_CONFIG_URL

    OIDC discovery document URL, for example `https://auth.example.com/.well-known/openid-configuration`.

  • MARKDOWN_VAULT_MCP_OIDC_CLIENT_ID

    OIDC client identifier registered with the provider.

  • MARKDOWN_VAULT_MCP_OIDC_CLIENT_SECRET
    secret

    OIDC client secret registered with the provider.

  • MARKDOWN_VAULT_MCP_OIDC_AUDIENCE

    Expected `aud` claim; tokens issued for another audience are rejected.

  • MARKDOWN_VAULT_MCP_OIDC_REQUIRED_SCOPES

    Scopes a caller must present, space- or comma-separated. Defaults to `openid` in oidc-proxy mode.

  • MARKDOWN_VAULT_MCP_OIDC_ADVERTISED_SCOPES

    Scopes advertised to MCP clients in protected-resource metadata, space- or comma-separated. Overrides the default `openid offline_access`; `oidc_required_scopes` is always added on top. Set this when the registered client is not permitted `offline_access`, or to have clients request extra claim scopes (such as `groups`) without also requiring them in every token.

  • MARKDOWN_VAULT_MCP_OIDC_JWT_SIGNING_KEY
    secret

    Signing key for issued tokens; used in oidc-proxy mode only. When unset, the key is derived deterministically from `oidc_client_secret`, so tokens survive a restart. Rotating that secret then invalidates every issued token. Set this explicitly to decouple token validity from secret rotation. Generate with `openssl rand -hex 32`.

  • MARKDOWN_VAULT_MCP_OIDC_VERIFY_ACCESS_TOKEN

    Validate the access token instead of the id token.

  • MARKDOWN_VAULT_MCP_APP_DOMAIN

    MCP Apps iframe domain, used for CSP sandboxing. Overrides the host derived from `base_url`.

  • MARKDOWN_VAULT_MCP_AUTH_MODE

    Explicit auth-mode override, accepting `remote` or `oidc-proxy` (case- and whitespace-insensitive). When unset the mode is auto-detected from which auth variables are set; the override exists because having all four OIDC variables set is ambiguous between those two modes. Other values are ignored with a warning.

  • MARKDOWN_VAULT_MCP_BEARER_TOKENS_FILE

    Path to a TOML file mapping bearer tokens to subjects; overrides the single-token `bearer_token` mode.

  • MARKDOWN_VAULT_MCP_BEARER_DEFAULT_SUBJECT

    Subject assigned to the single-token bearer mode; ignored when `bearer_tokens_file` is set, since mapped mode carries per-token subjects.

  • MARKDOWN_VAULT_MCP_HTTP_PATH

    Mount path for the MCP endpoint; the health routes derive their prefix from it.

  • MARKDOWN_VAULT_MCP_HEALTH_DETAIL

    How much the unauthenticated /health and /health/ready bodies say: status, standard (adds name, version and per-check verdicts), or full (adds redacted reasons; trusted networks only).

  • PUID

    Run the server process as this UID; the container entrypoint reassigns ownership of writable paths to match.

  • PGID

    Run the server process as this GID; pair with PUID to match the owner of a mounted volume.

~/Library/Application Support/Claude/claude_desktop_config.json
{
  "mcpServers": {
    "markdown-vault-mcp": {
      "command": "uvx",
      "args": [
        "markdown-vault-mcp"
      ],
      "env": {
        "MARKDOWN_VAULT_MCP_KV_STORE_URL": "<YOUR_MARKDOWN_VAULT_MCP_KV_STORE_URL>",
        "MARKDOWN_VAULT_MCP_TOOLS_ALLOW": "<YOUR_MARKDOWN_VAULT_MCP_TOOLS_ALLOW>",
        "MARKDOWN_VAULT_MCP_TOOLS_DENY": "<YOUR_MARKDOWN_VAULT_MCP_TOOLS_DENY>",
        "MARKDOWN_VAULT_MCP_SERVER_NAME": "<YOUR_MARKDOWN_VAULT_MCP_SERVER_NAME>",
        "MARKDOWN_VAULT_MCP_INSTANCE_DESCRIPTION": "<YOUR_MARKDOWN_VAULT_MCP_INSTANCE_DESCRIPTION>",
        "MARKDOWN_VAULT_MCP_INSTRUCTIONS_EXTRA": "<YOUR_MARKDOWN_VAULT_MCP_INSTRUCTIONS_EXTRA>",
        "MARKDOWN_VAULT_MCP_INSTRUCTIONS": "<YOUR_MARKDOWN_VAULT_MCP_INSTRUCTIONS>",
        "MARKDOWN_VAULT_MCP_LOG_LEVEL": "<YOUR_MARKDOWN_VAULT_MCP_LOG_LEVEL>",
        "MARKDOWN_VAULT_MCP_LOG_FORMAT": "<YOUR_MARKDOWN_VAULT_MCP_LOG_FORMAT>",
        "OLLAMA_HOST": "<YOUR_OLLAMA_HOST>",
        "OPENAI_API_KEY": "<YOUR_OPENAI_API_KEY>",
        "VOYAGE_API_KEY": "<YOUR_VOYAGE_API_KEY>",
        "OPENAI_BASE_URL": "<YOUR_OPENAI_BASE_URL>",
        "OPENAI_EMBEDDING_MODEL": "<YOUR_OPENAI_EMBEDDING_MODEL>",
        "MARKDOWN_VAULT_MCP_BUILD_TIMEOUT_S": "<YOUR_MARKDOWN_VAULT_MCP_BUILD_TIMEOUT_S>",
        "MARKDOWN_VAULT_MCP_DRAIN_TIMEOUT_S": "<YOUR_MARKDOWN_VAULT_MCP_DRAIN_TIMEOUT_S>",
        "MARKDOWN_VAULT_MCP_SOURCE_DIR": "<YOUR_MARKDOWN_VAULT_MCP_SOURCE_DIR>",
        "MARKDOWN_VAULT_MCP_READ_ONLY": "<YOUR_MARKDOWN_VAULT_MCP_READ_ONLY>",
        "MARKDOWN_VAULT_MCP_WRITE_PROTECT_EXISTING": "<YOUR_MARKDOWN_VAULT_MCP_WRITE_PROTECT_EXISTING>",
        "MARKDOWN_VAULT_MCP_DISABLE_APPS_UI": "<YOUR_MARKDOWN_VAULT_MCP_DISABLE_APPS_UI>",
        "MARKDOWN_VAULT_MCP_INDEX_PATH": "<YOUR_MARKDOWN_VAULT_MCP_INDEX_PATH>",
        "MARKDOWN_VAULT_MCP_STATE_PATH": "<YOUR_MARKDOWN_VAULT_MCP_STATE_PATH>",
        "MARKDOWN_VAULT_MCP_EMBEDDINGS_PATH": "<YOUR_MARKDOWN_VAULT_MCP_EMBEDDINGS_PATH>",
        "MARKDOWN_VAULT_MCP_INDEXED_FIELDS": "<YOUR_MARKDOWN_VAULT_MCP_INDEXED_FIELDS>",
        "MARKDOWN_VAULT_MCP_REQUIRED_FIELDS": "<YOUR_MARKDOWN_VAULT_MCP_REQUIRED_FIELDS>",
        "MARKDOWN_VAULT_MCP_EXCLUDE": "<YOUR_MARKDOWN_VAULT_MCP_EXCLUDE>",
        "MARKDOWN_VAULT_MCP_TITLE_FIELD": "<YOUR_MARKDOWN_VAULT_MCP_TITLE_FIELD>",
        "MARKDOWN_VAULT_MCP_SEARCHABLE_FIELDS": "<YOUR_MARKDOWN_VAULT_MCP_SEARCHABLE_FIELDS>",
        "MARKDOWN_VAULT_MCP_TEMPLATES_FOLDER": "<YOUR_MARKDOWN_VAULT_MCP_TEMPLATES_FOLDER>",
        "MARKDOWN_VAULT_MCP_PROMPTS_FOLDER": "<YOUR_MARKDOWN_VAULT_MCP_PROMPTS_FOLDER>",
        "MARKDOWN_VAULT_MCP_CONVENTIONS_FILE": "<YOUR_MARKDOWN_VAULT_MCP_CONVENTIONS_FILE>",
        "MARKDOWN_VAULT_MCP_OKF_MODE": "<YOUR_MARKDOWN_VAULT_MCP_OKF_MODE>",
        "MARKDOWN_VAULT_MCP_OKF_WRITE": "<YOUR_MARKDOWN_VAULT_MCP_OKF_WRITE>",
        "MARKDOWN_VAULT_MCP_OKF_VERIFY": "<YOUR_MARKDOWN_VAULT_MCP_OKF_VERIFY>",
        "MARKDOWN_VAULT_MCP_ATTACHMENT_EXTENSIONS": "<YOUR_MARKDOWN_VAULT_MCP_ATTACHMENT_EXTENSIONS>",
        "MARKDOWN_VAULT_MCP_MAX_ATTACHMENT_SIZE_MB": "<YOUR_MARKDOWN_VAULT_MCP_MAX_ATTACHMENT_SIZE_MB>",
        "MARKDOWN_VAULT_MCP_MAX_NOTE_READ_BYTES": "<YOUR_MARKDOWN_VAULT_MCP_MAX_NOTE_READ_BYTES>",
        "MARKDOWN_VAULT_MCP_DEFAULT_SEARCH_MODE": "<YOUR_MARKDOWN_VAULT_MCP_DEFAULT_SEARCH_MODE>",
        "MARKDOWN_VAULT_MCP_CHUNKS_PER_FILE": "<YOUR_MARKDOWN_VAULT_MCP_CHUNKS_PER_FILE>",
        "MARKDOWN_VAULT_MCP_SNIPPET_WORDS": "<YOUR_MARKDOWN_VAULT_MCP_SNIPPET_WORDS>",
        "MARKDOWN_VAULT_MCP_LENGTH_DOWNWEIGHT_ALPHA": "<YOUR_MARKDOWN_VAULT_MCP_LENGTH_DOWNWEIGHT_ALPHA>",
        "MARKDOWN_VAULT_MCP_MAX_CHUNK_WORDS": "<YOUR_MARKDOWN_VAULT_MCP_MAX_CHUNK_WORDS>",
        "MARKDOWN_VAULT_MCP_MAX_CHUNK_CHARS": "<YOUR_MARKDOWN_VAULT_MCP_MAX_CHUNK_CHARS>",
        "MARKDOWN_VAULT_MCP_CHUNK_OVERLAP_WORDS": "<YOUR_MARKDOWN_VAULT_MCP_CHUNK_OVERLAP_WORDS>",
        "MARKDOWN_VAULT_MCP_FOLDER_WEIGHTS": "<YOUR_MARKDOWN_VAULT_MCP_FOLDER_WEIGHTS>",
        "MARKDOWN_VAULT_MCP_FTS_WEIGHTS": "<YOUR_MARKDOWN_VAULT_MCP_FTS_WEIGHTS>",
        "MARKDOWN_VAULT_MCP_EMBEDDING_PROVIDER": "<YOUR_MARKDOWN_VAULT_MCP_EMBEDDING_PROVIDER>",
        "MARKDOWN_VAULT_MCP_OLLAMA_MODEL": "<YOUR_MARKDOWN_VAULT_MCP_OLLAMA_MODEL>",
        "MARKDOWN_VAULT_MCP_OLLAMA_CPU_ONLY": "<YOUR_MARKDOWN_VAULT_MCP_OLLAMA_CPU_ONLY>",
        "MARKDOWN_VAULT_MCP_VOYAGE_MODEL": "<YOUR_MARKDOWN_VAULT_MCP_VOYAGE_MODEL>",
        "MARKDOWN_VAULT_MCP_OPENAI_BASE_URL": "<YOUR_MARKDOWN_VAULT_MCP_OPENAI_BASE_URL>",
        "MARKDOWN_VAULT_MCP_OPENAI_EMBEDDING_MODEL": "<YOUR_MARKDOWN_VAULT_MCP_OPENAI_EMBEDDING_MODEL>",
        "MARKDOWN_VAULT_MCP_FASTEMBED_MODEL": "<YOUR_MARKDOWN_VAULT_MCP_FASTEMBED_MODEL>",
        "MARKDOWN_VAULT_MCP_FASTEMBED_CACHE_DIR": "<YOUR_MARKDOWN_VAULT_MCP_FASTEMBED_CACHE_DIR>",
        "MARKDOWN_VAULT_MCP_EMBED_CONTEXT": "<YOUR_MARKDOWN_VAULT_MCP_EMBED_CONTEXT>",
        "MARKDOWN_VAULT_MCP_EMBED_TIMEOUT_S": "<YOUR_MARKDOWN_VAULT_MCP_EMBED_TIMEOUT_S>",
        "MARKDOWN_VAULT_MCP_EMBEDDING_BATCH_SIZE": "<YOUR_MARKDOWN_VAULT_MCP_EMBEDDING_BATCH_SIZE>",
        "MARKDOWN_VAULT_MCP_GIT_TOKEN": "<YOUR_MARKDOWN_VAULT_MCP_GIT_TOKEN>",
        "MARKDOWN_VAULT_MCP_GIT_REPO_URL": "<YOUR_MARKDOWN_VAULT_MCP_GIT_REPO_URL>",
        "MARKDOWN_VAULT_MCP_GIT_USERNAME": "<YOUR_MARKDOWN_VAULT_MCP_GIT_USERNAME>",
        "MARKDOWN_VAULT_MCP_GIT_PULL_INTERVAL_S": "<YOUR_MARKDOWN_VAULT_MCP_GIT_PULL_INTERVAL_S>",
        "MARKDOWN_VAULT_MCP_GIT_PUSH_DELAY_S": "<YOUR_MARKDOWN_VAULT_MCP_GIT_PUSH_DELAY_S>",
        "MARKDOWN_VAULT_MCP_GIT_COMMIT_NAME": "<YOUR_MARKDOWN_VAULT_MCP_GIT_COMMIT_NAME>",
        "MARKDOWN_VAULT_MCP_GIT_COMMIT_EMAIL": "<YOUR_MARKDOWN_VAULT_MCP_GIT_COMMIT_EMAIL>",
        "MARKDOWN_VAULT_MCP_GIT_COMMIT_NAME_CLAIM": "<YOUR_MARKDOWN_VAULT_MCP_GIT_COMMIT_NAME_CLAIM>",
        "MARKDOWN_VAULT_MCP_GIT_COMMIT_EMAIL_CLAIM": "<YOUR_MARKDOWN_VAULT_MCP_GIT_COMMIT_EMAIL_CLAIM>",
        "MARKDOWN_VAULT_MCP_GIT_LFS": "<YOUR_MARKDOWN_VAULT_MCP_GIT_LFS>",
        "MARKDOWN_VAULT_MCP_FILE_WATCHER": "<YOUR_MARKDOWN_VAULT_MCP_FILE_WATCHER>",
        "MARKDOWN_VAULT_MCP_FILE_WATCHER_DEBOUNCE_S": "<YOUR_MARKDOWN_VAULT_MCP_FILE_WATCHER_DEBOUNCE_S>",
        "MARKDOWN_VAULT_MCP_FILE_WATCHER_ROOT_FLOOR": "<YOUR_MARKDOWN_VAULT_MCP_FILE_WATCHER_ROOT_FLOOR>",
        "MARKDOWN_VAULT_MCP_BOOT_REINDEX": "<YOUR_MARKDOWN_VAULT_MCP_BOOT_REINDEX>",
        "MARKDOWN_VAULT_MCP_GITHUB_WEBHOOK_SECRET": "<YOUR_MARKDOWN_VAULT_MCP_GITHUB_WEBHOOK_SECRET>",
        "MARKDOWN_VAULT_MCP_GITLAB_WEBHOOK_SIGNING_TOKEN": "<YOUR_MARKDOWN_VAULT_MCP_GITLAB_WEBHOOK_SIGNING_TOKEN>",
        "MARKDOWN_VAULT_MCP_GITLAB_WEBHOOK_SECRET_TOKEN": "<YOUR_MARKDOWN_VAULT_MCP_GITLAB_WEBHOOK_SECRET_TOKEN>",
        "MARKDOWN_VAULT_MCP_SUMMARIZE_PROVIDER": "<YOUR_MARKDOWN_VAULT_MCP_SUMMARIZE_PROVIDER>",
        "MARKDOWN_VAULT_MCP_SUMMARIZE_OPENAI_API_KEY": "<YOUR_MARKDOWN_VAULT_MCP_SUMMARIZE_OPENAI_API_KEY>",
        "MARKDOWN_VAULT_MCP_SUMMARIZE_OPENAI_BASE_URL": "<YOUR_MARKDOWN_VAULT_MCP_SUMMARIZE_OPENAI_BASE_URL>",
        "MARKDOWN_VAULT_MCP_SUMMARIZE_OPENAI_MODEL": "<YOUR_MARKDOWN_VAULT_MCP_SUMMARIZE_OPENAI_MODEL>",
        "MARKDOWN_VAULT_MCP_SUMMARIZE_MAX_TOKENS": "<YOUR_MARKDOWN_VAULT_MCP_SUMMARIZE_MAX_TOKENS>",
        "MARKDOWN_VAULT_MCP_SUMMARIZE_MAX_NOTES": "<YOUR_MARKDOWN_VAULT_MCP_SUMMARIZE_MAX_NOTES>",
        "MARKDOWN_VAULT_MCP_SUMMARIZE_MAX_INPUT_CHARS": "<YOUR_MARKDOWN_VAULT_MCP_SUMMARIZE_MAX_INPUT_CHARS>",
        "MARKDOWN_VAULT_MCP_SUMMARIZE_TIMEOUT": "<YOUR_MARKDOWN_VAULT_MCP_SUMMARIZE_TIMEOUT>",
        "MARKDOWN_VAULT_MCP_TRANSFER_TTL_DEFAULT_S": "<YOUR_MARKDOWN_VAULT_MCP_TRANSFER_TTL_DEFAULT_S>",
        "MARKDOWN_VAULT_MCP_TRANSFER_TTL_MAX_S": "<YOUR_MARKDOWN_VAULT_MCP_TRANSFER_TTL_MAX_S>",
        "MARKDOWN_VAULT_MCP_TRANSFER_GRACE_TTL_S": "<YOUR_MARKDOWN_VAULT_MCP_TRANSFER_GRACE_TTL_S>",
        "MARKDOWN_VAULT_MCP_TRANSFER_LEASE_S": "<YOUR_MARKDOWN_VAULT_MCP_TRANSFER_LEASE_S>",
        "MARKDOWN_VAULT_MCP_TRANSFER_MAX_UPLOAD_BYTES": "<YOUR_MARKDOWN_VAULT_MCP_TRANSFER_MAX_UPLOAD_BYTES>",
        "MARKDOWN_VAULT_MCP_JOBS_SOFT_DEADLINE_S": "<YOUR_MARKDOWN_VAULT_MCP_JOBS_SOFT_DEADLINE_S>",
        "MARKDOWN_VAULT_MCP_JOBS_RESULT_TTL_S": "<YOUR_MARKDOWN_VAULT_MCP_JOBS_RESULT_TTL_S>",
        "MARKDOWN_VAULT_MCP_JOBS_MAX_PER_SUBJECT": "<YOUR_MARKDOWN_VAULT_MCP_JOBS_MAX_PER_SUBJECT>",
        "MARKDOWN_VAULT_MCP_SHUTDOWN_GRACE_S": "<YOUR_MARKDOWN_VAULT_MCP_SHUTDOWN_GRACE_S>",
        "MARKDOWN_VAULT_MCP_BASE_URL": "<YOUR_MARKDOWN_VAULT_MCP_BASE_URL>",
        "MARKDOWN_VAULT_MCP_BEARER_TOKEN": "<YOUR_MARKDOWN_VAULT_MCP_BEARER_TOKEN>",
        "MARKDOWN_VAULT_MCP_OIDC_CONFIG_URL": "<YOUR_MARKDOWN_VAULT_MCP_OIDC_CONFIG_URL>",
        "MARKDOWN_VAULT_MCP_OIDC_CLIENT_ID": "<YOUR_MARKDOWN_VAULT_MCP_OIDC_CLIENT_ID>",
        "MARKDOWN_VAULT_MCP_OIDC_CLIENT_SECRET": "<YOUR_MARKDOWN_VAULT_MCP_OIDC_CLIENT_SECRET>",
        "MARKDOWN_VAULT_MCP_OIDC_AUDIENCE": "<YOUR_MARKDOWN_VAULT_MCP_OIDC_AUDIENCE>",
        "MARKDOWN_VAULT_MCP_OIDC_REQUIRED_SCOPES": "<YOUR_MARKDOWN_VAULT_MCP_OIDC_REQUIRED_SCOPES>",
        "MARKDOWN_VAULT_MCP_OIDC_ADVERTISED_SCOPES": "<YOUR_MARKDOWN_VAULT_MCP_OIDC_ADVERTISED_SCOPES>",
        "MARKDOWN_VAULT_MCP_OIDC_JWT_SIGNING_KEY": "<YOUR_MARKDOWN_VAULT_MCP_OIDC_JWT_SIGNING_KEY>",
        "MARKDOWN_VAULT_MCP_OIDC_VERIFY_ACCESS_TOKEN": "<YOUR_MARKDOWN_VAULT_MCP_OIDC_VERIFY_ACCESS_TOKEN>",
        "MARKDOWN_VAULT_MCP_APP_DOMAIN": "<YOUR_MARKDOWN_VAULT_MCP_APP_DOMAIN>",
        "MARKDOWN_VAULT_MCP_AUTH_MODE": "<YOUR_MARKDOWN_VAULT_MCP_AUTH_MODE>",
        "MARKDOWN_VAULT_MCP_BEARER_TOKENS_FILE": "<YOUR_MARKDOWN_VAULT_MCP_BEARER_TOKENS_FILE>",
        "MARKDOWN_VAULT_MCP_BEARER_DEFAULT_SUBJECT": "<YOUR_MARKDOWN_VAULT_MCP_BEARER_DEFAULT_SUBJECT>",
        "MARKDOWN_VAULT_MCP_HTTP_PATH": "<YOUR_MARKDOWN_VAULT_MCP_HTTP_PATH>",
        "MARKDOWN_VAULT_MCP_HEALTH_DETAIL": "<YOUR_MARKDOWN_VAULT_MCP_HEALTH_DETAIL>",
        "PUID": "<YOUR_PUID>",
        "PGID": "<YOUR_PGID>"
      }
    }
  }
}

Tools & capabilities

Tools this server exposes to the agent.

  • search — Hybrid search combining SQLite FTS5 keyword search (BM25, porter stemming) and semantic search with Reciprocal Rank Fusion, returning sentence-scale snippets with full-section recovery.
  • read — Read markdown notes by path, with optional section filtering and revision history support (read at specific git SHA).
  • write — Write or create markdown notes with overwrite protection (etag-based if_match), automatic index updates, and per-folder authoring rules.
  • edit — Edit existing notes with targeted modifications and automatic index updates.
  • append — Append content to existing notes.
  • delete — Delete notes with automatic index cleanup.
  • rename — Rename notes and update references.
  • move_folder — Move notes between folders.
  • fetch — Capture a URL as a markdown note.
  • git_sync — Synchronize vault with git remote (pull/push).
  • okf_verify — Verify OKF (Open Knowledge Format) conformance and handle human review workflows.
  • create_upload_link — Generate one-time transfer links for uploading files to the vault.
  • propose_links — Scan recently modified notes and propose wikilinks between unconnected notes.
  • conversation_search — Search Claude.ai conversations (Claude.ai only).
  • recent_chats — Retrieve recent conversations for distillation (Claude.ai only).
  • get_server_info — Confirm deployed server version and core version.

Use cases

  • Capture and summarize URLs as Resource notes, automatically linking related existing notes in your vault.
  • Research a topic by creating interlinked notes (one per regulation/concept) with a map-of-content note tying them together.
  • Distill daily conversations into Inbox notes with automatic summarization and linking.
  • Find and propose missing wikilinks between notes that should be connected but aren't yet.
  • Split or merge capture notes to organize and deduplicate content without losing information.

Markdown Vault MCP MCP server FAQ

What is Markdown Vault MCP?

It's an MCP server that gives Claude and other AI agents full read/write access to a markdown knowledge vault with hybrid search (keyword + semantic), git integration, and automatic indexing. It exposes 34 tools for searching, writing, editing, and managing notes.

Is it free?

Yes, Markdown Vault MCP is open-source (licensed under the repository's LICENSE file) and free to install and use. Embeddings may require paid APIs (OpenAI, Voyage AI) or can use free local models (FastEmbed, Ollama).

How do I install it in Claude Desktop?

Download the `.mcpb` bundle from GitHub Releases and double-click to install, or run `mcpb install markdown-vault-mcp-<version>.mcpb`. Claude Desktop will prompt for required environment variables via a GUI wizard.

How do I install it in Cursor?

Install via PyPI (`pip install markdown-vault-mcp`) or Docker, then configure the MCP server in Cursor's settings by pointing to the stdio transport (`markdown-vault-mcp serve`). See the Installation guide for detailed steps.

What authentication is required?

No authentication is required to run the server locally. For embeddings, you may need API keys (OpenAI, Voyage AI) or can use free local embeddings (FastEmbed, Ollama). Git integration uses your existing git credentials.

Does it support version control?

Yes, optional git integration auto-commits each write operation with deferred push, tracks history, and allows reading notes at specific git revisions. External changes can be synced via pull loop or GitHub/GitLab webhooks.

README (reference)

Source of truth, from the repository.

<!-- DOMAIN-START --> <p align="center"> <img src="assets/icon.svg" alt="Markdown Vault MCP logo" width="128" height="128"> </p> <!-- DOMAIN-END -->

Markdown Vault MCP

<!-- mcp-name: io.github.pvliesdonk/markdown-vault-mcp -->

CI Quality Gate Status Coverage Reliability Rating Security Rating Maintainability Rating PyPI Python License Docker Docs llms.txt Template

Generic markdown vault MCP with hybrid search

Documentation | Config wizard | PyPI | Docker

Features

<!-- DOMAIN-START -->
  • Hybrid search: SQLite FTS5 keyword search (BM25, porter stemming) and semantic search (FastEmbed, Ollama, OpenAI, or Voyage AI embeddings, plus any OpenAI-compatible endpoint via OPENAI_BASE_URL), fused with Reciprocal Rank Fusion; diversity-aware ranking returns sentence-scale snippets with full-section recovery via read(path, section=heading). See the Embeddings guide, including the recipe for OpenAI-compatible endpoints.
  • Frontmatter-aware indexing: YAML frontmatter fields become filterable and searchable, with optional required-field enforcement and adaptive heading-level chunking for long documents.
  • Write operations: the write tools (write, edit, append, delete, rename, move_folder, fetch, git_sync, the okf_* tools, create_upload_link) are registered by default and hidden when MARKDOWN_VAULT_MCP_READ_ONLY=true; writes update the index automatically, per-folder _conventions.md authoring rules are surfaced to LLM clients at write time, and attachments (PDFs, images, and other non-markdown files) are read/write too.
  • Incremental reindexing: hash-based change detection with boot-time reconciliation; the vector index converges to the reconciled chunk set, and parse-pipeline upgrades rebuild the index once automatically.
  • Git integration: optional auto-commit (one commit per write tool call) with deferred push, plus a pull loop or a GitHub or GitLab push webhook for external changes; history and diff tools read the log back. An overwriting write returns the revision holding the content it replaced, and read(path, revision=sha) reads a note back at that revision, so an overwrite is recoverable from the client that made it. When the clone stops reaching its remote, every write result carries a remote warning saying the content is committed locally only, and the log marks the transition rather than repeating each cycle. See the Git integration guide.
  • OKF-aware: recognizes Open Knowledge Format bundles and annotates results with each note's type, lifecycle status, staleness, and trust tier, plus conformance audit and migration tooling. Static bearer writes use tool provenance; human review through a bearer credential requires confirmation with okf_verify in elicit mode. See the OKF guide.
  • MCP surface: 34 LLM-visible tools, 9 resources, and 8 prompt templates, plus browser-based MCP Apps views and one-time transfer links. Full references: Tools, Resources, Prompts, MCP Apps, Transfer links, CLI.

Overwrite protection is enabled by default. Before replacing an existing file with write or fetch, read that destination and pass its etag as if_match. New files need no etag. Transfer upload links require a new destination because they have no if_match option. Set MARKDOWN_VAULT_MCP_WRITE_PROTECT_EXISTING=false to allow blind overwrites; see the transfer guide.

Python integrations use VaultSettings for configuration. See the Vault API for the migration from the removed 4.x constructor keywords and the configuration API for typed assembly. The Git API covers removal of the deprecated strategy claim keywords and the keyword-only LFS and repository options.

<!-- DOMAIN-END -->

What you can do with it

<!-- DOMAIN-START -->

With this server mounted in Claude, you can:

  • Capture a URL as a note. "Fetch <url>, summarize as a Resource note under 3-Resources/, and link any existing notes on the topic." Claude composes fetch + search + write.
  • Research a topic into your vault. "Research product security regulations, compare them, and create a set of interlinked notes: one per regulation, plus a map-of-content." Claude composes web-search tools (client-side) + write with wikilinks. See the Research workflows guide for the full loop.
  • Distill today's thinking. "Summarize today's conversations into Inbox notes." Claude.ai only; uses conversation_search + recent_chats + write. The para-capture-chats prompt is the one-click version.
  • Find missing links. Fire the propose-links prompt from the + menu: it scans recently modified notes and proposes links between notes that aren't yet connected, writing them on confirmation.
  • Split or merge captures. "Split this Inbox note into two." / "Merge this into <existing note> instead of duplicating." Claude composes read + write + delete.

The vault needs no external scheduler or separate capture app: it sits behind your conversations and absorbs their output.

<!-- DOMAIN-END --> <!-- ===== TEMPLATE-OWNED SECTIONS BELOW — DO NOT EDIT; CHANGES WILL BE OVERWRITTEN ON COPIER UPDATE ===== -->

Installation

From PyPI

pip install markdown-vault-mcp

If you add optional extras via the PROJECT-EXTRAS-START / PROJECT-EXTRAS-END sentinels in pyproject.toml, document them below:

<!-- DOMAIN-START -->
pip install markdown-vault-mcp[mcp]             # FastMCP server
pip install markdown-vault-mcp[embeddings-api]  # Ollama/OpenAI embeddings via API
pip install markdown-vault-mcp[embeddings]      # FastEmbed local embeddings
pip install markdown-vault-mcp[file-watcher]    # watchdog-based external-change watcher
pip install markdown-vault-mcp[all]             # MCP + FastEmbed + API embeddings

For the Claude Code plugin channel (/plugin install markdown-vault-mcp@pvliesdonk) and all other install routes, see the Installation guide and the Claude Code plugin guide.

<!-- DOMAIN-END -->

From source

git clone https://github.com/pvliesdonk/markdown-vault-mcp.git
cd markdown-vault-mcp
uv sync --all-extras --all-groups

Docker

docker pull ghcr.io/pvliesdonk/markdown-vault-mcp:latest

To run the newest merged code instead of the newest release, use the rolling edge tag. It is rebuilt on every merge to main and carries no version identity. See Image tags for the full tag list.

docker pull ghcr.io/pvliesdonk/markdown-vault-mcp:edge

A compose.yml ships at the repo root and runs as-is: copy .env.example to .env, then docker compose up -d. It publishes port 8000 on the host and assumes no reverse proxy; Docker Compose covers the configuration split, the domain sentinel blocks, and a Traefik overlay.

To attach a remote Python debugger (development only; the protocol is unauthenticated), see Remote debugging.

Linux packages (.deb / .rpm)

Download .deb or .rpm packages from the GitHub Releases page. Both install a hardened systemd unit; env configuration is sourced from /etc/markdown-vault-mcp/env (copy from the shipped /etc/markdown-vault-mcp/env.example).

Claude Desktop (.mcpb bundle)

Download the .mcpb bundle from the GitHub Releases page and double-click to install, or run:

mcpb install markdown-vault-mcp-<version>.mcpb

Claude Desktop prompts for required env vars via a GUI wizard, with no manual JSON editing needed.

For manual Claude Desktop configuration and setup options, see Claude Desktop deployment.

Release channels

Artifacts ship on three channels. Each row lists exactly what that channel publishes.

ChannelVersion identityArtifacts
edge (rolling)None; the commit is the identityDocker image :edge rebuilt on every merge to main; .mcpb bundle as the mcpb-bundle-edge workflow artifact; Claude Code plugin .zip as the plugin-zip-edge artifact; rolling unstable docs version. It leaves no git tag, GitHub release, or PyPI entry behind.
Pre-releasevX.Y.Z-rc.N, computed and reviewed in its release pull requestPyPI (as the pre-release X.Y.ZrcN); GitHub release with wheels, sdist, .deb/.rpm packages, .mcpb bundle, plugin .zip, and SBOM attached; Docker image under its immutable vX.Y.Z-rc.N tag plus the ordering-aware rolling rc tag. Skips the plugin marketplace, the MCP registry, and the docs deploy.
StablevX.Y.ZEverything: PyPI, Docker (version tag plus ordering-aware latest / vX / vX.Y), .deb/.rpm, GitHub release assets (wheels, sdist, .mcpb bundle, plugin .zip, SBOM), plugin marketplace and MCP registry entries (when the release is the newest stable), versioned docs with an ordering-aware latest alias.

Pre-releases reach PyPI so that a candidate's .mcpb bundle installs: the bundle points at PyPI rather than carrying the code. Ordinary installers never see them, because a PEP 440 resolver skips pre-releases unless the requirement pins one or you pass --pre. Ask for a candidate by name with pip install markdown-vault-mcp==X.Y.ZrcN. PyPI spells it in the PEP 440 canonical form, while tags use SemVer. Rolling pointers are ordering-aware, so a patch release cut from an old release/X.Y branch never moves latest-style tags back to older content, and a candidate for an already-released version never moves rc. See Release process for the full model.

Quick start

markdown-vault-mcp serve                                # stdio transport
markdown-vault-mcp serve --transport http --port 8000   # streamable HTTP

For library usage (embedding the domain logic without the MCP transport), import from the markdown_vault_mcp package directly. See the project's domain modules under src/markdown_vault_mcp/ for entry points.

Server info

The server registers a built-in get_server_info tool (via fastmcp_pvl_core.register_server_info_tool) so operators can confirm the deployed version with a single MCP call. The default response carries server_name, server_version, and core_version. Servers that talk to a remote upstream wire upstream version reporting inside the DOMAIN-UPSTREAM-START / DOMAIN-UPSTREAM-END sentinel in src/markdown_vault_mcp/server.py; see tool-registration for the wiring pattern.

Health

The server serves /health (liveness, a static 200) and /health/ready (readiness, 503 when a backing store or a domain check fails) outside the MCP mount and outside auth, via fastmcp_pvl_core.register_health_routes. compose.yml probes the first. Domain readiness checks go in the health_checks dict in src/markdown_vault_mcp/server.py; see Docker deployment for the routes, the mount-path rule, and MARKDOWN_VAULT_MCP_HEALTH_DETAIL.

Configuration

The most common environment variables, shared across all fastmcp-pvl-core-based services:

<!-- GENERATED-ENV-TABLE-CORE-START — generated by scripts/gen_config_surface.py; do not edit -->
VariableDefaultDescription
MARKDOWN_VAULT_MCP_KV_STORE_URLfile:///data/statePersistent-state backend URL shared by every pvl-core subsystem that needs state. memory:// is in-process and lost on restart; file:///path persists on one server; redis://, dynamodb:// and mongodb:// each need their matching extra. When unset, defaults to file:///data/state (the volume family Docker images mount), or to memory:// (with a warning) on a host where that directory is not usable.
MARKDOWN_VAULT_MCP_LOG_LEVELINFOLog level for every logger in the process, FastMCP's included (DEBUG / INFO / WARNING / ERROR / CRITICAL). The -v CLI flag overrides to DEBUG. The unprefixed FASTMCP_LOG_LEVEL still works for one major version and logs a deprecation warning.
MARKDOWN_VAULT_MCP_LOG_FORMAT(none)Log rendering. rich is one colour event key=value line per record, for a terminal; json is one JSON object per record, for a collector. Unset picks rich when stderr is a terminal and json everywhere else, so a container or journald gets JSON with no configuration.
<!-- GENERATED-ENV-TABLE-CORE-END -->

This table and the one under Domain configuration are curated subsets. The complete generated reference, with every variable the server reads, is the configuration reference; .env.example lists the same surface in copy-paste form.

Authentication

Callers authenticate via a bearer token or OIDC (mutually exclusive). See the Authentication guide for setup, mapped multi-subject tokens, OIDC, and troubleshooting.

Post-scaffold checklist

After copier copy and gh repo create --push:

  1. Fill in the DOMAIN blocks (every section marked with a DOMAIN sentinel comment) in this README and in AGENTS.md. The GENERATED-ENV-TABLE-* regions are not DOMAIN blocks; the config generator owns them and rewrites them on every run.
  2. Configure GitHub secrets (see below).
  3. Install dev + docs tooling: uv sync --all-extras --all-groups.
  4. Install pre-commit hooks: uv run pre-commit install.
  5. Run the gate locally: uv run pytest -x -q && uv run ruff check --fix . && uv run ruff format . && uv run mypy src/ tests/.
  6. Push the first commit. CI should be green.

GitHub secrets

CI workflows reference two required repository secrets and one optional Claude token. Configure them via Settings → Secrets and variables → Actions or with gh secret set:

SecretUsed byHow to generate
RELEASE_TOKENrelease-prepare.yml, release.yml, copier-update.yml, renovate.yml, bootstrap.ymlFine-grained PAT at https://github.com/settings/personal-access-tokens/new with contents: write, pull_requests: write, and administration: write (bootstrap applies the repository rulesets, auto-merge, the security settings, and the About block). Must belong to a repository admin: the shipped rulesets grant bypass to the admin role, and the release tag + GitHub release that knope creates after a release pull request merges rely on it (pull requests the token opens also need it so their CI runs). Scoped to this repo.
SONAR_TOKENci.ymlhttps://sonarcloud.io: after importing the repository, open its Administration → Analysis Method page. Turn Automatic Analysis off there first, because SonarQube Cloud refuses a CI scan while it is on; choosing GitHub Actions then shows the token. Until the secret exists, CI skips the scan.
CLAUDE_CODE_OAUTH_TOKENclaude.ymlOptional. Run claude setup-token locally and configure this only for @claude or opted-in automatic review.
gh secret set RELEASE_TOKEN
gh secret set SONAR_TOKEN
# Optional: enables @claude and opted-in automatic review.
gh secret set CLAUDE_CODE_OAUTH_TOKEN

Dependency updates are handled by Renovate (renovate.yml), which reuses RELEASE_TOKEN. It maintains uv.lock and auto-merges patch/minor bumps once the CI Success check is green; bootstrap.yml enables auto-merge, applies the repository rulesets (.github/rulesets/), turns on private vulnerability reporting and Dependabot alerts, and fills the repository's About block (description, website, topics) from pyproject.toml on first push. See Repository Protection for the per-branch posture, bypass model, and security settings. GitHub Actions are updated in the copier template and arrive via copier update, not per-repo.

GITHUB_TOKEN is auto-provided; no action needed.

Local development

The PR gate (matches CI):

uv run pytest -x -q                                  # tests
uv run ruff check --fix . && uv run ruff format .    # lint + format
uv run mypy src/ tests/                              # type-check

Pre-commit runs a subset of the gate on each commit; see .pre-commit-config.yaml for details, or AGENTS.md for the full Hard PR Acceptance Gates.

CI requires tests to pass on Python 3.11 through 3.14. Python 3.14 also collects branch coverage and enforces the 80% total and patch coverage thresholds. To reproduce that test command, run uv run --python 3.14 pytest --cov --cov-report=xml --durations=20.

Troubleshooting

Moving a scaffolded project

uv sync creates .venv/bin/* scripts with absolute shebangs pointing at the venv Python. If you move the repo after scaffolding (mv /old/path /new/path), uv run pytest fails with ModuleNotFoundError: No module named 'fastmcp' because the stale shebang resolves to a different interpreter than the venv's site-packages.

Fix:

rm -rf .venv
uv sync --all-extras --all-groups

uv run python -m pytest also works as a one-shot workaround (bypasses the stale entry-script shim).

uv.lock refresh after copier update

When copier update introduces new dependencies (such as a new extra added to pyproject.toml.jinja), the CI install step runs uv sync --locked, which fails against a stale lockfile. Run uv lock locally and commit the refreshed uv.lock alongside accepting the copier-update PR.

CI installs with --locked (and the review workflow with --frozen) so no job ever rewrites uv.lock in its own workspace: a job that re-locks hides the drift it just repaired, and a dirty workspace breaks any later git checkout in the same job. Lockfile drift then shows up as a red install step with a clear message, not as a silent mutation.

Contributing

CONTRIBUTING.md holds the rules for issues and pull requests, and where a fix belongs: fastmcp-pvl-core for library code, the template for template-owned files, this repository for anything inside its DOMAIN-* / CONFIG-* / PROJECT-* blocks. AGENTS.md carries the conventions and gates; the skills under .agents/skills/ carry the task procedures, among them self-reviewing (local self-review before a pull request), writing-release-notes (release notes), applying-template-updates (the weekly template update pull request) and authoring-issues-prs (filing). The release procedure is in docs/deployment/release-process.md; the template update procedure in docs/deployment/template-updates.md. SECURITY.md says how to report a vulnerability privately, and what to expect after.

Links

<!-- ===== TEMPLATE-OWNED SECTIONS END ===== -->

Domain configuration

The variables this project features as its entry points (domain variables use the MARKDOWN_VAULT_MCP_ prefix):

<!-- GENERATED-ENV-TABLE-DOMAIN-START — generated by scripts/gen_config_surface.py; do not edit -->
VariableDefaultRequiredDescription
MARKDOWN_VAULT_MCP_SOURCE_DIR/data/vaultNoPath to the markdown vault directory. When it does not exist, or the server cannot access it, the server starts but every tool fails with a message saying which until it is fixed (managed git mode clones into it). Symbolic links inside the vault are followed on Python 3.13+.
MARKDOWN_VAULT_MCP_READ_ONLYfalseNoSet to true to hide the write tools (write, edit, append, delete, rename, move_folder, fetch, git_sync, the okf_* tools, create_upload_link) and serve a search-only vault.
MARKDOWN_VAULT_MCP_WRITE_PROTECT_EXISTINGtrueNoRefuse a write that would overwrite an existing file when no if_match etag is supplied. Deliberate replacement still works: read the file first, then pass if_match. Unaffected: edit, append, delete, rename. Set to false to allow blind overwrites.
MARKDOWN_VAULT_MCP_DEFAULT_SEARCH_MODEautoNoMode used when a search call omits 'mode': auto, keyword, semantic, or hybrid. The default 'auto' picks hybrid when embeddings are configured and keyword when they are not. Pin 'keyword' to keep unqualified searches off the embedding provider (each hybrid or semantic search embeds the query, which costs an API call on a metered provider). A configured semantic/hybrid default also degrades to keyword without embeddings, so no setting can make a vault unsearchable; an explicit mode= argument is never downgraded.
MARKDOWN_VAULT_MCP_EMBEDDING_PROVIDER(none)NoEmbedding provider: openai, voyage, ollama, or fastembed. Unset auto-detects from the environment (never voyage). Any OpenAI-compatible endpoint works with openai plus OPENAI_BASE_URL; see the embeddings guide.
MARKDOWN_VAULT_MCP_GIT_REPO_URL(none)NoHTTPS remote URL for managed git mode: the server clones into an empty SOURCE_DIR on startup (or validates an existing origin) and enables the pull loop, auto-commit, and deferred push.
MARKDOWN_VAULT_MCP_FILE_WATCHERtrueNoWatch the vault for external filesystem changes; auto-disabled when git pull is active or a webhook can deliver (HTTP/SSE transports only). Requires the file-watcher extra.
MARKDOWN_VAULT_MCP_SUMMARIZE_OPENAI_BASE_URL(none)NoOpenAI-compatible endpoint base URL for the summarize tool; setting it enables the tool even without an API key. The bare OPENAI_BASE_URL routes traffic only when a key already enables the feature.
<!-- GENERATED-ENV-TABLE-DOMAIN-END -->

This is a curated subset: a field appears here when its tags metadata includes readme. Every domain variable is documented in the configuration reference, grouped the same way the config wizard presents them.

Domain-config fields are composed inside src/markdown_vault_mcp/config.py between the CONFIG-FIELDS-START / CONFIG-FIELDS-END sentinels; env reads go through fastmcp_pvl_core.env(_ENV_PREFIX, "SUFFIX", default) so naming stays consistent, and field invariants go in __post_init__ between the CONFIG-VALIDATE-START / CONFIG-VALIDATE-END sentinels. Each field's metadata help, tags, and wizard group generate the reference tables directly, so keep them accurate and complete.

Key design decisions

<!-- DOMAIN-START -->
  • Document identity is the relative path with .md extension; frontmatter is optional by default (REQUIRED_FIELDS opts into enforcement).
  • Hybrid search uses Reciprocal Rank Fusion over the FTS5 and vector result lists, with diversity-aware ranking capping chunks per document.
  • Tool semantics mirror Claude Code's Read/Write/Edit patterns, so LLM clients drive the vault with habits they already have.
  • The library is synchronous; the MCP layer wraps calls in asyncio.to_thread(). File writes return after saving, while index updates run in the background. Index-dependent mutations wait for prior writes; see index freshness.
  • Indexing is hash-based: unchanged files are never re-parsed, and any change to how stored rows derive from a note's bytes bumps INDEX_SEMANTICS_VERSION so deployed vaults rebuild themselves once on upgrade.

The full decision log lives in the design document.

<!-- DOMAIN-END -->

Related MCP servers

Paperless-NGX over MCP: search, read, upload and tag documents; manage correspondents and types.

1
Python
MIT
View repository →
SCScholar MCP logo

FastMCP server for scholarly papers, patents, books and standards with docling PDF conversion

2
Python
MIT
View repository →

MCP server for AI image generation via OpenAI, Stable Diffusion (SD WebUI), or placeholders.

1
Python
MIT
View repository →
LOLogo.dev MCP logo

Look up company logos and brand data via the logo.dev API.

0
Python
MIT
View repository →

Intelligent code knowledge graph for AI coding agents — 71% cheaper, 72% faster

0
TypeScript
MIT
View repository →

Pay-per-call LLM chat plus data tools: DNS, crypto, Base gas, Wikipedia. x402 USDC or Lightning.

0
JavaScript
View repository →