Obsidian EnhancedCAUTION
This is an enhanced version of the excellent cyanheads/obsidian-mcp-server with additional features specifically tailored for remote Claude.ai integration, advanced task querying, and security via Tailscale.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://www.typescriptlang.org/) [](https://modelcontextprotocol.io/) [](./CHANGELOG.md) [](https://opensource.org/licenses/Apache-2.0) [](https://github.com/BoweyLou/obsidian-mcp-server-enhanced/issues) [](https://github.com/cyanheads/obsidian-mcp-server)
Enhanced Obsidian MCP Server with Claude.ai Remote Integration, Tailscale Support, and Advanced Query Capabilities!
🔥 Enhanced Fork Notice: This is an enhanced version of the excellent cyanheads/obsidian-mcp-server with additional features specifically tailored for remote Claude.ai integration, advanced task querying, and security via Tailscale.
An MCP (Model Context Protocol) server providing comprehensive access to your Obsidian vault. Enables LLMs and AI agents to read, write, search, and manage your notes and files through the Obsidian Local REST API plugin.
Built on the `cyanheads/mcp-ts-template`, this server follows a modular architecture with robust error handling, logging, and security features.
🚀 Enhanced Features (This Fork)
🏛️ Multi-Vault Support
Simultaneous access to multiple Obsidian vaults through a single MCP server:
- Multiple Vault Management: Connect to multiple Obsidian instances on different ports simultaneously
- Vault-Specific Routing: Tools automatically route to the correct vault based on
vaultparameter - **Individua
63a6867431f9OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add obsidian-mcp-server --env MCP_AUTH_KEY=${MCP_AUTH_KEY} --env OBSIDIAN_API_KEY=${OBSIDIAN_API_KEY} -- npx -y [email protected]{
"mcpServers": {
"obsidian-mcp-server": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"MCP_AUTH_KEY": "${MCP_AUTH_KEY}",
"OBSIDIAN_API_KEY": "${OBSIDIAN_API_KEY}"
}
}
}
}Exposed tools (10)
4 read · 4 write · 2 destructive. Blast radius: 2 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
append_note | destructive | Append or prepend note content. Whole-note overwrite is not available here. |
create_daily_note | write | Create today |
create_note | write | Create a new note by vault-relative path. Existing notes are not overwritten. |
create_task | write | Create a Tasks-plugin compatible task. |
fetch | read | Fetch bounded Obsidian note content by vault-relative path. |
latest_note | read | Return the markdown note with the latest filesystem modification time. |
overwrite_note | destructive | Overwrite a note. Enable only for explicitly trusted connector clients. |
search | read | Bounded Obsidian vault search with snippets. |
task_query | read | Query Obsidian Tasks-plugin compatible tasks. |
update_task | write | Update an existing task by path and line or text match. |
Trust audit
CAUTIONgrade B · trust 83/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (6 observation(s))
- Network
- declared (11 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (20)
- **`OBSIDIAN_BASE_URL`**: **Required.** Base URL for the Obsidian Local REST API (e.g., `http://127.0.0.1:27123`).
- Provide the corresponding `OBSIDIAN_BASE_URL` (e.g., `http://127.0.0.1:27123`).
- If the user prefers to use the default encrypted HTTPS URL (e.g., `https://127.0.0.1:27124`), explain that it uses a self-signed certificate.
- **Example (for Obsidian API)**: `npm run fetch:spec http://127.0.0.1:27123/ docs/obsidian-api/obsidian_rest_api_spec` (Replace URL if your Obsidian API runs elsewhere)
CHATGPT_FACADE_TARGET ?= http://127.0.0.1:3020
append_note, overwrite_note
.clinerules
.ncurc.json
.env.template
return yaml.load(data) as object;
const parsedYaml = yaml.load(data) as object;
PROJECT_DIR="$(cd "$SCRIPT_DIR/../../.." && pwd)"
import { RequestContext, requestContextService } from "../../../utils/index.js";import { BaseErrorCode, McpError } from "../../../types-global/errors.js";import { ObsidianRestApiService } from "../../../services/obsidianRestAPI/index.js";import { RequestContext } from "../../../utils/index.js";@modelcontextprotocol/sdk, @types/jsonwebtoken, @types/sanitize-html, axios, date-fns, dotenv, express, ignore
res.setHeader("Access-Control-Allow-Credentials", "true");- **Unauthorized Access**: Verify API key setup
# Add to crontab for weekly log rotation
Gates applied: no_behavioural_pass.
63a6867431f9full audit observations/trust-audit/mcp-server/boweylou__obsidian-enhanced.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 63a6867431f9 | CAUTION | B | 83 | first audit |
Questions
What is the Obsidian Enhanced MCP server?
This is an enhanced version of the excellent cyanheads/obsidian-mcp-server with additional features specifically tailored for remote Claude.ai integration, advanced task querying, and security via Tailscale.
What tools does Obsidian Enhanced expose?
10 in total: 4 read-only, 4 that write, and 2 that can delete or overwrite (append_note, overwrite_note). Every one is listed on this page with its risk.
Is Obsidian Enhanced safe to connect to an agent?
With care. The audit graded it B (83/100) and found 20 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 2 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Obsidian Enhanced need?
It reads MCP_AUTH_KEY and OBSIDIAN_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Obsidian Enhanced run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as obsidian-mcp-server at 2.1.0.
How current is this page?
The grade is for one exact copy of the source (63a6867431f9), read on 2026-10-08. The repository is watched and re-audited when it changes.