Obsidian SyncCAUTION
MCP server for Obsidian — access your vault from any AI agent, even when your machine is off. Powered by Self-hosted LiveSync.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Give any AI agent access to your Obsidian vault over MCP. Run it locally against your vault files, or pair it with Self-hosted LiveSync and deploy to the cloud so it works even when your machine is off.
Example: From your phone, ask your AI: "What's in my daily note for today?" — and get the full content back, with a link to open it in Obsidian.
How it works
The server connects to your vault in two ways:
- Filesystem mode — reads
.mdfiles directly from your vault folder. No database needed. - CouchDB mode — reads from a CouchDB database, locally or in the cloud. Your vault syncs to CouchDB via Self-hosted LiveSync, the community Obsidian plugin (600k+ downloads). The MCP server reads from CouchDB directly using livesync-commonlib — the same library that powers the plugin — for proper chunk handling and E2E encryption support.
Both modes expose the same MCP tools over HTTP, so any MCP-compatible agent can connect: Claude, Copilot, custom agents, anything that speaks the Model Context Protocol.
Choose your setup
A. Deploy MCP to the cloud
You already have LiveSync and CouchDB on a
dc2f6c9675f0OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add obsidian-sync-mcp --env COUCHDB_PASSWORD=${COUCHDB_PASSWORD} --env COUCHDB_PASSPHRASE=${COUCHDB_PASSPHRASE} --env MCP_AUTH_TOKEN=${MCP_AUTH_TOKEN} -- npx -y [email protected]Exposed tools (10)
6 read · 3 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
delete_note | destructive | Delete a note from the Obsidian vault. |
edit_note | write | Edit a note without rewriting it. Use |
get_note_metadata | read | Get metadata about a note without reading its full content. Returns frontmatter, tags, outgoing links, backlinks (notes that link to this one), size, and timestamps. Use this to navigate the knowledge graph. |
list_folders | read | List all folders in the vault. Use this to discover folder names before writing or listing notes. Returns the folder tree with note counts. |
list_notes | read | List markdown notes in the vault with modification timestamps. Examples: list_notes(sort_by= |
list_tags | read | List all tags used in the vault, sorted by frequency. Use this to discover tags before filtering with list_notes. |
move_note | write | Move or rename a note. Use this to rename a note within the same folder, move it to a different folder, or both at once. Creates destination folders automatically. |
read_note | read | Read the content of a note from the Obsidian vault. Returns the markdown content and a deep link to open it in Obsidian. |
search_notes | read | Search note contents for terms, case-insensitive.\n |
write_note | write | Write or update a note in the Obsidian vault. Creates the note if it doesn |
Trust audit
CAUTIONgrade B · trust 84/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (2 observation(s))
- Network
- declared (5 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (20)
console.log(`Auth: /oauth/token request grant_type=${JSON.stringify(grantType)}`);console.log(`Auth: /oauth/token issuing access token client_id=${pending.clientId}`);delete_note
.gitmodules
for (const p of ["../escape.md", "a/../../etc/passwd.md", "/abs/note.md", "a\0b.md", "a//b.md", "folder/.md"]) {it("blocks ../../ traversal", async () => {await assert.rejects(() => vault.readNote("../../etc/shadow"), /Invalid note path/);await assert.rejects(() => vault.deleteNote("../../important.md"), /Invalid note path/);await assert.rejects(() => vault.listNotes("../../etc"), /Path traversal blocked/);- **Browser-attack protection (no auth mode)** — with no token, the server validates both the HTTP `Host` and `Origin` headers and rejects any request whose host/origin is not `localhost`/`127.0.0.1`/
assert.ok(isOriginAllowed("http://127.0.0.1:8787", allowed));diff-match-patch, fastmcp, fflate, minimatch, octagonal-wheels, pouchdb-adapter-http, pouchdb-core, pouchdb-errors
- **Fixed a critical authentication bypass in password-gated OAuth (GHSA-cc9w-6w4g-hqv7).** `/oauth/token` issued an access token for any authorization code that was in flight, without checking that t
cat > .env <<EOF
export PATH="$HOME/.fly/bin:$PATH" # add to ~/.zshrc or ~/.bashrc
export PATH="$HOME/.fly/bin:$PATH" # add to ~/.zshrc or ~/.bashrc
curl -L https://fly.io/install.sh | sh
curl -L https://fly.io/install.sh | sh
- Bump `@modelcontextprotocol/sdk` to 1.32.1, clearing a high-severity advisory (GHSA-6qxp-vccf-f47h: an OAuth client could send credentials to an authorization server chosen by the MCP server).
- **Browser-attack protection (no auth mode)** — with no token, the server validates both the HTTP `Host` and `Origin` headers and rejects any request whose host/origin is not `localhost`/`127.0.0.1`/
Gates applied: no_behavioural_pass.
dc2f6c9675f0full audit observations/trust-audit/mcp-server/es617__obsidian-sync.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | dc2f6c9675f0 | CAUTION | B | 84 | first audit |
Questions
What is the Obsidian Sync MCP server?
MCP server for Obsidian — access your vault from any AI agent, even when your machine is off. Powered by Self-hosted LiveSync.
What tools does Obsidian Sync expose?
10 in total: 6 read-only, 3 that write, and 1 that can delete or overwrite (delete_note). Every one is listed on this page with its risk.
Is Obsidian Sync safe to connect to an agent?
With care. The audit graded it B (84/100) and found 20 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Obsidian Sync need?
It reads COUCHDB_PASSPHRASE, COUCHDB_PASSWORD, MCP_AUTH_TOKEN and TEST_COUCHDB_PASSWORD from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Obsidian Sync run?
It speaks streamable-http, so it runs as a service you connect to over the network. It is published on npm as obsidian-sync-mcp at 0.8.0.
How current is this page?
The grade is for one exact copy of the source (dc2f6c9675f0), read on 2026-10-08. The repository is watched and re-audited when it changes.