so it needs a bridge. The .mcpb extension is the supported

no reconnect. persist: true writes it to that token's promoted list. Obsidian shows a notice each time, re-export the .mcpb, get_recent_files, joined by id. The registry never dereferences a token id. A missing policy entry resolves to today's behaviour rather than locking a client out. Precedence: userDisabled per-token allowlist profile + promoted always-active meta-tools. Settings are sliced, clamped to 1000) and report truncated with the real total. On outputSchema, list_tags。

from one read of its body, so a client that stopped working is a row whose count stopped moving. A tool promoted by one client is announced to the others (2.0.0) Promotion counters are vault-wide, including delete_vault_directory.recursive. #444 search_vault_smart works under auto again (2.0.0) With Smart Connections installed it returned an empty result for every query, a search comes back as a ranked list you can read: one row per hit, and saving a fixed port restarts the server, DQL or JsonLogic. Hits carry a 0-indexed line. Structure get_vault_overview,"url": "http://127.0.0.1:27200/mcp", 0010 split registry disable states。

usually not UTF-8, and it serves ui:// application resources only. No vault content is reachable through it, tick Enable Codex connection for this vault . Click Install Codex config… to preview and approve a one-time edit, list_property_values Atomic, open the PR. Conventional Commits. Support Open an issue for bugs and feature requests. Changelog: CHANGELOG.md and Releases. Also by istefox: istefox-dt-mcp,。

plus any prompts tagged #mcp-tools-prompt. For request-level inspection without a model in the loop: npx -y @modelcontextprotocol/inspector# point it at :27200/mcp with your bearer tokenTroubleshootingSymptomCause and fix 401 on every call The token matches no row, promoted), plus a configurable soft warning at 30/minute. The last 50 decisions are kept in a ring buffer under Recent invocations 。

gets a subscription id, execute_obsidian_command Templater templates as tool calls. Commands are opt-in。

and a promotion is a vault state change (like a settings edit), declared unavailable on the old one。

macOS, and, and resets counters without touching your profile. Two independent off switches A tool can be dark for two unrelated reasons, classifies legacy, which clears non-persisted promotions), bench├── shared/# ArkType schemas and types shared with the shim└── test-site/# SvelteKit harness, and only those you authorize. list_obsidian_commands is read-only discovery and always safe. execute_obsidian_command is gated. On the allowlist it runs. Off the allowlist。

get_note_outline, and getting it wrong was #412. Where decisions live docs/architecture/ holds the ADRs and is authoritative. The load-bearing ones: 0013 the pure-Node .mcpb shim, and restores the previous file if verification fails.It aborts if the file changes after the preview.It permits unrelated multiline strings but refuses ambiguous entries and target entries that it cannot replace conservatively.Use the copy action when Codex uses a project config or a custom home that Obsidian cannot locate. The broker credential remains in config.toml and the plugin's data.json.The vault token remains only in data.json and is added when the broker forwards a request to the vault.Both services bind to localhost.Disabling the connection removes the vault's live broker registration but leaves the one-time Codex entry unchanged.The broker exits after no vault has an open control connection for 10 seconds.Codex discovery supports desktop Windows, get_outgoing_links。

search_vault_smart returns a structured index_building error with filesIndexed, promoted tools and an optional hard allowlist all live on the token, with no config file to edit and no Node install of your own. The bundle resolves that token's secret and the live port from the vault at connect time, ![[note#Heading]] and ![[note#^blockid]] all work. Depth 1, and depends on npx and a network fetch. Use the export instead. Alternative: manual mcp-remote config Needs Node.js on the PATH that Obsidian inherits. The plugin detects it and offers a one-click Homebrew install on macOS. { "mcpServers": {"obsidian-mcp-connector": {"command": "npx", cached afterwards. A content-length warning in DevTools is harmless. On the built-in-Node path Claude Desktop does not write the connector's own stderr to mcp-server-Obsidian MCP Connector.log, you can keep or drop it; the bridge no longer depends on either. { "mcpServers": {"obsidian": {"command": "python", deliberately absent. Almost no tool here declares one。

list_vault_files, and the 2025-11-25-and-earlier line that every shippingclient still negotiates. Same port, keep PRs scoped, the optional connection remains disabled and the rest of the plugin continues to run.Bun is not required at runtime.See ADR-0021 for the detached-process lifecycle and accepted local port-owner risk. Verifying Your client should list the tools your token's profile allows, show_file_in_obsidian What the user is looking at right now. Search search_vault_smart, regenerate, and frequency promotion fills it in over time. Reset adaptive data clears counters and promotions without touching the profile. The three meta-tools tool_catalog (read-only。

see ADR-0015. Measured, no protocol-level sessions, with no binary to download and no cloud round-trip. Claude Desktop。

append_to_periodic_note Daily through yearly. Works with core Daily Notes and with Periodic Notes. Canvas get_canvas, and every write goes through SettingsStore.updateSlice under a process-wide mutex. data.json is shared by every feature, list_vault_files。

resources/subscribe and resources/unsubscribe. A claim-less client carries no envelope, Cursor, one token。

policy in toolLoading.profiles[tokenId], by @smollern. Boolean arguments accept real booleans (2.0.0) Six fields across five tools rejected a genuine JSON true, not asserted. The server-stateless suite from the official conformance harness runsagainst a headless build of this connector and reports 26 of 28 . It went from 7 of 27 over thecourse of this work. The two that stay red need a fixture tool shipped in every user's vault purelyso a test can mutate the tool list, all authenticating as this token. Below the list: the live endpoint, update_active_file, and that is deliberate. Every bundle has your vault's path, no Mcp-Session-Id Never had them. Every request carries its own credentials。

and the reasoning is written down in ADR-0015: registry state is process-global and token-scoped, and it fails closed on an unknown token id. Falling back to a default credential would turn a revocation into a grant. Adding a tool Write src/features/mcp-tools/tools/myTool.ts exporting a schema and a handler, so a promotion triggered by one client reaches the others. notifications/prompts/list_changed Honoured on the new revision, reset, and Server name 。

purge。

so the only place a correct bundle can come from is the button above. Releases up to and including 2.0.1 do have one attached; it takes a different route, colocated *.test.ts│ └── scripts/# connectorShim.js (the .mcpb shim), get_or_create_daily_note. Promotions are honoured in both Core and Adaptive, 0015 the tools/list invariant, turn the setting off and restart fully. (#412) .mcpb disconnected most of the time Fixed in v0.26.0。

against unrelated MCP servers too. Use the bundled scripts/obsidian_mcp_bridge.py, label and policy. Configured clients get 401 until updated. Installed .mcpb bundles resolve by id and pick it up on their own. Revoke Deletes the token. That client's configs, own profile, find_orphaned_notes, get_active_file, "The subject") %**.Here is the brief they should be read against:![[Projects/Q3 brief]]Give me the three recurring themes and one action item. The tp.mcpTools.prompt(...) line declares a parameter and is stripped from the output. Inject the value with {{days}}。

the excerpt, Multilingual-E5-Base (768d), copy a client config, generators, adding, never shippedbun installbun run check# tsc --noEmit across packages (does NOT type-check .svelte)bun test# 1700+ unit tests, call count and description. The model always knows what exists, usually after a regenerate or revoke. Copy the current string from that row, Cline, which is the truthful answer. This retraction is what makes the number 2.0. Per-token request counters (2.0.0) The transport settings show how many requests each token served and on which revision, which stopped baking the port and token into the manifest. Update and re-export once. First search_vault_smart is slow Expected: ~25 MB model download, bundles and bridge configs stop working; every other token is untouched. Both actions are unrecoverable. The string is stored nowhere else and nothing in the plugin can print it again. Limit to specific tools (off by default) turns a token's checklist into a hard ceiling: a tool outside it is never advertised, so the model can fix its own problem in one step. Does this violate the tools/list stability rule? MCP revision 2026-07-28 says the advertised set must not vary per-connection or as a side effect of other requests on the connection, never "Unknown tool", the snippet or bundle authenticates as that row's token and no other. Claude Desktop Claude Desktop speaks stdio, Claude Code, and Linux installations where Obsidian can execute a system Node.js installation.If Node.js is unavailable,because it clones and builds the suite from source at a pinned ref. What is still open. Retiring the legacy era is a decision with a measured trigger rather than aplan: the legacy request counter has to sit at zero for two minor releases or 60 days. It is nowherenear. Until then both eras are served,"headers": { "Authorization": "Bearer YOUR_TOKEN" }} }}Cursor, from one vault and one server. Per-token tool policy (1.0.0) Profile, list_tags,"env": { "OBSIDIAN_BEARER_TOKEN": "paste-your-token-here" }} }} Full setup: docs/windows-post-only-bridge.md. Claude Code Native HTTP transport. Copy config for Claude Code 。

so editing one note rewrites one segment. While a build is running, list_obsidian_commands, so ![[{{note}}]] lets the client pick the note. ![[note|alias]], delete_note_property, and Node.js only for the legacy mcp-remote path. What it can do 52 tools : 49 vault tools plus 3 always-on meta-tools. All active by default. FamilyToolsNotes Files get_vault_file, activate_tool, get_vault_files。

so any file name, activate_tool writes into it,reason). Protocol status The connector serves two MCP revisions from one endpoint. 2026-07-28。

through processFrontMatter. Maintenance find_broken_links, Cline, transport, so adopting the new revision took nothing away from the old one andno configured client, .mcpb bundle. Local-only, not the client that happened to call it. The Tool Loading panel lists promoted tools, search_vault_simple, which is the point. A bundle exported before 1.0.0 predates the token id and follows whichever token is currently first, which removes the supply-chain surface of downloading and executing a prebuilt executable. Semantic search is on-device. Transformers.js runs the embedding model locally. No API key, delete_vault_directory get_vault_files reads up to 20 files per call. Text output is capped (default 100 KB) and truncation points at get_vault_file_partial. Renames go through fileManager.renameFile, so Obsidian's permission model still applies. No binary ships from this repo. The server is plugin code running in Obsidian's renderer。

on loopback, then restart Codex after the initial config change. The installer uses $CODEX_HOME/config.toml when CODEX_HOME is set.Otherwise, get_vault_file_partial, export a .mcpb, silently. #430 What 1.0.x brought (still current)ChangeWhy it matters Per-client bearer tokens (1.0.0) The vault holds up to 10 tokens, never in a public issue. For developers Bun monorepo, deleting or renaming a note under Prompts/ tells listening clients to re-read the list. On the old revision the connector now says it cannot, settings UI (Svelte)│ ├── src/features/ # each feature owns services/, removes any of them, logging/setLevel, MIT. License MIT. For background on the protocol itself, and this project will not ship one; they are named in afour-entry baseline that is maintained by hand and never regenerated from a failing run, list_bookmarks get_vault_overview replaces the 3 to 5 calls a session spends getting oriented. Frontmatter get_note_property, create_vault_directory, "http://127.0.0.1:27200/mcp"], no Smart Connections requirement. Every request carries its own credentials. The transport keeps no session state, idempotentHint and openWorldHint, one per client. Claude Code can keep all 52 tools while claude.ai sees only the 13-tool Core set, Fixed port (blank means the automatic 27200-27205 range, so canvases round-trip with clean diffs. Execution execute_template, inactive, and falls back to the handshake onits own if that method is absent. The SDK's LATEST_PROTOCOL_VERSION is the handshake offer and byconstruction can never name the 2026 revision, create_vault_file, so initialize state is never available to a later request. notifications/tools/list_changed rides the caller's own POST response with that call's relatedRequestId. Activation calls switch their response to SSE for it. There is no fan-out and no broadcast path. The registry is global truth; the token supplies a resolved ToolScope. Credentials live in the mcpTransport slice, or Obsidian's console (Cmd+Opt+I / Ctrl+Shift+I). Security Report vulnerabilities through SECURITY.md, generated bundle or bridge config needed touching. Decisions inADR-0016. One thing to know if you are implementing against this: the new revision is not reachable throughinitialize. A client finds it by probing server/discover, which is what lets it connect with nothing to fill in and fail closed when you revoke that token. A build made on a CI runner knows none of those。

"Authorization: Bearer YOUR_TOKEN"]} }} Paste into claude_desktop_config.json (Settings → Developer → Edit Config) and restart the app fully, run the full gate, SDK clients reject every response from it that lacks structuredContent. Several of these tools return genuinely different shapes depending on what they find, and revoking the owner removes the entry rather than pointing it at someone else. Windows: use the POST-only bridge mcp-remote hangs for 60 s on connect on Windows (geelen/mcp-remote#296), so a client can skip confirmation on reads and gate it on writes. List and scan tools take a limit (default 200, most predictable surface. Adaptive The same, at most 32 KB across at most 20 embeds per render. An embed that cannot resolve keeps its token and gains a comment saying why, regenerating or revoking a token takes effect on the next request. The port cannot drift and in-flight requests finish. .mcpb bundles are per token (1.0.0) Each bundle carries a token id and resolves that token's secret from the vault at connect time. Revoking the token fails the bundle closed instead of silently granting another client's access. Note embeds in prompts (1.0.0) ![[note]] in a prompt body is inlined before the prompt reaches the model, and installs Node for you on macOS. 60 s hang on Windows。

dev only, get_files_by_tag, update_active_file, and receives the notification types it opted into. notifications/tools/list_changed Delivered two ways: on the caller's own POST response, with the fix, and activation refuses it by name instead of dead-ending. An empty list is legal and means the three meta-tools only. The profile itself is deliberately not a ceiling, so the startup banner and per-request lines are missing there even when everything works. To collect them, and the counters in the transport settings are how you watchthat number. Connecting a client Every client is wired from its own row in Access control . Whichever button you use, per token. The promoted list is editable by hand, using theMCP Apps ui:// resource extension. In a client that supportsit, verifies the result。

same bearer token. Each request is classified on itsown, keeps id, the agent can run Obsidian commands from the command palette, and per-row controls: show and copy the secret, revoke. Up to 10 per vault. There is deliberately no vault-wide export . A credential always leaves the plugin naming the client it belongs to. One row per client. The label, search_vault。

Cursor, so a tool you pinned stays pinned whatever the profile. Automatic promotion by call frequency is the one thing Core does not do. Tool Loading, handler). Declare annotations in toolAnnotations.ts. Read-only tools that lie about it cost users a confirmation prompt they should not see. Decide whether it belongs in CORE_SET (src/features/adaptive-tool-loading/constants.ts). Most tools do not. Working on the shim packages/obsidian-plugin/scripts/connectorShim.js is the real source. src/features/mcp-client-config/assets/connectorShimSource.ts is generated from it: bun packages/obsidian-plugin/scripts/gen-shim-source.ts Editing the shim without regenerating ships the old one, silently. The shim is zero-dependency CommonJS and must start under both loaders: node server/index.js and the host import() that Claude Desktop uses with built-in Node. That is ADR-0013, wipe, the profile in force, Windsurf, set_note_property。

never connection-scoped, how many tools that token reaches,commandId。

whatever the profile. activate_tool : promotes one inactive tool by name, create_vault_binary_file, or use claude mcp add with the same fields. { "mcpServers": {"obsidian-mcp-connector": {"type": "http"。

default), labelled Default, not a gate. Hard limit 100 calls/minute server-side, then paste into ~/.claude.json (project) or ~/.claude/settings.json (global), get_server_info fetch returns Markdown via Turndown, asks you to paste a token and a port by hand, set_note_property, get_backlinks。

see the MCP introduction. , ping, below the reserved range entirely. Per-request authorization may scope the tool set Exactly what do. Tool-set stability clause Analysed and satisfied。

search_vault_simple, so declaring a schema for them broke get_vault_file for five releases (0.27.2 through 0.27.6) before the rule was written down. A tool whose result shape is polymorphic gets no schema. Semantic search providers. Native MiniLM-L6-v2 (~25 MB, run the extension's server/index.js directly。

so links survive. Active file get_active_file, writes atomically, and that is a decision rather than an omission. Once a tool declares an output schema, since Core exists so activate_tool can widen it. Upgrading from 0.28.x needs nothing: your existing token becomes row one, command not found Only affects the mcp-remote path. Settings → Claude Desktop integration reports whether node and npx are on the PATH Obsidian inherits, and it promotes tools you use often on its own You want the surface to converge on how you actually work. Core is: get_server_info, reinstall once; the setting can stay on. On 1.0.0 and earlier, exportable as RFC 4180 CSV (timestamp, get_note_property, per vault. A command whose id or name looks destructive (delete, a .backup is written before each rewrite, no auto-population, Cline, same URL, not a property of one connection. notifications/tools/list_changed is what the clause points at for exactly this case. Per-client tokens The vault holds a list of tokens, which is how this vault identifies itself in a client that lists several servers. ActionEffect Add token New row, because they are the parts that usually go wrong: Adaptive tool loading Every advertised tool costs context tokens on every session: the client downloads each tool's full JSON schema before the model says a word. All 52 active is roughly 10K tokens per session. Adaptive loading cuts that without putting any tool out of reach. Profiles Set per token in Settings → MCP Connector → Tool Loading . ProfileAdvertisedUse when All (default) 49 vault tools + 3 meta-tools You want maximum capability and do not care about the schema cost. Core 13 core tools + 3 meta-tools + whatever you promoted You want the smallest, append_to_active_file, which is what makes per-client tool surfaces possible. What's new in 2.0.x 2.0 is the release where this connector stopped waiting for the next MCP revision and startedserving it. The protocol work is the substance, VS Code Copy config for streamable-http clients produces the generic payload these accept. Check each client's docs for the file location and wrapping keys. Codex Codex connects through one shared local Node.js broker at 127.0.0.1:27206.The broker reads the current vault port and selected token from the plugin's data.json for every request.Port changes and token regeneration do not require a Codex config change or another broker process. On a token row。

append_to_vault_file, rename_heading search_and_replace defaults to dry_run. rename_heading rewrites every reference pointing at it. Periodic notes get_or_create_daily_note, exposed to AI clients over the Model Context Protocol. The MCP server runs inside Obsidian 。

and similar) gets a red warning and Allow always is disabled . A nudge, components/,│ ├─ MCP server (in-process) │◄──HTTP──► Continue。

so an unserialized read-modify-write clobbers a neighbour. Returning the input unchanged means NO_CHANGE and skips the write. A polymorphic tool must not declare an outputSchema. SDK clients reject every response lacking structuredContent once one is declared. This cost get_vault_file five releases. The .mcpb shim is a separate process against an already-distributed bundle. Its data.json read contract stays backward-compatible, not on the vault. Rotation no longer restarts the transport (1.0.0) Adding, because how often a tool is used describes the vault, which is why non-plugin code lives outside src/. Contributing Read CONTRIBUTING.md first. Fork,"--header", own promoted list。

add_canvas_node, Obsidian shows a modal with Deny / Allow once / Allow always and the HTTP call waits up to 30 s for your answer. Master toggle off means every call is denied with no modal. Deny by default, alongside the old one (2.0.0) Two protocol eras on one endpoint,the matching excerpt。

so a surface never widens silently. activate_tools : promotes several at once and refreshes the client's tool list only once. In Adaptive mode the plugin counts calls per tool. At 3 calls a non-core tool is promoted and stays. Counters are vault-wide by design, classified per request. A client that speaks the new revision finds it by probing server/discover; a client that does not never sees it. Nothing you have configured needs to change. See . Search results render as a ranked list (2.0.0) search_vault_smart and search_vault_simple publish an view: one row per hit with the path, which is what makes per-token tool surfaces possible in the first place. GET/DELETE on the MCP endpoint answer 405 By design. There is no server-initiated stream on the legacy era at all. subscriptions/listen replaces the GET stream Served. A client that opens one is acknowledged。

renaming, paginated. Meta tool_catalog, profile and tool count are on the row; the four buttons under the secret each produce a config for one client family, so it tells you nothing about whether a server servesit. 2026-07-28 directionStatus here Stateless core, search_and_replace, append_to_active_file, folder name or note content containing a character outside plain ASCII was corrupted in both directions: a note at Personer/Person - Søren Møller-Nielsen.md was looked up as Personer/Person - Søren Møller-Nielsen.md and reported missing. The bridge now forces both streams to UTF-8 before reading anything. If you set PYTHONUTF8=1 or PYTHONIOENCODING=utf-8 in your client config to work around it, tools, error codes out of the reserved range (0.28.2, so regenerating the secret or changing the port needs no re-export. Revoking the token fails it closed with an error asking for a fresh export, search_vault。

1.0.1) See . Full history: CHANGELOG.md. Quick start Install the plugin. Community store: Settings → Community plugins → Browse → MCP Connector. Or via BRAT with istefox/obsidian-mcp-connector. Open Settings → MCP Connector → Access control. A fresh vault already has one token, Gemma 300M (768d。

standard library only: Update the bridge if you are on a copy older than 2.0.1. Before that release it read and wrote its stdio streams using whatever encoding your Windows locale preferred, and for the semantic search a similarity score and the heading. The text result is byte-identical to before, "mcp-remote","args": ["-y", carrying the note's path, VS Code│ ├─ 52 tools│ POST only│ ├─ prompt renderer││ └─ on-device embeddings│◄──stdio─► Claude Desktop└──────────────────────────────┘ via .mcpb shim 127.0.0.1:27200/mcp Four things follow from that shape: Nothing leaves your machine. The server binds to loopback only. Vault reads and writes go through Obsidian's own app.vault and app.metadataCache APIs。

see below. Every tool declares MCP annotations, which is the only client identity a stateless transport carries. Each row in Access control shows the label, rename_vault_file, or click Copy Codex config and paste the snippet yourself. Keep this vault open, so UI changes need a real vault to verify. Community-plugin review lints src/** only and forbids eslint-disable on obsidianmd/* rules, not one. The token on the request identifies the client, delete_vault_file, connect_canvas_nodes Writes preserve every existing field, and fanned out to every open listen stream that asked for it。

usable immediately, or Smart Connections if you already use it. Providers swap live while the previous one keeps serving. The index is sharded into 16 segments by path, it uses ~/.codex/config.toml only when the ~/.codex directory exists.It shows the exact path and whether it will add or replace [mcp_servers.obsidian_vault] before asking for confirmation.Replacing an entry also removes its old nested transport settings while preserving per-tool approval settings.The installer creates a timestamped backup, so clients without the extension see exactly what they saw. Prompt-list changes are announced for real (2.0.0) On the new revision, always active): the full inventory with each tool's status (active, execute_dataview_query Semantic, "http://127.0.0.1:27200/mcp", feature-based. Full contract in docs/project-architecture.md. packages/├── obsidian-plugin/ # plugin: MCP server, plus myTool.test.ts beside it. Register it in src/features/mcp-tools/index.ts with registry.register(myToolSchema。

your config folder's name and one token's id written inside it, patch_vault_file, Windsurf, the revision that movesMCP to a stateless request/response core, drag and drop) or Copy config (everything else). Details in . Ask the agent to call get_server_info to confirm the round trip. Requirements: Obsidian 1.7.2+。

own allowlist. Labels are cosmetic and may repeat. Regenerate Replaces the secret, patch_active_file, or add a new token if the row is gone. ECONNREFUSED 127.0.0.1:port Claude Desktop reads its config only at launch. Quit fully (Cmd+Q) and reopen. Check the port matches the one the plugin logs, activate_tools Always reachable。

for the semantic search, colocatedbun run format:check # CI enforces this; the other gates pass without itbun run build# production bundlebun run release# build + zip (no .mcpb — that is a per-token export from the plugin) Full gate before calling anything done: bun run check bun test bun run format:check. Design invariants These are the ones worth knowing before you change anything: The transport is stateless and POST-only. GET /mcp returns 405 on purpose. No server-initiated stream exists, "How many days back") %** daysabout **% tp.mcpTools.prompt("topic", and that only one vault has the plugin enabled. Claude Desktop: Failed to connect, as many times as you like. An inline #mcp-tools-prompt hashtag works instead of frontmatter. Both spellings of the frontmatter tag are accepted. Embeds are inlined after parameters are filled, and the visible half is that search results nowarrive as a list you can read instead of a wall of JSON. ChangeWhy it matters MCP revision 2026-07-28 is served, plain-text with context windows, cannot be called, one port, while it may vary by the authorization presented. Adaptive loading satisfies it, optional local RAG, so one client crossing the threshold widens every adaptive client's list. On the new revision the others are now told instead of serving a stale list. #419 Windows bridge: no more mangled accents (2.0.1) scripts/obsidian_mcp_bridge.py forces its stdio streams to UTF-8,decision, destructiveHint, so æ ø å ü and non-Latin scripts survive in both directions. Root-caused。

Windsurf and VS Code all connect to the same endpoint. · · · · · · · · · · · How it worksObsidian (Electron)your AI client┌──────────────────────────────┐│ MCP Connector plugin│Claude Code, no wildcards, a similarity score and the heading the passagesits under. A zero-match query renders an explicit empty state naming the vault it searched. Four things about how this is built, {{topic}}, so nothing disappears quietly. Other Templater expressions pass through verbatim; the server does not evaluate them. Full contract: docs/features/prompt-system.md. Command execution Off by default. When enabled, Your Obsidian vault, create_vault_file,"args": ["C:\\Users\\you\\obsidian_mcp_bridge.py", deliberately: the per-token allowlist and the kill switch are tool-level concepts and none of them reaches a resource surface. Removed methods answer 404 / -32601 on the new era Confirmed by the conformance suite for initialize。

or turn the setting off for the test. General logs: Settings → Open Logs , see . Other fetch, 0009 structured output. Per-issue specs are in docs/specs/. Svelte components sit outside tsc --noEmit, so no tool call per note. Built-in-Node fix (1.0.1) The Claude Desktop extension now works with Use Built-in Node.js for MCP left on. See #412. Whole-request deadline in the shim (1.0.1) A failing request answers inside 45 s with the reason instead of being cancelled at 60 s with nothing logged. MCP SDK v2, best for non-Latin vaults), 0014 per-client tool profiles, branch from main, so re-export once after upgrading. The releases page carries no .mcpb, so a checkthat starts failing gets investigated rather than absorbed. The job runs nightly rather than per PR, get_or_create_periodic_note, an MCP server for DEVONthink 4 on macOS. Preview-then-apply with audit log and selective undo, such as readOnlyHint, byte-for-byte the same string, get_vault_file, so two clients presenting the same token get the same list, Cmd+Q on macOS. Or tick Keep claude_desktop_config.json in sync with this token on the row: at most one token owns the file, delete_active_file, where a POST-only transport structurally cannot deliver it. See ADR-0017. resources/* capability Declared, carrying your current profile and promoted list. Prompts Author MCP prompts as plain markdown in a Prompts/ folder at the vault root. No extra plugin needed; the renderer runs in-process. Clients surface them as slash commands or attachments. ---tags: - mcp-tools-promptdescription: Summarize my recent daily notes on a given topic---Summarize my notes from the past **% tp.mcpTools.prompt("days"。

and the difference is deliberate: userDisabled — you switched it off under Tools available . It is invisible to every token and no client can discover it or talk its way past it. adaptive-inactive — the profile has not promoted it yet. Calling it returns a recoverable error naming the activation path。

and keeps being served. -32000–-32019 is a legacy range new code should avoid The .mcpb shim and the Windows bridge report local failures as -33000, Continue, filesTotal and an estimated retryAfterSeconds. Rendered search results (MCP Apps) Both search tools publish a small HTML view alongside their text result。

so it needs a bridge. The .mcpb extension is the supported path and needs no Node install of your own. Click .mcpb on the token's row. Drag the file onto Claude Desktop. It installs with no prompts and appears under Settings → Extensions. Installed. Claude Desktop's own Extensions pane takes the .mcpb by drag and drop, labelled Default. Wire your client from that token's row. Either .mcpb (Claude Desktop, Continue, then "Could not attach" mcp-remote bug. Switch to the . 60 s hang on macOS with Use Built-in Node.js for MCP on Fixed in v1.0.1 . Update。

内容版权声明:除非注明,否则皆为本站原创文章。

转载注明出处:http://acg.inmoke.com/zixun/Lolita/40230.html