Sign in
mcp server · aliasunder.github.io

Vault Cortex

Standalone MCP server for Obsidian vaults — hybrid search, notes & files, memory, tasks, OAuth 2.1

What it says

The record the registry holds

How you get it

There is no address to call. This one is a package you install and run yourself, wherever your assistant runs.

ghcr.io/aliasunder/vault-cortex:0.41.0 · oci
the record Copied from the official MCP registry, exactly as it holds it.
{
  "server": {
    "$schema": "https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json",
    "name": "io.github.aliasunder/vault-cortex",
    "description": "Standalone MCP server for Obsidian vaults — hybrid search, notes & files, memory, tasks, OAuth 2.1",
    "title": "Vault Cortex",
    "repository": {
      "url": "https://github.com/aliasunder/vault-cortex",
      "source": "github",
      "id": "1226067541"
    },
    "version": "0.41.0",
    "websiteUrl": "https://github.com/aliasunder/vault-cortex",
    "packages": [
      {
        "registryType": "oci",
        "identifier": "ghcr.io/aliasunder/vault-cortex:0.41.0",
        "runtimeHint": "docker",
        "transport": {
          "type": "streamable-http",
          "url": "http://localhost:8000/mcp",
          "headers": [
            {
              "description": "Bearer token used by the MCP client. Must match the MCP_AUTH_TOKEN env var passed to the container.",
              "isRequired": true,
              "value": "Bearer {MCP_AUTH_TOKEN}",
              "isSecret": true,
              "variables": {
                "MCP_AUTH_TOKEN": {
                  "description": "Bearer token for MCP client authentication. Generate with: openssl rand -hex 32",
                  "isRequired": true,
                  "isSecret": true
                }
              },
              "name": "Authorization"
            }
          ]
        },
        "runtimeArguments": [
          {
            "description": "Publish the container's port 8000 on the host.",
            "value": "8000:8000",
            "type": "named",
            "name": "-p"
          },
          {
            "description": "Bind-mount your Obsidian vault into the container at /vault.",
            "isRequired": true,
            "value": "{VAULT_PATH}:/vault:rw",
            "variables": {
              "VAULT_PATH": {
                "description": "Absolute path to your Obsidian vault on the host machine.",
                "isRequired": true,
                "format": "filepath"
              }
            },
            "type": "named",
            "name": "-v"
          },
          {
            "description": "Named volume for persistent state under /data — search index, OAuth token DB, and any log files. Keeps OAuth sessions alive across container restarts.",
            "value": "vault-cortex-data:/data",
            "type": "named",
            "name": "-v"
          }
        ],
        "environmentVariables": [
          {
            "description": "Bearer token for MCP client authentication. Must match the Authorization header sent by clients. Generate with: openssl rand -hex 32",
            "isRequired": true,
            "isSecret": true,
            "name": "MCP_AUTH_TOKEN"
          },
          {
            "description": "Public URL clients use to reach this server. Used as the OAuth issuer URL in discovery metadata. Override when exposing the server outside localhost or on a non-default port.",
            "default": "http://localhost:8000",
            "name": "PUBLIC_URL"
          },
          {
            "description": "Enable or disable the embedding pipeline. When false, no ONNX model is downloaded, no vector tables are created, and search uses FTS5 only.",
            "default": "true",
            "name": "EMBEDDING_ENABLED"
          },
          {
            "description": "Cross-encoder reranking mode: blended (position-aware score blending after RRF fusion) or none (skip reranking). Only takes effect when EMBEDDING_ENABLED is true.",
            "default": "blended",
            "choices": [
              "blended",
              "none"
            ],
            "name": "RERANK_MODE"
          },
          {
            "description": "Windows bind-mount mode: enables filesystem polling for the file watcher and rename-based moves across the Docker Desktop/WSL2 bridge. Set to true when the vault lives on a Windows drive.",
            "default": "false",
            "name": "WINDOWS_MODE"
          },
          {
            "description": "Enable or disable the structured memory layer. When false, memory tools are hidden, bootstrap is skipped, and server metadata omits memory references.",
            "default": "true",
            "name": "MEMORY_ENABLED"
          },
          {
            "description": "Enable or disable file tools (vault_read_file, vault_list_files). When false, file tools are hidden and server metadata omits file tool references.",
            "default": "true",
            "name": "FILE_TOOLS_ENABLED"
          },
          {
            "description": "Run the server read-only: every vault-writing tool is hidden, the memory folder is not auto-created, and server metadata omits write references.",
            "default": "false",
            "name": "READONLY_MODE"
          },
          {
            "description": "Hide individual tools by name, comma-separated. Subtractive only — it cannot re-enable a tool another setting hides; an unknown tool name stops the server at startup.",
            "name": "DISABLED_TOOLS"
          },
          {
            "description": "Vault folder for structured memory files (About Me-style notes). Memory tools are hidden when MEMORY_ENABLED is false, but this value still feeds the defaults for PROTECTED_PATHS and ORPHAN_EXCLUDE_FOLDERS.",
            "default": "About Me",
            "name": "MEMORY_DIR"
          },
          {
            "description": "Number of trusted reverse-proxy hops used to derive the client IP from X-Forwarded-For for OAuth rate limiting and request logs. With 0, injected forwarding headers are ignored.",
            "default": "0",
            "name": "TRUST_PROXY_HOPS"
          },
          {
            "description": "Trust the RFC 7239 Forwarded header as the client identity for OAuth rate limiting and request logs. Enable only when the proxy in front sets it (e.g. AWS API Gateway).",
            "default": "false",
            "name": "TRUST_FORWARDED_HEADER"
          },
          {
            "description": "IANA timezone for timestamps and daily note resolution.",
            "default": "UTC",
            "name": "TZ"
          },
          {
            "description": "Logging verbosity.",
            "default": "info",
            "choices": [
              "debug",
              "info",
              "warn",
              "error"
            ],
            "name": "LOG_LEVEL"
          },
          {
            "description": "Directory for log files that survive container re-creation. The container's own log is always written but discarded when the container is recreated; date-stamped files under LOG_DIR persist on the data volume. Default: /data/logs (remote image), none (local image). none keeps only the container log.",
            "format": "filepath",
            "name": "LOG_DIR"
          },
          {
            "description": "Days to keep log files before automatic cleanup on startup; only applies when LOG_DIR is a path.",
            "format": "number",
            "default": "90",
            "name": "LOG_RETENTION_DAYS"
          },
          {
            "description": "Comma-separated vault folder names blocked from vault_delete_note. Default: MEMORY_DIR and \"Daily Notes\".",
            "name": "PROTECTED_PATHS"
          },
          {
            "description": "Comma-separated vault folder names excluded from vault_find_orphans. Default: \"Daily Notes\", \"Templates\", MEMORY_DIR.",
            "name": "ORPHAN_EXCLUDE_FOLDERS"
          },
          {
            "description": "Override the OAuth service documentation URL exposed via discovery metadata.",
            "default": "https://github.com/aliasunder/vault-cortex",
            "name": "SERVICE_DOCUMENTATION_URL"
          },
          {
            "description": "Largest file vault_read_file will read, in bytes. Reading a larger file returns an error instead of content.",
            "format": "number",
            "default": "52428800",
            "name": "MAX_FILE_BYTES"
          },
          {
            "description": "Byte budget for images returned by vault_read_file, in binary bytes before base64 encoding. Images exceeding the budget are downscaled/recompressed server-side to fit; raise for clients that accept larger tool responses.",
            "format": "number",
            "default": "49152",
            "name": "MAX_IMAGE_OUTPUT_BYTES"
          },
          {
            "description": "Maximum PDF pages to render as images when raw: true is set on vault_read_file. The per-page byte budget is MAX_IMAGE_OUTPUT_BYTES divided evenly across the rendered pages.",
            "format": "number",
            "default": "5",
            "name": "MAX_PDF_RENDER_PAGES"
          }
        ]
      }
    ]
  },
  "_meta": {
    "io.modelcontextprotocol.registry/official": {
      "status": "active",
      "statusChangedAt": "2026-08-23T04:56:41.488012Z",
      "publishedAt": "2026-08-23T04:56:41.488012Z",
      "updatedAt": "2026-08-23T04:56:41.488012Z",
      "isLatest": true
    }
  }
}
Make it installable

Draft an Agent Plugin from this

An MCP server is raw capability: some tools, wired to something. An Agent Plugin is the packaging that says what job it does, what it leaves behind and where it stops. The prompt below carries this record and asks for the packaging; your own assistant writes it, and nothing here is sent anywhere.

Make it installable

Draft an Agent Plugin from Vault Cortex

Paste it into your assistant. It asks for the manifest, the server wiring and the skills, and for an honest account of what this record does not say. Read that second file first.

278 lines · the record is inside it, so nothing else is needed
Draft an Agent Plugin (agent-plugins.org, specification 1.1.0) that wraps the
MCP server described below, so that somebody could install one thing and have
an assistant that knows when and how to use it.

An Agent Plugin is one installable unit: a `plugin.json` manifest, an
`mcp.json` that wires up the servers it needs, and a `skills/` directory
where each skill is a folder holding a `SKILL.md`. Hand back every file in
full, each under its own path, ready to save.

1. Write `plugin.json` with `$schema` exactly `https://agent-plugins.org/schemas/1.1.0/plugin.schema.json`. The name is
   1 to 64 characters of a-z, 0-9, `-` and `.`, alphanumeric at both ends, with
   no `--` and no `..` in it.

2. Write `mcp.json` wiring THIS server exactly as its record declares it. A
   remote keeps the URL and the transport type as written. A package keeps the
   registry, the identifier and the version as written. Do not invent a command,
   a port, a flag or an argument that is not in the record.

3. Every secret stays an input. No key, token, password or connection string
   belongs in either file. Declare what has to be supplied, name it, and say what
   it is for.

4. Do not invent tools. The record lists the tools it lists, and if it lists
   none then the honest plugin says the tool list was not published rather than
   guessing one from the description.

5. Skills are jobs, not tools. Write one skill per thing somebody would actually
   ask for, and inside each one say when to reach for this server, what a good
   result looks like, and what to do when it comes back empty. A skill per tool
   is a manual page with a different filename.

6. Say where it stops. Name what this plugin will not do — what it has no tool
   for, what needs a person, and what it must not be pointed at. A plugin with no
   stated edge reads as one with no edge.

7. Keep the author's own words for the description. If you would rather say it
   differently, say yours somewhere else and leave theirs where it is.

8. Record which version of the server you wrapped, and where the record came
   from, at the top of `plugin.json`'s description or in the readme. A plugin
   nobody can trace back to a version is one nobody can update.

Produce a second file alongside them, `LIMITS.md`, and treat it as the more
important of the two. The plugin is for whoever installs it. This is for
whoever has to decide whether installing it is a good idea, and that is
usually a different person who will never read the manifest.

It has three parts.

**What this is built from.** One paragraph: whose server it is, what the
record says it does, which version, and the fact that the record is all you
had. Say plainly that nobody ran it.

**What the record does not say.** One entry per gap. Whether the tool list was
published. What the server does with what it reads. What it costs. Whether it
writes anything anywhere. What credentials it will ask for and what those
credentials can reach. An unanswered question stays an unanswered question:
do not fill one in from the description or from what similar servers usually do.

**What a person has to check before trusting it.** The specific things
somebody should verify for themselves, in the order that would stop them
soonest if the answer is bad.

Write it in plain English, and do not soften it. A plugin drafted from a
directory record is a starting point to argue with, not something to install
into anything that matters.

The server record follows, exactly as the public index holds it. It is
everything I have: nobody has run this server, called a tool on it, or checked
that the address answers.

```json
{
  "server": {
    "$schema": "https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json",
    "name": "io.github.aliasunder/vault-cortex",
    "description": "Standalone MCP server for Obsidian vaults — hybrid search, notes & files, memory, tasks, OAuth 2.1",
    "title": "Vault Cortex",
    "repository": {
      "url": "https://github.com/aliasunder/vault-cortex",
      "source": "github",
      "id": "1226067541"
    },
    "version": "0.41.0",
    "websiteUrl": "https://github.com/aliasunder/vault-cortex",
    "packages": [
      {
        "registryType": "oci",
        "identifier": "ghcr.io/aliasunder/vault-cortex:0.41.0",
        "runtimeHint": "docker",
        "transport": {
          "type": "streamable-http",
          "url": "http://localhost:8000/mcp",
          "headers": [
            {
              "description": "Bearer token used by the MCP client. Must match the MCP_AUTH_TOKEN env var passed to the container.",
              "isRequired": true,
              "value": "Bearer {MCP_AUTH_TOKEN}",
              "isSecret": true,
              "variables": {
                "MCP_AUTH_TOKEN": {
                  "description": "Bearer token for MCP client authentication. Generate with: openssl rand -hex 32",
                  "isRequired": true,
                  "isSecret": true
                }
              },
              "name": "Authorization"
            }
          ]
        },
        "runtimeArguments": [
          {
            "description": "Publish the container's port 8000 on the host.",
            "value": "8000:8000",
            "type": "named",
            "name": "-p"
          },
          {
            "description": "Bind-mount your Obsidian vault into the container at /vault.",
            "isRequired": true,
            "value": "{VAULT_PATH}:/vault:rw",
            "variables": {
              "VAULT_PATH": {
                "description": "Absolute path to your Obsidian vault on the host machine.",
                "isRequired": true,
                "format": "filepath"
              }
            },
            "type": "named",
            "name": "-v"
          },
          {
            "description": "Named volume for persistent state under /data — search index, OAuth token DB, and any log files. Keeps OAuth sessions alive across container restarts.",
            "value": "vault-cortex-data:/data",
            "type": "named",
            "name": "-v"
          }
        ],
        "environmentVariables": [
          {
            "description": "Bearer token for MCP client authentication. Must match the Authorization header sent by clients. Generate with: openssl rand -hex 32",
            "isRequired": true,
            "isSecret": true,
            "name": "MCP_AUTH_TOKEN"
          },
          {
            "description": "Public URL clients use to reach this server. Used as the OAuth issuer URL in discovery metadata. Override when exposing the server outside localhost or on a non-default port.",
            "default": "http://localhost:8000",
            "name": "PUBLIC_URL"
          },
          {
            "description": "Enable or disable the embedding pipeline. When false, no ONNX model is downloaded, no vector tables are created, and search uses FTS5 only.",
            "default": "true",
            "name": "EMBEDDING_ENABLED"
          },
          {
            "description": "Cross-encoder reranking mode: blended (position-aware score blending after RRF fusion) or none (skip reranking). Only takes effect when EMBEDDING_ENABLED is true.",
            "default": "blended",
            "choices": [
              "blended",
              "none"
            ],
            "name": "RERANK_MODE"
          },
          {
            "description": "Windows bind-mount mode: enables filesystem polling for the file watcher and rename-based moves across the Docker Desktop/WSL2 bridge. Set to true when the vault lives on a Windows drive.",
            "default": "false",
            "name": "WINDOWS_MODE"
          },
          {
            "description": "Enable or disable the structured memory layer. When false, memory tools are hidden, bootstrap is skipped, and server metadata omits memory references.",
            "default": "true",
            "name": "MEMORY_ENABLED"
          },
          {
            "description": "Enable or disable file tools (vault_read_file, vault_list_files). When false, file tools are hidden and server metadata omits file tool references.",
            "default": "true",
            "name": "FILE_TOOLS_ENABLED"
          },
          {
            "description": "Run the server read-only: every vault-writing tool is hidden, the memory folder is not auto-created, and server metadata omits write references.",
            "default": "false",
            "name": "READONLY_MODE"
          },
          {
            "description": "Hide individual tools by name, comma-separated. Subtractive only — it cannot re-enable a tool another setting hides; an unknown tool name stops the server at startup.",
            "name": "DISABLED_TOOLS"
          },
          {
            "description": "Vault folder for structured memory files (About Me-style notes). Memory tools are hidden when MEMORY_ENABLED is false, but this value still feeds the defaults for PROTECTED_PATHS and ORPHAN_EXCLUDE_FOLDERS.",
            "default": "About Me",
            "name": "MEMORY_DIR"
          },
          {
            "description": "Number of trusted reverse-proxy hops used to derive the client IP from X-Forwarded-For for OAuth rate limiting and request logs. With 0, injected forwarding headers are ignored.",
            "default": "0",
            "name": "TRUST_PROXY_HOPS"
          },
          {
            "description": "Trust the RFC 7239 Forwarded header as the client identity for OAuth rate limiting and request logs. Enable only when the proxy in front sets it (e.g. AWS API Gateway).",
            "default": "false",
            "name": "TRUST_FORWARDED_HEADER"
          },
          {
            "description": "IANA timezone for timestamps and daily note resolution.",
            "default": "UTC",
            "name": "TZ"
          },
          {
            "description": "Logging verbosity.",
            "default": "info",
            "choices": [
              "debug",
              "info",
              "warn",
              "error"
            ],
            "name": "LOG_LEVEL"
          },
          {
            "description": "Directory for log files that survive container re-creation. The container's own log is always written but discarded when the container is recreated; date-stamped files under LOG_DIR persist on the data volume. Default: /data/logs (remote image), none (local image). none keeps only the container log.",
            "format": "filepath",
            "name": "LOG_DIR"
          },
          {
            "description": "Days to keep log files before automatic cleanup on startup; only applies when LOG_DIR is a path.",
            "format": "number",
            "default": "90",
            "name": "LOG_RETENTION_DAYS"
          },
          {
            "description": "Comma-separated vault folder names blocked from vault_delete_note. Default: MEMORY_DIR and \"Daily Notes\".",
            "name": "PROTECTED_PATHS"
          },
          {
            "description": "Comma-separated vault folder names excluded from vault_find_orphans. Default: \"Daily Notes\", \"Templates\", MEMORY_DIR.",
            "name": "ORPHAN_EXCLUDE_FOLDERS"
          },
          {
            "description": "Override the OAuth service documentation URL exposed via discovery metadata.",
            "default": "https://github.com/aliasunder/vault-cortex",
            "name": "SERVICE_DOCUMENTATION_URL"
          },
          {
            "description": "Largest file vault_read_file will read, in bytes. Reading a larger file returns an error instead of content.",
            "format": "number",
            "default": "52428800",
            "name": "MAX_FILE_BYTES"
          },
          {
            "description": "Byte budget for images returned by vault_read_file, in binary bytes before base64 encoding. Images exceeding the budget are downscaled/recompressed server-side to fit; raise for clients that accept larger tool responses.",
            "format": "number",
            "default": "49152",
            "name": "MAX_IMAGE_OUTPUT_BYTES"
          },
          {
            "description": "Maximum PDF pages to render as images when raw: true is set on vault_read_file. The per-page byte budget is MAX_IMAGE_OUTPUT_BYTES divided evenly across the rendered pages.",
            "format": "number",
            "default": "5",
            "name": "MAX_PDF_RENDER_PAGES"
          }
        ]
      }
    ]
  },
  "_meta": {
    "io.modelcontextprotocol.registry/official": {
      "status": "active",
      "statusChangedAt": "2026-08-23T04:56:41.488012Z",
      "publishedAt": "2026-08-23T04:56:41.488012Z",
      "updatedAt": "2026-08-23T04:56:41.488012Z",
      "isLatest": true
    }
  }
}
```

The server is listed as "Vault Cortex".
What this is

MCP server

application/mcp-server-record+jsonlocal · you run it yourselfversion 0.41.0last seen 2026-08-23

These are the publisher's own words, filed by them with the official MCP registry and mirrored here. This catalog did not read them from the publisher and has not run, called or installed anything.

Where it lives

The publisher's own address

https://github.com/aliasunder/vault-cortex

The address the publisher put in their registry record, printed as they wrote it. Nobody here has opened it.