{"server":{"$schema":"https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json","name":"io.github.aliasunder/vault-cortex","description":"Standalone MCP server for Obsidian vaults — hybrid search, notes & files, memory, tasks, OAuth 2.1","title":"Vault Cortex","repository":{"url":"https://github.com/aliasunder/vault-cortex","source":"github","id":"1226067541"},"version":"0.50.2","websiteUrl":"https://github.com/aliasunder/vault-cortex","packages":[{"registryType":"oci","identifier":"ghcr.io/aliasunder/vault-cortex:0.50.2","runtimeHint":"docker","transport":{"type":"streamable-http","url":"http://localhost:8000/mcp","headers":[{"description":"Bearer token used by the MCP client. Must match the MCP_AUTH_TOKEN env var passed to the container.","isRequired":true,"value":"Bearer {MCP_AUTH_TOKEN}","isSecret":true,"variables":{"MCP_AUTH_TOKEN":{"description":"Bearer token for MCP client authentication. Generate with: openssl rand -hex 32","isRequired":true,"isSecret":true}},"name":"Authorization"}]},"runtimeArguments":[{"description":"Publish the container's port 8000 on the host.","value":"8000:8000","type":"named","name":"-p"},{"description":"Bind-mount your Obsidian vault into the container at /vault.","isRequired":true,"value":"{VAULT_PATH}:/vault:rw","variables":{"VAULT_PATH":{"description":"Absolute path to your Obsidian vault on the host machine.","isRequired":true,"format":"filepath"}},"type":"named","name":"-v"},{"description":"Named volume for persistent state under /data — search index, OAuth token DB, and any log files. Keeps OAuth sessions alive across container restarts.","value":"vault-cortex-data:/data","type":"named","name":"-v"}],"environmentVariables":[{"description":"Bearer token for MCP client authentication. Must match the Authorization header sent by clients. Generate with: openssl rand -hex 32","isRequired":true,"isSecret":true,"name":"MCP_AUTH_TOKEN"},{"description":"Public URL clients use to reach this server. Used as the OAuth issuer URL in discovery metadata. Override when exposing the server outside localhost or on a non-default port.","default":"http://localhost:8000","name":"PUBLIC_URL"},{"description":"Enable or disable the embedding pipeline. When false, no ONNX model is downloaded, no vector tables are created, and search uses FTS5 only.","default":"true","name":"EMBEDDING_ENABLED"},{"description":"Cross-encoder reranking mode: blended (position-aware score blending after RRF fusion) or none (skip reranking). Only takes effect when EMBEDDING_ENABLED is true.","default":"blended","choices":["blended","none"],"name":"RERANK_MODE"},{"description":"Windows bind-mount mode: enables filesystem polling for the file watcher and rename-based moves across the Docker Desktop/WSL2 bridge. Set to true when the vault lives on a Windows drive.","default":"false","name":"WINDOWS_MODE"},{"description":"Enable or disable the structured memory layer. When false, memory tools are hidden, bootstrap is skipped, and server metadata omits memory references.","default":"true","name":"MEMORY_ENABLED"},{"description":"Enable or disable file tools (vault_read_file, vault_list_files). When false, file tools are hidden and server metadata omits file tool references.","default":"true","name":"FILE_TOOLS_ENABLED"},{"description":"Run the server read-only: every vault-writing tool is hidden, the memory folder is not auto-created, and server metadata omits write references.","default":"false","name":"READONLY_MODE"},{"description":"Hide individual tools by name, comma-separated. Subtractive only — it cannot re-enable a tool another setting hides; an unknown tool name stops the server at startup.","name":"DISABLED_TOOLS"},{"description":"Vault folder for structured memory files (About Me-style notes). Memory tools are hidden when MEMORY_ENABLED is false, but this value still feeds the defaults for PROTECTED_PATHS and ORPHAN_EXCLUDE_FOLDERS.","default":"About Me","name":"MEMORY_DIR"},{"description":"Vault folder for daily notes. Overrides the folder configured in Obsidian's daily-notes plugin.","default":"Daily Notes","name":"DAILY_NOTES_FOLDER"},{"description":"Filename date format for daily notes (Moment.js tokens). Overrides the format configured in Obsidian's daily-notes plugin.","default":"YYYY-MM-DD","name":"DAILY_NOTES_FORMAT"},{"description":"Number of trusted reverse-proxy hops used to derive the client IP from X-Forwarded-For for OAuth rate limiting and request logs. With 0, injected forwarding headers are ignored.","default":"0","name":"TRUST_PROXY_HOPS"},{"description":"How many entries from the end of the RFC 7239 Forwarded header's for= list to count to reach the client IP for OAuth rate limiting and request logs. 0 ignores the header; 1 when the proxy in front writes it (e.g. AWS API Gateway); 2 when a CDN fronts that proxy and is the only way to reach it.","default":"0","name":"TRUST_FORWARDED_HOPS"},{"description":"IANA timezone for timestamps and daily note resolution.","default":"UTC","name":"TZ"},{"description":"Logging verbosity.","default":"info","choices":["debug","info","warn","error"],"name":"LOG_LEVEL"},{"description":"Directory for log files that survive container re-creation. The container's own log is always written but discarded when the container is recreated; date-stamped files under LOG_DIR persist on the data volume. Default: /data/logs (remote image), none (local image). none keeps only the container log.","format":"filepath","name":"LOG_DIR"},{"description":"Days to keep log files before automatic cleanup on startup; only applies when LOG_DIR is a path.","format":"number","default":"90","name":"LOG_RETENTION_DAYS"},{"description":"Comma-separated vault folder names blocked from vault_delete_note and vault_move_note. Default: MEMORY_DIR plus the daily notes folder, read from DAILY_NOTES_FOLDER or .obsidian/daily-notes.json (default Daily Notes). When set, overrides the default entirely.","name":"PROTECTED_PATHS"},{"description":"Comma-separated vault folder names excluded from vault_find_orphans. Default: \"Daily Notes\", \"Templates\", MEMORY_DIR.","name":"ORPHAN_EXCLUDE_FOLDERS"},{"description":"Override the OAuth service documentation URL exposed via discovery metadata.","default":"https://github.com/aliasunder/vault-cortex","name":"SERVICE_DOCUMENTATION_URL"},{"description":"Largest file vault_read_file will read, in bytes. Reading a larger file returns an error instead of content.","format":"number","default":"52428800","name":"MAX_FILE_BYTES"},{"description":"Byte budget for images returned by vault_read_file, in binary bytes before base64 encoding. Images exceeding the budget are downscaled/recompressed server-side to fit; raise for clients that accept larger tool responses.","format":"number","default":"49152","name":"MAX_IMAGE_OUTPUT_BYTES"},{"description":"Maximum PDF pages to render as images when raw: true is set on vault_read_file. The per-page byte budget is MAX_IMAGE_OUTPUT_BYTES divided evenly across the rendered pages.","format":"number","default":"5","name":"MAX_PDF_RENDER_PAGES"}]}]},"_meta":{"io.modelcontextprotocol.registry/official":{"status":"active","statusChangedAt":"2026-09-11T20:09:39.204504Z","publishedAt":"2026-09-11T20:09:39.204504Z","updatedAt":"2026-09-11T20:09:39.204504Z","isLatest":true}}}
