Back to Home
NasAndNora icon

obsidian-http-mcp

Verified Safe

by NasAndNora

Overview

Facilitates AI agents, such as Claude Code, to manage Obsidian notes by providing an HTTP-native Model Context Protocol (MCP) server, bypassing stdio transport bugs.

Installation

Run Command
obsidian-http-mcp

Environment Variables

  • OBSIDIAN_API_KEY
  • OBSIDIAN_BASE_URL
  • PORT

Security Notes

The server implements path traversal prevention, ReDoS protection (query length limit), PORT validation, type safety, and a request size limit. Soft delete is enabled by default, moving files to a trash directory. Crucially, the documentation explicitly states the server is designed for trusted networks (localhost, LAN, VPN) and does NOT include built-in authentication, rate limiting, or HTTPS. It binds to `0.0.0.0` for cross-platform compatibility, which requires a reverse proxy with authentication, rate limiting, and TLS for production or internet exposure. The strong emphasis on user responsibility for external security measures is a positive, but the lack of built-in measures limits its standalone security score.

Similar Servers

Stats

Interest Score31
Security Score8
Cost ClassLow
Stars3
Forks1
Last Update2025-11-19

Tags

ObsidianMCP ServerAI AgentNote ManagementDeveloper Tool