Secure MCP server for Obsidian with OWASP Top 10 controls and full audit logging.
Secure Model Context Protocol server that turns your Obsidian vault into a reliable data source for any MCP-compatible AI client β built from scratch with OWASP Top 10 controls and full audit logging.
Listed on the official Anthropic MCP Registry as io.github.dewtech-technologies/obsidian-mcp-secure.
It's the opposite: it's a bridge that lets Claude Desktop (or any MCP client) read and write inside Obsidian safely. Your AI assistant stays where it lives; your vault becomes a structured, auditable datasource it can reach.
βββββββββββββββββββ MCP ββββββββββββββββββββββββ HTTP ββββββββββββββββββββββ FS βββββββββββββββ
β β stdio β β :27123 β β β β
β Claude Desktop β ββββββββΆ β obsidian-mcp-secure β ββββββββΆ β Local REST API β ββββββΆ β Vault .md β
β (AI client) β β (this package) β β (Obsidian plugin) β β β
βββββββββββββββββββ ββββββββββββββββββββββββ ββββββββββββββββββββββ βββββββββββββββ
| Role in the pipeline | Component |
|---|---|
| Where you talk | Claude Desktop (or any MCP client) |
| Bridge / access control | obsidian-mcp-secure (this package) |
| Data gateway inside Obsidian | Local REST API plugin (by Adam Coddington) |
| Your knowledge | .md files in your vault |
One-liner: Claude is the brain, this MCP is the arm, Obsidian is the memory.
There are plugins that put Claude inside Obsidian. This is the inverse, and it exists because:
npx obsidian-mcp-secure and done. Works on Windows, macOS, Linux the same way.| Tool | Purpose |
|---|---|
read_note | Read a note by path |
list_notes | List files/folders in the vault or a subdirectory |
create_note | Create a new .md note |
edit_note | Overwrite an existing note (previous content goes to the audit log) |
delete_note | Delete a note β requires confirm: true (Zod rejects otherwise) |
search_notes | Full-text / tag search using Obsidian's own search engine |
find_note_by_name | Find notes by partial name β case-insensitive, no exact path needed |
list_tags | Enumerate all tags in the vault with usage count; sortable by name or frequency |
create_backlinks | Add [[wikilinks]] to a ## Relacionadas section in a note β explicit and auditable |
| Control | Implementation |
|---|---|
| A01 β Broken Access Control | Path traversal blocked (../, ..\\, encoded variants); .md extension enforced |
| A02 β Cryptographic Failures | API key read from .env or process env; never hardcoded, never logged |
| A03 β Injection | All inputs validated with Zod schemas; no eval, no exec, no shell |
| A04 β Insecure Design | 512 KB max note size; 50-result cap on search; destructive ops require explicit confirm: true |
| A05 β Security Misconfiguration | Only 127.0.0.1 / localhost accepted as host |
| A09 β Logging & Monitoring | Full audit log via winston with size-based rotation (5 MB / 10 files) |
Every tool call emits an audit line with action, params (sanitized), success, error, and timestamp.
Open %APPDATA%\Claude\claude_desktop_config.json on Windows (or ~/Library/Application Support/Claude/claude_desktop_config.json on macOS) and add:
{
"mcpServers": {
"obsidian-secure": {
"command": "npx",
"args": ["-y", "obsidian-mcp-secure"],
"env": {
"OBSIDIAN_API_KEY": "your-api-key-from-the-plugin",
"OBSIDIAN_HOST": "http://127.0.0.1",
"OBSIDIAN_PORT": "27123",
"LOG_DIR": "C:/path/to/your/logs"
}
}
}
}
Windows tip: if
npxfails silently, switch"command": "npx"to"command": "npx.cmd". Some Claude Desktop builds don't resolve barenpxon PATH.
Restart Claude Desktop (tray β Quit, then reopen) and the 9 tools will show up under obsidian-secure.
The real power of MCPs is composability. To reproduce the "read my note β fetch a URL β tell me if I'm applying it correctly" workflow, add the official fetch MCP alongside this one:
{
"mcpServers": {
"obsidian-secure": { "...": "as above" },
"fetch": {
"command": "npx",
"args": ["-y", "@modelcontextprotocol/server-fetch"]
}
}
}
Now Claude has both your vault and the live web in a single conversation.
With obsidian-secure + fetch enabled:
"Read my note
Projeto API Atendimento.md, then fetch https://developers.facebook.com/docs/whatsapp and tell me if my implementation matches the latest best practices."
"Search my vault for the tag
#ideiaand summarize the three ideas that appear most often. Then create a new note calledIdeias recorrentes.mdwith the summary."
"Read
Atomic Habits - Resumo.md, fetch https://jamesclear.com/atomic-habits, and point out where my notes drifted from the original."
Claude will orchestrate the tool calls automatically β no manual chaining.
If your workflow lives inside Obsidian's sidebar, plugins like obsidian-claude-code are the right fit. This MCP targets a different shape:
| Dimension | obsidian-claude-code (in-Obsidian) | obsidian-mcp-secure (this) |
|---|---|---|
| Where the AI lives | Sidebar inside Obsidian | Claude Desktop (or any MCP client) |
| Setup | git clone + bun build | npx obsidian-mcp-secure |
| Tools | Read/Write/Edit + Bash + Grep + Glob + WebFetch | 9 purpose-built, Zod-validated tools |
| Security posture | Full shell access to dev machine | Tight allowlist, audited, OWASP Top 10 |
| Distribution | Manual clone, requires Bun | npm + official MCP Registry |
| Composability with other sources | Inside its own sandbox | Any MCP-compatible client can mix it with fetch, GitHub, filesystem, etc. |
| Best for | Dev who lives in Obsidian | Professional whose main surface is Claude Desktop |
Both are valid β they occupy different niches.
| Variable | Required | Default | Description |
|---|---|---|---|
OBSIDIAN_API_KEY | β | β | API key from the Local REST API plugin |
OBSIDIAN_HOST | http://127.0.0.1 | Host (only 127.0.0.1 and localhost are accepted) | |
OBSIDIAN_PORT | 27123 | Port of the plugin's HTTP server | |
LOG_DIR | ./logs | Directory for the audit log files |
find_note_by_name searches full path (folder + filename)list_tags normalizes all API response formats (object, array of strings, array of objects with tagCount/taggedFilesCount)npm run build:dxt)find_note_by_name β partial, case-insensitive name match across the entire vaultcreate_backlinks β connect related notes with [[wikilinks]] (explicit, auditable)list_tags β enumerate all tags in the vault with usage countnpm audit + static security analysisIdeas and PRs welcome β see CONTRIBUTING.md.
MIT β see LICENSE.
Security issues? See SECURITY.md for disclosure instructions.
Source-derived launch command. Check the maintainerβs required arguments and credentials before running:
npx -y obsidian-mcp-secureMerge this template into ~/Library/Application Support/Claude/claude_desktop_config.json. Keep existing servers. Add any arguments, credentials, and permissions required by the maintainer; this template has not been install-tested.
{
"mcpServers": {
"io-github-dewtech-technologies-obsidian-mcp-secure": {
"command": "npx",
"args": [
"-y",
"obsidian-mcp-secure"
]
}
}
}Restart Claude Desktop completely for changes to take effect. Confirm the server appears connected in the clientβs tool list, then try a read-only example from its documentation.
Claude Desktop setup referenceobsidian-mcp-securenpmio.github.dewtech-technologies/obsidian-mcp-secure works with any MCP-compatible client. Copy the config snippet from the Configuration section above and add it to the file shown for your client, then restart the application.
~/Library/Application Support/Claude/claude_desktop_config.jsonRestart Claude Desktop completely for changes to take effect.~/.cursor/mcp.jsonRestart Cursor for changes to take effect..vscode/mcp.jsonReload VS Code window for changes to take effect.~/.codeium/windsurf/mcp_config.jsonRestart Windsurf for changes to take effect..mcp.jsonSave at the project root, then start Claude Code in that project and review the MCP server approval prompt. Keep real credentials out of shared files.