Skip to content

Vault Cortex

Runs onlineCredentials listedRepository declared by sourceUpdated 2026-10-08

io.github.aliasunder/vault-cortex · Registry status: active

Report data on this entry

At a glance

Standalone MCP server for Obsidian vaults — hybrid search, notes & files, memory, tasks, OAuth 2.1

Vendor's own description, untranslated and unverified

Execution location
Runs onlineMCP-Register · 2026-08-06
Required secrets declared
Credentials listedMCP-Register · 2026-08-06
Declared version and change
0.54.11 · Source-reported change date 2026-10-08MCP-Register · 2026-10-09
Repository as declared
github.com/aliasunder/vault-cortexMCP-Register · 2026-08-06
Configuration
can be built from the disclosed start template

Inspect connection paths and prerequisites

Related categories

6 of 12 categories. All categories in the segment catalogue

Page last changed:

Sources and collection
Runs
Runs online
Credentials
Credentials listed
Registry record changed
2026-10-08
Setup
Template available
Registry name
io.github.aliasunder/vault-cortex
Package coordinate
oci:ghcr.io/aliasunder/vault-cortex:0.54.11
Declared version
0.54.11
Source-reported listing date
2026-10-08
Source-reported change date
2026-10-08
First seen by tracevero
2026-08-06
Vendor's website
https://github.com/aliasunder/vault-cortex

Evidence for this page: The values on this page come from several collections. Each row therefore states its own origin. What the confidence levels mean

Measured values

Measured values
Required secrets declaredCredentials listed yes
Original data – Required secret variables (raw): MCP_AUTH_TOKEN
Original data – Required secret headers (raw): confirmed absent
Source: MCP-Register · collected on 2026-08-06 · derived
Execution locationRuns online remote
Original data – Transports (raw): streamable-http
Source: MCP-Register · collected on 2026-08-06 · derived
Path argument presentyes
Original data – Path arguments (raw): confirmed absent
Original data – Path environment variables (raw): LOG_DIR
Source: MCP-Register · collected on 2026-08-16 · derived
Repository URL listedRepository declared by source yes
Original data – Repository (raw): https://github.com/aliasunder/vault-cortex
Source: MCP-Register · collected on 2026-08-06 · derived
Field of use, derived from the vendor descriptionMemory
Original data – Description (raw): Standalone MCP server for Obsidian vaults — hybrid search, notes & files, memory, tasks, OAuth 2.1
Source: MCP-Register · collected on 2026-08-26 · derived
Field of use, derived from the vendor descriptionKnowledge
Original data – Description (raw): Standalone MCP server for Obsidian vaults — hybrid search, notes & files, memory, tasks, OAuth 2.1
Source: MCP-Register · collected on 2026-08-26 · derived
Declared version0.54.11
Source: MCP-Register · collected on 2026-10-09 · self-declared

What is measured is what a manifest declares, not what a piece of software does. This registry fetches no repository URL, no endpoint and no package index; nothing here is verified. Which value comes from which source, and by which rule it was formed, is set out in the Methodology.

Source data25

Evidence for this page: The values on this page come from several collections. Each row therefore states its own origin.

Raw values
Description (raw)Standalone MCP server for Obsidian vaults — hybrid search, notes & files, memory, tasks, OAuth 2.1
Source: MCP-Register · collected on 2026-08-26 · self-declared
Environment variables (raw)MCP_AUTH_TOKEN, PUBLIC_URL, EMBEDDING_ENABLED, RERANK_MODE, WINDOWS_MODE, MEMORY_ENABLED, FILE_TOOLS_ENABLED, READONLY_MODE, DISABLED_TOOLS, MEMORY_DIR, DAILY_NOTES_FOLDER, DAILY_NOTES_FORMAT, TRUST_PROXY_HOPS, TRUST_FORWARDED_HOPS, TZ, LOG_LEVEL, LOG_DIR, LOG_RETENTION_DAYS, PROTECTED_PATHS, ORPHAN_EXCLUDE_FOLDERS, SERVICE_DOCUMENTATION_URL, MAX_FILE_BYTES, MAX_IMAGE_OUTPUT_BYTES, MAX_PDF_RENDER_PAGES
Source: MCP-Register · collected on 2026-08-26 · self-declared
Required secret variables (raw)MCP_AUTH_TOKEN
Source: MCP-Register · collected on 2026-08-06 · self-declared
Transports (raw)streamable-http
Source: MCP-Register · collected on 2026-08-06 · self-declared
Path arguments (raw)confirmed absent
Source: MCP-Register · collected on 2026-08-06 · self-declared
Repository (raw)https://github.com/aliasunder/vault-cortex
Source: MCP-Register · collected on 2026-08-06 · self-declared
Package registries (raw)oci
Source: MCP-Register · collected on 2026-08-06 · self-declared
Required secret headers (raw)confirmed absent
Source: MCP-Register · collected on 2026-08-16 · self-declared
Path environment variables (raw)LOG_DIR
Source: MCP-Register · collected on 2026-08-16 · self-declared
Remote URLs (raw)confirmed absent
Source: MCP-Register · collected on 2026-08-16 · self-declared
Remote hosts (raw)confirmed absent
Source: MCP-Register · collected on 2026-08-16 · self-declared
Registry status message (raw)confirmed absent
Source: MCP-Register · collected on 2026-08-16 · self-declared
First listed in the registry (raw)2026-10-08
Source: MCP-Register · collected on 2026-10-09 · self-declared
Last changed in the registry (raw)2026-10-08
Source: MCP-Register · collected on 2026-10-09 · self-declared
Schema version of the raw record (raw)https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json
Source: MCP-Register · collected on 2026-08-16 · self-declared
Delivery form (raw)package
Source: MCP-Register · collected on 2026-08-16 · self-declared
Repository platform (raw)github
Source: MCP-Register · collected on 2026-08-16 · self-declared
Repository subfolder (raw)confirmed absent
Source: MCP-Register · collected on 2026-08-16 · self-declared
Package identifiers (raw)ghcr.io/aliasunder/vault-cortex:0.54.11
Source: MCP-Register · collected on 2026-10-09 · self-declared
Package versions (raw)confirmed absent
Source: MCP-Register · collected on 2026-08-16 · self-declared
Runtime hints (raw)docker
Source: MCP-Register · collected on 2026-08-16 · self-declared
Environment variable formats (raw)filepath, number
Source: MCP-Register · collected on 2026-08-16 · self-declared
Environment variable descriptions (raw)DAILY_NOTES_FOLDER=Vault folder for daily notes. Overrides the folder configured in Obsidian's daily-notes plugin. When unset, read from the vault's .obsidian/daily-notes.json, falling back to "Daily Notes". · DAILY_NOTES_FORMAT=Filename date format for daily notes (Moment.js tokens). Overrides the format configured in Obsidian's daily-notes plugin. When unset, read from the vault's .obsidian/daily-notes.json, falling back to "YYYY-MM-DD". · DISABLED_TOOLS=Hide individual tools by name, comma-separated. Subtractive only — it cannot re-enable a tool another setting hides; an unknown tool name stops the server at startup. · EMBEDDING_ENABLED=Enable or disable the embedding pipeline. When false, no ONNX model is downloaded, no vector tables are created, and search uses FTS5 only. · FILE_TOOLS_ENABLED=Enable or disable file tools (vault_read_file, vault_list_files). When false, file tools are hidden and server metadata omits file tool references. · LOG_DIR=Directory for log files that survive container re-creation. The container's own log is always written but discarded when the container is recreated; date-stamped files under LOG_DIR persist on the data volume. Default: /data/logs (remote image), $STORAGE_ROOT/data/logs (single-volume mode), none (local image). none keeps only the container log. · LOG_LEVEL=Logging verbosity. · LOG_RETENTION_DAYS=Days to keep log files before automatic cleanup on startup; only applies when LOG_DIR is a path. · MAX_FILE_BYTES=Largest file vault_read_file will read, in bytes. Reading a larger file returns an error instead of content. · MAX_IMAGE_OUTPUT_BYTES=Byte budget for images returned by vault_read_file, in binary bytes before base64 encoding. Images exceeding the budget are downscaled/recompressed server-side to fit; raise for clients that accept larger tool responses. · MAX_PDF_RENDER_PAGES=Maximum PDF pages to render as images when raw: true is set on vault_read_file. The per-page byte budget is MAX_IMAGE_OUTPUT_BYTES divided evenly across the rendered pages. · MCP_AUTH_TOKEN=Bearer token for MCP client authentication. Must match the Authorization header sent by clients. Generate with: openssl rand -hex 32 · MEMORY_DIR=Vault folder for structured memory files (About Me-style notes). Memory tools are hidden when MEMORY_ENABLED is false, but this value still feeds the defaults for PROTECTED_PATHS and ORPHAN_EXCLUDE_FOLDERS. · MEMORY_ENABLED=Enable or disable the structured memory layer. When false, memory tools are hidden, bootstrap is skipped, and server metadata omits memory references. · ORPHAN_EXCLUDE_FOLDERS=Comma-separated vault folder names excluded from vault_find_orphans. Default: the daily notes folder, "Templates", and MEMORY_DIR. DAILY_NOTES_FOLDER wins; otherwise .obsidian/daily-notes.json is read per query (fallback "Daily Notes"). When set, replaces the defaults entirely. Set to a comma (,) to exclude nothing; an empty value uses the defaults. · PROTECTED_PATHS=Comma-separated vault folder names blocked from vault_delete_note and vault_move_note. Default: MEMORY_DIR plus the daily notes folder, read from DAILY_NOTES_FOLDER or .obsidian/daily-notes.json (default Daily Notes). When set, overrides the default entirely. · PUBLIC_URL=Public URL clients use to reach this server. Used as the OAuth issuer URL in discovery metadata. Override when exposing the server outside localhost or on a non-default port. · READONLY_MODE=Run the server read-only: every vault-writing tool is hidden, the memory folder is not auto-created, and server metadata omits write references. · RERANK_MODE=Cross-encoder reranking mode: blended (position-aware score blending after RRF fusion) or none (skip reranking). Only takes effect when EMBEDDING_ENABLED is true. · SERVICE_DOCUMENTATION_URL=Override the OAuth service documentation URL exposed via discovery metadata. · TRUST_FORWARDED_HOPS=How many entries from the end of the RFC 7239 Forwarded header's for= list to count to reach the client IP for OAuth rate limiting and request logs. 0 ignores the header; 1 when the proxy in front writes it (e.g. AWS API Gateway); 2 when a CDN fronts that proxy and is the only way to reach it. · TRUST_PROXY_HOPS=Number of trusted reverse-proxy hops used to derive the client IP from X-Forwarded-For for OAuth rate limiting and request logs. With 0, injected forwarding headers are ignored. · TZ=IANA timezone for timestamps and daily note resolution. · WINDOWS_MODE=Windows bind-mount mode: enables filesystem polling for the file watcher and rename-based moves across the Docker Desktop/WSL2 bridge. Set to true when the vault lives on a Windows drive.
Source: MCP-Register · collected on 2026-10-07 · self-declared
Icon formats (raw)confirmed absent
Source: MCP-Register · collected on 2026-08-16 · self-declared
Connection paths (source structure){"packages":[{"registryType":"oci","identifier":"ghcr.io/aliasunder/vault-cortex:0.54.11","runtimeHint":"docker","transport":"streamable-http","environment":[{"name":"MCP_AUTH_TOKEN","description":"Bearer token for MCP client authentication. Must match the Authorization header sent by clients. Generate with: openssl rand -hex 32","required":true,"secret":true},{"name":"PUBLIC_URL","description":"Public URL clients use to reach this server. Used as the OAuth issuer URL in discovery metadata. Override when exposing the server outside localhost or on a non-default port.","required":false,"secret":false},{"name":"EMBEDDING_ENABLED","description":"Enable or disable the embedding pipeline. When false, no ONNX model is downloaded, no vector tables are created, and search uses FTS5 only.","required":false,"secret":false},{"name":"RERANK_MODE","description":"Cross-encoder reranking mode: blended (position-aware score blending after RRF fusion) or none (skip reranking). Only takes effect when EMBEDDING_ENABLED is true.","required":false,"secret":false},{"name":"WINDOWS_MODE","description":"Windows bind-mount mode: enables filesystem polling for the file watcher and rename-based moves across the Docker Desktop/WSL2 bridge. Set to true when the vault lives on a Windows drive.","required":false,"secret":false},{"name":"MEMORY_ENABLED","description":"Enable or disable the structured memory layer. When false, memory tools are hidden, bootstrap is skipped, and server metadata omits memory references.","required":false,"secret":false},{"name":"FILE_TOOLS_ENABLED","description":"Enable or disable file tools (vault_read_file, vault_list_files). When false, file tools are hidden and server metadata omits file tool references.","required":false,"secret":false},{"name":"READONLY_MODE","description":"Run the server read-only: every vault-writing tool is hidden, the memory folder is not auto-created, and server metadata omits write references.","required":false,"secret":false},{"name":"DISABLED_TOOLS","description":"Hide individual tools by name, comma-separated. Subtractive only — it cannot re-enable a tool another setting hides; an unknown tool name stops the server at startup.","required":false,"secret":false},{"name":"MEMORY_DIR","description":"Vault folder for structured memory files (About Me-style notes). Memory tools are hidden when MEMORY_ENABLED is false, but this value still feeds the defaults for PROTECTED_PATHS and ORPHAN_EXCLUDE_FOLDERS.","required":false,"secret":false},{"name":"DAILY_NOTES_FOLDER","description":"Vault folder for daily notes. Overrides the folder configured in Obsidian's daily-notes plugin. When unset, read from the vault's .obsidian/daily-notes.json, falling back to \"Daily Notes\".","required":false,"secret":false},{"name":"DAILY_NOTES_FORMAT","description":"Filename date format for daily notes (Moment.js tokens). Overrides the format configured in Obsidian's daily-notes plugin. When unset, read from the vault's .obsidian/daily-notes.json, falling back to \"YYYY-MM-DD\".","required":false,"secret":false},{"name":"TRUST_PROXY_HOPS","description":"Number of trusted reverse-proxy hops used to derive the client IP from X-Forwarded-For for OAuth rate limiting and request logs. With 0, injected forwarding headers are ignored.","required":false,"secret":false},{"name":"TRUST_FORWARDED_HOPS","description":"How many entries from the end of the RFC 7239 Forwarded header's for= list to count to reach the client IP for OAuth rate limiting and request logs. 0 ignores the header; 1 when the proxy in front writes it (e.g. AWS API Gateway); 2 when a CDN fronts that proxy and is the only way to reach it.","required":false,"secret":false},{"name":"TZ","description":"IANA timezone for timestamps and daily note resolution.","required":false,"secret":false},{"name":"LOG_LEVEL","description":"Logging verbosity.","required":false,"secret":false},{"name":"LOG_DIR","description":"Directory for log files that survive container re-creation. The container's own log is always written but discarded when the container is recreated; date-stamped files under LOG_DIR persist on the data volume. Default: /data/logs (remote image), $STORAGE_ROOT/data/logs (single-volume mode), none (local image). none keeps only the container log.","format":"filepath","required":false,"secret":false},{"name":"LOG_RETENTION_DAYS","description":"Days to keep log files before automatic cleanup on startup; only applies when LOG_DIR is a path.","format":"number","required":false,"secret":false},{"name":"PROTECTED_PATHS","description":"Comma-separated vault folder names blocked from vault_delete_note and vault_move_note. Default: MEMORY_DIR plus the daily notes folder, read from DAILY_NOTES_FOLDER or .obsidian/daily-notes.json (default Daily Notes). When set, overrides the default entirely.","required":false,"secret":false},{"name":"ORPHAN_EXCLUDE_FOLDERS","description":"Comma-separated vault folder names excluded from vault_find_orphans. Default: the daily notes folder, \"Templates\", and MEMORY_DIR. DAILY_NOTES_FOLDER wins; otherwise .obsidian/daily-notes.json is read per query (fallback \"Daily Notes\"). When set, replaces the defaults entirely. Set to a comma (,) to exclude nothing; an empty value uses the defaults.","required":false,"secret":false},{"name":"SERVICE_DOCUMENTATION_URL","description":"Override the OAuth service documentation URL exposed via discovery metadata.","required":false,"secret":false},{"name":"MAX_FILE_BYTES","description":"Largest file vault_read_file will read, in bytes. Reading a larger file returns an error instead of content.","format":"number","required":false,"secret":false},{"name":"MAX_IMAGE_OUTPUT_BYTES","description":"Byte budget for images returned by vault_read_file, in binary bytes before base64 encoding. Images exceeding the budget are downscaled/recompressed server-side to fit; raise for clients that accept larger tool responses.","format":"number","required":false,"secret":false},{"name":"MAX_PDF_RENDER_PAGES","description":"Maximum PDF pages to render as images when raw: true is set on vault_read_file. The per-page byte budget is MAX_IMAGE_OUTPUT_BYTES divided evenly across the rendered pages.","format":"number","required":false,"secret":false}],"additional_arguments_declared":true}],"remotes":[]}
Source: MCP-Register · collected on 2026-10-09 · self-declared
Embed this badge

Paste this line into a README of your own. The badge states how many values the registry holds for the entry and when it last looked, and it links back to this page.

tracevero: number of measured values and date of collection for this registry entry

[![tracevero: number of measured values and date of collection for this registry entry](https://tracevero.com/badge/mcp/io-github-aliasunder-vault-cortex.svg)](https://tracevero.com/mcp/io-github-aliasunder-vault-cortex)

The image is drawn again on every request, so it always reports the current state while the pasted line stays as it is. It carries no rating and no traffic light – only the two measured figures.

Changes

Changes
2026-10-09Declared version: 0.54.10 → 0.54.11
2026-10-09Last changed in the registry (raw): 2026-10-06 → 2026-10-08
2026-10-09First listed in the registry (raw): 2026-10-06 → 2026-10-08

These are the 3 most recent changes to this entry. Full history

tracevero · https://tracevero.com/mcp/io-github-aliasunder-vault-cortex