← Back to directory
COMPARE UP TO 4 SERVERS

Compare MCP servers

Compare scores, permissions, risks, and fit in one decision-focused table.

DimensionFilesystem MCP ServerLocal project-file access over stdio.Filesystem MCP ServerSecure local file read/write accessVault Cortex MCP ServerStandalone MCP server for Obsidian vaults: hybrid search, notes & files, structured memory, tasks, OAuth 2.1.
FMRS35 / 100 · D84 / 100 · B79 / 100 · B
Reliability6 / 2017 / 2012 / 20
Security and permissions6 / 2016 / 2018 / 20
Maintenance11 / 2016 / 2015 / 20
Documentation5 / 2017 / 2019 / 20
Setup experience7 / 2018 / 2015 / 20
Best for
  • Developers who need an MCP client to access a specified Claude Code project directory.
  • Local assistants that need to work inside explicitly approved directories
  • Individuals and development teams that want path-based data boundaries
  • Serious Obsidian users who want AI agents reading and writing their vault
  • Users wanting self-hosted, plugin-free operation with no external APIs
  • Mobile/multi-device workflows accessing the vault remotely
  • Security-conscious users (OAuth 2.1, atomic writes, container hardening)
Not for
  • Users who need database access or custom API tools.
  • Users who need remote deployment, SSE, or streamable-http transport.
  • Highly sensitive environments that cannot allow model access to local file contents
  • Shared remote file-service use cases
  • Users unwilling to run Docker or self-host a server
  • Non-Obsidian note tools (Notion, Logseq, etc.)
  • Scenarios requiring only a stdio local process without an HTTP server
  • Remote multi-device sync without an Obsidian Sync subscription (the remote image requires one)
Required permissions
  • Access to the local project directory specified by ${CLAUDE_PROJECT_DIR}.
  • The exact read/write scope depends on the client, operating system, and server implementation; the source does not specify it.
  • Read access to every local directory listed in the configuration
  • Filesystem write access when write or move tools are enabled
  • Read/write access to the Obsidian vault folder (bind mount /vault, rw)
  • Persistent /data volume (search index, OAuth token DB, logs)
  • MCP_AUTH_TOKEN as Bearer token (also the JWT signing key)
  • Obsidian Sync token for headless sync in remote mode
  • Local download of embedding/reranker models (~45MB total), no external API calls
Risks and side effects
  • The MCP server may access local files; specify only a directory you are willing to authorize.
  • The README warns that MCP servers, files, or other software included in plugins may not be controlled by Anthropic and are not guaranteed to work as intended or avoid making changes.
  • Sensitive files inside an allowed directory may enter model context
  • Write and move tools change real files; keep scopes narrow and maintain backups
  • The server can read and write personal notes — guard MCP_AUTH_TOKEN carefully; leaking it exposes the whole vault
  • Writes to real note files; despite atomic writes and protected paths, misconfiguration can alter data
  • OAuth token DB lives on the /data volume; container compromise could expose valid sessions
  • Remote deployments expose a public port — set PUBLIC_URL and reverse proxy correctly
  • The remote image bundles proprietary obsidian-headless (not MIT-licensed); requires an active Obsidian Sync subscription
Supported clientsClaude Desktop, Cursor, Cline, WindsurfClaude Code, Claude Desktop, claude.ai, Cursor, OpenCode, MCP Inspector
Tools0630