Home › Knowledge & Memory › Vault Cortex
Vault Cortex
Standalone MCP server for Obsidian vaults — hybrid search, notes & files, memory, tasks, OAuth 2.1
Topics: Knowledge & Memory
Connect
Review any command before running it. Package names and URLs come from the server's own registry entry.
Package (oci)
Package: oci ghcr.io/aliasunder/vault-cortex:0.54.2
MCP_AUTH_TOKENrequired secret — Bearer token for MCP client authentication. Must match the Authorization header sent by clients. Generate with: openssl rand -hex 32PUBLIC_URL— Public URL clients use to reach this server. Used as the OAuth issuer URL in discovery metadata. Override when exposing the server outside localhost or on a non-default port.EMBEDDING_ENABLED— Enable or disable the embedding pipeline. When false, no ONNX model is downloaded, no vector tables are created, and search uses FTS5 only.RERANK_MODE— Cross-encoder reranking mode: blended (position-aware score blending after RRF fusion) or none (skip reranking). Only takes effect when EMBEDDING_ENABLED is true.WINDOWS_MODE— Windows bind-mount mode: enables filesystem polling for the file watcher and rename-based moves across the Docker Desktop/WSL2 bridge. Set to true when the vault lives on a Windows drive.MEMORY_ENABLED— Enable or disable the structured memory layer. When false, memory tools are hidden, bootstrap is skipped, and server metadata omits memory references.FILE_TOOLS_ENABLED— Enable or disable file tools (vault_read_file, vault_list_files). When false, file tools are hidden and server metadata omits file tool references.READONLY_MODE— Run the server read-only: every vault-writing tool is hidden, the memory folder is not auto-created, and server metadata omits write references.DISABLED_TOOLS— Hide individual tools by name, comma-separated. Subtractive only — it cannot re-enable a tool another setting hides; an unknown tool name stops the server at startup.MEMORY_DIR— Vault folder for structured memory files (About Me-style notes). Memory tools are hidden when MEMORY_ENABLED is false, but this value still feeds the defaults for PROTECTED_PATHS and ORPHAN_EXCLUDE_FOLDERS.DAILY_NOTES_FOLDER— Vault folder for daily notes. Overrides the folder configured in Obsidian's daily-notes plugin. When unset, read from the vault's .obsidian/daily-notes.json, falling back to "Daily Notes".DAILY_NOTES_FORMAT— Filename date format for daily notes (Moment.js tokens). Overrides the format configured in Obsidian's daily-notes plugin. When unset, read from the vault's .obsidian/daily-notes.json, falling back to "YYYY-MM-DD".TRUST_PROXY_HOPS— Number of trusted reverse-proxy hops used to derive the client IP from X-Forwarded-For for OAuth rate limiting and request logs. With 0, injected forwarding headers are ignored.TRUST_FORWARDED_HOPS— How many entries from the end of the RFC 7239 Forwarded header's for= list to count to reach the client IP for OAuth rate limiting and request logs. 0 ignores the header; 1 when the proxy in front writes it (e.g. AWS API Gateway); 2 when a CDN fronts that proxy and is the only way to reach it.TZ— IANA timezone for timestamps and daily note resolution.LOG_LEVEL— Logging verbosity.LOG_DIR— Directory for log files that survive container re-creation. The container's own log is always written but discarded when the container is recreated; date-stamped files under LOG_DIR persist on the data volume. Default: /data/logs (remote image), $STORAGE_ROOT/data/logs (single-volume mode), none (local image). none keeps only the container log.LOG_RETENTION_DAYS— Days to keep log files before automatic cleanup on startup; only applies when LOG_DIR is a path.PROTECTED_PATHS— Comma-separated vault folder names blocked from vault_delete_note and vault_move_note. Default: MEMORY_DIR plus the daily notes folder, read from DAILY_NOTES_FOLDER or .obsidian/daily-notes.json (default Daily Notes). When set, overrides the default entirely.ORPHAN_EXCLUDE_FOLDERS— Comma-separated vault folder names excluded from vault_find_orphans. Default: DAILY_NOTES_FOLDER (else "Daily Notes"), "Templates", MEMORY_DIR.SERVICE_DOCUMENTATION_URL— Override the OAuth service documentation URL exposed via discovery metadata.MAX_FILE_BYTES— Largest file vault_read_file will read, in bytes. Reading a larger file returns an error instead of content.MAX_IMAGE_OUTPUT_BYTES— Byte budget for images returned by vault_read_file, in binary bytes before base64 encoding. Images exceeding the budget are downscaled/recompressed server-side to fit; raise for clients that accept larger tool responses.MAX_PDF_RENDER_PAGES— Maximum PDF pages to render as images when raw: true is set on vault_read_file. The per-page byte budget is MAX_IMAGE_OUTPUT_BYTES divided evenly across the rendered pages.
This server takes extra arguments — see its repository.
Related servers
Context7
Up-to-date code docs for any prompt
cognee
Memory manager for AI apps and Agents using various graph and vector stores and allowing ingestion from 30+ data sources
hindsight
Hindsight: Agent Memory That Works Like Human Memory - Built for AI Agents to manage Long Term Memory
Skill_Seekers
Transform 17 source types (docs, GitHub repos, PDFs, videos, Jupyter, Confluence, Notion, Slack/Discord) into AI-ready skills and RAG…
basic-memory
Local-first knowledge management with bi-directional LLM sync via Markdown files.
NoteDiscovery
Self-hosted plain-markdown knowledge base with a built-in MCP server. Lets Claude Desktop, Cursor, and any MCP client search, read,…
Listed in punkpeye/awesome-mcp-servers (MIT)
Data from the Official MCP Registry