npm · obsidian-mcp-server
$npx -y obsidian-mcp-server@3.7.0 OBSIDIAN_API_KEY (required) — Bearer token for the Obsidian Local REST API plugin (Settings → Community Plugins → Local REST API).
OBSIDIAN_BASE_URL — Base URL of the Obsidian Local REST API. Default: http://127.0.0.1:27123 (enable "Non-encrypted (HTTP) Server" in plugin settings). Use https://127.0.0.1:27124 for the always-on HTTPS port (self-signed cert; pair with OBSIDIAN_VERIFY_SSL=false).
OBSIDIAN_VERIFY_SSL — Whether to verify the TLS certificate on the Obsidian endpoint. Default false because the plugin uses a self-signed cert.
OBSIDIAN_REQUEST_TIMEOUT_MS — Per-request timeout in milliseconds.
OBSIDIAN_ENABLE_COMMANDS — Opt-in flag for the command-palette pair (obsidian_list_commands + obsidian_execute_command). Off by default — Obsidian commands are opaque and can be destructive.
OBSIDIAN_READ_PATHS — Optional comma-separated vault-relative folder allowlist for reads. Prefix-based with implicit recursion; case-insensitive; trailing slashes normalized. Unset = full vault. Write paths are implicitly readable. Example: 'public/,projects/'.
OBSIDIAN_WRITE_PATHS — Optional comma-separated vault-relative folder allowlist for writes. Same syntax as OBSIDIAN_READ_PATHS. Unset = full vault. Example: 'projects/,scratch/'.
OBSIDIAN_READ_ONLY — Global read-only kill switch. When true, every write is denied regardless of OBSIDIAN_WRITE_PATHS, and the command-palette pair is suppressed (commands can mutate). Useful for shared or public-facing deployments.
OBSIDIAN_DELETE_ELICITATION — Opt-in delete confirmation. When true, obsidian_delete_note asks the user to confirm each delete through an elicitation round (the client must support elicitation), and HTTP startup requires a stateful session unless OBSIDIAN_READ_ONLY=true disables the tool. Off by default — the delete runs on the first call, bounded by OBSIDIAN_WRITE_PATHS and OBSIDIAN_READ_ONLY.
OBSIDIAN_OMNISEARCH_URL — Override URL for the Omnisearch plugin HTTP server. Unset derives from OBSIDIAN_BASE_URL host with port 51361. Required only if the Omnisearch plugin is not on the default port.
MCP_LOG_LEVEL — Sets the minimum log level for output (e.g., 'debug', 'info', 'warn').
npm · obsidian-mcp-server
$npx -y obsidian-mcp-server@3.7.0 MCP_TRANSPORT_TYPE — Selects the HTTP transport.
OBSIDIAN_API_KEY (required) — Bearer token for the Obsidian Local REST API plugin (Settings → Community Plugins → Local REST API).
OBSIDIAN_BASE_URL — Base URL of the Obsidian Local REST API. Default: http://127.0.0.1:27123 (enable "Non-encrypted (HTTP) Server" in plugin settings). Use https://127.0.0.1:27124 for the always-on HTTPS port (self-signed cert; pair with OBSIDIAN_VERIFY_SSL=false).
OBSIDIAN_VERIFY_SSL — Whether to verify the TLS certificate on the Obsidian endpoint. Default false because the plugin uses a self-signed cert.
OBSIDIAN_REQUEST_TIMEOUT_MS — Per-request timeout in milliseconds.
OBSIDIAN_ENABLE_COMMANDS — Opt-in flag for the command-palette pair (obsidian_list_commands + obsidian_execute_command). Off by default — Obsidian commands are opaque and can be destructive.
OBSIDIAN_READ_PATHS — Optional comma-separated vault-relative folder allowlist for reads. Prefix-based with implicit recursion; case-insensitive; trailing slashes normalized. Unset = full vault. Write paths are implicitly readable. Example: 'public/,projects/'.
OBSIDIAN_WRITE_PATHS — Optional comma-separated vault-relative folder allowlist for writes. Same syntax as OBSIDIAN_READ_PATHS. Unset = full vault. Example: 'projects/,scratch/'.
OBSIDIAN_READ_ONLY — Global read-only kill switch. When true, every write is denied regardless of OBSIDIAN_WRITE_PATHS, and the command-palette pair is suppressed (commands can mutate). Useful for shared or public-facing deployments.
OBSIDIAN_DELETE_ELICITATION — Opt-in delete confirmation. When true, obsidian_delete_note asks the user to confirm each delete through an elicitation round (the client must support elicitation), and HTTP startup requires a stateful session unless OBSIDIAN_READ_ONLY=true disables the tool. Off by default — the delete runs on the first call, bounded by OBSIDIAN_WRITE_PATHS and OBSIDIAN_READ_ONLY.
OBSIDIAN_OMNISEARCH_URL — Override URL for the Omnisearch plugin HTTP server. Unset derives from OBSIDIAN_BASE_URL host with port 51361. Required only if the Omnisearch plugin is not on the default port.
MCP_HTTP_HOST — The hostname for the HTTP server.
MCP_HTTP_PORT — The port to run the HTTP server on.
MCP_HTTP_ENDPOINT_PATH — The endpoint path for the MCP server.
MCP_AUTH_MODE — Authentication mode to use: 'none', 'jwt', or 'oauth'.
MCP_LOG_LEVEL — Sets the minimum log level for output (e.g., 'debug', 'info', 'warn').