---
bezeichner: "io.github.aliasunder/vault-cortex"
art: "mcp_server"
slug: "io-github-aliasunder-vault-cortex"
paketkoordinate: "oci:ghcr.io/aliasunder/vault-cortex:0.54.11"
status: "aktiv"
homepage: "https://github.com/aliasunder/vault-cortex"
erhebungsstand: "2026-10-10T01:17:01.464Z"
namensraum: "io.github.aliasunder"
registerseite: "https://tracevero.de/mcp/io-github-aliasunder-vault-cortex"
abgerufen_am: "2026-10-10"
zugangsdaten_erforderlich: true
ausfuehrungsort: "entfernt"
dateisystem_pfadargument: true
quelloffen_einsehbar: true
einsatzgebiet: "wissen"
roh_beschreibung: "Standalone MCP server for Obsidian vaults — hybrid search, notes & files, memory, tasks, OAuth 2.1"
version: "0.54.11"
roh_umgebungsvariablen: "MCP_AUTH_TOKEN, PUBLIC_URL, EMBEDDING_ENABLED, RERANK_MODE, WINDOWS_MODE, MEMORY_ENABLED, FILE_TOOLS_ENABLED, READONLY_MODE, DISABLED_TOOLS, MEMORY_DIR, DAILY_NOTES_FOLDER, DAILY_NOTES_FORMAT, TRUST_PROXY_HOPS, TRUST_FORWARDED_HOPS, TZ, LOG_LEVEL, LOG_DIR, LOG_RETENTION_DAYS, PROTECTED_PATHS, ORPHAN_EXCLUDE_FOLDERS, SERVICE_DOCUMENTATION_URL, MAX_FILE_BYTES, MAX_IMAGE_OUTPUT_BYTES, MAX_PDF_RENDER_PAGES"
roh_geheime_pflichtvariablen: "MCP_AUTH_TOKEN"
roh_transportarten: "streamable-http"
roh_pfadargumente: ""
roh_repository_url: "https://github.com/aliasunder/vault-cortex"
roh_paketquellen: "oci"
roh_geheime_pflichtkopfzeilen: ""
roh_pfad_umgebungsvariablen: "LOG_DIR"
roh_remote_adressen: ""
roh_remote_hosts: ""
roh_statusmeldung: ""
roh_veroeffentlicht_am: "2026-10-08"
roh_aktualisiert_am: "2026-10-08"
roh_schemafassung: "https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json"
roh_bereitstellungsform: "paket"
roh_repository_quelle: "github"
roh_repository_unterordner: ""
roh_paketbezeichner: "ghcr.io/aliasunder/vault-cortex:0.54.11"
roh_paketversionen: ""
roh_laufzeithinweise: "docker"
roh_umgebungsformate: "filepath, number"
roh_umgebungsbeschreibungen: "DAILY_NOTES_FOLDER=Vault folder for daily notes. Overrides the folder configured in Obsidian's daily-notes plugin. When unset, read from the vault's .obsidian/daily-notes.json, falling back to \"Daily Notes\". · DAILY_NOTES_FORMAT=Filename date format for daily notes (Moment.js tokens). Overrides the format configured in Obsidian's daily-notes plugin. When unset, read from the vault's .obsidian/daily-notes.json, falling back to \"YYYY-MM-DD\". · DISABLED_TOOLS=Hide individual tools by name, comma-separated. Subtractive only — it cannot re-enable a tool another setting hides; an unknown tool name stops the server at startup. · EMBEDDING_ENABLED=Enable or disable the embedding pipeline. When false, no ONNX model is downloaded, no vector tables are created, and search uses FTS5 only. · FILE_TOOLS_ENABLED=Enable or disable file tools (vault_read_file, vault_list_files). When false, file tools are hidden and server metadata omits file tool references. · LOG_DIR=Directory for log files that survive container re-creation. The container's own log is always written but discarded when the container is recreated; date-stamped files under LOG_DIR persist on the data volume. Default: /data/logs (remote image), $STORAGE_ROOT/data/logs (single-volume mode), none (local image). none keeps only the container log. · LOG_LEVEL=Logging verbosity. · LOG_RETENTION_DAYS=Days to keep log files before automatic cleanup on startup; only applies when LOG_DIR is a path. · MAX_FILE_BYTES=Largest file vault_read_file will read, in bytes. Reading a larger file returns an error instead of content. · MAX_IMAGE_OUTPUT_BYTES=Byte budget for images returned by vault_read_file, in binary bytes before base64 encoding. Images exceeding the budget are downscaled/recompressed server-side to fit; raise for clients that accept larger tool responses. · MAX_PDF_RENDER_PAGES=Maximum PDF pages to render as images when raw: true is set on vault_read_file. The per-page byte budget is MAX_IMAGE_OUTPUT_BYTES divided evenly across the rendered pages. · MCP_AUTH_TOKEN=Bearer token for MCP client authentication. Must match the Authorization header sent by clients. Generate with: openssl rand -hex 32 · MEMORY_DIR=Vault folder for structured memory files (About Me-style notes). Memory tools are hidden when MEMORY_ENABLED is false, but this value still feeds the defaults for PROTECTED_PATHS and ORPHAN_EXCLUDE_FOLDERS. · MEMORY_ENABLED=Enable or disable the structured memory layer. When false, memory tools are hidden, bootstrap is skipped, and server metadata omits memory references. · ORPHAN_EXCLUDE_FOLDERS=Comma-separated vault folder names excluded from vault_find_orphans. Default: the daily notes folder, \"Templates\", and MEMORY_DIR. DAILY_NOTES_FOLDER wins; otherwise .obsidian/daily-notes.json is read per query (fallback \"Daily Notes\"). When set, replaces the defaults entirely. Set to a comma (,) to exclude nothing; an empty value uses the defaults. · PROTECTED_PATHS=Comma-separated vault folder names blocked from vault_delete_note and vault_move_note. Default: MEMORY_DIR plus the daily notes folder, read from DAILY_NOTES_FOLDER or .obsidian/daily-notes.json (default Daily Notes). When set, overrides the default entirely. · PUBLIC_URL=Public URL clients use to reach this server. Used as the OAuth issuer URL in discovery metadata. Override when exposing the server outside localhost or on a non-default port. · READONLY_MODE=Run the server read-only: every vault-writing tool is hidden, the memory folder is not auto-created, and server metadata omits write references. · RERANK_MODE=Cross-encoder reranking mode: blended (position-aware score blending after RRF fusion) or none (skip reranking). Only takes effect when EMBEDDING_ENABLED is true. · SERVICE_DOCUMENTATION_URL=Override the OAuth service documentation URL exposed via discovery metadata. · TRUST_FORWARDED_HOPS=How many entries from the end of the RFC 7239 Forwarded header's for= list to count to reach the client IP for OAuth rate limiting and request logs. 0 ignores the header; 1 when the proxy in front writes it (e.g. AWS API Gateway); 2 when a CDN fronts that proxy and is the only way to reach it. · TRUST_PROXY_HOPS=Number of trusted reverse-proxy hops used to derive the client IP from X-Forwarded-For for OAuth rate limiting and request logs. With 0, injected forwarding headers are ignored. · TZ=IANA timezone for timestamps and daily note resolution. · WINDOWS_MODE=Windows bind-mount mode: enables filesystem polling for the file watcher and rename-based moves across the Docker Desktop/WSL2 bridge. Set to true when the vault lives on a Windows drive."
roh_symbolformate: ""
roh_verbindungswege: "{\"packages\":[{\"registryType\":\"oci\",\"identifier\":\"ghcr.io/aliasunder/vault-cortex:0.54.11\",\"runtimeHint\":\"docker\",\"transport\":\"streamable-http\",\"environment\":[{\"name\":\"MCP_AUTH_TOKEN\",\"description\":\"Bearer token for MCP client authentication. Must match the Authorization header sent by clients. Generate with: openssl rand -hex 32\",\"required\":true,\"secret\":true},{\"name\":\"PUBLIC_URL\",\"description\":\"Public URL clients use to reach this server. Used as the OAuth issuer URL in discovery metadata. Override when exposing the server outside localhost or on a non-default port.\",\"required\":false,\"secret\":false},{\"name\":\"EMBEDDING_ENABLED\",\"description\":\"Enable or disable the embedding pipeline. When false, no ONNX model is downloaded, no vector tables are created, and search uses FTS5 only.\",\"required\":false,\"secret\":false},{\"name\":\"RERANK_MODE\",\"description\":\"Cross-encoder reranking mode: blended (position-aware score blending after RRF fusion) or none (skip reranking). Only takes effect when EMBEDDING_ENABLED is true.\",\"required\":false,\"secret\":false},{\"name\":\"WINDOWS_MODE\",\"description\":\"Windows bind-mount mode: enables filesystem polling for the file watcher and rename-based moves across the Docker Desktop/WSL2 bridge. Set to true when the vault lives on a Windows drive.\",\"required\":false,\"secret\":false},{\"name\":\"MEMORY_ENABLED\",\"description\":\"Enable or disable the structured memory layer. When false, memory tools are hidden, bootstrap is skipped, and server metadata omits memory references.\",\"required\":false,\"secret\":false},{\"name\":\"FILE_TOOLS_ENABLED\",\"description\":\"Enable or disable file tools (vault_read_file, vault_list_files). When false, file tools are hidden and server metadata omits file tool references.\",\"required\":false,\"secret\":false},{\"name\":\"READONLY_MODE\",\"description\":\"Run the server read-only: every vault-writing tool is hidden, the memory folder is not auto-created, and server metadata omits write references.\",\"required\":false,\"secret\":false},{\"name\":\"DISABLED_TOOLS\",\"description\":\"Hide individual tools by name, comma-separated. Subtractive only — it cannot re-enable a tool another setting hides; an unknown tool name stops the server at startup.\",\"required\":false,\"secret\":false},{\"name\":\"MEMORY_DIR\",\"description\":\"Vault folder for structured memory files (About Me-style notes). Memory tools are hidden when MEMORY_ENABLED is false, but this value still feeds the defaults for PROTECTED_PATHS and ORPHAN_EXCLUDE_FOLDERS.\",\"required\":false,\"secret\":false},{\"name\":\"DAILY_NOTES_FOLDER\",\"description\":\"Vault folder for daily notes. Overrides the folder configured in Obsidian's daily-notes plugin. When unset, read from the vault's .obsidian/daily-notes.json, falling back to \\\"Daily Notes\\\".\",\"required\":false,\"secret\":false},{\"name\":\"DAILY_NOTES_FORMAT\",\"description\":\"Filename date format for daily notes (Moment.js tokens). Overrides the format configured in Obsidian's daily-notes plugin. When unset, read from the vault's .obsidian/daily-notes.json, falling back to \\\"YYYY-MM-DD\\\".\",\"required\":false,\"secret\":false},{\"name\":\"TRUST_PROXY_HOPS\",\"description\":\"Number of trusted reverse-proxy hops used to derive the client IP from X-Forwarded-For for OAuth rate limiting and request logs. With 0, injected forwarding headers are ignored.\",\"required\":false,\"secret\":false},{\"name\":\"TRUST_FORWARDED_HOPS\",\"description\":\"How many entries from the end of the RFC 7239 Forwarded header's for= list to count to reach the client IP for OAuth rate limiting and request logs. 0 ignores the header; 1 when the proxy in front writes it (e.g. AWS API Gateway); 2 when a CDN fronts that proxy and is the only way to reach it.\",\"required\":false,\"secret\":false},{\"name\":\"TZ\",\"description\":\"IANA timezone for timestamps and daily note resolution.\",\"required\":false,\"secret\":false},{\"name\":\"LOG_LEVEL\",\"description\":\"Logging verbosity.\",\"required\":false,\"secret\":false},{\"name\":\"LOG_DIR\",\"description\":\"Directory for log files that survive container re-creation. The container's own log is always written but discarded when the container is recreated; date-stamped files under LOG_DIR persist on the data volume. Default: /data/logs (remote image), $STORAGE_ROOT/data/logs (single-volume mode), none (local image). none keeps only the container log.\",\"format\":\"filepath\",\"required\":false,\"secret\":false},{\"name\":\"LOG_RETENTION_DAYS\",\"description\":\"Days to keep log files before automatic cleanup on startup; only applies when LOG_DIR is a path.\",\"format\":\"number\",\"required\":false,\"secret\":false},{\"name\":\"PROTECTED_PATHS\",\"description\":\"Comma-separated vault folder names blocked from vault_delete_note and vault_move_note. Default: MEMORY_DIR plus the daily notes folder, read from DAILY_NOTES_FOLDER or .obsidian/daily-notes.json (default Daily Notes). When set, overrides the default entirely.\",\"required\":false,\"secret\":false},{\"name\":\"ORPHAN_EXCLUDE_FOLDERS\",\"description\":\"Comma-separated vault folder names excluded from vault_find_orphans. Default: the daily notes folder, \\\"Templates\\\", and MEMORY_DIR. DAILY_NOTES_FOLDER wins; otherwise .obsidian/daily-notes.json is read per query (fallback \\\"Daily Notes\\\"). When set, replaces the defaults entirely. Set to a comma (,) to exclude nothing; an empty value uses the defaults.\",\"required\":false,\"secret\":false},{\"name\":\"SERVICE_DOCUMENTATION_URL\",\"description\":\"Override the OAuth service documentation URL exposed via discovery metadata.\",\"required\":false,\"secret\":false},{\"name\":\"MAX_FILE_BYTES\",\"description\":\"Largest file vault_read_file will read, in bytes. Reading a larger file returns an error instead of content.\",\"format\":\"number\",\"required\":false,\"secret\":false},{\"name\":\"MAX_IMAGE_OUTPUT_BYTES\",\"description\":\"Byte budget for images returned by vault_read_file, in binary bytes before base64 encoding. Images exceeding the budget are downscaled/recompressed server-side to fit; raise for clients that accept larger tool responses.\",\"format\":\"number\",\"required\":false,\"secret\":false},{\"name\":\"MAX_PDF_RENDER_PAGES\",\"description\":\"Maximum PDF pages to render as images when raw: true is set on vault_read_file. The per-page byte budget is MAX_IMAGE_OUTPUT_BYTES divided evenly across the rendered pages.\",\"format\":\"number\",\"required\":false,\"secret\":false}],\"additional_arguments_declared\":true}],\"remotes\":[]}"
---

# Vault Cortex

## Gemessene Werte

| Merkmal | Wert | Quelle | Erhoben am | Vertrauensgrad | Rohangabe |
| --- | --- | --- | --- | --- | --- |
| Pflicht-Geheimnisse deklariert | true | MCP-Register | 2026-08-06T13:57:41.838Z | abgeleitet | roh_geheime_pflichtvariablen: MCP_AUTH_TOKEN; roh_geheime_pflichtkopfzeilen: |
| Ausführungsort | entfernt | MCP-Register | 2026-08-06T13:57:41.838Z | abgeleitet | roh_transportarten: streamable-http |
| Pfadargument vorhanden | true | MCP-Register | 2026-08-16T01:17:01.420Z | abgeleitet | roh_pfadargumente: ; roh_pfad_umgebungsvariablen: LOG_DIR |
| Repository-Adresse geführt | true | MCP-Register | 2026-08-06T13:57:41.838Z | abgeleitet | roh_repository_url: https://github.com/aliasunder/vault-cortex |
| Einsatzgebiet, aus der Anbieterbeschreibung abgeleitet | gedaechtnis | MCP-Register | 2026-08-26T16:45:01.514Z | abgeleitet | roh_beschreibung: Standalone MCP server for Obsidian vaults — hybrid search, notes & files, memory, tasks, OAuth 2.1 |
| Einsatzgebiet, aus der Anbieterbeschreibung abgeleitet | wissen | MCP-Register | 2026-08-26T16:45:01.514Z | abgeleitet | roh_beschreibung: Standalone MCP server for Obsidian vaults — hybrid search, notes & files, memory, tasks, OAuth 2.1 |
| Beschreibung (Rohangabe) | Standalone MCP server for Obsidian vaults — hybrid search, notes & files, memory, tasks, OAuth 2.1 | MCP-Register | 2026-08-26T16:45:01.514Z | selbstauskunft |  |
| Deklarierte Version | 0.54.11 | MCP-Register | 2026-10-09T01:17:01.645Z | selbstauskunft |  |
| Umgebungsvariablen (Rohangabe) | MCP_AUTH_TOKEN, PUBLIC_URL, EMBEDDING_ENABLED, RERANK_MODE, WINDOWS_MODE, MEMORY_ENABLED, FILE_TOOLS_ENABLED, READONLY_MODE, DISABLED_TOOLS, MEMORY_DIR, DAILY_NOTES_FOLDER, DAILY_NOTES_FORMAT, TRUST_PROXY_HOPS, TRUST_FORWARDED_HOPS, TZ, LOG_LEVEL, LOG_DIR, LOG_RETENTION_DAYS, PROTECTED_PATHS, ORPHAN_EXCLUDE_FOLDERS, SERVICE_DOCUMENTATION_URL, MAX_FILE_BYTES, MAX_IMAGE_OUTPUT_BYTES, MAX_PDF_RENDER_PAGES | MCP-Register | 2026-08-26T01:17:02.201Z | selbstauskunft |  |
| Geheime Pflichtvariablen (Rohangabe) | MCP_AUTH_TOKEN | MCP-Register | 2026-08-06T13:57:41.838Z | selbstauskunft |  |
| Transportarten (Rohangabe) | streamable-http | MCP-Register | 2026-08-06T13:57:41.838Z | selbstauskunft |  |
| Pfadargumente (Rohangabe) |  | MCP-Register | 2026-08-06T13:57:41.838Z | selbstauskunft |  |
| Repository (Rohangabe) | https://github.com/aliasunder/vault-cortex | MCP-Register | 2026-08-06T13:57:41.838Z | selbstauskunft |  |
| Paketquellen (Rohangabe) | oci | MCP-Register | 2026-08-06T13:57:41.838Z | selbstauskunft |  |
| Geheime Pflichtkopfzeilen (Rohangabe) |  | MCP-Register | 2026-08-16T01:17:01.420Z | selbstauskunft |  |
| Pfad-Umgebungsvariablen (Rohangabe) | LOG_DIR | MCP-Register | 2026-08-16T01:17:01.420Z | selbstauskunft |  |
| Remote-Adressen (Rohangabe) |  | MCP-Register | 2026-08-16T01:17:01.420Z | selbstauskunft |  |
| Remote-Hosts (Rohangabe) |  | MCP-Register | 2026-08-16T01:17:01.420Z | selbstauskunft |  |
| Statusmeldung des Registers (Rohangabe) |  | MCP-Register | 2026-08-16T01:17:01.420Z | selbstauskunft |  |
| Im Register eingetragen am (Rohangabe) | 2026-10-08 | MCP-Register | 2026-10-09T01:17:01.645Z | selbstauskunft |  |
| Im Register geändert am (Rohangabe) | 2026-10-08 | MCP-Register | 2026-10-09T01:17:01.645Z | selbstauskunft |  |
| Schemafassung des Rohsatzes (Rohangabe) | https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json | MCP-Register | 2026-08-16T01:17:01.420Z | selbstauskunft |  |
| Bereitstellungsform (Rohangabe) | paket | MCP-Register | 2026-08-16T01:17:01.420Z | selbstauskunft |  |
| Repository-Plattform (Rohangabe) | github | MCP-Register | 2026-08-16T01:17:01.420Z | selbstauskunft |  |
| Repository-Unterordner (Rohangabe) |  | MCP-Register | 2026-08-16T01:17:01.420Z | selbstauskunft |  |
| Paketbezeichner (Rohangabe) | ghcr.io/aliasunder/vault-cortex:0.54.11 | MCP-Register | 2026-10-09T01:17:01.645Z | selbstauskunft |  |
| Paketversionen (Rohangabe) |  | MCP-Register | 2026-08-16T01:17:01.420Z | selbstauskunft |  |
| Laufzeithinweise (Rohangabe) | docker | MCP-Register | 2026-08-16T01:17:01.420Z | selbstauskunft |  |
| Formate der Umgebungsvariablen (Rohangabe) | filepath, number | MCP-Register | 2026-08-16T01:17:01.420Z | selbstauskunft |  |
| Beschreibungen der Umgebungsvariablen (Rohangabe) | DAILY_NOTES_FOLDER=Vault folder for daily notes. Overrides the folder configured in Obsidian's daily-notes plugin. When unset, read from the vault's .obsidian/daily-notes.json, falling back to "Daily Notes". · DAILY_NOTES_FORMAT=Filename date format for daily notes (Moment.js tokens). Overrides the format configured in Obsidian's daily-notes plugin. When unset, read from the vault's .obsidian/daily-notes.json, falling back to "YYYY-MM-DD". · DISABLED_TOOLS=Hide individual tools by name, comma-separated. Subtractive only — it cannot re-enable a tool another setting hides; an unknown tool name stops the server at startup. · EMBEDDING_ENABLED=Enable or disable the embedding pipeline. When false, no ONNX model is downloaded, no vector tables are created, and search uses FTS5 only. · FILE_TOOLS_ENABLED=Enable or disable file tools (vault_read_file, vault_list_files). When false, file tools are hidden and server metadata omits file tool references. · LOG_DIR=Directory for log files that survive container re-creation. The container's own log is always written but discarded when the container is recreated; date-stamped files under LOG_DIR persist on the data volume. Default: /data/logs (remote image), $STORAGE_ROOT/data/logs (single-volume mode), none (local image). none keeps only the container log. · LOG_LEVEL=Logging verbosity. · LOG_RETENTION_DAYS=Days to keep log files before automatic cleanup on startup; only applies when LOG_DIR is a path. · MAX_FILE_BYTES=Largest file vault_read_file will read, in bytes. Reading a larger file returns an error instead of content. · MAX_IMAGE_OUTPUT_BYTES=Byte budget for images returned by vault_read_file, in binary bytes before base64 encoding. Images exceeding the budget are downscaled/recompressed server-side to fit; raise for clients that accept larger tool responses. · MAX_PDF_RENDER_PAGES=Maximum PDF pages to render as images when raw: true is set on vault_read_file. The per-page byte budget is MAX_IMAGE_OUTPUT_BYTES divided evenly across the rendered pages. · MCP_AUTH_TOKEN=Bearer token for MCP client authentication. Must match the Authorization header sent by clients. Generate with: openssl rand -hex 32 · MEMORY_DIR=Vault folder for structured memory files (About Me-style notes). Memory tools are hidden when MEMORY_ENABLED is false, but this value still feeds the defaults for PROTECTED_PATHS and ORPHAN_EXCLUDE_FOLDERS. · MEMORY_ENABLED=Enable or disable the structured memory layer. When false, memory tools are hidden, bootstrap is skipped, and server metadata omits memory references. · ORPHAN_EXCLUDE_FOLDERS=Comma-separated vault folder names excluded from vault_find_orphans. Default: the daily notes folder, "Templates", and MEMORY_DIR. DAILY_NOTES_FOLDER wins; otherwise .obsidian/daily-notes.json is read per query (fallback "Daily Notes"). When set, replaces the defaults entirely. Set to a comma (,) to exclude nothing; an empty value uses the defaults. · PROTECTED_PATHS=Comma-separated vault folder names blocked from vault_delete_note and vault_move_note. Default: MEMORY_DIR plus the daily notes folder, read from DAILY_NOTES_FOLDER or .obsidian/daily-notes.json (default Daily Notes). When set, overrides the default entirely. · PUBLIC_URL=Public URL clients use to reach this server. Used as the OAuth issuer URL in discovery metadata. Override when exposing the server outside localhost or on a non-default port. · READONLY_MODE=Run the server read-only: every vault-writing tool is hidden, the memory folder is not auto-created, and server metadata omits write references. · RERANK_MODE=Cross-encoder reranking mode: blended (position-aware score blending after RRF fusion) or none (skip reranking). Only takes effect when EMBEDDING_ENABLED is true. · SERVICE_DOCUMENTATION_URL=Override the OAuth service documentation URL exposed via discovery metadata. · TRUST_FORWARDED_HOPS=How many entries from the end of the RFC 7239 Forwarded header's for= list to count to reach the client IP for OAuth rate limiting and request logs. 0 ignores the header; 1 when the proxy in front writes it (e.g. AWS API Gateway); 2 when a CDN fronts that proxy and is the only way to reach it. · TRUST_PROXY_HOPS=Number of trusted reverse-proxy hops used to derive the client IP from X-Forwarded-For for OAuth rate limiting and request logs. With 0, injected forwarding headers are ignored. · TZ=IANA timezone for timestamps and daily note resolution. · WINDOWS_MODE=Windows bind-mount mode: enables filesystem polling for the file watcher and rename-based moves across the Docker Desktop/WSL2 bridge. Set to true when the vault lives on a Windows drive. | MCP-Register | 2026-10-07T01:17:01.897Z | selbstauskunft |  |
| Symbolformate (Rohangabe) |  | MCP-Register | 2026-08-16T01:17:01.420Z | selbstauskunft |  |
| Verbindungswege (Quellstruktur) | {"packages":[{"registryType":"oci","identifier":"ghcr.io/aliasunder/vault-cortex:0.54.11","runtimeHint":"docker","transport":"streamable-http","environment":[{"name":"MCP_AUTH_TOKEN","description":"Bearer token for MCP client authentication. Must match the Authorization header sent by clients. Generate with: openssl rand -hex 32","required":true,"secret":true},{"name":"PUBLIC_URL","description":"Public URL clients use to reach this server. Used as the OAuth issuer URL in discovery metadata. Override when exposing the server outside localhost or on a non-default port.","required":false,"secret":false},{"name":"EMBEDDING_ENABLED","description":"Enable or disable the embedding pipeline. When false, no ONNX model is downloaded, no vector tables are created, and search uses FTS5 only.","required":false,"secret":false},{"name":"RERANK_MODE","description":"Cross-encoder reranking mode: blended (position-aware score blending after RRF fusion) or none (skip reranking). Only takes effect when EMBEDDING_ENABLED is true.","required":false,"secret":false},{"name":"WINDOWS_MODE","description":"Windows bind-mount mode: enables filesystem polling for the file watcher and rename-based moves across the Docker Desktop/WSL2 bridge. Set to true when the vault lives on a Windows drive.","required":false,"secret":false},{"name":"MEMORY_ENABLED","description":"Enable or disable the structured memory layer. When false, memory tools are hidden, bootstrap is skipped, and server metadata omits memory references.","required":false,"secret":false},{"name":"FILE_TOOLS_ENABLED","description":"Enable or disable file tools (vault_read_file, vault_list_files). When false, file tools are hidden and server metadata omits file tool references.","required":false,"secret":false},{"name":"READONLY_MODE","description":"Run the server read-only: every vault-writing tool is hidden, the memory folder is not auto-created, and server metadata omits write references.","required":false,"secret":false},{"name":"DISABLED_TOOLS","description":"Hide individual tools by name, comma-separated. Subtractive only — it cannot re-enable a tool another setting hides; an unknown tool name stops the server at startup.","required":false,"secret":false},{"name":"MEMORY_DIR","description":"Vault folder for structured memory files (About Me-style notes). Memory tools are hidden when MEMORY_ENABLED is false, but this value still feeds the defaults for PROTECTED_PATHS and ORPHAN_EXCLUDE_FOLDERS.","required":false,"secret":false},{"name":"DAILY_NOTES_FOLDER","description":"Vault folder for daily notes. Overrides the folder configured in Obsidian's daily-notes plugin. When unset, read from the vault's .obsidian/daily-notes.json, falling back to \\"Daily Notes\\".","required":false,"secret":false},{"name":"DAILY_NOTES_FORMAT","description":"Filename date format for daily notes (Moment.js tokens). Overrides the format configured in Obsidian's daily-notes plugin. When unset, read from the vault's .obsidian/daily-notes.json, falling back to \\"YYYY-MM-DD\\".","required":false,"secret":false},{"name":"TRUST_PROXY_HOPS","description":"Number of trusted reverse-proxy hops used to derive the client IP from X-Forwarded-For for OAuth rate limiting and request logs. With 0, injected forwarding headers are ignored.","required":false,"secret":false},{"name":"TRUST_FORWARDED_HOPS","description":"How many entries from the end of the RFC 7239 Forwarded header's for= list to count to reach the client IP for OAuth rate limiting and request logs. 0 ignores the header; 1 when the proxy in front writes it (e.g. AWS API Gateway); 2 when a CDN fronts that proxy and is the only way to reach it.","required":false,"secret":false},{"name":"TZ","description":"IANA timezone for timestamps and daily note resolution.","required":false,"secret":false},{"name":"LOG_LEVEL","description":"Logging verbosity.","required":false,"secret":false},{"name":"LOG_DIR","description":"Directory for log files that survive container re-creation. The container's own log is always written but discarded when the container is recreated; date-stamped files under LOG_DIR persist on the data volume. Default: /data/logs (remote image), $STORAGE_ROOT/data/logs (single-volume mode), none (local image). none keeps only the container log.","format":"filepath","required":false,"secret":false},{"name":"LOG_RETENTION_DAYS","description":"Days to keep log files before automatic cleanup on startup; only applies when LOG_DIR is a path.","format":"number","required":false,"secret":false},{"name":"PROTECTED_PATHS","description":"Comma-separated vault folder names blocked from vault_delete_note and vault_move_note. Default: MEMORY_DIR plus the daily notes folder, read from DAILY_NOTES_FOLDER or .obsidian/daily-notes.json (default Daily Notes). When set, overrides the default entirely.","required":false,"secret":false},{"name":"ORPHAN_EXCLUDE_FOLDERS","description":"Comma-separated vault folder names excluded from vault_find_orphans. Default: the daily notes folder, \\"Templates\\", and MEMORY_DIR. DAILY_NOTES_FOLDER wins; otherwise .obsidian/daily-notes.json is read per query (fallback \\"Daily Notes\\"). When set, replaces the defaults entirely. Set to a comma (,) to exclude nothing; an empty value uses the defaults.","required":false,"secret":false},{"name":"SERVICE_DOCUMENTATION_URL","description":"Override the OAuth service documentation URL exposed via discovery metadata.","required":false,"secret":false},{"name":"MAX_FILE_BYTES","description":"Largest file vault_read_file will read, in bytes. Reading a larger file returns an error instead of content.","format":"number","required":false,"secret":false},{"name":"MAX_IMAGE_OUTPUT_BYTES","description":"Byte budget for images returned by vault_read_file, in binary bytes before base64 encoding. Images exceeding the budget are downscaled/recompressed server-side to fit; raise for clients that accept larger tool responses.","format":"number","required":false,"secret":false},{"name":"MAX_PDF_RENDER_PAGES","description":"Maximum PDF pages to render as images when raw: true is set on vault_read_file. The per-page byte budget is MAX_IMAGE_OUTPUT_BYTES divided evenly across the rendered pages.","format":"number","required":false,"secret":false}],"additional_arguments_declared":true}],"remotes":[]} | MCP-Register | 2026-10-09T01:17:01.645Z | selbstauskunft |  |

## Verweise

- Namensraum: [[namensraum/io-github-aliasunder|io.github.aliasunder]]

---

- Registerseite: <https://tracevero.de/mcp/io-github-aliasunder-vault-cortex>
- Abgerufen am: 2026-10-10
