AgentHubAgentHub

Vault Cortex MCP配置与使用教程

MCP ServerMCP Registry官方收录

io.github.aliasunder/vault-cortex · v0.54.8

面向 Obsidian 仓库的独立 MCP 服务器——混合搜索、笔记与文件、记忆、任务、OAuth 2.1。

原文描述:Standalone MCP server for Obsidian vaults — hybrid search, notes & files, memory, tasks, OAuth 2.1

建议先在本页复制安装配置,再到上游核对文档与权限。

产品介绍

面向 Obsidian 仓库的独立 MCP 服务器——混合搜索、笔记与文件、记忆、任务、OAuth 2.1。 Vault Cortex 是一个MCP Server,收录自 官方 MCP Registry。支持 streamable-http 传输。本页提供产品介绍、配置教程、安装命令与适用场景,支持 Trae、通义灵码、Cursor、Claude Code、VS Code 等。

适用场景

AgentHub Verified 可用性验证技术测试通过

自动化测试流水线已校验安装命令、传输协议与客户端兼容性

最近校验时间2026-10-04
安装配置格式测试有效CLI 与 mcpServers JSON 语法校验通过
协议连接与握手响应正常支持标准 JSON-RPC 2.0 规格规范
上游数据源存活来源 official-mcp-registry,可正常下载依赖
测试可用客户端Claude Code、Claude Desktop、Cursor 等
安全等级: A+ 级 · 官方认证推荐 (A+)·该工具由官方或知名生态团队维护,源码遵循标准开源许可协议,可安全接入 Cursor / Claude。

按平台快速复制

选择你的平台查看安装方式

  1. 打开项目根目录下的 .cursor/mcp.json(没有就新建)
  2. 点击「复制配置」粘贴进去;若已有其他 MCP,只合并 mcpServers 里的本条目
  3. 将 env 中的 <占位符> 替换为真实密钥(见下方「环境变量」)
  4. 保存后按 Cmd+Shift+P(Windows:Ctrl+Shift+P)→ 输入 Reload Window 并执行

预填环境变量与密钥(可选)

必填secret
隐私安全承诺:所有参数与密钥仅在您本机的浏览器前端进行实时文本替换,AgentHub 绝不向任何服务器上传或存储您的敏感凭据。
点击「复制配置」直接粘贴到客户端
{
  "mcpServers": {
    "vault-cortex": {
      "command": "docker",
      "args": [
        "run",
        "-i",
        "--rm",
        "ghcr.io/aliasunder/vault-cortex:0.54.8"
      ],
      "env": {
        "MCP_AUTH_TOKEN": "<MCP_AUTH_TOKEN>"
      }
    }
  }
}

配置教程

  1. 打开 Vault Cortex 详情页,确认这是你需要的 MCP Server(来源 官方 MCP Registry)。
  2. 按客户端选择 Trae、通义灵码、Cursor、Claude Code 或 VS Code,复制 JSON 配置或 CLI 命令。
  3. 将配置合并进 mcpServers,并把环境变量占位符替换为真实密钥。
  4. 重载窗口后,在 Agent 对话中调用该 MCP 提供的工具。

安装命令

以下安装命令与配置步骤已写入页面 HTML,搜索引擎与未启用 JavaScript 的浏览器均可直接读取。

Claude Code(本地)

  1. 确保已安装 Claude Code CLI
  2. 复制下方命令,将 <占位符> 替换为真实环境变量值后,在终端执行
  3. 若下方列出了环境变量,请对照填写
claude mcp add vault-cortex --env MCP_AUTH_TOKEN=<MCP_AUTH_TOKEN> -- docker run -i --rm ghcr.io/aliasunder/vault-cortex:0.54.8

Cursor — .cursor/mcp.json(本地)

  1. 打开项目根目录下的 .cursor/mcp.json(没有就新建)
  2. 点击「复制配置」粘贴进去;若已有其他 MCP,只合并 mcpServers 里的本条目
  3. 将 env 中的 <占位符> 替换为真实密钥(见下方「环境变量」)
  4. 保存后按 Cmd+Shift+P(Windows:Ctrl+Shift+P)→ 输入 Reload Window 并执行
{
  "mcpServers": {
    "vault-cortex": {
      "command": "docker",
      "args": [
        "run",
        "-i",
        "--rm",
        "ghcr.io/aliasunder/vault-cortex:0.54.8"
      ],
      "env": {
        "MCP_AUTH_TOKEN": "<MCP_AUTH_TOKEN>"
      }
    }
  }
}

VS Code — .vscode/mcp.json(本地)

  1. 确保 VS Code 已安装 GitHub Copilot 扩展并支持 MCP
  2. 打开项目根目录下的 .vscode/mcp.json(没有就新建)
  3. 点击「复制配置」粘贴;若已有其他 MCP,只合并 mcpServers 里的本条目
  4. 将 env 中的 <占位符> 替换为真实密钥(见下方「环境变量」)
  5. 保存后重新加载 VS Code 窗口
{
  "mcpServers": {
    "vault-cortex": {
      "command": "docker",
      "args": [
        "run",
        "-i",
        "--rm",
        "ghcr.io/aliasunder/vault-cortex:0.54.8"
      ],
      "env": {
        "MCP_AUTH_TOKEN": "<MCP_AUTH_TOKEN>"
      }
    }
  }
}

Claude Desktop — claude_desktop_config.json(本地)

  1. 打开 Claude Desktop 的 claude_desktop_config.json(路径见远程指引)
  2. 点击「复制配置」合并到 mcpServers
  3. 将 env 中的 <占位符> 替换为真实密钥
  4. 完全退出并重启 Claude Desktop
{
  "mcpServers": {
    "vault-cortex": {
      "command": "docker",
      "args": [
        "run",
        "-i",
        "--rm",
        "ghcr.io/aliasunder/vault-cortex:0.54.8"
      ],
      "env": {
        "MCP_AUTH_TOKEN": "<MCP_AUTH_TOKEN>"
      }
    }
  }
}

Trae — .trae/mcp.json(本地)

  1. 打开 Trae → 设置 → MCP,或编辑 .trae/mcp.json / 全局 mcp.json
  2. 点击「复制配置」粘贴并合并 mcpServers
  3. 将 env 中的 <占位符> 替换为真实密钥
  4. 保存后重载 Trae 窗口
{
  "mcpServers": {
    "vault-cortex": {
      "command": "docker",
      "args": [
        "run",
        "-i",
        "--rm",
        "ghcr.io/aliasunder/vault-cortex:0.54.8"
      ],
      "env": {
        "MCP_AUTH_TOKEN": "<MCP_AUTH_TOKEN>"
      }
    }
  }
}

Cherry Studio — MCP 设置(本地)

  1. 打开 Cherry Studio → 设置 → MCP 服务器 → 添加(STDIO)
  2. 也可直接导入下方 JSON:点击「复制配置」合并到 mcpServers
  3. 将 env 中的 <占位符> 替换为真实密钥,并确保本机已安装 Node.js / uv(npx、uvx)
  4. 启用服务并查看工具列表是否加载成功
{
  "mcpServers": {
    "vault-cortex": {
      "command": "docker",
      "args": [
        "run",
        "-i",
        "--rm",
        "ghcr.io/aliasunder/vault-cortex:0.54.8"
      ],
      "env": {
        "MCP_AUTH_TOKEN": "<MCP_AUTH_TOKEN>"
      }
    }
  }
}

通义灵码 — MCP 配置(本地)

  1. 通义灵码:个人设置 → MCP 服务 → 「+」→ 手工添加(STDIO)或配置文件添加
  2. 点击「复制配置」合并 mcpServers;命令/参数/环境变量与 JSON 一致
  3. 将 env 中的 <占位符> 替换为真实密钥;本机需 Node.js 18+(npx)或已安装 uv(uvx)
  4. 确认服务状态为已连接后再在智能体对话中调用
{
  "mcpServers": {
    "vault-cortex": {
      "command": "docker",
      "args": [
        "run",
        "-i",
        "--rm",
        "ghcr.io/aliasunder/vault-cortex:0.54.8"
      ],
      "env": {
        "MCP_AUTH_TOKEN": "<MCP_AUTH_TOKEN>"
      }
    }
  }
}

Windsurf — mcp_config.json(本地)

  1. 编辑 ~/.codeium/windsurf/mcp_config.json
  2. 点击「复制配置」合并 mcpServers(本地 stdio 与 Cursor 格式相同)
  3. 将 env 中的 <占位符> 替换为真实密钥后保存并刷新 Cascade
{
  "mcpServers": {
    "vault-cortex": {
      "command": "docker",
      "args": [
        "run",
        "-i",
        "--rm",
        "ghcr.io/aliasunder/vault-cortex:0.54.8"
      ],
      "env": {
        "MCP_AUTH_TOKEN": "<MCP_AUTH_TOKEN>"
      }
    }
  }
}

Cline — MCP Servers(本地)

  1. Cline 面板 → 设置 → MCP Servers
  2. 点击「复制配置」粘贴并合并
  3. 将 env 中的 <占位符> 替换为真实密钥后保存
{
  "mcpServers": {
    "vault-cortex": {
      "command": "docker",
      "args": [
        "run",
        "-i",
        "--rm",
        "ghcr.io/aliasunder/vault-cortex:0.54.8"
      ],
      "env": {
        "MCP_AUTH_TOKEN": "<MCP_AUTH_TOKEN>"
      }
    }
  }
}

WorkBuddy — .workbuddy/mcp.json(本地)

  1. 编辑 ~/.workbuddy/mcp.json(用户级)或项目目录 .workbuddy/mcp.json
  2. 也可在界面:插件 → MCP 服务器 → 配置 MCP,粘贴下方 JSON
  3. 将 env 中的 <占位符> 替换为真实密钥;Windows 下 command/脚本路径建议用绝对路径
  4. 保存并重启 WorkBuddy,确认连接器状态为绿色
{
  "mcpServers": {
    "vault-cortex": {
      "command": "docker",
      "args": [
        "run",
        "-i",
        "--rm",
        "ghcr.io/aliasunder/vault-cortex:0.54.8"
      ],
      "env": {
        "MCP_AUTH_TOKEN": "<MCP_AUTH_TOKEN>"
      }
    }
  }
}

常见报错排查与运行避坑 (Troubleshooting)FAQ

针对 Vault Cortex 在 Cursor、Claude Code 中的常见连接错误与解决办法

在 Cursor / Claude Code 中配置 Vault Cortex 提示 connection closed 或 exit code 1?

通常由本地运行时环境缺失或命令路径未被 IDE 继承引起。排查步骤: 1. 确认已安装 Node.js 18+(支持 npx)或 Python 3.10+(支持 uvx); 2. 尝试在终端运行 which npx 或 which uvx,把配置文件中的 "command" 字段改为完整绝对路径; 3. 修改 mcp.json 后,必须完全重载或重启客户端窗口。

Fix Snippet
# 终端测试命令是否存在:
which npx
node -v
提示 spawn npx ENOENT 或 command not found?

这是因为编辑器后台进程未加载完整的终端环境变量(PATH)。解决方案:在全局安装该包(如 npm install -g 包名),或在配置文件中将 command 设置为系统的实际路径(如 Windows 下的 C:\Program Files\nodejs\npx.cmd,Mac 下的 /usr/local/bin/npx)。

提示 Missing required environment variable 或 API 认证失败?

Vault Cortex 依赖环境变量(如 MCP_AUTH_TOKEN)。请在客户端配置文件的 "env" 对象中填入有效密钥,注意不要包含多余空格或未闭合的双引号。

Fix Snippet
// .cursor/mcp.json 或 claude_desktop_config.json
{
  "env": {
    "MCP_AUTH_TOKEN": "your_actual_key_here"
  }
}

免安装模拟调用 (Playground)

仿真环境

Vault Cortex 核心接口调用仿真 · 无需配置本地环境,直接预览调用参数与返回格式

沙盒就绪 (Virtual Mock)
fn: vault_cortexStandalone MCP server for Obsidian vaults — hybrid search, notes & files, memory, tasks, OAuth 2.1
请求入参 (Arguments)JSON Schema
{
  "target": "Vault Cortex",
  "action": "execute",
  "options": {
    "mode": "standard",
    "timeoutMs": 5000
  }
}
💡Agent 在规划任务时会自动生成并传递上述入参
Agent Tool Output

点击上方「模拟运行」按钮

查看该工具在 Agent 内部的返回数据格式

测试环境:AgentHub Virtual SandboxJSON-RPC 2.0

选型与决策建议(为什么选它?)

帮助你快速判断该资源是否契合当前项目,避免盲目折腾

适合什么任务?
  • PR 自动审查
  • 生成 changelog
  • 跨仓库 Issue 检索
什么时候不建议用?
  • 替代人工安全审计
  • 在无授权仓库上操作
推荐工作流搭配:查看完整场景 →

Vault Cortex + 对应场景 Prompt → 组成标准 Agent 自动化任务

MCP 实战教程:从安装到看见效果

按完整实例走一遍(含期望效果与对比验收)。装完本页资源后,用教程里的提示词核对是否真正生效。

打开教程 →

相关资源

常搭配使用

LinkedIn

v1.2.6

SkillClawHub13.5k

io.clawhub.byungkyu/linkedin-api

通过托管 OAuth 集成 LinkedIn API。分享帖子、管理资料、访问 LinkedIn 功能。当用户想在 LinkedIn 分享内容、获取资料/组织信息或与 LinkedIn 平台交互时使用。广告功能(营销活动、广告账户)需要额外的 OAuth 权限,使用前请核实已授予的权限。其他第三方应用请使用 api-gateway 技能(https://clawhub.ai/byungkyu/api-gateway)。需要网络访问和有效的 Maton API key。调用通过 `maton` CLI 配合 OAuth 登录,或在无法安装 CLI 时通过原始 HTTP 配合 Maton API key 执行。每次调用都以用户连接身份认证,仅访问该连接授权允许的资源,由服务商在每次请求时强制执行;此处记录的端点是本技能所使用的,应用的其他任何端点都需要用户指名要求才可调用。默认使用读取和列表调用,每次写入或新建连接前都与用户确认。

source

WhatsApp Business

v1.2.8

SkillClawHub24.1k

io.clawhub.byungkyu/whatsapp-business

WhatsApp Business API 集成,采用托管式 OAuth。发送消息、管理模板并处理会话。当用户需要与 WhatsApp Business 交互时使用本技能;其他第三方应用请使用 api-gateway 技能(https://clawhub.ai/byungkyu/api-gateway)。调用通过 `maton` CLI 配合 OAuth 登录执行,或在无法安装 CLI 时凭 Maton API Key 走原始 HTTP。每次调用都以用户连接身份认证,仅能访问该连接授权范围内的数据,服务端对每个请求强制执行鉴权;此处记录的端点即本技能所用端点,若需该应用的其他端点,须由用户点名提出。默认只做读取与列表调用,任何写入或新连接都需经用户确认。本文件还按使用顺序记录把 WhatsApp Business 连接变成自动化的三个构件:连接(第一步)、通过 Maton SDK 执行 WhatsApp Business 操作的托管函数,以及……(原文截断)

source

Salesforce

v1.2.7

SkillClawHub20.1k

io.clawhub.byungkyu/salesforce-api

Salesforce CRM API 集成,采用托管式 OAuth。仅在需要管理 Salesforce CRM 时安装。请以可用的最小权限连接,破坏性或批量操作优先使用沙箱组织,每次请求前核对目标连接 ID,并及时吊销未使用的连接。本集成可能修改 CRM 记录——仅在核对确切的 sObject、记录 ID 及影响后,再批准具体写操作。其他第三方应用请使用 api-gateway 技能(https://clawhub.ai/byungkyu/api-gateway)。调用通过 `maton` CLI 配合 OAuth 登录执行,或在无法安装 CLI 时凭 Maton API Key 走原始 HTTP。每次调用都以用户连接身份认证,仅能访问该连接授权范围内的数据,服务端对每个请求强制执行鉴权;此处记录的端点即本技能所用端点,若需该应用的其他端点,须由用户点名提出。默认只做读取与列表调用,任何写……(原文截断)

source

继续逛 AgentHub

大多数人安装前还会对比同类工具或看场景方案——下面这些能帮你少走弯路。

收录徽章:把 AgentHub 挂到你的官网

复制下面任意一段代码到项目主页、官网或 GitHub README。徽章是 SVG 热链,无需上传文件,链接指向本页,访客可由此直接找到安装方式。

预览AgentHub 已收录:Vault Cortex
HTML
<a href="https://myagenthub.cn/p/io.github.aliasunder/vault-cortex" title="AgentHub 已收录:Vault Cortex" target="_blank" rel="noopener">
  <img src="https://myagenthub.cn/badge/io.github.aliasunder/vault-cortex" alt="AgentHub 已收录:Vault Cortex" height="20" style="border:0"/>
</a>
Markdown(GitHub README)
[![AgentHub 已收录:Vault Cortex](https://myagenthub.cn/badge/io.github.aliasunder/vault-cortex)](https://myagenthub.cn/p/io.github.aliasunder/vault-cortex)

徽章由 /badge/<资源ID> 动态生成,名称与收录状态变化后自动更新;请保留链接指向,它是收录来源的判定依据。

统一 Manifest

{
  "id": "io.github.aliasunder/vault-cortex",
  "type": "mcp-server",
  "version": "0.54.8",
  "displayName": "Vault Cortex",
  "description": "Standalone MCP server for Obsidian vaults — hybrid search, notes & files, memory, tasks, OAuth 2.1",
  "repository": {
    "url": "https://github.com/aliasunder/vault-cortex",
    "source": "github"
  },
  "homepage": "https://github.com/aliasunder/vault-cortex",
  "distribution": {
    "packages": [
      {
        "registryType": "oci",
        "identifier": "ghcr.io/aliasunder/vault-cortex:0.54.8",
        "runtimeHint": "docker",
        "transport": "streamable-http",
        "environmentVariables": [
          {
            "name": "MCP_AUTH_TOKEN",
            "description": "Bearer token for MCP client authentication. Must match the Authorization header sent by clients. Generate with: openssl rand -hex 32",
            "isRequired": true,
            "isSecret": true
          },
          {
            "name": "PUBLIC_URL",
            "description": "Public URL clients use to reach this server. Used as the OAuth issuer URL in discovery metadata. Override when exposing the server outside localhost or on a non-default port."
          },
          {
            "name": "EMBEDDING_ENABLED",
            "description": "Enable or disable the embedding pipeline. When false, no ONNX model is downloaded, no vector tables are created, and search uses FTS5 only."
          },
          {
            "name": "RERANK_MODE",
            "description": "Cross-encoder reranking mode: blended (position-aware score blending after RRF fusion) or none (skip reranking). Only takes effect when EMBEDDING_ENABLED is true."
          },
          {
            "name": "WINDOWS_MODE",
            "description": "Windows bind-mount mode: enables filesystem polling for the file watcher and rename-based moves across the Docker Desktop/WSL2 bridge. Set to true when the vault lives on a Windows drive."
          },
          {
            "name": "MEMORY_ENABLED",
            "description": "Enable or disable the structured memory layer. When false, memory tools are hidden, bootstrap is skipped, and server metadata omits memory references."
          },
          {
            "name": "FILE_TOOLS_ENABLED",
            "description": "Enable or disable file tools (vault_read_file, vault_list_files). When false, file tools are hidden and server metadata omits file tool references."
          },
          {
            "name": "READONLY_MODE",
            "description": "Run the server read-only: every vault-writing tool is hidden, the memory folder is not auto-created, and server metadata omits write references."
          },
          {
            "name": "DISABLED_TOOLS",
            "description": "Hide individual tools by name, comma-separated. Subtractive only — it cannot re-enable a tool another setting hides; an unknown tool name stops the server at startup."
          },
          {
            "name": "MEMORY_DIR",
            "description": "Vault folder for structured memory files (About Me-style notes). Memory tools are hidden when MEMORY_ENABLED is false, but this value still feeds the defaults for PROTECTED_PATHS and ORPHAN_EXCLUDE_FOLDERS."
          },
          {
            "name": "DAILY_NOTES_FOLDER",
            "description": "Vault folder for daily notes. Overrides the folder configured in Obsidian's daily-notes plugin. When unset, read from the vault's .obsidian/daily-notes.json, falling back to \"Daily Notes\"."
          },
          {
            "name": "DAILY_NOTES_FORMAT",
            "description": "Filename date format for daily notes (Moment.js tokens). Overrides the format configured in Obsidian's daily-notes plugin. When unset, read from the vault's .obsidian/daily-notes.json, falling back to \"YYYY-MM-DD\"."
          },
          {
            "name": "TRUST_PROXY_HOPS",
            "description": "Number of trusted reverse-proxy hops used to derive the client IP from X-Forwarded-For for OAuth rate limiting and request logs. With 0, injected forwarding headers are ignored."
          },
          {
            "name": "TRUST_FORWARDED_HOPS",
            "description": "How many entries from the end of the RFC 7239 Forwarded header's for= list to count to reach the client IP for OAuth rate limiting and request logs. 0 ignores the header; 1 when the proxy in front writes it (e.g. AWS API Gateway); 2 when a CDN fronts that proxy and is the only way to reach it."
          },
          {
            "name": "TZ",
            "description": "IANA timezone for timestamps and daily note resolution."
          },
          {
            "name": "LOG_LEVEL",
            "description": "Logging verbosity."
          },
          {
            "name": "LOG_DIR",
            "description": "Directory for log files that survive container re-creation. The container's own log is always written but discarded when the container is recreated; date-stamped files under LOG_DIR persist on the data volume. Default: /data/logs (remote image), $STORAGE_ROOT/data/logs (single-volume mode), none (local image). none keeps only the container log."
          },
          {
            "name": "LOG_RETENTION_DAYS",
            "description": "Days to keep log files before automatic cleanup on startup; only applies when LOG_DIR is a path."
          },
          {
            "name": "PROTECTED_PATHS",
            "description": "Comma-separated vault folder names blocked from vault_delete_note and vault_move_note. Default: MEMORY_DIR plus the daily notes folder, read from DAILY_NOTES_FOLDER or .obsidian/daily-notes.json (default Daily Notes). When set, overrides the default entirely."
          },
          {
            "name": "ORPHAN_EXCLUDE_FOLDERS",
            "description": "Comma-separated vault folder names excluded from vault_find_orphans. Default: DAILY_NOTES_FOLDER (else \"Daily Notes\"), \"Templates\", MEMORY_DIR."
          },
          {
            "name": "SERVICE_DOCUMENTATION_URL",
            "description": "Override the OAuth service documentation URL exposed via discovery metadata."
          },
          {
            "name": "MAX_FILE_BYTES",
            "description": "Largest file vault_read_file will read, in bytes. Reading a larger file returns an error instead of content."
          },
          {
            "name": "MAX_IMAGE_OUTPUT_BYTES",
            "description": "Byte budget for images returned by vault_read_file, in binary bytes before base64 encoding. Images exceeding the budget are downscaled/recompressed server-side to fit; raise for clients that accept larger tool responses."
          },
          {
            "name": "MAX_PDF_RENDER_PAGES",
            "description": "Maximum PDF pages to render as images when raw: true is set on vault_read_file. The per-page byte budget is MAX_IMAGE_OUTPUT_BYTES divided evenly across the rendered pages."
          }
        ]
      }
    ],
    "remotes": []
  },
  "dependencies": [],
  "installTargets": [
    "claude-code",
    "claude-desktop",
    "cursor",
    "vscode",
    "trae",
    "cherry-studio",
    "lingma",
    "windsurf",
    "cline",
    "workbuddy"
  ],
  "keywords": [],
  "provenance": {
    "origin": "official-mcp-registry",
    "originalId": "io.github.aliasunder/vault-cortex",
    "originalUrl": "https://registry.modelcontextprotocol.io/v0.1/servers/io.github.aliasunder%2Fvault-cortex/versions/latest",
    "isOfficial": true,
    "status": "active"
  }
}