Field-by-field comparison
Compare the evidence before choosing an MCP.
Each signal stays separate, missing facts remain visible, and the column order follows your selection.
| Evidence field | MCPVault for ObsidianMCP100 Selected | Codebase MemoryMCP100 Selected |
|---|---|---|
| Task fit | ||
| Best for |
|
|
| Not ideal for |
|
|
| Avoid when |
|
|
| Provenance | ||
| Provenance details | Community implementation BitBonsai · Publisher source ↗ | Community implementation io.github.DeusData · Publisher source ↗ |
| Maintenance | ||
| Maintenance details | Repo: Aug 13, 2026 Package: Aug 9, 2026 | Repo: Aug 14, 2026 Package: Aug 14, 2026 |
| Popularity evidence | ||
| GitHub stars | 1,613 GitHub stars · checked 2026-08-14T18:46:26.000Z | 38,935 GitHub stars · checked 2026-08-14T18:46:26.000Z |
| 30-day package downloads | 64,139 30-day package downloads · checked 2026-08-14T18:46:26.000Z | 28,015 30-day package downloads · checked 2026-08-14T18:46:26.000Z |
| External adoption evidence |
|
|
| Client coverage | ||
| Client coverage details | Claude Code✓ Local stdio Claude Desktop✓ Local stdio Codex✓ Local stdio VS Code✓ Local stdio Cursor✓ Local stdio OpenCode✓ Local stdio | Claude Code✓ Local stdio Claude Desktop✓ Local stdio Codex✓ Local stdio VS Code✓ Local stdio Cursor✓ Local stdio OpenCode✓ Local stdio |
| Client coverage note | Local stdio runs on your computer. Streamable HTTP connects to a remotely hosted MCP server. | |
| Access and data | ||
| Authentication | None at the local stdio layer. | No authentication or API key is documented for local stdio. CBM_ALLOWED_ROOT is an optional filesystem containment control; no containment is imposed when it is unset. |
| Cost | MCPVault is MIT licensed and free to run locally. MCP-host, model, backup, and storage costs remain. | The MIT-licensed native software lists no service fee. Local storage and package-manager costs are separate. |
| Permissions | The server has filesystem read and write access within the supplied vault root, including note creation, overwrite or patch, frontmatter changes, moves, tags, and deletion. Operating-system permissions and the configured vault path are the primary boundary. | Indexes repositories, queries code and graphs, performs architecture and impact analysis, manages ADRs and watchers, deletes projects, and writes agent configuration, instruction, Skill, and hook files. |
| Data handling | Vault content and metadata are read locally and returned to the MCP client and model. Changes are written directly to local files. MCPVault states that it does not receive, store, or transmit vault data, while the selected AI provider still processes content sent by the client. | The publisher says processing is local and code does not leave the machine. Indexes, embeddings, memories, SQLite data, and logs persist under the local CBM cache directory. |
| Limitations | ||
| Tradeoffs |
|
|
| Risk context | A selected vault can contain a large body of private knowledge, and write tools can overwrite, move, or delete it. Use a dedicated vault, reliable backups or version control, an absolute path, a reviewed package version, and explicit approval for writes. | Indexing can capture sensitive files, while persistent graph data and installer/configuration writes expand local exposure. Set CBM_ALLOWED_ROOT, protect the cache, and use explicit project paths. |
| Evidence date | ||
| Editorial review | 2026-07-24 | 2026-08-11 |
| Candidate evidence | 2026-08-14T18:46:26.000Z | 2026-08-14T18:46:26.000Z |
Popularity, maintenance, fit, permissions, and client support are independent evidence fields.
Read the evidence method →