Field-by-field comparison
Compare the evidence before choosing an MCP.
Each signal stays separate, missing facts remain visible, and the column order follows your selection.
| Evidence field | Citra (PDF Reader MCP)Watchlist candidate | MCPVault for ObsidianMCP100 Selected |
|---|---|---|
| Task fit | ||
| Best for |
|
|
| Not ideal for |
|
|
| Avoid when |
|
|
| Provenance | ||
| Provenance details | First-party MCP SylphxAI · Publisher source ↗ | Community implementation BitBonsai · Publisher source ↗ |
| Maintenance | ||
| Maintenance details | Repo: Aug 8, 2026 Package: Aug 7, 2026 | Repo: Aug 13, 2026 Package: Aug 9, 2026 |
| Popularity evidence | ||
| GitHub stars | 891 GitHub stars · checked 2026-08-14T18:46:26.000Z | 1,613 GitHub stars · checked 2026-08-14T18:46:26.000Z |
| 30-day package downloads | No reliable download data | 64,139 30-day package downloads · checked 2026-08-14T18:46:26.000Z |
| External adoption evidence |
|
|
| Client coverage | ||
| Client coverage details | Claude Code✓ Local stdio Claude Desktop✓ Local stdio Codex✓ Local stdio VS Code✓ Local stdio Cursor✓ Local stdio OpenCode✓ Local stdio | Claude Code✓ Local stdio Claude Desktop✓ Local stdio Codex✓ Local stdio VS Code✓ Local stdio Cursor✓ Local stdio OpenCode✓ Local stdio |
| Client coverage note | Local stdio runs on your computer. Streamable HTTP connects to a remotely hosted MCP server. | |
| Access and data | ||
| Authentication | Default stdio needs no service credential. Optional HTTP mode supports MCP_API_KEY and binds loopback by default; configured HTTP or OpenAI-compatible visual providers may use their own headers or API key, while local command providers do not inherently require one. | None at the local stdio layer. |
| Cost | The MIT-licensed local server has no documented usage fee. Pricing for any operator-selected external OCR, visual, network, or client provider is outside the Citra documentation and remains provider-specific. | MCPVault is MIT licensed and free to run locally. MCP-host, model, backup, and storage costs remain. |
| Permissions | The tools read PDF paths and URLs available to the process. Directory allowlists can restrict local reach; URL handling blocks private addresses by default unless the operator overrides it. | The server has filesystem read and write access within the supplied vault root, including note creation, overwrite or patch, frontmatter changes, moves, tags, and deletion. Operating-system permissions and the configured vault path are the primary boundary. |
| Data handling | Default stdio processing is local. Optional OCR or visual providers may receive rendered content according to their configuration, and URL inputs are fetched from their source. | Vault content and metadata are read locally and returned to the MCP client and model. Changes are written directly to local files. MCPVault states that it does not receive, store, or transmit vault data, while the selected AI provider still processes content sent by the client. |
| Limitations | ||
| Tradeoffs |
|
|
| Risk context | Use stdio, configure explicit allowed PDF directories, retain private-IP URL blocking, require an API key before any non-loopback HTTP deployment, and review native artifacts before installation. | A selected vault can contain a large body of private knowledge, and write tools can overwrite, move, or delete it. Use a dedicated vault, reliable backups or version control, an absolute path, a reviewed package version, and explicit approval for writes. |
| Evidence date | ||
| Editorial review | 2026-08-14 | 2026-07-24 |
| Candidate evidence | 2026-08-14T18:46:26.000Z | 2026-08-14T18:46:26.000Z |
Popularity, maintenance, fit, permissions, and client support are independent evidence fields.
Read the evidence method →