Filesystem MCP server
Last verified: 2026-09
Read and write files inside a folder you choose.
Official reference Files & knowledge No API key Claude Desktop, Cursor, Windsurf, Claude Code, VS Code
What it does
The first MCP server most people install. The model can list, read, write, move, and search files inside directories you pass as arguments — nothing outside those roots. That jail is the whole product: useful for a repo or a notes folder, dangerous if the root is your home directory.
It sits in Files & knowledge: These servers put the model inside a folder, a notes vault, or a Drive.
Good for
- Let Cursor edit files in one repo without opening the rest of the disk.
- Dump a notes folder in and ask for a weekly summary as a new markdown file.
- Search a project for a symbol, then apply a targeted edit_file patch.
- Read a screenshot or diagram in the allowed folder via read_media_file.
Tools
- read_file / read_text_file — Read a file as text.
- read_media_file — Read an image or audio file so the model can see it.
- write_file — Create or overwrite a file.
- edit_file — Apply a targeted text edit.
- create_directory / list_directory / directory_tree — Walk the allowed tree.
- move_file / search_files / get_file_info — Rename, find, and inspect.
- list_allowed_directories — Show the roots you configured.
Config (Claude Desktop / Cursor / Windsurf)
Paste the JSON below. Same mcpServers shape. Replace placeholder paths and secrets.
Windows paths look like C:\\Users\\you\\project, not /path/to.
Host-side steps →
Claude Desktop
| OS | Config file |
|---|---|
| macOS | ~/Library/Application Support/Claude/claude_desktop_config.json |
| Windows | %APPDATA%\Claude\claude_desktop_config.json
(usually C:\Users\<you>\AppData\Roaming\Claude\) |
| Linux | ~/.config/Claude/claude_desktop_config.json |
Cursor
| Scope | macOS / Linux | Windows |
|---|---|---|
| This project | .cursor/mcp.json in the repo root | |
| This user | ~/.cursor/mcp.json |
%USERPROFILE%\.cursor\mcp.json |
Windsurf
| OS | Config file |
|---|---|
| macOS / Linux | ~/.codeium/windsurf/mcp_config.json |
| Windows | %USERPROFILE%\.codeium\windsurf\mcp_config.json |
{
"mcpServers": {
"filesystem": {
"command": "npx",
"args": [
"-y",
"@modelcontextprotocol/server-filesystem",
"/path/to/allowed"
]
}
}
}
Windsurf remote MCP: use serverUrl instead of url if the block below is HTTP.
One-liner: npx -y @modelcontextprotocol/server-filesystem /path/to/folder
Secrets it wants: none — pass the allowed directory as an argument
How to get started
- Pick one folder the model is allowed to touch — a project, not $HOME.
- Paste the JSON below into Claude Desktop (claude_desktop_config.json) or Cursor (mcp.json).
- Restart the host and ask it to list the allowed directories.
- If you only need reads, point it at a copy of the tree or a git worktree.
Access risk
Write access is on by default. A confused or prompt-injected model can edit or delete anything under the allowed roots. Treat those roots as untrusted input.
When to skip it
Skip it if you only need git history (use Git) or cloud files (use Google Drive / Obsidian). Do not point it at a folder that contains .env, SSH keys, or password managers.
Instead: Git, Google Drive, Obsidian.
Vs alternatives
| Server | Official? | Needs a secret? | Best for |
|---|---|---|---|
| Filesystem | Yes | No | Read and write files inside a folder you choose. |
| Git | Yes | No | Read a local git repo: log, diff, status. |
| Google Drive | Yes | Yes | List and read files from a Google Drive account. |
| Obsidian | No | Yes | Read and search a local Obsidian vault. |
More in Files & knowledge
FAQ
Can Filesystem see files outside the folder I passed?
No. Roots are the arguments after the package name. A parent of .env still exposes .env — pick a narrower folder or a worktree.
Is this better than opening the repo in the editor?
The editor already has the files. Use Filesystem when the chat host is Claude Desktop or another app that does not have the workspace, or when you want a second, jailed tree.
Can I make it read-only?
The official server writes by default. Point it at a copy, or use Git if you only need history.
Why not point it at $HOME?
Then SSH keys, password-manager exports, and every .env are in scope. One injected prompt can read or delete them.