Suggest a server AI tools directory →

Filesystem MCP server

Last verified: 2026-09

Read and write files inside a folder you choose.

Official reference Files & knowledge No API key Claude Desktop, Cursor, Windsurf, Claude Code, VS Code

What it does

The first MCP server most people install. The model can list, read, write, move, and search files inside directories you pass as arguments — nothing outside those roots. That jail is the whole product: useful for a repo or a notes folder, dangerous if the root is your home directory.

It sits in Files & knowledge: These servers put the model inside a folder, a notes vault, or a Drive.

Good for

  • Let Cursor edit files in one repo without opening the rest of the disk.
  • Dump a notes folder in and ask for a weekly summary as a new markdown file.
  • Search a project for a symbol, then apply a targeted edit_file patch.
  • Read a screenshot or diagram in the allowed folder via read_media_file.

Tools

  • read_file / read_text_file — Read a file as text.
  • read_media_file — Read an image or audio file so the model can see it.
  • write_file — Create or overwrite a file.
  • edit_file — Apply a targeted text edit.
  • create_directory / list_directory / directory_tree — Walk the allowed tree.
  • move_file / search_files / get_file_info — Rename, find, and inspect.
  • list_allowed_directories — Show the roots you configured.

Config (Claude Desktop / Cursor / Windsurf)

Paste the JSON below. Same mcpServers shape. Replace placeholder paths and secrets. Windows paths look like C:\\Users\\you\\project, not /path/to. Host-side steps →

Claude Desktop

OSConfig file
macOS~/Library/Application Support/Claude/claude_desktop_config.json
Windows%APPDATA%\Claude\claude_desktop_config.json (usually C:\Users\<you>\AppData\Roaming\Claude\)
Linux~/.config/Claude/claude_desktop_config.json

Cursor

ScopemacOS / LinuxWindows
This project.cursor/mcp.json in the repo root
This user~/.cursor/mcp.json %USERPROFILE%\.cursor\mcp.json

Windsurf

OSConfig file
macOS / Linux~/.codeium/windsurf/mcp_config.json
Windows%USERPROFILE%\.codeium\windsurf\mcp_config.json
{
  "mcpServers": {
    "filesystem": {
      "command": "npx",
      "args": [
        "-y",
        "@modelcontextprotocol/server-filesystem",
        "/path/to/allowed"
      ]
    }
  }
}

Windsurf remote MCP: use serverUrl instead of url if the block below is HTTP.

One-liner: npx -y @modelcontextprotocol/server-filesystem /path/to/folder

Secrets it wants: none — pass the allowed directory as an argument

Source repo →

How to get started

  1. Pick one folder the model is allowed to touch — a project, not $HOME.
  2. Paste the JSON below into Claude Desktop (claude_desktop_config.json) or Cursor (mcp.json).
  3. Restart the host and ask it to list the allowed directories.
  4. If you only need reads, point it at a copy of the tree or a git worktree.

Access risk

Write access is on by default. A confused or prompt-injected model can edit or delete anything under the allowed roots. Treat those roots as untrusted input.

When to skip it

Skip it if you only need git history (use Git) or cloud files (use Google Drive / Obsidian). Do not point it at a folder that contains .env, SSH keys, or password managers.

Instead: Git, Google Drive, Obsidian.

Vs alternatives

ServerOfficial?Needs a secret?Best for
FilesystemYesNoRead and write files inside a folder you choose.
GitYesNoRead a local git repo: log, diff, status.
Google DriveYesYesList and read files from a Google Drive account.
ObsidianNoYesRead and search a local Obsidian vault.

More in Files & knowledge

All 6 in this category →

FAQ

Can Filesystem see files outside the folder I passed?

No. Roots are the arguments after the package name. A parent of .env still exposes .env — pick a narrower folder or a worktree.

Is this better than opening the repo in the editor?

The editor already has the files. Use Filesystem when the chat host is Claude Desktop or another app that does not have the workspace, or when you want a second, jailed tree.

Can I make it read-only?

The official server writes by default. Point it at a copy, or use Git if you only need history.

Why not point it at $HOME?

Then SSH keys, password-manager exports, and every .env are in scope. One injected prompt can read or delete them.