
@modelcontextprotocol/server-filesystem
Officialby modelcontextprotocol
Filesystem MCP Server
Node.js server implementing Model Context Protocol (MCP) for filesystem operations.
Published on npm as @modelcontextprotocol/server-filesystem.
Features
- Read/write files
- Create/list/delete directories
- Move files/directories
- Search files
- Get file metadata
- Dynamic directory access control via Roots
Directory Access Control
The server uses a flexible directory access control system. Directories can be specified via command-line arguments or dynamically via Roots.
Method 1: Command-line Arguments
Specify Allowed directories when starting the server:
mcp-server-filesystem /path/to/dir1 /path/to/dir2
Method 2: MCP Roots (Recommended)
MCP clients that support Roots can dynamically update the Allowed directories.
Roots notified by Client to Server, completely replace any server-side Allowed directories when provided.
Important: If server starts without command-line arguments AND client doesn't support roots protocol (or provides empty roots), the server will throw an error during initialization.
This is the recommended method, as this enables runtime directory updates via roots/list_changed notifications without server restart, providing a more flexible and modern integration experience.
How It Works
The server's directory access control follows this flow:
-
Server Startup
- Server starts with directories from command-line arguments (if provided)
- If no arguments provided, server starts with empty allowed directories
-
Client Connection & Initialization
- Client connects and sends
initializerequest with capabilities - Server checks if client supports roots protocol (
capabilities.roots)
- Client connects and sends
-
Roots Protocol Handling (if client supports roots)
- On initialization: Server requests roots from client via
roots/list - Client responds with its configured roots
- Server replaces ALL allowed directories with client's roots
- On runtime updates: Client can send
notifications/roots/list_changed - Server requests updated roots and replaces allowed directories again
- On initialization: Server requests roots from client via
-
Fallback Behavior (if client doesn't support roots)
- Server continues using command-line directories only
- No dynamic updates possible
-
Access Control
- All filesystem operations are restricted to allowed directories
- Use
list_allowed_directoriestool to see current directories - Server requires at least ONE allowed directory to operate
Note: The server will only allow operations within directories specified either via args or via Roots.
API
Tools
-
read_text_file
- Read complete contents of a file as text
- Inputs:
path(string)head(number, optional): First N linestail(number, optional): Last N lines
- Always treats the file as UTF-8 text regardless of extension
- Cannot specify both
headandtailsimultaneously
-
read_media_file
- Read a file and return it as a base64-encoded content block with its MIME type
- Inputs:
path(string)
- Streams the file and returns base64 data with the corresponding MIME type. Image and
audio files are returned as
image/audiocontent; any other file type is returned as an embeddedresource(a valid MCP content block for arbitrary binary data)
-
read_multiple_files
- Read multiple files simultaneously
- Input:
paths(string[]) - Failed reads won't stop the entire operation
-
write_file
- Create new file or overwrite existing (exercise caution with this)
- Inputs:
path(string): File locationcontent(string): File content
-
edit_file
- Make selective edits using
Related servers

mcp-server-git
Officialby modelcontextprotocol
A Model Context Protocol server providing tools to read, search, and manipulate Git repositories programmatically via LLMs

@modelcontextprotocol/server-everything
Officialby modelcontextprotocol
MCP server that exercises all the features of the MCP protocol

mcp-server-fetch
Officialby modelcontextprotocol
A Model Context Protocol server providing tools to fetch and convert web content for usage by LLMs

@modelcontextprotocol/server-memory
Officialby modelcontextprotocol
MCP server for enabling memory for Claude through a knowledge graph