write_note and edit_note with connected write storage and notes.write in authenticated mode. Open local mode skips the permission check. Inspect tools/list before calling conditional tools; valid read-only tokens connect without write tools. Neither server has a folders tool. Folders are HTTP GET /v1/folders. Create credentials through Access tokens.
A cloud or desktop session binds vault_id and overwrites a caller-supplied value. Pass the arguments below. Do not rely on naming a different vault.
Config: MCP local (stdio) and MCP cloud (POST /mcp).
get_attachment on the cloud returns a presigned URL. On local MCP the URL is a file path. query_notes is the structured frontmatter query, the same contract as POST /v1/query.
filter on search_notes, grep_notes, list_notes, and list_tags is the same AIP-160 string as GET /v1/notes?filter=. See API overview.
min_seq is a write’s committed_seq. The tool waits, bounded, for the index to reach it, or answers with coverage.stale.
write_note and edit_note follow write policy and budget. Personal-token writes use actor pat:<prefix>, regardless of the supplied agent_id. Reuse idempotency_key only for an identical retry.
A queued MCP result contains status and pending_id; it does not include the HTTP slug. An applied MCP result includes note/version/hash and sequence fields, but no embedded HTTP note. Inspect status first.
status: "queued" means the note has not changed. Record and report pending_id. In authenticated mode, polling GET /v1/writes/{id} also requires notes.review; a write-only token must hand the ID to a reviewer. Approve and reject stay on HTTP. The API accepts review-scoped personal tokens, but agents must leave approval to a human and must not request review permission merely to finish a proposal.