Memory#File management

Filesystem MCP: read, write and search files in allowed folders

One of the official MCP reference servers. Agents read, edit, move and search files only inside folders you allow; every tool carries safety hints.

Project and installation docs

View project

https://github.com/modelcontextprotocol/servers

Chat clients like Claude Desktop can’t touch your disk out of the box. If you want one to tidy a folder or fix a few config files, it needs a controlled way in. Filesystem MCP is the reference implementation in the official MCP servers repo: you list the directories it may use, and the agent can read, write, move and search files only inside them. Anything outside is refused.

What it does

  • Reading: read_text_file can return just the first or last N lines, read_media_file returns images and audio with their MIME type, and read_multiple_files batches several reads.
  • Diff-based edits: edit_file replaces text fragments and returns a git-style diff; dryRun previews the change before it’s written.
  • Directory work: create and list directories (optionally sorted by size), get a JSON directory_tree, glob-search with search_files, and rename or move with move_file.
  • Live access control: with clients that support MCP Roots, the allowed folders can change at runtime without a restart, and list_allowed_directories shows the current scope.

Who it’s for

  • Claude Desktop users who want help sorting downloads, batch-renaming files or summarizing a folder of notes.
  • Developers who need to give a model a clearly bounded working directory in a client with no built-in file tools.

Setup

Needs Node.js. Allowed directories go at the end of the args:

{
  "mcpServers": {
    "filesystem": {
      "command": "npx",
      "args": [
        "-y",
        "@modelcontextprotocol/server-filesystem",
        "/Users/username/Desktop",
        "/path/to/other/allowed/dir"
      ]
    }
  }
}

There’s also an mcp/filesystem Docker image; mount folders under /projects and add ro for read-only.

Our take

Plenty of servers do file access, and this is the baseline: officially maintained, with clear access control and MCP tool annotations (readOnlyHint, destructiveHint and so on) that let capable clients ask before a write. It lives in the MCP servers monorepo, which had about 91k stars as of 2026-10-06. Two caveats. write_file overwrites without asking and move_file removes the source, so granting your whole home folder hands all of that over; scope it to a project folder. And Claude Code, Cursor and similar coding tools already read and write files, so this server matters most for chat clients that can’t. The repo is moving from MIT to Apache-2.0 licensing.