Filesystem MCP: read, write and search files in allowed folders
One of the official MCP reference servers. Agents read, edit, move and search files only inside folders you allow; every tool carries safety hints.
Project and installation docs
View projecthttps://github.com/modelcontextprotocol/servers
Chat clients like Claude Desktop can’t touch your disk out of the box. If you want one to tidy a folder or fix a few config files, it needs a controlled way in. Filesystem MCP is the reference implementation in the official MCP servers repo: you list the directories it may use, and the agent can read, write, move and search files only inside them. Anything outside is refused.
What it does
- Reading:
read_text_filecan return just the first or last N lines,read_media_filereturns images and audio with their MIME type, andread_multiple_filesbatches several reads. - Diff-based edits:
edit_filereplaces text fragments and returns a git-style diff;dryRunpreviews the change before it’s written. - Directory work: create and list directories (optionally sorted by size), get a JSON
directory_tree, glob-search withsearch_files, and rename or move withmove_file. - Live access control: with clients that support MCP Roots, the allowed folders can change at runtime without a restart, and
list_allowed_directoriesshows the current scope.
Who it’s for
- Claude Desktop users who want help sorting downloads, batch-renaming files or summarizing a folder of notes.
- Developers who need to give a model a clearly bounded working directory in a client with no built-in file tools.
Setup
Needs Node.js. Allowed directories go at the end of the args:
{
"mcpServers": {
"filesystem": {
"command": "npx",
"args": [
"-y",
"@modelcontextprotocol/server-filesystem",
"/Users/username/Desktop",
"/path/to/other/allowed/dir"
]
}
}
}
There’s also an mcp/filesystem Docker image; mount folders under /projects and add ro for read-only.
Our take
Plenty of servers do file access, and this is the baseline: officially maintained, with clear access control and MCP tool annotations (readOnlyHint, destructiveHint and so on) that let capable clients ask before a write. It lives in the MCP servers monorepo, which had about 91k stars as of 2026-10-06. Two caveats. write_file overwrites without asking and move_file removes the source, so granting your whole home folder hands all of that over; scope it to a project folder. And Claude Code, Cursor and similar coding tools already read and write files, so this server matters most for chat clients that can’t. The repo is moving from MIT to Apache-2.0 licensing.