
Company News
AWS Security Hub Adds Socket for Supply Chain Security
Socket is now in the AWS Security Hub Extended plan. Adopt it through AWS, apply committed spend, and block malicious open source packages.
@mdedit/mcp-server
Advanced tools
Model Context Protocol server for live mdedit.ai document collaboration.
Use mdedit.ai Markdown Documents from Claude Code and other Model Context
Protocol clients. The server runs locally over stdio and authenticates with a
scoped API key. It can also share an OS-keychain OAuth profile created by
mdedit auth login in environments where the release-gated OAuth endpoint has
been enabled.
The generally available setup uses a scoped API key:
claude mcp add --transport stdio \
--env MDEDIT_API_KEY=mdh_your_key \
mdedit -- npx -y @mdedit/mcp-server
Use --scope user before mdedit if you want the server available in every project. Verify the connection with claude mcp get mdedit or /mcp inside Claude Code.
When OAuth is enabled for your environment, mdedit auth login may be used
before the same claude mcp add command without the API-key environment value.
Reviewer agents normally use articles:read,reviews:write. Editing agents need articles:write. Accepting a suggestion also requires articles:write because it changes document content.
Agents that publish public links need publishing:write; publication status only needs
publishing:read.
list_articlescreate_articleread_articlepublish_articleget_publish_statusunpublish_articleedit_articleadd_commentadd_suggestionreply_to_threadresolve_threadlist_review_threadsget_presencepublish_article and unpublish_article require explicit confirmation fields in
their tool inputs. A published document is readable by anyone with its mded.it link.
For a new link, publish_article defaults to mode: "live". Later durable edits
automatically update a Live link at the same stable URL. Pass mode: "snapshot" for
a frozen artifact. When updating an existing link, omit mode to preserve the stored
mode, or pass "live" / "snapshot" to switch deliberately.
publish_article and get_publish_status return the stored mode, source
revision/version, last successful sync time, and synchronization status. A failed Live
sync leaves the last good public content and URL available; inspect syncStatus and
syncError before claiming the public page is current.
Local stdio keeps one live collaborative session open across tool calls. The hosted HTTP adapter uses operation-scoped sessions and does not depend on process-local state or load-balancer stickiness. Non-collaborative documents use the REST fallback and report an empty live-presence list.
MDEDIT_API_KEY - optional scoped API key override; takes precedence over OAuthMDEDIT_PROFILE - optional shared OAuth profile name; defaults to the active CLI profileMDEDIT_API_URL — optional API host overrideMDEDIT_AGENT_NAME — optional awareness display hint; defaults to mdedit-mcpMDEDIT_MCP_IDLE_TIMEOUT_MS — optional positive idle timeout in millisecondsNever commit API keys to a repository or place them in shared project MCP configuration.
The repository includes a manual Claude Code smoke test. It creates a uniquely named fixture article in the selected test workspace, enables collaboration, exercises list/read/comment/list/resolve/presence through MCP, verifies the resolved comment through the review API, and deletes the fixture.
MDEDIT_API_KEY=mdh_launch_gate_key \
MDEDIT_SMOKE_WORKSPACE_ID=workspace_id \
yarn workspace @mdedit/mcp-server smoke:claude
Use a test workspace and a key with articles:write,reviews:write. The key owner must have access to the workspace and the collaboration entitlement.
FAQs
Model Context Protocol server for live mdedit.ai document collaboration.
The npm package @mdedit/mcp-server receives a total of 690 weekly downloads. As such, @mdedit/mcp-server popularity was classified as not popular.
We found that @mdedit/mcp-server demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Company News
Socket is now in the AWS Security Hub Extended plan. Adopt it through AWS, apply committed spend, and block malicious open source packages.

Research
/Security News
Popular npm packages keyv and cacheable compromised.

Security News
A misconfiguration gave three Anthropic models internet access, and one, believing it was in a simulation, shipped a credential-stealing package to PyPI.