
Research
/Security News
Popular npm Packages in the keyv and Cacheable Namespaces Compromised in Active Supply Chain Attack
Popular npm packages keyv and cacheable compromised.
obsideo-mcp
Advanced tools
MCP server for Obsideo: encrypted, S3-compatible storage with continuous cryptographic possession proofs. Self-serve signup (12 GB free, no card), put/get/ls/rm/usage tools. Runs on YOUR machine; credentials and keys never leave it.
Give any MCP-capable agent (Claude Desktop, Claude Code, Cursor, Cline, ...) durable, encrypted, cryptographically verified storage. Self-serve signup from inside the conversation: 12 GB free, no card, no CAPTCHA, no expiry.
Obsideo is S3-compatible object storage where every stored object is replicated to 3 providers and challenged with chunk-level merkle proofs on a continuous cycle; providers are paid only for proofs they pass. Paid tier: $15/TB-month, egress included.
~/.obsideo/ and are sent nowhere except the endpoints they authenticate
against.~/.obsideo/signing.pem private. Re-running signup rotates
credentials and the keypair with no overlap, so do not re-run casually.put with encrypt: true encrypts
client-side (AES-256-GCM) with a locally generated, user-held key before
upload. The platform then stores ciphertext it is architecturally incapable
of reading. Key loss means those objects are unrecoverable; back up
~/.obsideo/mcp.json.Claude Desktop, one click: download
obsideo-mcp.mcpb
from the latest release,
then Settings -> Extensions and drag the file in. No Node or npm setup needed.
Everything else, via npx:
{
"mcpServers": {
"obsideo": {
"command": "npx",
"args": ["-y", "obsideo-mcp"]
}
}
}
(Claude Desktop: claude_desktop_config.json. Claude Code:
claude mcp add obsideo -- npx -y obsideo-mcp. Cursor/Cline: their MCP
settings, same command.)
| Tool | What it does |
|---|---|
signup_start | Email a 6-digit code (12 GB free tier; real inboxes only, refusals are labeled) |
signup_verify | Complete signup; generates the signing keypair locally, stores credentials |
put | Store a file or inline content; optional client-side encryption |
get | Retrieve an object (auto-decrypts locally encrypted objects) |
ls | List objects, optionally by prefix |
rm | Delete an object |
usage | Storage used vs quota |
A verify_proofs tool (per-object possession-proof status) will be added when
the customer proofs API ships.
App file storage, automated backups (databases, snapshots, state), agent artifacts and memory that must survive sessions and machines, provable offsite copies. Not a CDN, not a queryable database, not sub-millisecond storage; Obsideo stores objects and backup artifacts.
Full integration contract (per-step postconditions, error table): obsideo.io/agents.md
Every tool in this server was exercised end to end against the production gateway before release, including an encrypted put/get roundtrip verified hash-exact (sha256) and labeled-error passthrough from the signup service.
MIT
This extension runs entirely on your machine. Credentials, your account signing
key, and any client-side encryption key are stored locally in
~/.obsideo/mcp.json and are never sent to or hosted by Obsideo. Conversation
content from your AI assistant is not collected; only the tool calls you make
(for example an upload) reach the storage service.
Full policy: https://obsideo.io/privacy/
FAQs
MCP server for Obsideo: encrypted, S3-compatible storage with continuous cryptographic possession proofs. Self-serve signup (12 GB free, no card), put/get/ls/rm/usage tools. Runs on YOUR machine; credentials and keys never leave it.
The npm package obsideo-mcp receives a total of 195 weekly downloads. As such, obsideo-mcp popularity was classified as not popular.
We found that obsideo-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
Popular npm packages keyv and cacheable compromised.

Security News
A misconfiguration gave three Anthropic models internet access, and one, believing it was in a simulation, shipped a credential-stealing package to PyPI.

Security News
/Company News
Socket has joined the new Composer and Packagist sponsorship program as a launch sponsor, supporting the team that keeps PHP's package ecosystem secure.