Code MCP serverOfficialLocal

Filesystem MCP Server

The reference Filesystem MCP server gives your AI agent file access limited to the folders you name. Ideal for Claude Desktop and for learning MCP.

By the MCP project · Last updated

Set up

Terminal
claude mcp add --transport stdio filesystem -- npx -y @modelcontextprotocol/server-filesystem@2026.8.31 '<YOUR_ALLOWED_FOLDER>'

Needs Node.js. Adds it for you in this project. Add --scope user to have it in every project.

Or share it with your team in .mcp.json

.mcp.json
{
  "mcpServers": {
    "filesystem": {
      "command": "npx",
      "args": [
        "-y",
        "@modelcontextprotocol/server-filesystem@2026.8.31",
        "<YOUR_ALLOWED_FOLDER>"
      ]
    }
  }
}

This file is meant to be committed, so secrets are ${NAME}: Claude Code fills them in from each person's environment.

Fill in this value

  • ALLOWED_FOLDER

    The full path of the folder it may read and write, e.g. your project folder.

    Get it from the folder's path in your file manager, or run pwd inside it. To allow more folders, list each one after it.

Replace each <YOUR_…> in the snippet with your own value, on your machine. This page never asks for it.

Claude Code MCP docs

What it can do

Reads only look. Writes change something on your account, and read-only mode turns them off.

Files

Reads

  • Read a text file whole, or just its first or last lines
  • Read several files at once
  • Read an image or audio file
  • Get a file's size, dates and permissions

Writes

  • Create a file or overwrite one completely
  • Edit a file by replacing exact lines, and see the diff
  • Move or rename a file or folder

Folders

Reads

  • List a folder, with or without sizes, or as a tree
  • Search for files by name pattern
  • List the folders it is allowed to use

Writes

  • Create folders

What it can touch

Official
Yes. Published by the MCP project, who make the product it connects to.
Sign-in
None. It needs no account.
Read-only mode
No. It can do anything your credentials allow.
What leaves your machine
Nothing, by itself: it only reads and writes files on your machine. The contents of files your agent reads go to your AI tool's model like anything else in the chat.
Pinned version
@modelcontextprotocol/server-filesystem@2026.8.31 when you run it locally. The remote server is whatever version the publisher is running.
MCP registry
Not listed. The MCP project publishes its reference servers to npm from the modelcontextprotocol/servers repo, not to the registry.
Licence
Apache-2.0 AND MIT
Last reviewed
How we check an MCP server is safe
Check it yourself

MCP servers checklist

0 of 11 checked

Who made it

Before reading a line of it, know whose code you are about to run.

What's inside

The part people skip. Read what your agent will read.

What it can reach

Give it the least access that still does the job.

Keeping it that way

What you checked today is only what runs tomorrow if you pin it.

Your ticks are saved in this browser only.

The Filesystem server gives your AI agent tools to read, write and search files, but only inside the folders you list when it starts. It is one of the reference servers the MCP project maintains to show how the protocol works, which makes it a good first server: it runs on your machine, needs no account, and its folder limit is easy to see and test.

Prompts to try

  • "List the allowed folders, then show me the tree of the first one."
  • "Find every Markdown file under docs and give me a one-line summary of each."
  • "Read package.json and list the scripts it defines, with what each one runs."
  • "Rename draft.md to 2026-09-notes.md." (a write: your tool should ask first)

Gotchas

  • The folder is the whole security model. Name the smallest folder that does the job: a project folder, not your home folder, where your SSH keys and .env files live.
  • Your tool can override the folder. If your AI tool sends MCP roots (its own list of workspace folders), those replace the ones in the config. Ask the agent to list its allowed folders to see what it really has.
  • Writes overwrite without warning. The write tool replaces a file whole. Keep the folder under version control so a bad write is one undo away.
  • It is a reference implementation. The MCP project says these servers are "educational examples" rather than production-ready. For a personal project folder that is fine; for anything shared, it is your threat model to check.
  • On Windows, npx needs cmd /c. The README wraps the command as cmd /c npx -y … in the config there.

When not to use it

If your AI tool already edits files in your project, as Claude Code, Cursor and Codex do, this adds a second way to do the same thing. Use it where there is no built-in file access, or to fence an agent into one folder.

FAQ

Can it reach files outside the folder I give it?

No. Every tool checks the path against the allowed folders, symlinks included, and refuses anything outside them. It can still read everything inside, so do not point it at your home folder.

Can it delete files?

There is no delete tool. It can still destroy a file's contents, because the write tool overwrites a file whole without asking. Moving a file will not replace one that already exists.

Does it have a read-only mode?

Not as a switch. The README's Docker setup can mount a folder with the ro flag, which makes it read-only for the server. Otherwise, rely on your AI tool asking before each write.

Do I need it in Claude Code, Cursor or Codex?

Usually not. Coding agents already read and edit files in your project. It earns its place in tools that cannot touch files on their own, like Claude Desktop, or when you want a hard limit on which folders an agent can reach.

See all MCP servers