← Integration Hub

Obsidian

Action requiredNot connectedMOCK

Knowledge search, recent and pinned notes, quick capture and Daily Notes — through the scoped Knowledge Gateway.

How it connects
Paste a key or token
Health
healthy
Integration status
connected
Credential
Not configured
Last sync
never
Connected
not yet

2 of 4 steps done

Setup

  1. Enable the Local REST API plugin in Obsidian

    You are hereNot done yet
    YouProvider console (one time)

    Obsidian → Settings → Community plugins → Local REST API. Enable it and copy the API key it shows. This is the transport that lets a headless PAXX server reach a vault at all.

    Open the provider's console
  2. Encrypted credential storage initialized

    Done
    Administrator (once)In the Hub

    Credentials are sealed with AES-256-GCM before they reach the database, and PAXX refuses to store them at all without a key. Initialize it with one click in the Integration Hub, or set the key in the server environment if you would rather manage it yourself.

  3. Paste the URL, key and folder scopes

    Not done yet
    YouIn the Hub

    Press Connect. PAXX contacts the vault before storing anything, so an unreachable host or a wrong key fails here and no credential is written.

  4. Deployment-wide folder ceiling (optional, environment only)

    optionalDone
    Administrator (once)Server environment

    OBSIDIAN_VAULT_SCOPES caps every grant this deployment can issue, including the owner's, regardless of what is connected in the browser. It is environment-only on purpose: a ceiling a browser session could raise is not a ceiling.

    This step cannot be completed from the browser — it needs shell access to the server environment and a restart to pick the value up.

Paste a key or token

Connect

Enable the Local REST API plugin, then paste its URL, API key and the folders PAXX may touch.

Live check

Connection test

The Local REST API plugin's own status endpoint, through the Knowledge Gateway — so a pass means the vault is reachable *and* the scoping layer accepted the connection.

3 declared

Permissions

What PAXX asks the provider for. The provider's own consent screen is the authoritative grant — this list is what will be requested, and after connecting, what was actually returned.

  • readRead notesnot requested yetSearch, read and list notes inside the granted folders.
  • writeQuick captureoptionalnot requested yetAppend captures to the configured capture target.
  • writeDaily Notesoptionalnot requested yetAppend to today's Daily Note.

Capabilities

What you get

  • Scoped note search

    readNot available

    Search and read inside the granted folders only. A path outside them is refused with a 403, never silently filtered.

    Available once this provider is connected.

    /knowledgeCommand palette
  • Quick capture

    writeNot available

    Append-only writes to the capture target. There is no code path that can replace a note body.

    Available once this provider is connected.

    /knowledge
  • Daily Notes

    writeNot available

    Today's Daily Note, with append.

    Available once this provider is connected.

    /knowledge

Requirements

Diagnostics

Administrator requirements

One-time work for whoever administers this PAXX instance.

  • Encrypted credential storage initialized

    Satisfied
    Administrator (once)In the Hub

    Credentials are sealed with AES-256-GCM before they reach the database, and PAXX refuses to store them at all without a key. Initialize it with one click in the Integration Hub, or set the key in the server environment if you would rather manage it yourself.

Your requirements

Per-person steps — the authorization is yours, not the deployment's.

  • Enable the Local REST API plugin in Obsidian

    Not satisfied
    YouProvider console (one time)

    Obsidian → Settings → Community plugins → Local REST API. Enable it and copy the API key it shows. This is the transport that lets a headless PAXX server reach a vault at all.

    Open
  • Paste the URL, key and folder scopes

    Not satisfied
    YouIn the Hub

    Press Connect. PAXX contacts the vault before storing anything, so an unreachable host or a wrong key fails here and no credential is written.