Obsidian
Action requiredNot connectedMOCKKnowledge search, recent and pinned notes, quick capture and Daily Notes — through the scoped Knowledge Gateway.
- How it connects
- Paste a key or token
- Health
- healthy
- Integration status
- connected
- Credential
- Not configured
- Last sync
- never
- Connected
- not yet
2 of 4 steps done
Setup
Enable the Local REST API plugin in Obsidian
You are hereNot done yetYouProvider console (one time)Obsidian → Settings → Community plugins → Local REST API. Enable it and copy the API key it shows. This is the transport that lets a headless PAXX server reach a vault at all.
Open the provider's consoleEncrypted credential storage initialized
DoneAdministrator (once)In the HubCredentials are sealed with AES-256-GCM before they reach the database, and PAXX refuses to store them at all without a key. Initialize it with one click in the Integration Hub, or set the key in the server environment if you would rather manage it yourself.
Paste the URL, key and folder scopes
Not done yetYouIn the HubPress Connect. PAXX contacts the vault before storing anything, so an unreachable host or a wrong key fails here and no credential is written.
Deployment-wide folder ceiling (optional, environment only)
optionalDoneAdministrator (once)Server environmentOBSIDIAN_VAULT_SCOPES caps every grant this deployment can issue, including the owner's, regardless of what is connected in the browser. It is environment-only on purpose: a ceiling a browser session could raise is not a ceiling.
This step cannot be completed from the browser — it needs shell access to the server environment and a restart to pick the value up.
Paste a key or token
Connect
Enable the Local REST API plugin, then paste its URL, API key and the folders PAXX may touch.
Live check
Connection test
The Local REST API plugin's own status endpoint, through the Knowledge Gateway — so a pass means the vault is reachable *and* the scoping layer accepted the connection.
3 declared
Permissions
What PAXX asks the provider for. The provider's own consent screen is the authoritative grant — this list is what will be requested, and after connecting, what was actually returned.
- readRead notesnot requested yetSearch, read and list notes inside the granted folders.
- writeQuick captureoptionalnot requested yetAppend captures to the configured capture target.
- writeDaily Notesoptionalnot requested yetAppend to today's Daily Note.
Capabilities
What you get
Scoped note search
readNot availableSearch and read inside the granted folders only. A path outside them is refused with a 403, never silently filtered.
Available once this provider is connected.
/knowledgeCommand paletteQuick capture
writeNot availableAppend-only writes to the capture target. There is no code path that can replace a note body.
Available once this provider is connected.
/knowledgeDaily Notes
writeNot availableToday's Daily Note, with append.
Available once this provider is connected.
/knowledge
Requirements
Diagnostics
Administrator requirements
One-time work for whoever administers this PAXX instance.
Encrypted credential storage initialized
SatisfiedAdministrator (once)In the HubCredentials are sealed with AES-256-GCM before they reach the database, and PAXX refuses to store them at all without a key. Initialize it with one click in the Integration Hub, or set the key in the server environment if you would rather manage it yourself.
Your requirements
Per-person steps — the authorization is yours, not the deployment's.
Enable the Local REST API plugin in Obsidian
Not satisfiedYouProvider console (one time)Obsidian → Settings → Community plugins → Local REST API. Enable it and copy the API key it shows. This is the transport that lets a headless PAXX server reach a vault at all.
OpenPaste the URL, key and folder scopes
Not satisfiedYouIn the HubPress Connect. PAXX contacts the vault before storing anything, so an unreachable host or a wrong key fails here and no credential is written.