Repository files navigation

RefMD MCP Server

A Model Context Protocol server that exposes RefMD documents over a hosted SSE endpoint, so chatbots can browse and edit Markdown through RefMD's API.

Features

  • Streamable HTTP/SSE transport compatible with hosted MCP clients (e.g. Claude, Cursor)
  • Resource template refmd://document/{id} to read document Markdown and metadata
  • Tools for listing, searching, creating, and updating documents via the RefMD API
  • Chunked document reads through optional offset/limit parameters (each call returns up to 120,000 characters)
  • Partial Markdown patching via refmd-patch-document-content (insert/delete/replace without reuploading the entire file)

Prerequisites

  • Node.js 18+
  • Access to an existing RefMD instance
  • Either a personal access token (JWT) or credentials that can log in via /api/auth/login

Configuration

The server now authenticates users via OAuth 2.1 with PKCE. Configure it with the following variables:

VariableDescription
REFMD_API_BASERequired. Base URL of your RefMD API (e.g. https://refmd.example.com).
OAUTH_CLIENT_IDSComma-separated list of allowed client_id values. Leave empty to allow any.
OAUTH_ALLOWED_REDIRECTSComma-separated list of allowed redirect URIs. Defaults to allowing HTTPS URLs and http://localhost. Include ChatGPT’s callback URL (https://chat.openai.com/aip/mcp/oauth/callback).
OAUTH_ISSUEROptional public issuer URL (defaults to the current request origin).
ACCESS_TOKEN_TTL_SECONDSOptional access-token lifetime (default 3600).
REFRESH_TOKEN_TTL_SECONDSOptional refresh-token lifetime (default 2592000, i.e. 30 days).
MCP_DB_DRIVEROptional. Set to sqlite, postgres, or mysql to persist OAuth tokens. Defaults to in-memory storage.
MCP_DB_URLOptional connection string for the configured driver (e.g. postgres://user:pass@host/db). For SQLite you may omit this and use MCP_DB_SQLITE_PATH.
MCP_DB_SQLITE_PATHOptional filesystem path for SQLite storage (defaults to ./data/refmd-mcp.sqlite). Accepts plain paths or file:/// URLs; ensure the path resolves to persistent storage when using SQLite.
PORT / HOSTOptional listen port / host (defaults: 3334 / 0.0.0.0).

Allowing multiple hosted clients: set OAUTH_CLIENT_IDS to a comma-separated list (e.g. chatgpt-connector,Claude) and mirror the same set in OAUTH_ALLOWED_REDIRECTS. Leaving either variable empty keeps it open to any HTTPS redirect, but as soon as you specify one value you must list every connector you want to permit.

Remote MCP clients (Claude Web included) expect the OAuth Protected Resource Metadata document at https://<host>/.well-known/oauth-protected-resource so they can follow the resource_metadata hint in WWW-Authenticate challenges. The server serves that document automatically (including mirrored aliases like /mcp/.well-known/...), so make sure your reverse proxy forwards those paths.

If you terminate TLS in a reverse proxy, make sure it forwards either the standard Forwarded header or X-Forwarded-Proto / X-Forwarded-Host so the OAuth metadata advertises the correct https:// origin. Set OAUTH_ISSUER=https://your-domain if you prefer an explicit override.

ℹ️ Install the appropriate database driver when enabling persistence:
npm install better-sqlite3 for SQLite, npm install pg for PostgreSQL, or npm install mysql2 for MySQL/MariaDB.

Install & Build

cd mcp-server
npm install
npm run build

Run

npm start
REFMD_API_BASE="https://refmd.example.com" \
OAUTH_CLIENT_IDS="chatgpt-connector" \
OAUTH_ALLOWED_REDIRECTS="https://chat.openai.com/aip/mcp/oauth/callback" \
npm start

The server exposes two transports:

  • http://<host>:<port>/sse — SSE transport (compatible with Claude SSE etc.)
  • http://<host>:<port>/mcp — Streamable HTTP transport (one-shot POST per exchange)

OAuth flow

  1. Configure your client (e.g. ChatGPT custom connector) with:
    • Authorization URL:https://your-domain.example.com/oauth/authorize
    • Token URL:https://your-domain.example.com/oauth/token
    • Revocation URL:https://your-domain.example.com/oauth/revoke
    • Scopes: (leave blank)
    • PKCE: enabled (ChatGPT uses S256 automatically)
  2. When prompted, the browser shows the RefMD MCP consent page. Paste a RefMD API token generated from Profile → API tokens and approve.
  3. The connector receives an access token and can call /sse or /mcp with Authorization: Bearer <token>.

Tokens can be revoked from RefMD (profile page) or via POST /oauth/revoke.

Run with Docker

# Build image
docker build -t refmd-mcp .
docker run -p 3334:3334 \
-e REFMD_API_BASE="https://refmd.example.com" \
-e OAUTH_CLIENT_IDS="chatgpt-connector" \
-e OAUTH_ALLOWED_REDIRECTS="https://chat.openai.com/aip/mcp/oauth/callback" \
-e MCP_DB_DRIVER="sqlite" \
-e MCP_DB_SQLITE_PATH="/data/refmd-mcp.sqlite" \
-v refmd-mcp-data:/data \
refmd-mcp

Mount a persistent volume (as shown above) so the SQLite database file survives container restarts.

Connecting a Chat Client

  • Claude (CLI):
    claude mcp add --transport sse refmd https://your-domain.example.com/sse
  • Cursor / VS Code / MCP Inspector: choose an SSE transport and supply the same URL.

Once connected, resources appear under refmd://document/{id}. Available tools include refmd-list-documents, refmd-search-documents, refmd-create-document, refmd-read-document, refmd-update-document-content, and more.

Reading Large Documents

The refmd-read-document tool and the refmd://document/{id} resource both support optional pagination parameters so large Markdown files stay under the Model Context Protocol payload limits:

  • offset (default 0): starting character position (zero-based).
  • limit (default 120000, capped at 120000): maximum characters to return in the response.

Example resource URI: refmd://document/123e4567-e89b-12d3-a456-426614174000?offset=60000&limit=60000.

Each response includes range metadata and the next offset so clients can issue follow-up calls until the full document is retrieved.

Patching Document Content

Use the refmd-patch-document-content tool to insert, delete, or replace specific spans without sending the entire Markdown body:

{
"id": "document-uuid",
"operations": [
{ "op": "insert", "offset": 120, "text": "New paragraph." },
{ "op": "delete", "offset": 42, "length": 5 }
]
}

Offsets/lengths are counted in Unicode code points to match RefMD’s editor behavior. The server validates ranges and applies the operations atomically before emitting document-change events, so downstream integrations stay in sync.

Release workflow

The GitHub Actions workflow CI MCP Server ships the container image. It runs automatically on pushes/PRs touching mcp-server and publishes to GHCR when:

  • the push is a tag matching mcp-server-v* (versioned release), or
  • the workflow is manually triggered with publish=true.

Tags published to ghcr.io/<owner>/refmd-mcp include semantic versions (1.2.0, 1.2, 1), the raw git tag, and latest. Use the extra-tag input for additional labels when invoking the workflow manually.

Development

Run in watch mode with TSX:

npm run dev

Any code changes require a rebuild (npm run build) before deploying or running with npm start.

About

No description, website, or topics provided.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Repository files navigation

RefMD MCP Server

A Model Context Protocol server that exposes RefMD documents over a hosted SSE endpoint, so chatbots can browse and edit Markdown through RefMD's API.

Features

  • Streamable HTTP/SSE transport compatible with hosted MCP clients (e.g. Claude, Cursor)
  • Resource template refmd://document/{id} to read document Markdown and metadata
  • Tools for listing, searching, creating, and updating documents via the RefMD API
  • Chunked document reads through optional offset/limit parameters (each call returns up to 120,000 characters)
  • Partial Markdown patching via refmd-patch-document-content (insert/delete/replace without reuploading the entire file)

Prerequisites

  • Node.js 18+
  • Access to an existing RefMD instance
  • Either a personal access token (JWT) or credentials that can log in via /api/auth/login

Configuration

The server now authenticates users via OAuth 2.1 with PKCE. Configure it with the following variables:

VariableDescription
REFMD_API_BASERequired. Base URL of your RefMD API (e.g. https://refmd.example.com).
OAUTH_CLIENT_IDSComma-separated list of allowed client_id values. Leave empty to allow any.
OAUTH_ALLOWED_REDIRECTSComma-separated list of allowed redirect URIs. Defaults to allowing HTTPS URLs and http://localhost. Include ChatGPT’s callback URL (https://chat.openai.com/aip/mcp/oauth/callback).
OAUTH_ISSUEROptional public issuer URL (defaults to the current request origin).
ACCESS_TOKEN_TTL_SECONDSOptional access-token lifetime (default 3600).
REFRESH_TOKEN_TTL_SECONDSOptional refresh-token lifetime (default 2592000, i.e. 30 days).
MCP_DB_DRIVEROptional. Set to sqlite, postgres, or mysql to persist OAuth tokens. Defaults to in-memory storage.
MCP_DB_URLOptional connection string for the configured driver (e.g. postgres://user:pass@host/db). For SQLite you may omit this and use MCP_DB_SQLITE_PATH.
MCP_DB_SQLITE_PATHOptional filesystem path for SQLite storage (defaults to ./data/refmd-mcp.sqlite). Accepts plain paths or file:/// URLs; ensure the path resolves to persistent storage when using SQLite.
PORT / HOSTOptional listen port / host (defaults: 3334 / 0.0.0.0).

Allowing multiple hosted clients: set OAUTH_CLIENT_IDS to a comma-separated list (e.g. chatgpt-connector,Claude) and mirror the same set in OAUTH_ALLOWED_REDIRECTS. Leaving either variable empty keeps it open to any HTTPS redirect, but as soon as you specify one value you must list every connector you want to permit.

Remote MCP clients (Claude Web included) expect the OAuth Protected Resource Metadata document at https://<host>/.well-known/oauth-protected-resource so they can follow the resource_metadata hint in WWW-Authenticate challenges. The server serves that document automatically (including mirrored aliases like /mcp/.well-known/...), so make sure your reverse proxy forwards those paths.

If you terminate TLS in a reverse proxy, make sure it forwards either the standard Forwarded header or X-Forwarded-Proto / X-Forwarded-Host so the OAuth metadata advertises the correct https:// origin. Set OAUTH_ISSUER=https://your-domain if you prefer an explicit override.

ℹ️ Install the appropriate database driver when enabling persistence:
npm install better-sqlite3 for SQLite, npm install pg for PostgreSQL, or npm install mysql2 for MySQL/MariaDB.

Install & Build

cd mcp-server
npm install
npm run build

Run

npm start
REFMD_API_BASE="https://refmd.example.com" \
OAUTH_CLIENT_IDS="chatgpt-connector" \
OAUTH_ALLOWED_REDIRECTS="https://chat.openai.com/aip/mcp/oauth/callback" \
npm start

The server exposes two transports:

  • http://<host>:<port>/sse — SSE transport (compatible with Claude SSE etc.)
  • http://<host>:<port>/mcp — Streamable HTTP transport (one-shot POST per exchange)

OAuth flow

  1. Configure your client (e.g. ChatGPT custom connector) with:
    • Authorization URL:https://your-domain.example.com/oauth/authorize
    • Token URL:https://your-domain.example.com/oauth/token
    • Revocation URL:https://your-domain.example.com/oauth/revoke
    • Scopes: (leave blank)
    • PKCE: enabled (ChatGPT uses S256 automatically)
  2. When prompted, the browser shows the RefMD MCP consent page. Paste a RefMD API token generated from Profile → API tokens and approve.
  3. The connector receives an access token and can call /sse or /mcp with Authorization: Bearer <token>.

Tokens can be revoked from RefMD (profile page) or via POST /oauth/revoke.

Run with Docker

# Build image
docker build -t refmd-mcp .
docker run -p 3334:3334 \
-e REFMD_API_BASE="https://refmd.example.com" \
-e OAUTH_CLIENT_IDS="chatgpt-connector" \
-e OAUTH_ALLOWED_REDIRECTS="https://chat.openai.com/aip/mcp/oauth/callback" \
-e MCP_DB_DRIVER="sqlite" \
-e MCP_DB_SQLITE_PATH="/data/refmd-mcp.sqlite" \
-v refmd-mcp-data:/data \
refmd-mcp

Mount a persistent volume (as shown above) so the SQLite database file survives container restarts.

Connecting a Chat Client

  • Claude (CLI):
    claude mcp add --transport sse refmd https://your-domain.example.com/sse
  • Cursor / VS Code / MCP Inspector: choose an SSE transport and supply the same URL.

Once connected, resources appear under refmd://document/{id}. Available tools include refmd-list-documents, refmd-search-documents, refmd-create-document, refmd-read-document, refmd-update-document-content, and more.

Reading Large Documents

The refmd-read-document tool and the refmd://document/{id} resource both support optional pagination parameters so large Markdown files stay under the Model Context Protocol payload limits:

  • offset (default 0): starting character position (zero-based).
  • limit (default 120000, capped at 120000): maximum characters to return in the response.

Example resource URI: refmd://document/123e4567-e89b-12d3-a456-426614174000?offset=60000&limit=60000.

Each response includes range metadata and the next offset so clients can issue follow-up calls until the full document is retrieved.

Patching Document Content

Use the refmd-patch-document-content tool to insert, delete, or replace specific spans without sending the entire Markdown body:

{
"id": "document-uuid",
"operations": [
{ "op": "insert", "offset": 120, "text": "New paragraph." },
{ "op": "delete", "offset": 42, "length": 5 }
]
}

Offsets/lengths are counted in Unicode code points to match RefMD’s editor behavior. The server validates ranges and applies the operations atomically before emitting document-change events, so downstream integrations stay in sync.

Release workflow

The GitHub Actions workflow CI MCP Server ships the container image. It runs automatically on pushes/PRs touching mcp-server and publishes to GHCR when:

  • the push is a tag matching mcp-server-v* (versioned release), or
  • the workflow is manually triggered with publish=true.

Tags published to ghcr.io/<owner>/refmd-mcp include semantic versions (1.2.0, 1.2, 1), the raw git tag, and latest. Use the extra-tag input for additional labels when invoking the workflow manually.

Development

Run in watch mode with TSX:

npm run dev

Any code changes require a rebuild (npm run build) before deploying or running with npm start.

About

No description, website, or topics provided.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

RefMD MCP Server

A Model Context Protocol server that exposes RefMD documents over a hosted SSE endpoint, so chatbots can browse and edit Markdown through RefMD's API.

Features

  • Streamable HTTP/SSE transport compatible with hosted MCP clients (e.g. Claude, Cursor)
  • Resource template refmd://document/{id} to read document Markdown and metadata
  • Tools for listing, searching, creating, and updating documents via the RefMD API
  • Chunked document reads through optional offset/limit parameters (each call returns up to 120,000 characters)
  • Partial Markdown patching via refmd-patch-document-content (insert/delete/replace without reuploading the entire file)

Prerequisites

  • Node.js 18+
  • Access to an existing RefMD instance
  • Either a personal access token (JWT) or credentials that can log in via /api/auth/login

Configuration

The server now authenticates users via OAuth 2.1 with PKCE. Configure it with the following variables:

VariableDescription
REFMD_API_BASERequired. Base URL of your RefMD API (e.g. https://refmd.example.com).
OAUTH_CLIENT_IDSComma-separated list of allowed client_id values. Leave empty to allow any.
OAUTH_ALLOWED_REDIRECTSComma-separated list of allowed redirect URIs. Defaults to allowing HTTPS URLs and http://localhost. Include ChatGPT’s callback URL (https://chat.openai.com/aip/mcp/oauth/callback).
OAUTH_ISSUEROptional public issuer URL (defaults to the current request origin).
ACCESS_TOKEN_TTL_SECONDSOptional access-token lifetime (default 3600).
REFRESH_TOKEN_TTL_SECONDSOptional refresh-token lifetime (default 2592000, i.e. 30 days).
MCP_DB_DRIVEROptional. Set to sqlite, postgres, or mysql to persist OAuth tokens. Defaults to in-memory storage.
MCP_DB_URLOptional connection string for the configured driver (e.g. postgres://user:pass@host/db). For SQLite you may omit this and use MCP_DB_SQLITE_PATH.
MCP_DB_SQLITE_PATHOptional filesystem path for SQLite storage (defaults to ./data/refmd-mcp.sqlite). Accepts plain paths or file:/// URLs; ensure the path resolves to persistent storage when using SQLite.
PORT / HOSTOptional listen port / host (defaults: 3334 / 0.0.0.0).

Allowing multiple hosted clients: set OAUTH_CLIENT_IDS to a comma-separated list (e.g. chatgpt-connector,Claude) and mirror the same set in OAUTH_ALLOWED_REDIRECTS. Leaving either variable empty keeps it open to any HTTPS redirect, but as soon as you specify one value you must list every connector you want to permit.

Remote MCP clients (Claude Web included) expect the OAuth Protected Resource Metadata document at https://<host>/.well-known/oauth-protected-resource so they can follow the resource_metadata hint in WWW-Authenticate challenges. The server serves that document automatically (including mirrored aliases like /mcp/.well-known/...), so make sure your reverse proxy forwards those paths.

If you terminate TLS in a reverse proxy, make sure it forwards either the standard Forwarded header or X-Forwarded-Proto / X-Forwarded-Host so the OAuth metadata advertises the correct https:// origin. Set OAUTH_ISSUER=https://your-domain if you prefer an explicit override.

ℹ️ Install the appropriate database driver when enabling persistence:
npm install better-sqlite3 for SQLite, npm install pg for PostgreSQL, or npm install mysql2 for MySQL/MariaDB.

Install & Build

cd mcp-server
npm install
npm run build

Run

npm start
REFMD_API_BASE="https://refmd.example.com" \
OAUTH_CLIENT_IDS="chatgpt-connector" \
OAUTH_ALLOWED_REDIRECTS="https://chat.openai.com/aip/mcp/oauth/callback" \
npm start

The server exposes two transports:

  • http://<host>:<port>/sse — SSE transport (compatible with Claude SSE etc.)
  • http://<host>:<port>/mcp — Streamable HTTP transport (one-shot POST per exchange)

OAuth flow

  1. Configure your client (e.g. ChatGPT custom connector) with:
    • Authorization URL:https://your-domain.example.com/oauth/authorize
    • Token URL:https://your-domain.example.com/oauth/token
    • Revocation URL:https://your-domain.example.com/oauth/revoke
    • Scopes: (leave blank)
    • PKCE: enabled (ChatGPT uses S256 automatically)
  2. When prompted, the browser shows the RefMD MCP consent page. Paste a RefMD API token generated from Profile → API tokens and approve.
  3. The connector receives an access token and can call /sse or /mcp with Authorization: Bearer <token>.

Tokens can be revoked from RefMD (profile page) or via POST /oauth/revoke.

Run with Docker

# Build image
docker build -t refmd-mcp .
docker run -p 3334:3334 \
-e REFMD_API_BASE="https://refmd.example.com" \
-e OAUTH_CLIENT_IDS="chatgpt-connector" \
-e OAUTH_ALLOWED_REDIRECTS="https://chat.openai.com/aip/mcp/oauth/callback" \
-e MCP_DB_DRIVER="sqlite" \
-e MCP_DB_SQLITE_PATH="/data/refmd-mcp.sqlite" \
-v refmd-mcp-data:/data \
refmd-mcp

Mount a persistent volume (as shown above) so the SQLite database file survives container restarts.

Connecting a Chat Client

  • Claude (CLI):
    claude mcp add --transport sse refmd https://your-domain.example.com/sse
  • Cursor / VS Code / MCP Inspector: choose an SSE transport and supply the same URL.

Once connected, resources appear under refmd://document/{id}. Available tools include refmd-list-documents, refmd-search-documents, refmd-create-document, refmd-read-document, refmd-update-document-content, and more.

Reading Large Documents

The refmd-read-document tool and the refmd://document/{id} resource both support optional pagination parameters so large Markdown files stay under the Model Context Protocol payload limits:

  • offset (default 0): starting character position (zero-based).
  • limit (default 120000, capped at 120000): maximum characters to return in the response.

Example resource URI: refmd://document/123e4567-e89b-12d3-a456-426614174000?offset=60000&limit=60000.

Each response includes range metadata and the next offset so clients can issue follow-up calls until the full document is retrieved.

Patching Document Content

Use the refmd-patch-document-content tool to insert, delete, or replace specific spans without sending the entire Markdown body:

{
"id": "document-uuid",
"operations": [
{ "op": "insert", "offset": 120, "text": "New paragraph." },
{ "op": "delete", "offset": 42, "length": 5 }
]
}

Offsets/lengths are counted in Unicode code points to match RefMD’s editor behavior. The server validates ranges and applies the operations atomically before emitting document-change events, so downstream integrations stay in sync.

Release workflow

The GitHub Actions workflow CI MCP Server ships the container image. It runs automatically on pushes/PRs touching mcp-server and publishes to GHCR when:

  • the push is a tag matching mcp-server-v* (versioned release), or
  • the workflow is manually triggered with publish=true.

Tags published to ghcr.io/<owner>/refmd-mcp include semantic versions (1.2.0, 1.2, 1), the raw git tag, and latest. Use the extra-tag input for additional labels when invoking the workflow manually.

Development

Run in watch mode with TSX:

npm run dev

Any code changes require a rebuild (npm run build) before deploying or running with npm start.

About

No description, website, or topics provided.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

RefMD MCP Server

A Model Context Protocol server that exposes RefMD documents over a hosted SSE endpoint, so chatbots can browse and edit Markdown through RefMD's API.

Features

  • Streamable HTTP/SSE transport compatible with hosted MCP clients (e.g. Claude, Cursor)
  • Resource template refmd://document/{id} to read document Markdown and metadata
  • Tools for listing, searching, creating, and updating documents via the RefMD API
  • Chunked document reads through optional offset/limit parameters (each call returns up to 120,000 characters)
  • Partial Markdown patching via refmd-patch-document-content (insert/delete/replace without reuploading the entire file)

Prerequisites

  • Node.js 18+
  • Access to an existing RefMD instance
  • Either a personal access token (JWT) or credentials that can log in via /api/auth/login

Configuration

The server now authenticates users via OAuth 2.1 with PKCE. Configure it with the following variables:

VariableDescription
REFMD_API_BASERequired. Base URL of your RefMD API (e.g. https://refmd.example.com).
OAUTH_CLIENT_IDSComma-separated list of allowed client_id values. Leave empty to allow any.
OAUTH_ALLOWED_REDIRECTSComma-separated list of allowed redirect URIs. Defaults to allowing HTTPS URLs and http://localhost. Include ChatGPT’s callback URL (https://chat.openai.com/aip/mcp/oauth/callback).
OAUTH_ISSUEROptional public issuer URL (defaults to the current request origin).
ACCESS_TOKEN_TTL_SECONDSOptional access-token lifetime (default 3600).
REFRESH_TOKEN_TTL_SECONDSOptional refresh-token lifetime (default 2592000, i.e. 30 days).
MCP_DB_DRIVEROptional. Set to sqlite, postgres, or mysql to persist OAuth tokens. Defaults to in-memory storage.
MCP_DB_URLOptional connection string for the configured driver (e.g. postgres://user:pass@host/db). For SQLite you may omit this and use MCP_DB_SQLITE_PATH.
MCP_DB_SQLITE_PATHOptional filesystem path for SQLite storage (defaults to ./data/refmd-mcp.sqlite). Accepts plain paths or file:/// URLs; ensure the path resolves to persistent storage when using SQLite.
PORT / HOSTOptional listen port / host (defaults: 3334 / 0.0.0.0).

Allowing multiple hosted clients: set OAUTH_CLIENT_IDS to a comma-separated list (e.g. chatgpt-connector,Claude) and mirror the same set in OAUTH_ALLOWED_REDIRECTS. Leaving either variable empty keeps it open to any HTTPS redirect, but as soon as you specify one value you must list every connector you want to permit.

Remote MCP clients (Claude Web included) expect the OAuth Protected Resource Metadata document at https://<host>/.well-known/oauth-protected-resource so they can follow the resource_metadata hint in WWW-Authenticate challenges. The server serves that document automatically (including mirrored aliases like /mcp/.well-known/...), so make sure your reverse proxy forwards those paths.

If you terminate TLS in a reverse proxy, make sure it forwards either the standard Forwarded header or X-Forwarded-Proto / X-Forwarded-Host so the OAuth metadata advertises the correct https:// origin. Set OAUTH_ISSUER=https://your-domain if you prefer an explicit override.

ℹ️ Install the appropriate database driver when enabling persistence:
npm install better-sqlite3 for SQLite, npm install pg for PostgreSQL, or npm install mysql2 for MySQL/MariaDB.

Install & Build

cd mcp-server
npm install
npm run build

Run

npm start
REFMD_API_BASE="https://refmd.example.com" \
OAUTH_CLIENT_IDS="chatgpt-connector" \
OAUTH_ALLOWED_REDIRECTS="https://chat.openai.com/aip/mcp/oauth/callback" \
npm start

The server exposes two transports:

  • http://<host>:<port>/sse — SSE transport (compatible with Claude SSE etc.)
  • http://<host>:<port>/mcp — Streamable HTTP transport (one-shot POST per exchange)

OAuth flow

  1. Configure your client (e.g. ChatGPT custom connector) with:
    • Authorization URL:https://your-domain.example.com/oauth/authorize
    • Token URL:https://your-domain.example.com/oauth/token
    • Revocation URL:https://your-domain.example.com/oauth/revoke
    • Scopes: (leave blank)
    • PKCE: enabled (ChatGPT uses S256 automatically)
  2. When prompted, the browser shows the RefMD MCP consent page. Paste a RefMD API token generated from Profile → API tokens and approve.
  3. The connector receives an access token and can call /sse or /mcp with Authorization: Bearer <token>.

Tokens can be revoked from RefMD (profile page) or via POST /oauth/revoke.

Run with Docker

# Build image
docker build -t refmd-mcp .
docker run -p 3334:3334 \
-e REFMD_API_BASE="https://refmd.example.com" \
-e OAUTH_CLIENT_IDS="chatgpt-connector" \
-e OAUTH_ALLOWED_REDIRECTS="https://chat.openai.com/aip/mcp/oauth/callback" \
-e MCP_DB_DRIVER="sqlite" \
-e MCP_DB_SQLITE_PATH="/data/refmd-mcp.sqlite" \
-v refmd-mcp-data:/data \
refmd-mcp

Mount a persistent volume (as shown above) so the SQLite database file survives container restarts.

Connecting a Chat Client

  • Claude (CLI):
    claude mcp add --transport sse refmd https://your-domain.example.com/sse
  • Cursor / VS Code / MCP Inspector: choose an SSE transport and supply the same URL.

Once connected, resources appear under refmd://document/{id}. Available tools include refmd-list-documents, refmd-search-documents, refmd-create-document, refmd-read-document, refmd-update-document-content, and more.

Reading Large Documents

The refmd-read-document tool and the refmd://document/{id} resource both support optional pagination parameters so large Markdown files stay under the Model Context Protocol payload limits:

  • offset (default 0): starting character position (zero-based).
  • limit (default 120000, capped at 120000): maximum characters to return in the response.

Example resource URI: refmd://document/123e4567-e89b-12d3-a456-426614174000?offset=60000&limit=60000.

Each response includes range metadata and the next offset so clients can issue follow-up calls until the full document is retrieved.

Patching Document Content

Use the refmd-patch-document-content tool to insert, delete, or replace specific spans without sending the entire Markdown body:

{
"id": "document-uuid",
"operations": [
{ "op": "insert", "offset": 120, "text": "New paragraph." },
{ "op": "delete", "offset": 42, "length": 5 }
]
}

Offsets/lengths are counted in Unicode code points to match RefMD’s editor behavior. The server validates ranges and applies the operations atomically before emitting document-change events, so downstream integrations stay in sync.

Release workflow

The GitHub Actions workflow CI MCP Server ships the container image. It runs automatically on pushes/PRs touching mcp-server and publishes to GHCR when:

  • the push is a tag matching mcp-server-v* (versioned release), or
  • the workflow is manually triggered with publish=true.

Tags published to ghcr.io/<owner>/refmd-mcp include semantic versions (1.2.0, 1.2, 1), the raw git tag, and latest. Use the extra-tag input for additional labels when invoking the workflow manually.

Development

Run in watch mode with TSX:

npm run dev

Any code changes require a rebuild (npm run build) before deploying or running with npm start.

About

No description, website, or topics provided.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Repository files navigation

RefMD MCP Server

A Model Context Protocol server that exposes RefMD documents over a hosted SSE endpoint, so chatbots can browse and edit Markdown through RefMD's API.

Features

  • Streamable HTTP/SSE transport compatible with hosted MCP clients (e.g. Claude, Cursor)
  • Resource template refmd://document/{id} to read document Markdown and metadata
  • Tools for listing, searching, creating, and updating documents via the RefMD API
  • Chunked document reads through optional offset/limit parameters (each call returns up to 120,000 characters)
  • Partial Markdown patching via refmd-patch-document-content (insert/delete/replace without reuploading the entire file)

Prerequisites

  • Node.js 18+
  • Access to an existing RefMD instance
  • Either a personal access token (JWT) or credentials that can log in via /api/auth/login

Configuration

The server now authenticates users via OAuth 2.1 with PKCE. Configure it with the following variables:

VariableDescription
REFMD_API_BASERequired. Base URL of your RefMD API (e.g. https://refmd.example.com).
OAUTH_CLIENT_IDSComma-separated list of allowed client_id values. Leave empty to allow any.
OAUTH_ALLOWED_REDIRECTSComma-separated list of allowed redirect URIs. Defaults to allowing HTTPS URLs and http://localhost. Include ChatGPT’s callback URL (https://chat.openai.com/aip/mcp/oauth/callback).
OAUTH_ISSUEROptional public issuer URL (defaults to the current request origin).
ACCESS_TOKEN_TTL_SECONDSOptional access-token lifetime (default 3600).
REFRESH_TOKEN_TTL_SECONDSOptional refresh-token lifetime (default 2592000, i.e. 30 days).
MCP_DB_DRIVEROptional. Set to sqlite, postgres, or mysql to persist OAuth tokens. Defaults to in-memory storage.
MCP_DB_URLOptional connection string for the configured driver (e.g. postgres://user:pass@host/db). For SQLite you may omit this and use MCP_DB_SQLITE_PATH.
MCP_DB_SQLITE_PATHOptional filesystem path for SQLite storage (defaults to ./data/refmd-mcp.sqlite). Accepts plain paths or file:/// URLs; ensure the path resolves to persistent storage when using SQLite.
PORT / HOSTOptional listen port / host (defaults: 3334 / 0.0.0.0).

Allowing multiple hosted clients: set OAUTH_CLIENT_IDS to a comma-separated list (e.g. chatgpt-connector,Claude) and mirror the same set in OAUTH_ALLOWED_REDIRECTS. Leaving either variable empty keeps it open to any HTTPS redirect, but as soon as you specify one value you must list every connector you want to permit.

Remote MCP clients (Claude Web included) expect the OAuth Protected Resource Metadata document at https://<host>/.well-known/oauth-protected-resource so they can follow the resource_metadata hint in WWW-Authenticate challenges. The server serves that document automatically (including mirrored aliases like /mcp/.well-known/...), so make sure your reverse proxy forwards those paths.

If you terminate TLS in a reverse proxy, make sure it forwards either the standard Forwarded header or X-Forwarded-Proto / X-Forwarded-Host so the OAuth metadata advertises the correct https:// origin. Set OAUTH_ISSUER=https://your-domain if you prefer an explicit override.

ℹ️ Install the appropriate database driver when enabling persistence:
npm install better-sqlite3 for SQLite, npm install pg for PostgreSQL, or npm install mysql2 for MySQL/MariaDB.

Install & Build

cd mcp-server
npm install
npm run build

Run

npm start
REFMD_API_BASE="https://refmd.example.com" \
OAUTH_CLIENT_IDS="chatgpt-connector" \
OAUTH_ALLOWED_REDIRECTS="https://chat.openai.com/aip/mcp/oauth/callback" \
npm start

The server exposes two transports:

  • http://<host>:<port>/sse — SSE transport (compatible with Claude SSE etc.)
  • http://<host>:<port>/mcp — Streamable HTTP transport (one-shot POST per exchange)

OAuth flow

  1. Configure your client (e.g. ChatGPT custom connector) with:
    • Authorization URL:https://your-domain.example.com/oauth/authorize
    • Token URL:https://your-domain.example.com/oauth/token
    • Revocation URL:https://your-domain.example.com/oauth/revoke
    • Scopes: (leave blank)
    • PKCE: enabled (ChatGPT uses S256 automatically)
  2. When prompted, the browser shows the RefMD MCP consent page. Paste a RefMD API token generated from Profile → API tokens and approve.
  3. The connector receives an access token and can call /sse or /mcp with Authorization: Bearer <token>.

Tokens can be revoked from RefMD (profile page) or via POST /oauth/revoke.

Run with Docker

# Build image
docker build -t refmd-mcp .
docker run -p 3334:3334 \
-e REFMD_API_BASE="https://refmd.example.com" \
-e OAUTH_CLIENT_IDS="chatgpt-connector" \
-e OAUTH_ALLOWED_REDIRECTS="https://chat.openai.com/aip/mcp/oauth/callback" \
-e MCP_DB_DRIVER="sqlite" \
-e MCP_DB_SQLITE_PATH="/data/refmd-mcp.sqlite" \
-v refmd-mcp-data:/data \
refmd-mcp

Mount a persistent volume (as shown above) so the SQLite database file survives container restarts.

Connecting a Chat Client

  • Claude (CLI):
    claude mcp add --transport sse refmd https://your-domain.example.com/sse
  • Cursor / VS Code / MCP Inspector: choose an SSE transport and supply the same URL.

Once connected, resources appear under refmd://document/{id}. Available tools include refmd-list-documents, refmd-search-documents, refmd-create-document, refmd-read-document, refmd-update-document-content, and more.

Reading Large Documents

The refmd-read-document tool and the refmd://document/{id} resource both support optional pagination parameters so large Markdown files stay under the Model Context Protocol payload limits:

  • offset (default 0): starting character position (zero-based).
  • limit (default 120000, capped at 120000): maximum characters to return in the response.

Example resource URI: refmd://document/123e4567-e89b-12d3-a456-426614174000?offset=60000&limit=60000.

Each response includes range metadata and the next offset so clients can issue follow-up calls until the full document is retrieved.

Patching Document Content

Use the refmd-patch-document-content tool to insert, delete, or replace specific spans without sending the entire Markdown body:

{
"id": "document-uuid",
"operations": [
{ "op": "insert", "offset": 120, "text": "New paragraph." },
{ "op": "delete", "offset": 42, "length": 5 }
]
}

Offsets/lengths are counted in Unicode code points to match RefMD’s editor behavior. The server validates ranges and applies the operations atomically before emitting document-change events, so downstream integrations stay in sync.

Release workflow

The GitHub Actions workflow CI MCP Server ships the container image. It runs automatically on pushes/PRs touching mcp-server and publishes to GHCR when:

  • the push is a tag matching mcp-server-v* (versioned release), or
  • the workflow is manually triggered with publish=true.

Tags published to ghcr.io/<owner>/refmd-mcp include semantic versions (1.2.0, 1.2, 1), the raw git tag, and latest. Use the extra-tag input for additional labels when invoking the workflow manually.

Development

Run in watch mode with TSX:

npm run dev

Any code changes require a rebuild (npm run build) before deploying or running with npm start.

About

No description, website, or topics provided.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

RefMD MCP Server

A Model Context Protocol server that exposes RefMD documents over a hosted SSE endpoint, so chatbots can browse and edit Markdown through RefMD's API.

Features

  • Streamable HTTP/SSE transport compatible with hosted MCP clients (e.g. Claude, Cursor)
  • Resource template refmd://document/{id} to read document Markdown and metadata
  • Tools for listing, searching, creating, and updating documents via the RefMD API
  • Chunked document reads through optional offset/limit parameters (each call returns up to 120,000 characters)
  • Partial Markdown patching via refmd-patch-document-content (insert/delete/replace without reuploading the entire file)

Prerequisites

  • Node.js 18+
  • Access to an existing RefMD instance
  • Either a personal access token (JWT) or credentials that can log in via /api/auth/login

Configuration

The server now authenticates users via OAuth 2.1 with PKCE. Configure it with the following variables:

VariableDescription
REFMD_API_BASERequired. Base URL of your RefMD API (e.g. https://refmd.example.com).
OAUTH_CLIENT_IDSComma-separated list of allowed client_id values. Leave empty to allow any.
OAUTH_ALLOWED_REDIRECTSComma-separated list of allowed redirect URIs. Defaults to allowing HTTPS URLs and http://localhost. Include ChatGPT’s callback URL (https://chat.openai.com/aip/mcp/oauth/callback).
OAUTH_ISSUEROptional public issuer URL (defaults to the current request origin).
ACCESS_TOKEN_TTL_SECONDSOptional access-token lifetime (default 3600).
REFRESH_TOKEN_TTL_SECONDSOptional refresh-token lifetime (default 2592000, i.e. 30 days).
MCP_DB_DRIVEROptional. Set to sqlite, postgres, or mysql to persist OAuth tokens. Defaults to in-memory storage.
MCP_DB_URLOptional connection string for the configured driver (e.g. postgres://user:pass@host/db). For SQLite you may omit this and use MCP_DB_SQLITE_PATH.
MCP_DB_SQLITE_PATHOptional filesystem path for SQLite storage (defaults to ./data/refmd-mcp.sqlite). Accepts plain paths or file:/// URLs; ensure the path resolves to persistent storage when using SQLite.
PORT / HOSTOptional listen port / host (defaults: 3334 / 0.0.0.0).

Allowing multiple hosted clients: set OAUTH_CLIENT_IDS to a comma-separated list (e.g. chatgpt-connector,Claude) and mirror the same set in OAUTH_ALLOWED_REDIRECTS. Leaving either variable empty keeps it open to any HTTPS redirect, but as soon as you specify one value you must list every connector you want to permit.

Remote MCP clients (Claude Web included) expect the OAuth Protected Resource Metadata document at https://<host>/.well-known/oauth-protected-resource so they can follow the resource_metadata hint in WWW-Authenticate challenges. The server serves that document automatically (including mirrored aliases like /mcp/.well-known/...), so make sure your reverse proxy forwards those paths.

If you terminate TLS in a reverse proxy, make sure it forwards either the standard Forwarded header or X-Forwarded-Proto / X-Forwarded-Host so the OAuth metadata advertises the correct https:// origin. Set OAUTH_ISSUER=https://your-domain if you prefer an explicit override.

ℹ️ Install the appropriate database driver when enabling persistence:
npm install better-sqlite3 for SQLite, npm install pg for PostgreSQL, or npm install mysql2 for MySQL/MariaDB.

Install & Build

cd mcp-server
npm install
npm run build

Run

npm start
REFMD_API_BASE="https://refmd.example.com" \
OAUTH_CLIENT_IDS="chatgpt-connector" \
OAUTH_ALLOWED_REDIRECTS="https://chat.openai.com/aip/mcp/oauth/callback" \
npm start

The server exposes two transports:

  • http://<host>:<port>/sse — SSE transport (compatible with Claude SSE etc.)
  • http://<host>:<port>/mcp — Streamable HTTP transport (one-shot POST per exchange)

OAuth flow

  1. Configure your client (e.g. ChatGPT custom connector) with:
    • Authorization URL:https://your-domain.example.com/oauth/authorize
    • Token URL:https://your-domain.example.com/oauth/token
    • Revocation URL:https://your-domain.example.com/oauth/revoke
    • Scopes: (leave blank)
    • PKCE: enabled (ChatGPT uses S256 automatically)
  2. When prompted, the browser shows the RefMD MCP consent page. Paste a RefMD API token generated from Profile → API tokens and approve.
  3. The connector receives an access token and can call /sse or /mcp with Authorization: Bearer <token>.

Tokens can be revoked from RefMD (profile page) or via POST /oauth/revoke.

Run with Docker

# Build image
docker build -t refmd-mcp .
docker run -p 3334:3334 \
-e REFMD_API_BASE="https://refmd.example.com" \
-e OAUTH_CLIENT_IDS="chatgpt-connector" \
-e OAUTH_ALLOWED_REDIRECTS="https://chat.openai.com/aip/mcp/oauth/callback" \
-e MCP_DB_DRIVER="sqlite" \
-e MCP_DB_SQLITE_PATH="/data/refmd-mcp.sqlite" \
-v refmd-mcp-data:/data \
refmd-mcp

Mount a persistent volume (as shown above) so the SQLite database file survives container restarts.

Connecting a Chat Client

  • Claude (CLI):
    claude mcp add --transport sse refmd https://your-domain.example.com/sse
  • Cursor / VS Code / MCP Inspector: choose an SSE transport and supply the same URL.

Once connected, resources appear under refmd://document/{id}. Available tools include refmd-list-documents, refmd-search-documents, refmd-create-document, refmd-read-document, refmd-update-document-content, and more.

Reading Large Documents

The refmd-read-document tool and the refmd://document/{id} resource both support optional pagination parameters so large Markdown files stay under the Model Context Protocol payload limits:

  • offset (default 0): starting character position (zero-based).
  • limit (default 120000, capped at 120000): maximum characters to return in the response.

Example resource URI: refmd://document/123e4567-e89b-12d3-a456-426614174000?offset=60000&limit=60000.

Each response includes range metadata and the next offset so clients can issue follow-up calls until the full document is retrieved.

Patching Document Content

Use the refmd-patch-document-content tool to insert, delete, or replace specific spans without sending the entire Markdown body:

{
"id": "document-uuid",
"operations": [
{ "op": "insert", "offset": 120, "text": "New paragraph." },
{ "op": "delete", "offset": 42, "length": 5 }
]
}

Offsets/lengths are counted in Unicode code points to match RefMD’s editor behavior. The server validates ranges and applies the operations atomically before emitting document-change events, so downstream integrations stay in sync.

Release workflow

The GitHub Actions workflow CI MCP Server ships the container image. It runs automatically on pushes/PRs touching mcp-server and publishes to GHCR when:

  • the push is a tag matching mcp-server-v* (versioned release), or
  • the workflow is manually triggered with publish=true.

Tags published to ghcr.io/<owner>/refmd-mcp include semantic versions (1.2.0, 1.2, 1), the raw git tag, and latest. Use the extra-tag input for additional labels when invoking the workflow manually.

Development

Run in watch mode with TSX:

npm run dev

Any code changes require a rebuild (npm run build) before deploying or running with npm start.

About

No description, website, or topics provided.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

RefMD MCP Server

A Model Context Protocol server that exposes RefMD documents over a hosted SSE endpoint, so chatbots can browse and edit Markdown through RefMD's API.

Features

  • Streamable HTTP/SSE transport compatible with hosted MCP clients (e.g. Claude, Cursor)
  • Resource template refmd://document/{id} to read document Markdown and metadata
  • Tools for listing, searching, creating, and updating documents via the RefMD API
  • Chunked document reads through optional offset/limit parameters (each call returns up to 120,000 characters)
  • Partial Markdown patching via refmd-patch-document-content (insert/delete/replace without reuploading the entire file)

Prerequisites

  • Node.js 18+
  • Access to an existing RefMD instance
  • Either a personal access token (JWT) or credentials that can log in via /api/auth/login

Configuration

The server now authenticates users via OAuth 2.1 with PKCE. Configure it with the following variables:

VariableDescription
REFMD_API_BASERequired. Base URL of your RefMD API (e.g. https://refmd.example.com).
OAUTH_CLIENT_IDSComma-separated list of allowed client_id values. Leave empty to allow any.
OAUTH_ALLOWED_REDIRECTSComma-separated list of allowed redirect URIs. Defaults to allowing HTTPS URLs and http://localhost. Include ChatGPT’s callback URL (https://chat.openai.com/aip/mcp/oauth/callback).
OAUTH_ISSUEROptional public issuer URL (defaults to the current request origin).
ACCESS_TOKEN_TTL_SECONDSOptional access-token lifetime (default 3600).
REFRESH_TOKEN_TTL_SECONDSOptional refresh-token lifetime (default 2592000, i.e. 30 days).
MCP_DB_DRIVEROptional. Set to sqlite, postgres, or mysql to persist OAuth tokens. Defaults to in-memory storage.
MCP_DB_URLOptional connection string for the configured driver (e.g. postgres://user:pass@host/db). For SQLite you may omit this and use MCP_DB_SQLITE_PATH.
MCP_DB_SQLITE_PATHOptional filesystem path for SQLite storage (defaults to ./data/refmd-mcp.sqlite). Accepts plain paths or file:/// URLs; ensure the path resolves to persistent storage when using SQLite.
PORT / HOSTOptional listen port / host (defaults: 3334 / 0.0.0.0).

Allowing multiple hosted clients: set OAUTH_CLIENT_IDS to a comma-separated list (e.g. chatgpt-connector,Claude) and mirror the same set in OAUTH_ALLOWED_REDIRECTS. Leaving either variable empty keeps it open to any HTTPS redirect, but as soon as you specify one value you must list every connector you want to permit.

Remote MCP clients (Claude Web included) expect the OAuth Protected Resource Metadata document at https://<host>/.well-known/oauth-protected-resource so they can follow the resource_metadata hint in WWW-Authenticate challenges. The server serves that document automatically (including mirrored aliases like /mcp/.well-known/...), so make sure your reverse proxy forwards those paths.

If you terminate TLS in a reverse proxy, make sure it forwards either the standard Forwarded header or X-Forwarded-Proto / X-Forwarded-Host so the OAuth metadata advertises the correct https:// origin. Set OAUTH_ISSUER=https://your-domain if you prefer an explicit override.

ℹ️ Install the appropriate database driver when enabling persistence:
npm install better-sqlite3 for SQLite, npm install pg for PostgreSQL, or npm install mysql2 for MySQL/MariaDB.

Install & Build

cd mcp-server
npm install
npm run build

Run

npm start
REFMD_API_BASE="https://refmd.example.com" \
OAUTH_CLIENT_IDS="chatgpt-connector" \
OAUTH_ALLOWED_REDIRECTS="https://chat.openai.com/aip/mcp/oauth/callback" \
npm start

The server exposes two transports:

  • http://<host>:<port>/sse — SSE transport (compatible with Claude SSE etc.)
  • http://<host>:<port>/mcp — Streamable HTTP transport (one-shot POST per exchange)

OAuth flow

  1. Configure your client (e.g. ChatGPT custom connector) with:
    • Authorization URL:https://your-domain.example.com/oauth/authorize
    • Token URL:https://your-domain.example.com/oauth/token
    • Revocation URL:https://your-domain.example.com/oauth/revoke
    • Scopes: (leave blank)
    • PKCE: enabled (ChatGPT uses S256 automatically)
  2. When prompted, the browser shows the RefMD MCP consent page. Paste a RefMD API token generated from Profile → API tokens and approve.
  3. The connector receives an access token and can call /sse or /mcp with Authorization: Bearer <token>.

Tokens can be revoked from RefMD (profile page) or via POST /oauth/revoke.

Run with Docker

# Build image
docker build -t refmd-mcp .
docker run -p 3334:3334 \
-e REFMD_API_BASE="https://refmd.example.com" \
-e OAUTH_CLIENT_IDS="chatgpt-connector" \
-e OAUTH_ALLOWED_REDIRECTS="https://chat.openai.com/aip/mcp/oauth/callback" \
-e MCP_DB_DRIVER="sqlite" \
-e MCP_DB_SQLITE_PATH="/data/refmd-mcp.sqlite" \
-v refmd-mcp-data:/data \
refmd-mcp

Mount a persistent volume (as shown above) so the SQLite database file survives container restarts.

Connecting a Chat Client

  • Claude (CLI):
    claude mcp add --transport sse refmd https://your-domain.example.com/sse
  • Cursor / VS Code / MCP Inspector: choose an SSE transport and supply the same URL.

Once connected, resources appear under refmd://document/{id}. Available tools include refmd-list-documents, refmd-search-documents, refmd-create-document, refmd-read-document, refmd-update-document-content, and more.

Reading Large Documents

The refmd-read-document tool and the refmd://document/{id} resource both support optional pagination parameters so large Markdown files stay under the Model Context Protocol payload limits:

  • offset (default 0): starting character position (zero-based).
  • limit (default 120000, capped at 120000): maximum characters to return in the response.

Example resource URI: refmd://document/123e4567-e89b-12d3-a456-426614174000?offset=60000&limit=60000.

Each response includes range metadata and the next offset so clients can issue follow-up calls until the full document is retrieved.

Patching Document Content

Use the refmd-patch-document-content tool to insert, delete, or replace specific spans without sending the entire Markdown body:

{
"id": "document-uuid",
"operations": [
{ "op": "insert", "offset": 120, "text": "New paragraph." },
{ "op": "delete", "offset": 42, "length": 5 }
]
}

Offsets/lengths are counted in Unicode code points to match RefMD’s editor behavior. The server validates ranges and applies the operations atomically before emitting document-change events, so downstream integrations stay in sync.

Release workflow

The GitHub Actions workflow CI MCP Server ships the container image. It runs automatically on pushes/PRs touching mcp-server and publishes to GHCR when:

  • the push is a tag matching mcp-server-v* (versioned release), or
  • the workflow is manually triggered with publish=true.

Tags published to ghcr.io/<owner>/refmd-mcp include semantic versions (1.2.0, 1.2, 1), the raw git tag, and latest. Use the extra-tag input for additional labels when invoking the workflow manually.

Development

Run in watch mode with TSX:

npm run dev

Any code changes require a rebuild (npm run build) before deploying or running with npm start.

About

No description, website, or topics provided.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Repository files navigation

RefMD MCP Server

A Model Context Protocol server that exposes RefMD documents over a hosted SSE endpoint, so chatbots can browse and edit Markdown through RefMD's API.

Features

  • Streamable HTTP/SSE transport compatible with hosted MCP clients (e.g. Claude, Cursor)
  • Resource template refmd://document/{id} to read document Markdown and metadata
  • Tools for listing, searching, creating, and updating documents via the RefMD API
  • Chunked document reads through optional offset/limit parameters (each call returns up to 120,000 characters)
  • Partial Markdown patching via refmd-patch-document-content (insert/delete/replace without reuploading the entire file)

Prerequisites

  • Node.js 18+
  • Access to an existing RefMD instance
  • Either a personal access token (JWT) or credentials that can log in via /api/auth/login

Configuration

The server now authenticates users via OAuth 2.1 with PKCE. Configure it with the following variables:

VariableDescription
REFMD_API_BASERequired. Base URL of your RefMD API (e.g. https://refmd.example.com).
OAUTH_CLIENT_IDSComma-separated list of allowed client_id values. Leave empty to allow any.
OAUTH_ALLOWED_REDIRECTSComma-separated list of allowed redirect URIs. Defaults to allowing HTTPS URLs and http://localhost. Include ChatGPT’s callback URL (https://chat.openai.com/aip/mcp/oauth/callback).
OAUTH_ISSUEROptional public issuer URL (defaults to the current request origin).
ACCESS_TOKEN_TTL_SECONDSOptional access-token lifetime (default 3600).
REFRESH_TOKEN_TTL_SECONDSOptional refresh-token lifetime (default 2592000, i.e. 30 days).
MCP_DB_DRIVEROptional. Set to sqlite, postgres, or mysql to persist OAuth tokens. Defaults to in-memory storage.
MCP_DB_URLOptional connection string for the configured driver (e.g. postgres://user:pass@host/db). For SQLite you may omit this and use MCP_DB_SQLITE_PATH.
MCP_DB_SQLITE_PATHOptional filesystem path for SQLite storage (defaults to ./data/refmd-mcp.sqlite). Accepts plain paths or file:/// URLs; ensure the path resolves to persistent storage when using SQLite.
PORT / HOSTOptional listen port / host (defaults: 3334 / 0.0.0.0).

Allowing multiple hosted clients: set OAUTH_CLIENT_IDS to a comma-separated list (e.g. chatgpt-connector,Claude) and mirror the same set in OAUTH_ALLOWED_REDIRECTS. Leaving either variable empty keeps it open to any HTTPS redirect, but as soon as you specify one value you must list every connector you want to permit.

Remote MCP clients (Claude Web included) expect the OAuth Protected Resource Metadata document at https://<host>/.well-known/oauth-protected-resource so they can follow the resource_metadata hint in WWW-Authenticate challenges. The server serves that document automatically (including mirrored aliases like /mcp/.well-known/...), so make sure your reverse proxy forwards those paths.

If you terminate TLS in a reverse proxy, make sure it forwards either the standard Forwarded header or X-Forwarded-Proto / X-Forwarded-Host so the OAuth metadata advertises the correct https:// origin. Set OAUTH_ISSUER=https://your-domain if you prefer an explicit override.

ℹ️ Install the appropriate database driver when enabling persistence:
npm install better-sqlite3 for SQLite, npm install pg for PostgreSQL, or npm install mysql2 for MySQL/MariaDB.

Install & Build

cd mcp-server
npm install
npm run build

Run

npm start
REFMD_API_BASE="https://refmd.example.com" \
OAUTH_CLIENT_IDS="chatgpt-connector" \
OAUTH_ALLOWED_REDIRECTS="https://chat.openai.com/aip/mcp/oauth/callback" \
npm start

The server exposes two transports:

  • http://<host>:<port>/sse — SSE transport (compatible with Claude SSE etc.)
  • http://<host>:<port>/mcp — Streamable HTTP transport (one-shot POST per exchange)

OAuth flow

  1. Configure your client (e.g. ChatGPT custom connector) with:
    • Authorization URL:https://your-domain.example.com/oauth/authorize
    • Token URL:https://your-domain.example.com/oauth/token
    • Revocation URL:https://your-domain.example.com/oauth/revoke
    • Scopes: (leave blank)
    • PKCE: enabled (ChatGPT uses S256 automatically)
  2. When prompted, the browser shows the RefMD MCP consent page. Paste a RefMD API token generated from Profile → API tokens and approve.
  3. The connector receives an access token and can call /sse or /mcp with Authorization: Bearer <token>.

Tokens can be revoked from RefMD (profile page) or via POST /oauth/revoke.

Run with Docker

# Build image
docker build -t refmd-mcp .
docker run -p 3334:3334 \
-e REFMD_API_BASE="https://refmd.example.com" \
-e OAUTH_CLIENT_IDS="chatgpt-connector" \
-e OAUTH_ALLOWED_REDIRECTS="https://chat.openai.com/aip/mcp/oauth/callback" \
-e MCP_DB_DRIVER="sqlite" \
-e MCP_DB_SQLITE_PATH="/data/refmd-mcp.sqlite" \
-v refmd-mcp-data:/data \
refmd-mcp

Mount a persistent volume (as shown above) so the SQLite database file survives container restarts.

Connecting a Chat Client

  • Claude (CLI):
    claude mcp add --transport sse refmd https://your-domain.example.com/sse
  • Cursor / VS Code / MCP Inspector: choose an SSE transport and supply the same URL.

Once connected, resources appear under refmd://document/{id}. Available tools include refmd-list-documents, refmd-search-documents, refmd-create-document, refmd-read-document, refmd-update-document-content, and more.

Reading Large Documents

The refmd-read-document tool and the refmd://document/{id} resource both support optional pagination parameters so large Markdown files stay under the Model Context Protocol payload limits:

  • offset (default 0): starting character position (zero-based).
  • limit (default 120000, capped at 120000): maximum characters to return in the response.

Example resource URI: refmd://document/123e4567-e89b-12d3-a456-426614174000?offset=60000&limit=60000.

Each response includes range metadata and the next offset so clients can issue follow-up calls until the full document is retrieved.

Patching Document Content

Use the refmd-patch-document-content tool to insert, delete, or replace specific spans without sending the entire Markdown body:

{
"id": "document-uuid",
"operations": [
{ "op": "insert", "offset": 120, "text": "New paragraph." },
{ "op": "delete", "offset": 42, "length": 5 }
]
}

Offsets/lengths are counted in Unicode code points to match RefMD’s editor behavior. The server validates ranges and applies the operations atomically before emitting document-change events, so downstream integrations stay in sync.

Release workflow

The GitHub Actions workflow CI MCP Server ships the container image. It runs automatically on pushes/PRs touching mcp-server and publishes to GHCR when:

  • the push is a tag matching mcp-server-v* (versioned release), or
  • the workflow is manually triggered with publish=true.

Tags published to ghcr.io/<owner>/refmd-mcp include semantic versions (1.2.0, 1.2, 1), the raw git tag, and latest. Use the extra-tag input for additional labels when invoking the workflow manually.

Development

Run in watch mode with TSX:

npm run dev

Any code changes require a rebuild (npm run build) before deploying or running with npm start.

About

No description, website, or topics provided.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages