MCP Security
August 23, 2026 · 5 min read
Connecting an AI agent to your personal notes requires trust. xNotePadAI's MCP server is built with six independent security layers — each addressing a different attack surface, each verifiable from the published source code.
1. Bearer Token Authentication
Every request requires a Bearer token in the Authorization header. Tokens are SHA-256 hashed before storage — the database holds hashes, never plain tokens. If the database were compromised, attackers get unusable hashes. Tokens can be revoked instantly from Settings — access stops the moment you click.
2. Tenant Isolation
Your token maps to exactly one tenant. The server derives tenant identity from the token hash lookup — never from client-supplied arguments. If a client passes a different tenant_id in the request body, the server ignores it and uses the authenticated one. Cross-tenant access is architecturally impossible.
3. Agent Sandboxing
AI agents operate under strict write boundaries:
Agents CAN
Read notes, search, ask questions, create new notes, tag/link/archive
Agents CANNOT
Update or delete human-created notes — only notes tagged agent-created
4. Tool Annotations
Every tool carries machine-readable safety hints:
- • readOnlyHint — 5 tools (list, get, search, ask, versions) marked read-only
- • destructiveHint — 3 tools (update, delete, merge) flagged destructive
- • idempotentHint — index_notes marked safe to retry
Well-behaved clients (Claude, Cursor) read these and prompt for confirmation before running destructive operations.
5. Rate Limiting
30 requests per minute per IP. This prevents runaway agent loops, brute-force attempts, and accidental infinite recursion. The free tier caps at 1,000 MCP calls per month — enough for real use, not enough for abuse.
6. Confidential Exclusion
Any content wrapped in <!-- CONFIDENTIAL --> markers is permanently stripped from all MCP responses. Even with a valid token, an agent cannot read confidential sections. This happens server-side — the data never enters the response body.
What's NOT Protected
Transparency matters: if you enable AI and sync your notes to the server, the server holds readable copies for AI processing. The zero-knowledge claim applies to encrypted sync blobs — not to the AI-indexed copies. See Can AI Read Encrypted Notes? for the full architectural explanation.