Skip to content
xNotePadAI
📝 App

MCP Security

August 23, 2026 · 5 min read

Connecting an AI agent to your personal notes requires trust. xNotePadAI's MCP server is built with six independent security layers — each addressing a different attack surface, each verifiable from the published source code.

1. Bearer Token Authentication

Every request requires a Bearer token in the Authorization header. Tokens are SHA-256 hashed before storage — the database holds hashes, never plain tokens. If the database were compromised, attackers get unusable hashes. Tokens can be revoked instantly from Settings — access stops the moment you click.

2. Tenant Isolation

Your token maps to exactly one tenant. The server derives tenant identity from the token hash lookup — never from client-supplied arguments. If a client passes a different tenant_id in the request body, the server ignores it and uses the authenticated one. Cross-tenant access is architecturally impossible.

3. Agent Sandboxing

AI agents operate under strict write boundaries:

Agents CAN

Read notes, search, ask questions, create new notes, tag/link/archive

Agents CANNOT

Update or delete human-created notes — only notes tagged agent-created

4. Tool Annotations

Every tool carries machine-readable safety hints:

Well-behaved clients (Claude, Cursor) read these and prompt for confirmation before running destructive operations.

5. Rate Limiting

30 requests per minute per IP. This prevents runaway agent loops, brute-force attempts, and accidental infinite recursion. The free tier caps at 1,000 MCP calls per month — enough for real use, not enough for abuse.

6. Confidential Exclusion

Any content wrapped in <!-- CONFIDENTIAL --> markers is permanently stripped from all MCP responses. Even with a valid token, an agent cannot read confidential sections. This happens server-side — the data never enters the response body.

What's NOT Protected

Transparency matters: if you enable AI and sync your notes to the server, the server holds readable copies for AI processing. The zero-knowledge claim applies to encrypted sync blobs — not to the AI-indexed copies. See Can AI Read Encrypted Notes? for the full architectural explanation.