Pod

Available as Markdown and JSON. Pod is also available over MCP.

Reported issues for Engram: AI memory you can edit in Obsidian

Pod holds 19 of 25 GitHub reports that passed its relevance review. This can include external user reports, maintainer-confirmed bugs, and concrete feature gaps. Treat them as evidence to inspect, not a count of distinct defects.

Back to Engram: AI memory you can edit in Obsidian.

Most discussed

Deleting the default vault strands MCP/API clients — list_vaults and set_vault 404

Found by dogfooding 2026-07-08 ~00:55Z (user 019ec4e2). After deleting the user's DEFAULT vault (old Engram, 4c2057f9), the MCP connection fails not_found on EVERY call — including list_vaults and the no-arg set_vault() reset — because the client's default-vault pointer dangles at the deleted vault.

Impact: any customer who deletes their default vault hard-breaks their Claude/MCP integration with no recovery path from the client side.

Fix directions:

  1. On vault delete, repoint the…

Read the thread · 2026-07-08 · open · 2 comments

p0: discovery advertises client_secret_post/basic but the CIMD path refuses them

We advertise two auth methods we then refuse

lib/engram_web/controllers/well_known_controller.ex:112 publishes:

token_endpoint_auth_methods_supported: [
  "none",
  "client_secret_post",
  "client_secret_basic"
]

lib/engram/oauth/cimd.ex:355 then rejects any CIMD document naming anything but none:

document["token_endpoint_auth_method"] not in [nil, "none"] ->
  {:error, :confidential_not_supported}

A client that reads our discovery metadata, picks…

Read the thread · 2026-09-15 · closed · 1 comment

MCP protocol conformance: ping, Host-rebinding rejection, and a 2025-03-26 protocol announcement

Surfaced by mcpjam protocol conformance, which had never run against us until 2026-08-05. Those 32 checks were skipping silently — 29 of them for want of a bearer token — so none of this was visible.

Measured against a CI stack built from fix/oauth-base-url-port, with a valid token.

Findings

1. ping is unimplemented

Fails at our own announced protocol version (2025-03-26). MCP defines ping as a baseline utility method; clients use it for liveness before deciding a session…

Read the thread · 2026-08-05 · closed · 1 comment

[P0] MCP set_vault is cosmetic — all reads silently hit the default vault

Priority: P0 (no P0 label in repo yet — applied bug; add priority label when available)

Summary

Through the MCP server, set_vault accepts a vault UUID and echoes the correct vault name, but every read tool ignores it and returns the default vault. A caller who scopes to a non-default vault silently receives default-vault data with no error. There is currently no way, via MCP, to read any vault other than the default.

This is the **MCP-server twin of the…

Read the thread · 2026-07-10 · closed · 1 comment

fix(mcp): get_note silently truncates some note bodies (returns header + intro only)

Summary

get_note intermittently returns only the note header + intro block, silently dropping the rest of the body. No error, no truncation flag.

Reproduction

##…

Read the thread · 2026-06-24 · closed · 1 comment

MCP: surface pending-terms notice in tool responses so the AI prompts the user to re-accept

Target: v1.1+ (part of the non-blocking material-change re-acceptance flow — see #312). Filing now so it isn't lost.

Background

The terms re-acceptance gate (RequireOnboarding) is only on the vault-scoped pipeline (router.ex:191). The MCP endpoint POST /api/mcp runs :oauth_api + OAuthScopeEnforce only (router.ex:241) — it does NOT pass through RequireOnboarding.

Consequence: a user who works primarily (or entirely) through an MCP client (Claude Desktop, etc.)…

Read the thread · 2026-05-26 · open · 1 comment

Split monolithic mcp OAuth scope into granular per-action scopes

Problem

Today the MCP OAuth flow issues tokens with a single monolithic scope `mcp`:

```elixir

backend/lib/engram/oauth.ex

@valid_scopes ~w(mcp) ```

A client with the `mcp` scope can do everything the user can — read, search, write, delete, edit folders, attach files. There's no in-protocol way to grant "read + search only" to a less-trusted agent.

The marketing docs (engram-marketing#42) currently advise users:…

Read the thread · 2026-05-21 · open · 1 comment

history 8: surfaces — SPA revision list + diff, MCP tools, plugin modals

Part of #609. Depends on #1711 and #1717.

SPA

The tree is one cache (['vault-tree']) with sidebar views as selects of it — do not add a second cache. See folder-tree-optimistic-rebuild.md and frontend-tree-cache-and-virtualizer.md.

MCP

New tools: list_note_revisions, get_note_revision,…

Read the thread · 2026-09-18 · open · 0 comments

Most recent

ci: the SaaS onboarding chain is never exercised

Found during the #1670 review. Needs a decision from a human because it requires provisioning a CI secret.

config/runtime.exs:462: billing_enabled = auth_provider == :clerk and System.get_env("PADDLE_API_KEY") != nil.

PADDLE_API_KEY appears in no workflow (grep .github/workflows/ is empty) and is not in the clerk webServer.env in playwright.config.ts. So CI always runs billing_enabled=false, and the onboarding chain is [tools, vault].

That means the /onboard/agreement…

Read the thread · 2026-09-16 · open · 0 comments

e2e: prove a resumed MCP grant can actually call a tool

Split out of #1670 review rather than bundled.

frontend/e2e/oauth-consent-onboarding.spec.ts asserts that approving after the onboarding detour yields an authorization code with the original state. Minting a code always worked, including with #1666 present. The bug was that the resulting tokens then 403'd on every tool call, forever.

So the headline test for the #1666 fix does not actually exercise the failure mode. A regression where the wizard completes but the profile or vault…

Read the thread · 2026-09-16 · open · 0 comments

p1: MCP-first signup dead-ends — OAuth succeeds, every tool call 403s onboarding_required forever

Summary

A user who reaches Engram through an MCP client's OAuth flow, and never through app.engram.page, ends up with an account that can do nothing. OAuth succeeds, tokens are issued, and then every MCP tool call returns 403 onboarding_required forever. Nothing in the OAuth path runs or links to the onboarding wizard, so the user has no path forward and no way to know what is wrong.

This is a signup funnel leak with a legal component: these accounts exist with **no terms acceptance…

Read the thread · 2026-09-16 · closed · 0 comments

p0: ChatGPT cannot connect — CIMD refuses private_key_jwt, and we have no client_assertion support

ChatGPT cannot connect to our MCP server, and has never been able to

lib/engram/oauth/cimd.ex:355 refuses any CIMD document that names an auth method other than none:

document["token_endpoint_auth_method"] not in [nil, "none"] ->
  {:error, :confidential_not_supported}

ChatGPT identifies itself with a signed client assertion (private_key_jwt), not a shared secret. Verified from their side: https://chatgpt.com/oauth/jwks.json returns 200 application/json with an RSA…

Read the thread · 2026-09-15 · closed · 0 comments

suggest_folder counts chunks instead of notes

Bug

suggest_folder and auto-placement count chunks, not notes (lib/engram/mcp/handlers.ex:178, 754). One long note with 8 matching chunks outvotes other notes, and the "Notes" column shows chunk counts.

Fix

Pass group_by_note: true. One line.

Minor, same area: the Jina reranker mixes the raw first-stage score (an RRF rank score in hybrid mode) with its own normalized score (lib/engram/rerankers/jina.ex:92). Reranker is off in prod.

Read the thread · 2026-09-11 · open · 0 comments

P0: MCP list_folder ignores its path argument and always returns the vault root

Impact

list_folder (singular) returns the vault root's contents for every value of path. It does not error, so a caller has no way to know the answer is wrong — it just silently sees the wrong folder.

Sibling of #1491, which is the same defect in delete_folder where the consequence is data loss rather than a wrong answer. This one is filed separately because it is read-only, trivially reproducible, and is the cheapest way to probe the shared path-handling bug.

Repro

Against…

Read the thread · 2026-08-28 · closed · 0 comments

P0: MCP delete_folder ignores its path argument and targets the vault root

Impact

delete_folder appears to ignore the path argument entirely and resolve to the vault root. The only thing standing between a caller and a full-vault recursive delete is the "Refusing to delete the vault root" guard.

Hit this live against prod (vault a800afc8-…, 2026-08-28 ~07:15 UTC) while cleaning up a 20-note test folder:

delete_folder(path="99 Load Test/worker-split", recursive=true)
  → "Refusing to delete the vault root."
delete_folder(path="99 Load Test",…

[Read the thread](https://github.com/engram-app/Engram/issues/1491) · 2026-08-28 · closed · 0 comments

### Free-tier API write/RPS gates do not apply to MCP-authenticated traffic

## Summary

Free tier's "no API access" entitlement does not apply to traffic authenticated over MCP or the device flow. `RequireApiWriteEnabled` and `RequireApiRpsBudget` exempt any request that has no `:current_api_key` assign, which was intended to exempt the web SPA but also catches MCP / OAuth / device-flow tokens.

Net effect on a Free account:

| Credential | Writes | Rate limit |
|---|---|---|
| API key (`engram_…`) | 402 `api_write_not_available` | `api_rps_cap: 0`, denied |
| MCP /…

[Read the thread](https://github.com/engram-app/Engram/issues/1471) · 2026-08-25 · open · 0 comments

### fix(sync): note_changed Channel broadcast 500s on invalid UTF-8 content

## Summary
Same root cause as #727: note content can hold invalid UTF-8 (encrypted → stored as `bytea`, bypassing Postgres UTF-8 validation). When a `note_changed` event is broadcast over Phoenix Channels, the V2 JSON serializer calls `Jason.encode` on the payload `content`/`title`/etc. and raises `Jason.EncodeError`, terminating `Engram.PubSub.Adapter`.

## Evidence (prod, 2026-06-24)

GenServer Engram.PubSub.Adapter terminating ** (Jason.EncodeError) invalid byte 0xE2 in <<55, 49, 226>>…

Read the thread · 2026-06-24 · closed · 0 comments

feat(mcp): add folder-delete and attachment (binary) move operations

Summary

Two missing capabilities hit during a full vault reorganization:

  1. No folder-delete — empty folders cannot be removed via MCP (left an orphaned empty folder after moving all notes out).
  2. No attachment move — binary attachments (e.g. stamped PDFs in a Formation/ subfolder) are not visible to list_folder and cannot be moved via rename_note; they had to be moved manually in Obsidian.

Impact

Reorg/maintenance cannot be completed via MCP alone — requires manual…

Read the thread · 2026-06-24 · closed · 0 comments

fix(mcp): get_note response repeats title/tags ~3x (injected header + frontmatter + H1)

Summary

get_note responses repeat the title/tags ~3×: an injected header block (Title/Tags/Path/Folder) + the note's own YAML frontmatter + its # H1.

Impact

Token waste at scale and noisier context for AI clients.

Proposed fix

Return one canonical metadata block; don't duplicate injected header + frontmatter + H1.


Found during the 2026-06-23 Engram vault dogfooding session. Full running list: business-vault 40 Operations/Engram MCP Issue Tracker.

Read the thread · 2026-06-24 · closed · 0 comments

The remaining reports are on the project's issue tracker.