Reported issues for Engram: AI memory you can edit in Obsidian
Pod holds 19 of 25 GitHub reports that passed its relevance review. This can include external user reports, maintainer-confirmed bugs, and concrete feature gaps. Treat them as evidence to inspect, not a count of distinct defects.
Back to Engram: AI memory you can edit in Obsidian.
Most discussed
Deleting the default vault strands MCP/API clients — list_vaults and set_vault 404
Found by dogfooding 2026-07-08 ~00:55Z (user 019ec4e2). After deleting the user's DEFAULT vault (old Engram, 4c2057f9), the MCP connection fails not_found on EVERY call — including list_vaults and the no-arg set_vault() reset — because the client's default-vault pointer dangles at the deleted vault.
Impact: any customer who deletes their default vault hard-breaks their Claude/MCP integration with no recovery path from the client side.
Fix directions:
- On vault delete, repoint the…
Read the thread · 2026-07-08 · open · 2 comments
p0: discovery advertises client_secret_post/basic but the CIMD path refuses them
We advertise two auth methods we then refuse
lib/engram_web/controllers/well_known_controller.ex:112 publishes:
token_endpoint_auth_methods_supported: [
"none",
"client_secret_post",
"client_secret_basic"
]
lib/engram/oauth/cimd.ex:355 then rejects any CIMD document naming anything but none:
document["token_endpoint_auth_method"] not in [nil, "none"] ->
{:error, :confidential_not_supported}
A client that reads our discovery metadata, picks…
Read the thread · 2026-09-15 · closed · 1 comment
MCP protocol conformance: ping, Host-rebinding rejection, and a 2025-03-26 protocol announcement
Surfaced by mcpjam protocol conformance, which had never run against us until
2026-08-05. Those 32 checks were skipping silently — 29 of them for want of a bearer
token — so none of this was visible.
Measured against a CI stack built from fix/oauth-base-url-port, with a valid token.
Findings
1. ping is unimplemented
Fails at our own announced protocol version (2025-03-26). MCP defines ping as a
baseline utility method; clients use it for liveness before deciding a session…
Read the thread · 2026-08-05 · closed · 1 comment
[P0] MCP set_vault is cosmetic — all reads silently hit the default vault
Priority: P0 (no P0 label in repo yet — applied bug; add priority label when available)
Summary
Through the MCP server, set_vault accepts a vault UUID and echoes the correct vault name, but every read tool ignores it and returns the default vault. A caller who scopes to a non-default vault silently receives default-vault data with no error. There is currently no way, via MCP, to read any vault other than the default.
This is the **MCP-server twin of the…
Read the thread · 2026-07-10 · closed · 1 comment
fix(mcp): get_note silently truncates some note bodies (returns header + intro only)
Summary
get_note intermittently returns only the note header + intro block, silently dropping the rest of the body. No error, no truncation flag.
Reproduction
- Reproduced across 3 independent sessions/agents on the same notes (e.g.
Engram Sync,Engram MCP & Search Improvements). - Other long notes (8–10 KB) return in full → truncation is content/structure-dependent, not a length cap → unpredictable.
- No
offset/pagination param exists to retrieve the remainder.
##…
Read the thread · 2026-06-24 · closed · 1 comment
MCP: surface pending-terms notice in tool responses so the AI prompts the user to re-accept
Target: v1.1+ (part of the non-blocking material-change re-acceptance flow — see #312). Filing now so it isn't lost.
Background
The terms re-acceptance gate (RequireOnboarding) is only on the vault-scoped pipeline (router.ex:191). The MCP endpoint POST /api/mcp runs :oauth_api + OAuthScopeEnforce only (router.ex:241) — it does NOT pass through RequireOnboarding.
Consequence: a user who works primarily (or entirely) through an MCP client (Claude Desktop, etc.)…
Read the thread · 2026-05-26 · open · 1 comment
Split monolithic mcp OAuth scope into granular per-action scopes
Problem
Today the MCP OAuth flow issues tokens with a single monolithic scope `mcp`:
```elixir
backend/lib/engram/oauth.ex
@valid_scopes ~w(mcp) ```
A client with the `mcp` scope can do everything the user can — read, search, write, delete, edit folders, attach files. There's no in-protocol way to grant "read + search only" to a less-trusted agent.
The marketing docs (engram-marketing#42) currently advise users:…
Read the thread · 2026-05-21 · open · 1 comment
history 8: surfaces — SPA revision list + diff, MCP tools, plugin modals
Part of #609. Depends on #1711 and #1717.
SPA
- Revision list in the note view (session timestamps,
+N -Mfromchar_count) - Side-by-side diff using the CodeMirror we already ship
- Trash node in the sidebar tree
The tree is one cache (['vault-tree']) with sidebar views as selects of it — do not add a
second cache. See folder-tree-optimistic-rebuild.md and
frontend-tree-cache-and-virtualizer.md.
MCP
New tools: list_note_revisions, get_note_revision,…
Read the thread · 2026-09-18 · open · 0 comments
Most recent
ci: the SaaS onboarding chain is never exercised
Found during the #1670 review. Needs a decision from a human because it requires provisioning a CI secret.
config/runtime.exs:462: billing_enabled = auth_provider == :clerk and System.get_env("PADDLE_API_KEY") != nil.
PADDLE_API_KEY appears in no workflow (grep .github/workflows/ is empty) and is not in the clerk webServer.env in playwright.config.ts. So CI always runs billing_enabled=false, and the onboarding chain is [tools, vault].
That means the /onboard/agreement…
Read the thread · 2026-09-16 · open · 0 comments
e2e: prove a resumed MCP grant can actually call a tool
Split out of #1670 review rather than bundled.
frontend/e2e/oauth-consent-onboarding.spec.ts asserts that approving after the onboarding detour yields an authorization code with the original state. Minting a code always worked, including with #1666 present. The bug was that the resulting tokens then 403'd on every tool call, forever.
So the headline test for the #1666 fix does not actually exercise the failure mode. A regression where the wizard completes but the profile or vault…
Read the thread · 2026-09-16 · open · 0 comments
p1: MCP-first signup dead-ends — OAuth succeeds, every tool call 403s onboarding_required forever
Summary
A user who reaches Engram through an MCP client's OAuth flow, and never through app.engram.page, ends up with an account that can do nothing. OAuth succeeds, tokens are issued, and then every MCP tool call returns 403 onboarding_required forever. Nothing in the OAuth path runs or links to the onboarding wizard, so the user has no path forward and no way to know what is wrong.
This is a signup funnel leak with a legal component: these accounts exist with **no terms acceptance…
Read the thread · 2026-09-16 · closed · 0 comments
p0: ChatGPT cannot connect — CIMD refuses private_key_jwt, and we have no client_assertion support
ChatGPT cannot connect to our MCP server, and has never been able to
lib/engram/oauth/cimd.ex:355 refuses any CIMD document that names an auth method other than none:
document["token_endpoint_auth_method"] not in [nil, "none"] ->
{:error, :confidential_not_supported}
ChatGPT identifies itself with a signed client assertion (private_key_jwt), not a shared secret. Verified from their side: https://chatgpt.com/oauth/jwks.json returns 200 application/json with an RSA…
Read the thread · 2026-09-15 · closed · 0 comments
suggest_folder counts chunks instead of notes
Bug
suggest_folder and auto-placement count chunks, not notes (lib/engram/mcp/handlers.ex:178, 754). One long note with 8 matching chunks outvotes other notes, and the "Notes" column shows chunk counts.
Fix
Pass group_by_note: true. One line.
Minor, same area: the Jina reranker mixes the raw first-stage score (an RRF rank score in hybrid mode) with its own normalized score (lib/engram/rerankers/jina.ex:92). Reranker is off in prod.
Read the thread · 2026-09-11 · open · 0 comments
P0: MCP list_folder ignores its path argument and always returns the vault root
Impact
list_folder (singular) returns the vault root's contents for every value of path. It does not error, so a caller has no way to know the answer is wrong — it just silently sees the wrong folder.
Sibling of #1491, which is the same defect in delete_folder where the consequence is data loss rather than a wrong answer. This one is filed separately because it is read-only, trivially reproducible, and is the cheapest way to probe the shared path-handling bug.
Repro
Against…
Read the thread · 2026-08-28 · closed · 0 comments
P0: MCP delete_folder ignores its path argument and targets the vault root
Impact
delete_folder appears to ignore the path argument entirely and resolve to the vault root. The only thing standing between a caller and a full-vault recursive delete is the "Refusing to delete the vault root" guard.
Hit this live against prod (vault a800afc8-…, 2026-08-28 ~07:15 UTC) while cleaning up a 20-note test folder:
delete_folder(path="99 Load Test/worker-split", recursive=true)
→ "Refusing to delete the vault root."
delete_folder(path="99 Load Test",…
[Read the thread](https://github.com/engram-app/Engram/issues/1491) · 2026-08-28 · closed · 0 comments
### Free-tier API write/RPS gates do not apply to MCP-authenticated traffic
## Summary
Free tier's "no API access" entitlement does not apply to traffic authenticated over MCP or the device flow. `RequireApiWriteEnabled` and `RequireApiRpsBudget` exempt any request that has no `:current_api_key` assign, which was intended to exempt the web SPA but also catches MCP / OAuth / device-flow tokens.
Net effect on a Free account:
| Credential | Writes | Rate limit |
|---|---|---|
| API key (`engram_…`) | 402 `api_write_not_available` | `api_rps_cap: 0`, denied |
| MCP /…
[Read the thread](https://github.com/engram-app/Engram/issues/1471) · 2026-08-25 · open · 0 comments
### fix(sync): note_changed Channel broadcast 500s on invalid UTF-8 content
## Summary
Same root cause as #727: note content can hold invalid UTF-8 (encrypted → stored as `bytea`, bypassing Postgres UTF-8 validation). When a `note_changed` event is broadcast over Phoenix Channels, the V2 JSON serializer calls `Jason.encode` on the payload `content`/`title`/etc. and raises `Jason.EncodeError`, terminating `Engram.PubSub.Adapter`.
## Evidence (prod, 2026-06-24)
GenServer Engram.PubSub.Adapter terminating ** (Jason.EncodeError) invalid byte 0xE2 in <<55, 49, 226>>…
Read the thread · 2026-06-24 · closed · 0 comments
feat(mcp): add folder-delete and attachment (binary) move operations
Summary
Two missing capabilities hit during a full vault reorganization:
- No folder-delete — empty folders cannot be removed via MCP (left an orphaned empty folder after moving all notes out).
- No attachment move — binary attachments (e.g. stamped PDFs in a
Formation/subfolder) are not visible tolist_folderand cannot be moved viarename_note; they had to be moved manually in Obsidian.
Impact
Reorg/maintenance cannot be completed via MCP alone — requires manual…
Read the thread · 2026-06-24 · closed · 0 comments
fix(mcp): get_note response repeats title/tags ~3x (injected header + frontmatter + H1)
Summary
get_note responses repeat the title/tags ~3×: an injected header block (Title/Tags/Path/Folder) + the note's own YAML frontmatter + its # H1.
Impact
Token waste at scale and noisier context for AI clients.
Proposed fix
Return one canonical metadata block; don't duplicate injected header + frontmatter + H1.
Found during the 2026-06-23 Engram vault dogfooding session. Full running list: business-vault 40 Operations/Engram MCP Issue Tracker.
Read the thread · 2026-06-24 · closed · 0 comments
The remaining reports are on the project's issue tracker.