# Reported issues for Engram: AI memory you can edit in Obsidian

Pod holds 19 of 25 GitHub reports that passed its relevance review. This can include external user reports, maintainer-confirmed bugs, and concrete feature gaps. Treat them as evidence to inspect, not a count of distinct defects.

Back to [Engram: AI memory you can edit in Obsidian](/mcp/engram-ai-memory-you-can-edit-in-obsidian).

## Most discussed

### Deleting the default vault strands MCP/API clients — list_vaults and set_vault 404

Found by dogfooding 2026-07-08 ~00:55Z (user 019ec4e2). After deleting the user's DEFAULT vault (old `Engram`, 4c2057f9), the MCP connection fails `not_found` on EVERY call — including `list_vaults` and the no-arg `set_vault()` reset — because the client's default-vault pointer dangles at the deleted vault.

Impact: any customer who deletes their default vault hard-breaks their Claude/MCP integration with no recovery path from the client side.

Fix directions:
1. On vault delete, repoint the…

[Read the thread](https://github.com/engram-app/Engram/issues/951) · 2026-07-08 · open · 2 comments

### p0: discovery advertises client_secret_post/basic but the CIMD path refuses them

## We advertise two auth methods we then refuse

`lib/engram_web/controllers/well_known_controller.ex:112` publishes:

```elixir
token_endpoint_auth_methods_supported: [
  "none",
  "client_secret_post",
  "client_secret_basic"
]
```

`lib/engram/oauth/cimd.ex:355` then rejects any CIMD document naming anything but `none`:

```elixir
document["token_endpoint_auth_method"] not in [nil, "none"] ->
  {:error, :confidential_not_supported}
```

A client that reads our discovery metadata, picks…

[Read the thread](https://github.com/engram-app/Engram/issues/1634) · 2026-09-15 · closed · 1 comment

### MCP protocol conformance: ping, Host-rebinding rejection, and a 2025-03-26 protocol announcement

Surfaced by `mcpjam protocol conformance`, which had **never run against us** until
2026-08-05. Those 32 checks were skipping silently — 29 of them for want of a bearer
token — so none of this was visible.

Measured against a CI stack built from `fix/oauth-base-url-port`, with a valid token.

## Findings

### 1. `ping` is unimplemented
Fails at our own announced protocol version (2025-03-26). MCP defines `ping` as a
baseline utility method; clients use it for liveness before deciding a session…

[Read the thread](https://github.com/engram-app/Engram/issues/1259) · 2026-08-05 · closed · 1 comment

### [P0] MCP set_vault is cosmetic — all reads silently hit the default vault

**Priority: P0** (no `P0` label in repo yet — applied `bug`; add priority label when available)

## Summary
Through the MCP server, `set_vault` accepts a vault UUID and echoes the correct vault name, but **every read tool ignores it** and returns the **default vault**. A caller who scopes to a non-default vault silently receives default-vault data with **no error**. There is currently no way, via MCP, to read any vault other than the default.

This is the **MCP-server twin of the…

[Read the thread](https://github.com/engram-app/Engram/issues/985) · 2026-07-10 · closed · 1 comment

### fix(mcp): get_note silently truncates some note bodies (returns header + intro only)

## Summary
`get_note` intermittently returns only the note **header + intro block**, silently dropping the rest of the body. No error, no truncation flag.

## Reproduction
- Reproduced across **3 independent sessions/agents on the same notes** (e.g. `Engram Sync`, `Engram MCP & Search Improvements`).
- Other long notes (8–10 KB) return in full → truncation is **content/structure-dependent, not a length cap** → unpredictable.
- No `offset`/pagination param exists to retrieve the remainder.

##…

[Read the thread](https://github.com/engram-app/Engram/issues/726) · 2026-06-24 · closed · 1 comment

### MCP: surface pending-terms notice in tool responses so the AI prompts the user to re-accept

**Target: v1.1+** (part of the non-blocking material-change re-acceptance flow — see #312). Filing now so it isn't lost.

## Background
The terms re-acceptance gate (`RequireOnboarding`) is only on the **vault-scoped** pipeline (`router.ex:191`). The MCP endpoint `POST /api/mcp` runs `:oauth_api` + `OAuthScopeEnforce` only (`router.ex:241`) — it does **NOT** pass through `RequireOnboarding`.

Consequence: a user who works primarily (or entirely) through an MCP client (Claude Desktop, etc.)…

[Read the thread](https://github.com/engram-app/Engram/issues/321) · 2026-05-26 · open · 1 comment

### Split monolithic `mcp` OAuth scope into granular per-action scopes

## Problem

Today the MCP OAuth flow issues tokens with a **single monolithic scope** \`mcp\`:

\`\`\`elixir
# backend/lib/engram/oauth.ex
@valid_scopes ~w(mcp)
\`\`\`

A client with the \`mcp\` scope can do everything the user can — read, search, write, delete, edit folders, attach files. There's no in-protocol way to grant "read + search only" to a less-trusted agent.

The marketing docs ([engram-marketing#42](https://github.com/engram-app/engram-marketing/pull/42)) currently advise users:…

[Read the thread](https://github.com/engram-app/Engram/issues/174) · 2026-05-21 · open · 1 comment

### history 8: surfaces — SPA revision list + diff, MCP tools, plugin modals

Part of #609. Depends on #1711 and #1717.

## SPA

- Revision list in the note view (session timestamps, `+N -M` from `char_count`)
- Side-by-side diff using the CodeMirror we already ship
- Trash node in the sidebar tree

The tree is one cache (`['vault-tree']`) with sidebar views as `select`s of it — do not add a
second cache. See `folder-tree-optimistic-rebuild.md` and
`frontend-tree-cache-and-virtualizer.md`.

## MCP

New tools: `list_note_revisions`, `get_note_revision`,…

[Read the thread](https://github.com/engram-app/Engram/issues/1718) · 2026-09-18 · open · 0 comments

## Most recent

### ci: the SaaS onboarding chain is never exercised

Found during the #1670 review. Needs a decision from a human because it requires provisioning a CI secret.

`config/runtime.exs:462`: `billing_enabled = auth_provider == :clerk and System.get_env("PADDLE_API_KEY") != nil`.

`PADDLE_API_KEY` appears in **no** workflow (grep `.github/workflows/` is empty) and is not in the clerk `webServer.env` in `playwright.config.ts`. So CI always runs `billing_enabled=false`, and the onboarding chain is `[tools, vault]`.

That means the `/onboard/agreement`…

[Read the thread](https://github.com/engram-app/Engram/issues/1676) · 2026-09-16 · open · 0 comments

### e2e: prove a resumed MCP grant can actually call a tool

Split out of #1670 review rather than bundled.

`frontend/e2e/oauth-consent-onboarding.spec.ts` asserts that approving after the onboarding detour yields an authorization **code** with the original `state`. Minting a code always worked, including with #1666 present. The bug was that the resulting tokens then 403'd on **every tool call, forever**.

So the headline test for the #1666 fix does not actually exercise the failure mode. A regression where the wizard completes but the profile or vault…

[Read the thread](https://github.com/engram-app/Engram/issues/1675) · 2026-09-16 · open · 0 comments

### p1: MCP-first signup dead-ends — OAuth succeeds, every tool call 403s onboarding_required forever

## Summary

A user who reaches Engram through an MCP client's OAuth flow, and never through `app.engram.page`, ends up with an account that can do nothing. OAuth succeeds, tokens are issued, and then every MCP tool call returns `403 onboarding_required` forever. Nothing in the OAuth path runs or links to the onboarding wizard, so the user has no path forward and no way to know what is wrong.

This is a signup funnel leak with a legal component: these accounts exist with **no terms acceptance…

[Read the thread](https://github.com/engram-app/Engram/issues/1666) · 2026-09-16 · closed · 0 comments

### p0: ChatGPT cannot connect — CIMD refuses private_key_jwt, and we have no client_assertion support

## ChatGPT cannot connect to our MCP server, and has never been able to

`lib/engram/oauth/cimd.ex:355` refuses any CIMD document that names an auth method other than `none`:

```elixir
document["token_endpoint_auth_method"] not in [nil, "none"] ->
  {:error, :confidential_not_supported}
```

ChatGPT identifies itself with a signed client assertion (`private_key_jwt`), not a shared secret. Verified from their side: `https://chatgpt.com/oauth/jwks.json` returns 200 `application/json` with an RSA…

[Read the thread](https://github.com/engram-app/Engram/issues/1633) · 2026-09-15 · closed · 0 comments

### suggest_folder counts chunks instead of notes

## Bug

`suggest_folder` and auto-placement count chunks, not notes (`lib/engram/mcp/handlers.ex:178, 754`). One long note with 8 matching chunks outvotes other notes, and the "Notes" column shows chunk counts.

## Fix

Pass `group_by_note: true`. One line.

Minor, same area: the Jina reranker mixes the raw first-stage score (an RRF rank score in hybrid mode) with its own normalized score (`lib/engram/rerankers/jina.ex:92`). Reranker is off in prod.

[Read the thread](https://github.com/engram-app/Engram/issues/1624) · 2026-09-11 · open · 0 comments

### P0: MCP list_folder ignores its path argument and always returns the vault root

## Impact

`list_folder` (singular) returns the **vault root's** contents for every value of `path`. It does not error, so a caller has no way to know the answer is wrong — it just silently sees the wrong folder.

Sibling of #1491, which is the same defect in `delete_folder` where the consequence is data loss rather than a wrong answer. This one is filed separately because it is read-only, trivially reproducible, and is the cheapest way to probe the shared path-handling bug.

## Repro

Against…

[Read the thread](https://github.com/engram-app/Engram/issues/1492) · 2026-08-28 · closed · 0 comments

### P0: MCP delete_folder ignores its path argument and targets the vault root

## Impact

`delete_folder` appears to ignore the `path` argument entirely and resolve to the **vault root**. The only thing standing between a caller and a full-vault recursive delete is the "Refusing to delete the vault root" guard.

Hit this live against prod (vault `a800afc8-…`, 2026-08-28 ~07:15 UTC) while cleaning up a 20-note test folder:

```
delete_folder(path="99 Load Test/worker-split", recursive=true)
  → "Refusing to delete the vault root."
delete_folder(path="99 Load Test",…

[Read the thread](https://github.com/engram-app/Engram/issues/1491) · 2026-08-28 · closed · 0 comments

### Free-tier API write/RPS gates do not apply to MCP-authenticated traffic

## Summary

Free tier's "no API access" entitlement does not apply to traffic authenticated over MCP or the device flow. `RequireApiWriteEnabled` and `RequireApiRpsBudget` exempt any request that has no `:current_api_key` assign, which was intended to exempt the web SPA but also catches MCP / OAuth / device-flow tokens.

Net effect on a Free account:

| Credential | Writes | Rate limit |
|---|---|---|
| API key (`engram_…`) | 402 `api_write_not_available` | `api_rps_cap: 0`, denied |
| MCP /…

[Read the thread](https://github.com/engram-app/Engram/issues/1471) · 2026-08-25 · open · 0 comments

### fix(sync): note_changed Channel broadcast 500s on invalid UTF-8 content

## Summary
Same root cause as #727: note content can hold invalid UTF-8 (encrypted → stored as `bytea`, bypassing Postgres UTF-8 validation). When a `note_changed` event is broadcast over Phoenix Channels, the V2 JSON serializer calls `Jason.encode` on the payload `content`/`title`/etc. and raises `Jason.EncodeError`, terminating `Engram.PubSub.Adapter`.

## Evidence (prod, 2026-06-24)
```
GenServer Engram.PubSub.Adapter terminating
** (Jason.EncodeError) invalid byte 0xE2 in <<55, 49, 226>>…

[Read the thread](https://github.com/engram-app/Engram/issues/738) · 2026-06-24 · closed · 0 comments

### feat(mcp): add folder-delete and attachment (binary) move operations

## Summary
Two missing capabilities hit during a full vault reorganization:
1. **No folder-delete** — empty folders cannot be removed via MCP (left an orphaned empty folder after moving all notes out).
2. **No attachment move** — binary attachments (e.g. stamped PDFs in a `Formation/` subfolder) are **not visible to `list_folder`** and cannot be moved via `rename_note`; they had to be moved manually in Obsidian.

## Impact
Reorg/maintenance cannot be completed via MCP alone — requires manual…

[Read the thread](https://github.com/engram-app/Engram/issues/733) · 2026-06-24 · closed · 0 comments

### fix(mcp): get_note response repeats title/tags ~3x (injected header + frontmatter + H1)

## Summary
`get_note` responses repeat the title/tags **~3×**: an injected header block (Title/Tags/Path/Folder) **+** the note's own YAML frontmatter **+** its `# H1`.

## Impact
Token waste at scale and noisier context for AI clients.

## Proposed fix
Return **one** canonical metadata block; don't duplicate injected header + frontmatter + H1.

---
_Found during the 2026-06-23 Engram vault dogfooding session. Full running list: business-vault `40 Operations/Engram MCP Issue Tracker`._

[Read the thread](https://github.com/engram-app/Engram/issues/731) · 2026-06-24 · closed · 0 comments

The remaining reports are on [the project's issue tracker](https://github.com/engram-app/engram/issues).
