π§ SecondBrainBridge
Your Obsidian vault, searchable and reasoned over β inside ChatGPT, from your own Mac.

SecondBrainBridge is a Model Context Protocol (MCP) connector that lets ChatGPT search and reason over your Obsidian-style Markdown vault β a folder of notes on your Mac. It never uploads your notes to a third party β every action runs on your own Mac through a tiny local agent. The cloud piece is only a stateless relay that shuttles requests between ChatGPT and your Mac.
ChatGPT ββOAuthβββΊ SecondBrainBridge relay ββjob queueβββΊ second-brain-agent βββΊ Obsidian vault
(connector) (Vercel, stateless) (your Mac, polls & executes) (Markdown notes on your Mac)
Your Mac is the only place your notes are ever read or written. The relay stores only short-lived job payloads and your account record; it never sees note content unless a job is in flight, and jobs expire in seconds.
For users β 3 steps
1. Create your account at secondbrainbridge.vercel.app and generate a pairing code.
2. Install the Mac agent (needs Node 18+):
npx second-brain-agent pair <YOUR-CODE>
npx second-brain-agent install
Point it at your vault folder β set SECONDBRAIN_VAULT=/path/to/your/vault, or save the path in ~/.secondbrainbridge-agent.json. The first time the agent reads a vault kept in a protected location (Documents, Desktop, or iCloud Drive), macOS asks once for Files-and-Folders access β click OK.
3. Connect ChatGPT: Settings β Plugins β turn on Developer mode (Security & login) β Create a custom plugin β paste the MCP Server URL https://secondbrainbridge.vercel.app/mcp β Authentication OAuth β sign in & Allow.
That's it. In a new chat: "Search my notes for the Q3 planning doc" or "What did I decide about Project Atlas?"
Your Mac must be awake with the agent running. npx second-brain-agent install makes it start automatically at login and restart if it ever crashes.
Managing the agent
npx second-brain-agent status
npx second-brain-agent logs
npx second-brain-agent uninstall
What ChatGPT can do
| Tool | Action | Plan |
|---|
search_knowledge | Search your vault by keyword; returns ranked passages | Free |
ask | Ask a question and get an answer grounded in your own notes | Free |
get_note | Read one full note by title or id | Free |
list_sources | List the folders/sources in your vault | Free |
backlinks | Show the notes that link to a note (the [[wikilinks]] graph) | Pro |
create_note | Create a new Markdown note in your vault | Pro |
get_plan | Show your current plan and an upgrade link | Free |
Retrieval is v1 ranked keyword + title match, so answers stay grounded in the passages that actually appear in your notes. (Semantic/cloud ranking is a Pro/cloud enhancement.)
Plans
SecondBrainBridge is free to start. Upgrade to Pro when you want the full graph and write access.
| Free | Pro β $8/mo |
|---|
| Search, ask, and read your notes | β | β |
| List folders/sources | β | β |
| Searches per day | 20 / day | Unlimited |
Backlinks / [[wikilinks]] graph | β | β |
| Create notes from chat | β | β |
| Cloud aggregation across Macs | β | coming soon |
Billing is handled by Stripe. Upgrade at secondbrainbridge.vercel.app/upgrade, and run get_plan in any chat to see your current plan plus an upgrade link. The relay enforces the Free daily cap and gates the Pro tools by your Stripe subscription (test mode for now).
Self-hosting
You can run your own relay so nothing depends on the hosted instance.
Prereqs: a Vercel account and a Supabase project (free tiers are fine).
- Storage β in your Supabase project's SQL editor, run
supabase/schema.sql. It creates a tiny Redis-shaped KV + queue surface (nb_* functions) with RLS on.
- Deploy the
server/ directory to Vercel.
- Set env vars (see
server/.env.example):
SUPABASE_URL, SUPABASE_SERVICE_ROLE_KEY β your project + service-role key
JWT_SECRET β openssl rand -hex 32
STRIPE_SECRET_KEY, STRIPE_WEBHOOK_SECRET β for the Pro tier (optional; Free-only if omitted)
- Verify:
curl https://YOUR-APP.vercel.app/api/health β redisConfigured, redisOk, jwtSecretSet all true.
- Point the agent at it:
npx second-brain-agent pair <CODE> --server https://YOUR-APP.vercel.app.
How it works
- Auth β OAuth 2.1 with PKCE and Dynamic Client Registration (RFC 7591). ChatGPT registers itself, the user signs in on the SecondBrainBridge consent page, and ChatGPT gets a scoped MCP access token. JWTs are HMAC-signed; three kinds (
session, agent, mcp) with distinct privileges. Optional email verification via Resend (RESEND_API_KEY); off unless configured, and enforcement is opt-in (REQUIRE_EMAIL_VERIFICATION).
- Relay β MCP tool call β job pushed to
jobs:<user> (TTL β€ the caller's wait window, so an abandoned job can't run late) β the Mac agent (holding a hanging long-poll) is handed the job within ~200ms, executes it, pushes the result β the MCP handler returns it. The long-poll means jobs are delivered on arrival rather than on a fixed interval, so relay overhead is ~300ms instead of ~1s. The agent is considered "online" only while it's actively connected. The relay also enforces the Free daily search cap and unlocks the Pro tools based on the account's Stripe subscription.
- Agent β a dependency-free Node CLI. It indexes the Markdown files in your vault folder and answers retrieval queries locally (ranked keyword + title match);
create_note writes a new Markdown file into the vault. Reads and writes happen straight against the filesystem β the first touch of a protected folder triggers the one-time macOS Files-and-Folders prompt. A macOS LaunchAgent keeps it alive across logins and crashes.
Repository layout
server/ Vercel functions: OAuth + MCP endpoint + relay + Stripe billing (deploy this)
agent/ second-brain-agent β the npm-published Mac CLI that indexes your vault (users npx this)
kit/ Browser automations: register the dev-mode connector AND
fill the OpenAI directory submission (see kit/README.md)
supabase/ schema.sql for self-hosting the storage
test/ end-to-end OAuth + MCP integration test
Development
cd server && cp .env.example .env.local
node test/e2e-oauth.mjs
node --test agent/test-agent-unit.mjs
Security & privacy
- Notes are read/written only on your Mac. The relay never persists note content β job payloads live in Redis-shaped storage with a short TTL and are deleted on delivery.
- The agent token (and your vault path) is stored at
~/.secondbrainbridge-agent.json (mode 600); the vault path can also come from SECONDBRAIN_VAULT.
- No secrets are committed; see
.gitignore and the .env.example files.
- The write tool (
create_note) is marked destructive so ChatGPT asks before adding a note.
License
MIT Β© Isaiah Dupree