Skip to content

MCP Roots and File System Access

How MCP clients tell servers which directories are in scope, and how to handle file system access safely.

Editorial team 1 min read

Many MCP servers work with files: reading project code, searching documents, writing output. The protocol and good practice help keep this access bounded.

Roots

Clients can tell servers which roots — typically directories — are relevant to the current session, such as the project the user has open. Servers should confine their work to these locations.

Roots are a coordination mechanism, not an enforcement mechanism: a local server with file system access could still read elsewhere. Enforcement comes from sandboxing and operating-system permissions.

Safe File Access

  • Resolve paths and reject ones outside allowed directories, including via .. segments and symbolic links.
  • Separate read and write tools; make write tools clearly labelled.
  • Avoid exposing sensitive locations: home directory secrets, SSH keys, credential files.
  • Limit file sizes returned.

For Users

Grant file servers access only to the directories they need, and run untrusted servers in isolated environments.

Remote Servers

Remote servers don't see local files at all unless the host sends content; they work on their own storage with user-specific permissions.

More in MCP

All MCP guides →
MCP Guide · 1 min

MCP Architecture: Hosts, Clients and Servers

How the Model Context Protocol is structured: the host application, the clients it creates and the servers that expose capabilities.

MCP 1 min read 2 Sep 2025

MCP Guide · 2 min

MCP Tools, Resources and Prompts

The three main things an MCP server can offer, who controls each, and when to use which.

MCP 2 min read 1 Sep 2025

MCP Guide · 1 min

MCP Transports: stdio and HTTP

How MCP messages travel: standard input and output for local servers, HTTP for remote ones, and how to choose.

MCP 1 min read 31 Aug 2025

MCP Guide · 1 min

Building Your First MCP Server

A walkthrough of the steps to create a simple MCP server that exposes a tool, and how to test it.

MCP 1 min read 30 Aug 2025