Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
To run the official filesystem MCP server on Windows, configure your MCP client to launch npx through cmd /c, then pass only the folders the server should be allowed to access. In VS Code, use its MCP user configuration or a workspace .vscode/mcp.json; for Docker, mount the permitted folders and use the matching container paths. The server’s allowlist limits its filesystem operations, but it is not by itself a Windows-wide security sandbox.
What the filesystem MCP server does
The official Model Context Protocol filesystem server is a Node.js package named @modelcontextprotocol/server-filesystem. It exposes tools for reading and writing files, creating, listing, and deleting directories, moving files or directories, searching, viewing file metadata, and reporting allowed directories. Its operations are restricted to the directories made available through startup arguments or supported MCP Roots. See the official filesystem server project and its implementation.
This is useful when an MCP-capable editor or desktop assistant needs to work with project files. The important setup decision is not merely how to start the process: it is which paths to expose and whether the workflow actually needs write access.
Recommended Free Tools
Before you configure it
- Choose the MCP client first. Configuration filenames and JSON structure differ between hosts; use that client’s current documentation for its required envelope.
- Install or otherwise make available Node.js and npm/npx if using the npx route. The official example uses
npx -yand does not pin a package version, so it can retrieve the current package selected by npm. - Choose a specific project or working folder, rather than granting a broad location such as your entire user profile or a drive root.
- If you plan to use Docker, confirm Docker is available and decide which host folders the container needs to see.
The project documentation describes these configuration forms; it does not establish that Node.js, Docker, or every MCP client is already installed or compatible on a particular Windows machine.
#1 Best Overall
- Easily store and access 2TB to content on the go with the Seagate Portable Drive, a USB external hard drive
- Designed to work with Windows or Mac computers, this external hard drive makes backup a snap just drag and drop
- To get set up, connect the portable hard drive to a computer for automatic recognition no software required
- This USB drive provides plug and play simplicity with the included 18 inch USB 3.0 cable
- The available storage capacity may vary.
Set up the server with npx on Windows
The documented Windows launch pattern invokes npx through cmd /c. A minimal server entry looks like this:
{
"command": "cmd",
"args": [
"/c",
"npx",
"-y",
"@modelcontextprotocol/server-filesystem",
"C:\Users\you\Documents\project"
]
}
Replace the sample path with the exact directory you intend to expose. If you need multiple locations, pass each as an additional path argument after the package name. For example:
{
"command": "cmd",
"args": [
"/c",
"npx",
"-y",
"@modelcontextprotocol/server-filesystem",
"C:\Users\you\Documents\project",
"D:\Shared\reference-files"
]
}
These are server-entry fragments, not complete universal client configuration files. Put the entry under the key and in the JSON file required by your host. The project README also shows Windows paths with forward slashes and a VS Code example that uses ${workspaceFolder}; follow the syntax supported by your client.
Free tools Windows power users keep installed
One-click scans. No signup required.
Why the cmd /c wrapper matters
On Windows, the documented npx example asks the client to run cmd, with /c telling the command interpreter to run the following command and exit. The remaining arguments identify npx, accept the package prompt with -y, name the filesystem server package, and specify its allowed path or paths.
Using forward slashes or workspace paths
JSON strings require backslashes in Windows paths to be escaped, as in C:UsersyouDocumentsproject in the JSON source. Some documented examples use forward slashes, which can make paths easier to read in JSON. A client may also substitute a workspace variable such as ${workspaceFolder}; use it only where the host recognizes that variable, and check that the resolved folder is the one you intend to grant.
Configure it in VS Code
The project README describes two VS Code configuration locations: user-level configuration opened with the MCP: Open User Configuration command, and workspace configuration at .vscode/mcp.json. The user-level route is for a personal setup; the workspace file scopes the configuration to a project and may be shared with that workspace. The precise JSON wrapper and supported features can change with VS Code, so follow its current MCP configuration schema and place the server entry there.
Rank #2
- Easily store and access 5TB of content on the go with the Seagate portable drive, a USB external hard Drive
- Designed to work with Windows or Mac computers, this external hard drive makes backup a snap just drag and drop
- To get set up, connect the portable hard drive to a computer for automatic recognition software required
- This USB drive provides plug and play simplicity with the included 18 inch USB 3.0 cable
- The available storage capacity may vary.
- Open the Command Palette and choose
MCP: Open User Configuration, or open/create.vscode/mcp.jsonin the intended workspace. - Add the server definition using the host’s expected JSON envelope. Set the command to
cmdand its arguments to/c,npx,-y,@modelcontextprotocol/server-filesystem, and the allowed folder path or paths. - Save the configuration and use VS Code’s MCP controls to start or enable the server, as applicable to your installed version.
- Use the server’s
list_allowed_directoriestool, if exposed by the client, to inspect the active directory boundary.
A workspace configuration can make the server definition portable, but it should not automatically grant access to a broad or sensitive path just because the file is shared. Review the paths before enabling a workspace’s server.
Limit which folders the server can access
Use least privilege: give the server only the directory or directories needed for the task. Startup directory arguments provide a fixed boundary for that launch. If an MCP client supports Roots, it can provide the directories dynamically instead; the server uses supplied Roots as its allowed directories and can update them when it receives a Roots-changed notification.
Roots support is client-dependent. If the client does not support Roots, or does not supply usable roots, provide at least one startup directory. The project warns that initialization can fail when no startup directories are supplied and the client cannot provide usable Roots. The server’s list_allowed_directories tool can help confirm which directories are active.
Choose writable or read-only access deliberately
The filesystem server includes mutating tools. write_file can create a file or overwrite an existing one; edit_file changes content and offers a dry-run diff option; moving files and directories also changes the filesystem. The implementation marks actions such as write, edit, and move as destructive. Keep the allowed paths narrow, and review consequential tool calls rather than treating the allowlist as approval for every change.
Where the workflow only needs reading and the client or deployment supports a read-only boundary, use it. Docker bind mounts can be marked read-only; that constrains writes through that mount. A server-level allowed-directory list and a Docker mount are distinct controls: the former limits the server’s intended operations, while the latter determines what host files are mounted into the container.
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Repair Windows errors before they cause bigger problemsFix Now →Use Docker instead of npx
The project also documents a Docker route. It can suit a setup that prefers a containerized runtime, but it requires the host directory mounts and the paths passed to the server to agree. The README’s VS Code Docker example mounts folders under /projects inside the container, and shows a read-only mount form for a selected folder.
Rank #3
- Easily store and access 1TB to content on the go with the Seagate Portable Drive, a USB external hard drive.Specific uses: Personal
- Designed to work with Windows or Mac computers, this external hard drive makes backup a snap just drag and drop. Reformatting may be required for Mac
- To get set up, connect the portable hard drive to a computer for automatic recognition no software required
- This USB drive provides plug and play simplicity with the included 18 inch USB 3.0 cable
- The available storage capacity may vary.
Conceptually, if a host folder is mounted at /projects/work, the server’s allowed path should refer to /projects/work in the container, not the original Windows host path. Mount only the folders needed, and use the documented Docker configuration shape for your host. A read-only mount is appropriate when file modification is unnecessary; a writable mount is necessary for tasks that must create or edit files.
| Choice | What sets the boundary | Good fit |
|---|---|---|
| npx with startup paths | Paths passed as command-line arguments at launch | A direct setup when Node.js/npm are available and a fixed folder set is sufficient |
| MCP Roots | Directories supplied and potentially updated by a Roots-capable client | A host that supports dynamic Roots and can provide the intended directories |
| Docker with bind mounts | Host folders exposed at container paths, optionally read-only, plus server paths inside the container | A container-based setup where explicit mounts fit the workflow |
None of these choices is universally safer or easier: the result depends on the client, runtime, actual paths, permissions, and mounts you configure.
Verify the active boundary and test cautiously
- Start the server through the MCP client and check the client’s server status or logs for startup errors.
- Call
list_allowed_directoriesand check that the reported paths are the intended scope. - Try a non-destructive listing or metadata operation on a file inside an allowed folder.
- If write access is required, test first on a disposable file in the project folder. Confirm overwrite and edit behavior before allowing consequential changes to important files.
- For Docker, verify both that the host folder is mounted and that the server is using the matching container path. If read-only behavior is intended, confirm that writes are not permitted through the mount.
Troubleshooting common setup failures
The client cannot start cmd or npx
Check that the command is exactly cmd, that the first argument is /c, and that npx is available in the environment seen by the client. Node.js/npm may be installed for an interactive shell but not visible to a client launched with a different environment. Confirm the installation and PATH for the account running the client, then restart the client if it does not refresh environment variables.
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →JSON fails to parse
Check commas, quotation marks, and escaped backslashes in Windows paths. In JSON, write a backslash as \ in the actual configuration text. Also ensure you have added the entry inside the structure required by the MCP host rather than pasting the fragment as a whole file.
The server reports initialization failure or no accessible folders
Pass one or more valid startup directories, unless you know the client supports Roots and is supplying usable directories. Verify the path exists, is spelled correctly, and is accessible to the Windows account running the process. With Docker, remember that a host path is not automatically visible in the container: mount it and pass the container-side path.
The server starts, but a requested file is outside the allowed directories
Check list_allowed_directories, then add the specific required folder to the startup arguments or configure the client’s Roots correctly. Do not solve a path mismatch by exposing an entire drive unless the task genuinely requires that scope.
Rank #4
- Easily store and access 4TB of content on the go with the Seagate Portable Drive, a USB external hard drive.Specific uses: Personal
- Designed to work with Windows or Mac computers, this external hard drive makes backup a snap just drag and drop
- To get set up, connect the portable hard drive to a computer for automatic recognition no software required
- This USB drive provides plug and play simplicity with the included 18 inch USB 3.0 cable
- The available storage capacity may vary.
A Docker path works on the host but not in the container
Compare the host source path, the mount destination, and the server’s allowed path. They must form a consistent mapping. If the container sees the folder under /projects, pass that container path to the server rather than a Windows drive-letter path.
Changes fail in a read-only setup
A read-only Docker mount intentionally prevents changes through that mount. Use a writable mount only if the task needs edits, and keep it limited to the required folder. If using the npx route, inspect the specific client and operating-system permissions as well as the server allowlist; the allowlist is not an OS-level read-only guarantee.
How this differs from Windows agent registration
Adding the server to VS Code or another MCP host config connects that particular client to the server. It is separate from registering a server with Windows’ on-device agent registry. Microsoft describes registry registration routes involving package identity/MSIX, direct installation of an MCP bundle, or manual registration through a registry command-line tool. Microsoft also describes contained agent sessions with access restricted to approved resources as the default for servers accessed through that registry. Directly installed bundles without package identity cannot run in that contained process and require users to reduce connector protections to make them accessible. Those Windows registry rules do not automatically apply to every editor or MCP client. See Microsoft’s MCP servers on Windows overview.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Or skip the browser setup
The filesystem MCP server is for local files. If the job is to capture a website, ScreenshotNeo is a separate website screenshot API and MCP server for developers. One GET request can return a PNG, JPEG, WebP, or PDF. Its capture flow accepts cookie/consent banners and removes more than 60 known consent platforms, newsletter popups, and chat widgets; each step can be turned off. Bot checks, blank pages, timeouts, failed loads, and cache hits are not billed, with the outcome reported in response headers. An MCP server provides take_screenshot, get_page_info, and capture_pdf tools for Claude, Cursor, and other MCP clients.
Example cURL request (replace YOUR_API_KEY with your key):
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
See the ScreenshotNeo API documentation for configuration and available options. The same request can be made in Python:
import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"}, timeout=90)
open("shot.webp", "wb").write(r.content)
Or in Node.js:
const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);
ScreenshotNeo’s free plan includes 1,000 shots per month with no card; paid plans start at $5 for 3,000 shots. Sign up for 1,000 free screenshots a month with no card.
Best Value
- [Upgraded Version] - This external hard drive features a mirrored logo stripe combined with a striped anti-slip design, and the rounded corners of the casing make it easier to grip. The stripes also have a heat dissipation function, ensuring stable and fast data transfer.
- 【Ultra-thin and quiet】 - The motherboard adopts JMicron 578 noise-free solution, giving you a quiet working environment. Lightweight and portable size designed to fit in your pocket for easy portability.
- 【Ultra-Fast Data Transfers】 - Pairing this external hard drive with JMicron 578 solution USB 3.0 and USB 2.0 interfaces enables blazing-fast data transfer. It boasts theoretical read speeds of up to 125MB/s and write speeds of up to 103MB/s.
- 【Plug and Play】 - With no software to install, just plug it in and the drive is ready to use.The hard disk chip is wrapped with an aluminum anti-interference layer to increase heat dissipation and protect data.
- 【What You Get】 - 1 x Portable Hard Drive, 1 x USB 3.0 Cable, 1 x User Manual, Gift-type shell packaging ,Three-year manufacturer's warranty and free technical support services.
Cost, reliability, and maintenance notes
The filesystem server itself is launched from the npm package using the documented unpinned npx -y pattern. Because that does not name a fixed package version, a later launch may resolve a newer release; check the current project or package information if reproducibility matters. For a stable team setup, document the client configuration, paths, and runtime expectations, and review package changes through your normal dependency-management process.
Startup reliability depends on the pieces in your own environment: the MCP host, command resolution, Node.js/npm or Docker, filesystem permissions, and correct paths. A server process starting successfully does not prove that the path scope is appropriate; inspect the active directories and test the intended operations.
Frequently Asked Questions
Can I give the filesystem MCP server access to my whole C: drive?
The server accepts allowed directories, but broad access increases the consequences of a mistaken or malicious file operation. Prefer the smallest project folder that meets the task.
Does configuring the server in VS Code register it with Windows?
No. VS Code MCP configuration connects VS Code to the server; Windows on-device agent registry registration is a separate platform mechanism.
Can I use this server without Node.js?
The documented npx route requires Node.js/npm tooling. The project also documents Docker as an alternative deployment route.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

