Linkwarden keeps a permanent copy of every page it saves. get_link_content serves that article text, so a saved link can be summarised or quoted without fetching the live site again — and long articles are sliced, not dumped.
Organises without clobbering
Linkwarden's update routes replace whole records. This server reads the current state and merges, so changing a title never silently strips a link's tags or a collection's collaborators.
Destructive actions ask a person
Deleting, re-preserving, renaming a tag or publishing a collection raises a real dialog through MCP elicitation — one the model cannot answer on its behalf. Where the client cannot show one it falls back to a token bound to the exact target, and says which of the two it was rather than implying somebody approved.
You choose what is registered
LINKWARDEN_READ_ONLY=true does not register the write tools at all — they are absent from tools/list, not merely refused at call time. LINKWARDEN_ALLOW_TOOLS cuts finer still — essential for a curated eight, your own comma-separated list, or a whole family with list_* — while LINKWARDEN_DENY_TOOLS removes individual tools. A name that matches nothing stops the server at startup rather than quietly hiding a tool.
The server holds no state of its own beyond short-lived approvals.
"What did that article I bookmarked about the Model Context Protocol actually say about transports?"
The assistant searches your collection, finds the link, and reads the copy Linkwarden preserved — even if the original page has since changed or gone.
A token is an account, not a scope
Linkwarden has no per-token permissions: a token carries everything the account that created it can do. Create a dedicated account with access only to the collections this server should see. See Security.
A client that cannot spawn a local process — ChatGPT connectors, Claude on the web, Cursor, LibreChat — cannot start linkwarden-mcp the way Claude Code does. mcp-hub is the bridge: one container serves many stdio MCP servers over Streamable HTTP, with an OAuth 2.1 login behind a single password and long-lived tokens for the clients that cannot do OAuth. Its /hub endpoint puts every server behind six meta-tools, so one connector reaches all of them without N×tool schemas in the model's context, and it speaks both protocol revisions — a question this server asks travels through it to the person at the far end instead of ending at the gateway.
Its configuration is Claude Code's mcpServers format, so the entry you already have is the entry it takes: Through mcp-hub.