← Pando

Letting your agent read the notes you already have

Any MCP client and Pando, for reading the notes you already have.

The notes are already written: three years of meeting notes in an Obsidian vault, a project wiki in Notion, the decision log you kept before any agent was around to read it. What you want now is an agent that looks there first, before it asks you something those notes already answer.

If your agent works in files on the computer that holds your Obsidian vault, as Claude Code does, start it in the vault folder, and for Notion, connect it to Notion’s own MCP server, so it reads the notes where they are. For an agent that can reach neither, import them into Pando one Markdown file at a time with Import a file… in Settings, where an agent connected to Pando can read them, as a copy that does not follow later edits.

First, whether you need a copy at all

Obsidian’s help says it "stores your notes as Markdown-formatted plain text files in a vault", and that "A vault is a folder on your local file system". If your agent is Claude Code and the vault is on the same computer, open a terminal in the vault folder and start claude. Anthropic describes Claude Code as a tool that "reads your codebase, edits files, runs commands", and a vault is a folder of files, so it reads your notes where they are, with nothing copied and nothing to keep in step.

Notion runs a server of its own for this. Its developer docs call it "a remote MCP server hosted by Notion", at https://mcp.notion.com/mcp, and say that once you authorize the connection, "the MCP client can use Notion MCP tools to read and update content that you can access." If your agent speaks MCP, connect it there, and it reads your pages as they stand, including what you change in them tomorrow.

A copy in Pando is for the other cases: notes you are moving out of the old app for good, notes an agent has to reach when it does not run on the computer that holds the vault, or one project’s notes that an agent should read without the rest of what you keep. It is also for an agent that cannot sign in through a browser, a scheduled job on a server for one: Notion’s docs say its MCP server "currently requires you to complete the OAuth authorization flow", while a Pando key goes in a header and needs no sign-in. If the notes go on changing in the old app, the copy falls behind them.

Set it up

  1. Point the client at https://pando.ink/mcp, which speaks streamable HTTP.
  2. Authenticate with OAuth 2.1 and dynamic client registration, or paste a key from Agents and API keys as a Bearer token.

When the client sends you to Pando, the consent page offers “Read and write your outline” or “Read your outline only”. Reading is enough for notes, and either one starts the agent on your whole outline, the imported notes included. The box beneath, ticked by default, makes a bullet under Home, named after the client, for it to remember in.

A key works too. An agent created under Agents and API keys with “Let it read and write this outline” and “Give it a bullet of its own to remember in” both unticked reaches nothing until you give it a bullet with the press described further down, which suits an agent that should reach your notes and nothing else. It can write where you hold it, so lock the notes as that section says. Its key begins with pf_ and goes in an Authorization: Bearer header. ChatGPT cannot send one, and the Claude apps only through the Request headers setting of a custom connector, which Anthropic calls a beta for a limited set of organizations.

Bringing a note in

There is no format to choose. The picker offers .md, .markdown, .txt, .opml, .xml, .csv and .tsv, and each file is read by its own shape: Markdown, OPML, a nested HTML list, CSV, TSV or plain text. UTF-8, UTF-16 and older Windows files all read. A CSV, such as a Notion database, usually arrives as one table bullet named after the file. If the sheet says markdown beside a .csv name, the file was read line by line instead: a cell that holds a list, or a cell whose text runs over several lines, can cause that.

One file per press

The picker takes one file. It does not take a folder, and it does not open a zip: a zip is not text, and nothing comes in. Dropping a note onto the outline does not import it either, because a drop attaches a picture, a clip or a PDF and refuses anything else.

So a vault costs one press per note, and one bullet you make for each. Import the notes the agent needs for the work at hand, and let the rest wait in the old app. Notion’s export comes as one archive: choose Markdown & CSV, and its help says Export then downloads "a zip file to your hard drive containing your CSV files and Markdown versions of your Notion page(s)", so unpack it first and import the Markdown files one at a time.

Two routes carry more than one file, with limits of their own. An agent that can read the files, Claude Code started in the vault for one, can write them into Pando itself with the create tool, up to 200 bullets a call, and can put each note under a bullet named after its file as it goes. And a script holding an agent’s key can send each file’s text to POST /api/v1/import, which takes 20 imports an hour from one address.

What a note becomes

What stays behind

Two things to fix in the file first

A copy, not a sync

The import reads the file once and makes new bullets with addresses of their own. Nothing ties them back to the file, so an edit you make in Obsidian or Notion afterwards never reaches Pando, and an edit in Pando never reaches the file. If the old app stays where you write, the copy falls further behind every week, and reading the notes where they are, as above, is the better route. If you are moving over, write in Pando from then on. Export as Markdown in Settings takes the branch you are in back out whenever you want it.

Letting the agent read them, and nothing else

A connector you approve starts with your whole outline. To hold it to the notes, open the bullet above them, one called From Obsidian with Library under it for example, then open Agents and API keys in Settings, tap the agent’s row under Your agents, and press Let it reach only “…”, the bullet you are in. It then reads and writes that bullet and everything under it, remembers there, and reaches nothing else in your outline, even if you approved it read only.

That press lets it write there, so lock the notes themselves if they are for reading. Lock Library, and not the bullet above it: choose Protect it from changes in its menu, open the menu again, choose How it is protected…, and under Refuses pick Agents only. The lock covers everything under it, notes you import there later included, and it does not refuse you, so you can go on importing there. An agent writing the notes in for you is refused there, so put the lock on after it has finished. The agent still reads the notes and is refused every change to them, and it keeps the unlocked bullet above to remember in. A lock stops changes, not reading.

Tell the agent how to read them, too. The tree tool’s default outline mode leaves notes out, so the lines that became notes are missing from it. Asked for markdown mode, tree returns a branch as a document, notes, headings and tables included, which is the closest thing to the file you imported. Search with no branch named looks everywhere the agent can reach.

At the bullet limit

The free plan holds 1,000 bullets, and nearly every line of an imported note becomes one of them, so a vault fills it faster than its number of notes suggests. A spreadsheet costs one bullet per cell, empty cells included, and one more for the table: 100 rows of 10 columns under a row of column names come to 1,011 bullets, more than the free plan holds.

The sheet does not check the file against the room you have left. The import goes in pieces of up to 400 bullets, the first piece that does not fit is refused whole, and the pieces before it stay. The app then says the import stopped and how many of the bullets came in, and may open a sheet about the bullet limit as well. On the free plan, with 700 bullets already in your outline, a 350-bullet note brings in none of it.

It does not pick up where it stopped: importing the file again brings the pieces that already arrived in a second time, so undo or delete them first. Deleting bullets you no longer need makes room, since the limit counts what is in your outline, and edits, moves and deletes pass at any count. A script sending the file to POST /api/v1/import with an agent’s key is checked before anything is written, so a file that does not fit never arrives in part.

What it costs

Nothing, for 1,000 bullets, with every feature and no card. Every bullet an import makes counts as one of them.

Deeper

Connect an agent, about two minutes · The twelve tools · Which note apps an agent can reach · Who runs this