Apple Notes MCP
MCP server for Apple Notes on macOS.
Provides access to notes and folders for creation, organization, and management. Keep Notes as the system of record while enabling agents to read, create, update, move, and delete notes.
When to use
- Notes-only workflows
- Stronger isolation than the all-in-one server
- Structured note and folder operations through the native Notes app
What It Does
- List accounts and folders
- List, search, and manage notes (CRUD)
- Create, rename, and delete folders
- List note attachments
- Tool discovery helpers
search_toolsandget_tool_infofor context-constrained clients - Recent-note resources and organization prompts
- Health and permission checks:
notes_health,notes_permission_guide,notes_recheck_permissions
Install On This Mac
From a clone
git clone https://github.com/JonathanRReed/Apple-MCPs.git
cd Apple-MCPs
uv sync --all-packages
This builds one workspace environment with every server's entry point in .venv/bin (for example .venv/bin/apple-notes-mcp). You can also point an MCP client at AppleNotes-MCP/start.sh, which prefers uv run and falls back to a plain venv bootstrap (Python 3.11+ required).
Install In AI Agents
Generic MCP client config
{
"mcpServers": {
"apple-notes": {
"command": "uvx",
"args": ["apple-mcp-notes"],
"env": {
"APPLE_NOTES_MCP_SAFETY_MODE": "full_access"
}
}
}
}
Running from a clone instead? Use /path/to/Apple-MCPs/AppleNotes-MCP/start.sh as the command with empty args.
Claude Code example
claude mcp add --transport stdio --scope project apple-notes -- uvx apple-mcp-notes
Safety Modes
safe_readonlysafe_managefull_access
Transport
stdio is the default and recommended transport. Set APPLE_NOTES_MCP_TRANSPORT=streamable-http (with optional APPLE_NOTES_MCP_HOST and APPLE_NOTES_MCP_PORT) to serve Streamable HTTP instead.
Script Timeout
Every AppleScript call is bounded by APPLE_NOTES_MCP_SCRIPT_TIMEOUT_SECONDS (default 60, minimum 5) so a stalled Notes.app can never hang an MCP request indefinitely. If a create-note call times out after the note was already committed, the server looks the note up by title in the target folder and returns it; when the outcome cannot be verified it returns a structured NOTE_CREATE_STATUS_UNKNOWN error instead of leaving the client guessing.
macOS Permissions
- Automation access to Notes is required
Launch Checklist
- Add
uvx apple-mcp-notes(or a clone'sAppleNotes-MCP/start.sh) to your MCP client - Reload or reconnect the client so the Notes tool surface is loaded into context
- Call
notes_healthfirst - If Notes automation is blocked, call
notes_permission_guide - After changing macOS permissions, call
notes_recheck_permissions
Prompting Notes
tools/listreturns the full Notes tool surface. Context-constrained clients can usesearch_toolsfirst, thenget_tool_infofor the Notes tool they need.- Multiple accounts may each contain a Notes folder. Identify available accounts and folders on first use and set a default.
- Use Notes for reference material and saved context.
- Time-sensitive items should go to Reminders or Calendar instead.
Related
Release files for apple-mcp-notes 1.0.4
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| apple_mcp_notes-1.0.4.tar.gz | 23.0 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| apple_mcp_notes-1.0.4-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 52.1 kB
Release files / apple_mcp_notes-1.0.4.tar.gz
| Download URL | apple_mcp_notes-1.0.4.tar.gz |
|---|---|
| Size | 23.0 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
66728311d8ffba248bc05939562e5670dcc8b9222ae842278e79f65418ace541
|
|
BLAKE2b-256 checksum How to use checksums |
02a083eaa3bfb0ae405e5e18aa3e9408af74288127dca45c1355fc751e11dab3
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 4, 2026.
Transparency logRelease files / apple_mcp_notes-1.0.4-py3-none-any.whl
| Download URL | apple_mcp_notes-1.0.4-py3-none-any.whl |
|---|---|
| Size | 29.0 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
d7bd4e3ac7bd936a1563e540538dfe724d58df481de26a70b6fca3129d4b2571
|
|
BLAKE2b-256 checksum How to use checksums |
6c10e79ea887e689e46a0300264b58690f5204e4db36615917fff3feaabbb790
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 4, 2026.
Transparency log