Apple Messages MCP
MCP server for Apple Messages on macOS.
Provides access to message history, conversation search, and sending via Messages.app. Requires Full Disk Access for history and Automation access for sending.
When to use
- Messages-only workflows
- Message history and sending without the all-in-one server
- Tighter app-level separation for permissions
What It Does
- List conversations with pagination
- Search messages and view attachment metadata
- Send and reply to messages
- Tool discovery helpers
search_toolsandget_tool_infofor context-constrained clients - Unread and recent conversation resources
- Health checks that separate history access from automation failures
- Permission recovery:
messages_permission_guide,messages_recheck_permissions
Install On This Mac
Quick start (uvx, from PyPI)
With uv installed:
uvx apple-messages-mcp
No clone, no venv management.
From a clone
git clone https://github.com/JonathanRReed/Apple-MCPs.git
cd Apple-MCPs
uv sync --all-packages
This builds one workspace environment with every server's entry point in .venv/bin (for example .venv/bin/apple-messages-mcp). You can also point an MCP client at AppleMessages-MCP/start.sh, which prefers uv run and falls back to a plain venv bootstrap (Python 3.11+ required).
Install In AI Agents
Generic MCP client config
{
"mcpServers": {
"apple-messages": {
"command": "uvx",
"args": ["apple-messages-mcp"],
"env": {
"APPLE_MESSAGES_MCP_SAFETY_MODE": "full_access"
}
}
}
}
Running from a clone instead? Use /path/to/Apple-MCPs/AppleMessages-MCP/start.sh as the command with empty args.
Claude Code example
claude mcp add --transport stdio --scope project apple-messages -- uvx apple-messages-mcp
Transport
stdio is the default and recommended transport. Set APPLE_MESSAGES_MCP_TRANSPORT=streamable-http (with optional APPLE_MESSAGES_MCP_HOST and APPLE_MESSAGES_MCP_PORT) to serve Streamable HTTP instead.
macOS Permissions
- Automation access to Messages is required for send and reply
- Full Disk Access is required for history, search, and attachment metadata from
~/Library/Messages/chat.db messages_healthreports both permission surfaces separately, so agents can tell whether send, history, or both are blocked
Launch Checklist
- Add
uvx apple-messages-mcp(or a clone'sAppleMessages-MCP/start.sh) to your MCP client - Reload or reconnect the client so the Messages tool surface is loaded into context
- Call
messages_healthfirst - If either permission surface is blocked, call
messages_permission_guide - After changing macOS permissions, call
messages_recheck_permissions
Prompting Notes
tools/listreturns the full Messages tool surface. Context-constrained clients can usesearch_toolsfirst, thenget_tool_infofor the Messages tool they need.- Resolve the recipient via Contacts before any send or reply when the user names a person.
- Confirm the intended person if Contacts returns multiple matches.
- Omit
service_nameon iMessage sends. Passing it can trigger AppleScript error-1728.
Related
Release files for apple-messages-mcp 1.0.4
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| apple_messages_mcp-1.0.4.tar.gz | 17.6 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| apple_messages_mcp-1.0.4-py3-none-any.whl | Python 3 | none | any | Details |
Total release size:33.3 kB
Release files / apple_messages_mcp-1.0.4.tar.gz
| Download URL | apple_messages_mcp-1.0.4.tar.gz |
|---|---|
| Size | 17.6 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
e70b570b7b7ec8651aa850e428059ca1bbdc9f0f34183f6f609c6349e8d21b4b
|
|
BLAKE2b-256 checksum How to use checksums |
b4e2c4bac93e29ed558a0ddcbc0f341a571581daec2fcc0193c1e32bdbbf407f
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 4, 2026.
Transparency logRelease files / apple_messages_mcp-1.0.4-py3-none-any.whl
| Download URL | apple_messages_mcp-1.0.4-py3-none-any.whl |
|---|---|
| Size | 15.8 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
8478335164173efacc475f20b347fcf7afbe4c347bd39ba61304122823588708
|
|
BLAKE2b-256 checksum How to use checksums |
87fdcd85f1f8b8e7cf598b6fc6298bda8cdb7a16d0a9131d196366a8fc36812b
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 4, 2026.
Transparency log