Skip to main content

Apple Messages MCP

MCP server for Apple Messages on macOS.

Provides access to message history, conversation search, and sending via Messages.app. Requires Full Disk Access for history and Automation access for sending.

When to use

  • Messages-only workflows
  • Message history and sending without the all-in-one server
  • Tighter app-level separation for permissions

What It Does

  • List conversations with pagination
  • Search messages and view attachment metadata
  • Send and reply to messages
  • Tool discovery helpers search_tools and get_tool_info for context-constrained clients
  • Unread and recent conversation resources
  • Health checks that separate history access from automation failures
  • Permission recovery: messages_permission_guide, messages_recheck_permissions

Install On This Mac

Quick start (uvx, from PyPI)

With uv installed:

uvx apple-messages-mcp

No clone, no venv management.

From a clone
git clone https://github.com/JonathanRReed/Apple-MCPs.git
cd Apple-MCPs
uv sync --all-packages

This builds one workspace environment with every server's entry point in .venv/bin (for example .venv/bin/apple-messages-mcp). You can also point an MCP client at AppleMessages-MCP/start.sh, which prefers uv run and falls back to a plain venv bootstrap (Python 3.11+ required).

Install In AI Agents

Generic MCP client config
{
  "mcpServers": {
    "apple-messages": {
      "command": "uvx",
      "args": ["apple-messages-mcp"],
      "env": {
        "APPLE_MESSAGES_MCP_SAFETY_MODE": "full_access"
      }
    }
  }
}

Running from a clone instead? Use /path/to/Apple-MCPs/AppleMessages-MCP/start.sh as the command with empty args.

Claude Code example
claude mcp add --transport stdio --scope project apple-messages -- uvx apple-messages-mcp

Transport

stdio is the default and recommended transport. Set APPLE_MESSAGES_MCP_TRANSPORT=streamable-http (with optional APPLE_MESSAGES_MCP_HOST and APPLE_MESSAGES_MCP_PORT) to serve Streamable HTTP instead.

macOS Permissions

  • Automation access to Messages is required for send and reply
  • Full Disk Access is required for history, search, and attachment metadata from ~/Library/Messages/chat.db
  • messages_health reports both permission surfaces separately, so agents can tell whether send, history, or both are blocked

Launch Checklist

  • Add uvx apple-messages-mcp (or a clone's AppleMessages-MCP/start.sh) to your MCP client
  • Reload or reconnect the client so the Messages tool surface is loaded into context
  • Call messages_health first
  • If either permission surface is blocked, call messages_permission_guide
  • After changing macOS permissions, call messages_recheck_permissions

Prompting Notes

  • tools/list returns the full Messages tool surface. Context-constrained clients can use search_tools first, then get_tool_info for the Messages tool they need.
  • Resolve the recipient via Contacts before any send or reply when the user names a person.
  • Confirm the intended person if Contacts returns multiple matches.
  • Omit service_name on iMessage sends. Passing it can trigger AppleScript error -1728.

Related

Release files for apple-messages-mcp 1.0.4

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for apple-messages-mcp 1.0.4
File Size Uploaded
apple_messages_mcp-1.0.4.tar.gz 17.6 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for apple-messages-mcp 1.0.4
File Interpreter ABI Platform
apple_messages_mcp-1.0.4-py3-none-any.whl Python 3 none any Details

Total release size:33.3 kB

Release files / apple_messages_mcp-1.0.4.tar.gz

Download URL apple_messages_mcp-1.0.4.tar.gz
Size 17.6 kB
Tags Source
SHA-256 checksum
How to use checksums
e70b570b7b7ec8651aa850e428059ca1bbdc9f0f34183f6f609c6349e8d21b4b
BLAKE2b-256 checksum
How to use checksums
b4e2c4bac93e29ed558a0ddcbc0f341a571581daec2fcc0193c1e32bdbbf407f
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 4, 2026.

Transparency log

Release files / apple_messages_mcp-1.0.4-py3-none-any.whl

Download URL apple_messages_mcp-1.0.4-py3-none-any.whl
Size 15.8 kB
Tags Python 3
SHA-256 checksum
How to use checksums
8478335164173efacc475f20b347fcf7afbe4c347bd39ba61304122823588708
BLAKE2b-256 checksum
How to use checksums
87fdcd85f1f8b8e7cf598b6fc6298bda8cdb7a16d0a9131d196366a8fc36812b
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 4, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

1.0.4 This release

2 release files

1.0.3

2 release files

1.0.2

2 release files

1.0.1

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page