Apple Messages MCP
MCP server for Apple Messages on macOS.
Provides access to message history, conversation search, and sending via Messages.app. Requires Full Disk Access for history and Automation access for sending.
When to use
- Messages-only workflows
- Message history and sending without the all-in-one server
- Tighter app-level separation for permissions
What It Does
- List conversations with pagination
- Search messages and view attachment metadata
- Send and reply to messages
- Tool discovery helpers
search_toolsandget_tool_infofor context-constrained clients - Unread and recent conversation resources
- Health checks that separate history access from automation failures
- Permission recovery:
messages_permission_guide,messages_recheck_permissions
Install On This Mac
Quick start (uvx, from PyPI)
With uv installed:
uvx apple-messages-mcp
No clone, no venv management.
From a clone
git clone https://github.com/JonathanRReed/Apple-MCPs.git
cd Apple-MCPs
uv sync --all-packages
This builds one workspace environment with every server's entry point in .venv/bin (for example .venv/bin/apple-messages-mcp). You can also point an MCP client at AppleMessages-MCP/start.sh, which prefers uv run and falls back to a plain venv bootstrap (Python 3.11+ required).
Install In AI Agents
Generic MCP client config
{
"mcpServers": {
"apple-messages": {
"command": "uvx",
"args": ["apple-messages-mcp"],
"env": {
"APPLE_MESSAGES_MCP_SAFETY_MODE": "full_access"
}
}
}
}
Running from a clone instead? Use /path/to/Apple-MCPs/AppleMessages-MCP/start.sh as the command with empty args.
Claude Code example
claude mcp add --transport stdio --scope project apple-messages -- uvx apple-messages-mcp
Transport
stdio is the default and recommended transport. Set APPLE_MESSAGES_MCP_TRANSPORT=streamable-http (with optional APPLE_MESSAGES_MCP_HOST and APPLE_MESSAGES_MCP_PORT) to serve Streamable HTTP instead.
macOS Permissions
- Automation access to Messages is required for send and reply
- Full Disk Access is required for history, search, and attachment metadata from
~/Library/Messages/chat.db messages_healthreports both permission surfaces separately, so agents can tell whether send, history, or both are blocked
Launch Checklist
- Add
uvx apple-messages-mcp(or a clone'sAppleMessages-MCP/start.sh) to your MCP client - Reload or reconnect the client so the Messages tool surface is loaded into context
- Call
messages_healthfirst - If either permission surface is blocked, call
messages_permission_guide - After changing macOS permissions, call
messages_recheck_permissions
Prompting Notes
tools/listreturns the full Messages tool surface. Context-constrained clients can usesearch_toolsfirst, thenget_tool_infofor the Messages tool they need.- Resolve the recipient via Contacts before any send or reply when the user names a person.
- Confirm the intended person if Contacts returns multiple matches.
- Omit
service_nameon iMessage sends. Passing it can trigger AppleScript error-1728.
Related
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file apple_messages_mcp-1.0.2.tar.gz.
File metadata
- Download URL: apple_messages_mcp-1.0.2.tar.gz
- Upload date:
- Size: 17.4 kB
- Tags: Source
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/7.0.0 CPython/3.13.14
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
61bc7792207622385690c8d7323846c647c86a07b5c88f8f2d68d09a597cbbe5
|
|
| MD5 |
96cc3dd80fb3df35c855a374ae883bd9
|
|
| BLAKE2b-256 |
ca3c20525404aa42e2fb4f1e4e3ea3063cce483698fc2508699e0dc1b8d8b98a
|
Provenance
The following attestation bundles were made for apple_messages_mcp-1.0.2.tar.gz:
Publisher:
release.yml on JonathanRReed/Apple-MCPs
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
apple_messages_mcp-1.0.2.tar.gz -
Subject digest:
61bc7792207622385690c8d7323846c647c86a07b5c88f8f2d68d09a597cbbe5 - Sigstore transparency entry: 2348226941
- Sigstore integration time:
-
Permalink:
JonathanRReed/Apple-MCPs@60c2d5aafb6fa38f1b2e992a03bcf0f9f31b020a -
Branch / Tag:
refs/tags/v1.0.2 - Owner: https://github.com/JonathanRReed
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
release.yml@60c2d5aafb6fa38f1b2e992a03bcf0f9f31b020a -
Trigger Event:
push
-
Statement type:
File details
Details for the file apple_messages_mcp-1.0.2-py3-none-any.whl.
File metadata
- Download URL: apple_messages_mcp-1.0.2-py3-none-any.whl
- Upload date:
- Size: 15.7 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/7.0.0 CPython/3.13.14
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
16dae96a4af14e7fc4510b446b01cb2ef58c4348f0575f350c82e13b37ef0a24
|
|
| MD5 |
8b96388e48cd034fe2b2be1801232a03
|
|
| BLAKE2b-256 |
706b86d56fc4097f52da694a4df9e50cd8b7dc986215064e9c9c1df9560d66e4
|
Provenance
The following attestation bundles were made for apple_messages_mcp-1.0.2-py3-none-any.whl:
Publisher:
release.yml on JonathanRReed/Apple-MCPs
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
apple_messages_mcp-1.0.2-py3-none-any.whl -
Subject digest:
16dae96a4af14e7fc4510b446b01cb2ef58c4348f0575f350c82e13b37ef0a24 - Sigstore transparency entry: 2348227888
- Sigstore integration time:
-
Permalink:
JonathanRReed/Apple-MCPs@60c2d5aafb6fa38f1b2e992a03bcf0f9f31b020a -
Branch / Tag:
refs/tags/v1.0.2 - Owner: https://github.com/JonathanRReed
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
release.yml@60c2d5aafb6fa38f1b2e992a03bcf0f9f31b020a -
Trigger Event:
push
-
Statement type: