Skip to main content

Apple Messages MCP

MCP server for Apple Messages on macOS.

Provides access to message history, conversation search, and sending via Messages.app. Requires Full Disk Access for history and Automation access for sending.

When to use

  • Messages-only workflows
  • Message history and sending without the all-in-one server
  • Tighter app-level separation for permissions

What It Does

  • List conversations with pagination
  • Search messages and view attachment metadata
  • Send and reply to messages
  • Tool discovery helpers search_tools and get_tool_info for context-constrained clients
  • Unread and recent conversation resources
  • Health checks that separate history access from automation failures
  • Permission recovery: messages_permission_guide, messages_recheck_permissions

Install On This Mac

Quick start (uvx, from PyPI)

With uv installed:

uvx apple-messages-mcp

No clone, no venv management.

From a clone
git clone https://github.com/JonathanRReed/Apple-MCPs.git
cd Apple-MCPs
uv sync --all-packages

This builds one workspace environment with every server's entry point in .venv/bin (for example .venv/bin/apple-messages-mcp). You can also point an MCP client at AppleMessages-MCP/start.sh, which prefers uv run and falls back to a plain venv bootstrap (Python 3.11+ required).

Install In AI Agents

Generic MCP client config
{
  "mcpServers": {
    "apple-messages": {
      "command": "uvx",
      "args": ["apple-messages-mcp"],
      "env": {
        "APPLE_MESSAGES_MCP_SAFETY_MODE": "full_access"
      }
    }
  }
}

Running from a clone instead? Use /path/to/Apple-MCPs/AppleMessages-MCP/start.sh as the command with empty args.

Claude Code example
claude mcp add --transport stdio --scope project apple-messages -- uvx apple-messages-mcp

Transport

stdio is the default and recommended transport. Set APPLE_MESSAGES_MCP_TRANSPORT=streamable-http (with optional APPLE_MESSAGES_MCP_HOST and APPLE_MESSAGES_MCP_PORT) to serve Streamable HTTP instead.

macOS Permissions

  • Automation access to Messages is required for send and reply
  • Full Disk Access is required for history, search, and attachment metadata from ~/Library/Messages/chat.db
  • messages_health reports both permission surfaces separately, so agents can tell whether send, history, or both are blocked

Launch Checklist

  • Add uvx apple-messages-mcp (or a clone's AppleMessages-MCP/start.sh) to your MCP client
  • Reload or reconnect the client so the Messages tool surface is loaded into context
  • Call messages_health first
  • If either permission surface is blocked, call messages_permission_guide
  • After changing macOS permissions, call messages_recheck_permissions

Prompting Notes

  • tools/list returns the full Messages tool surface. Context-constrained clients can use search_tools first, then get_tool_info for the Messages tool they need.
  • Resolve the recipient via Contacts before any send or reply when the user names a person.
  • Confirm the intended person if Contacts returns multiple matches.
  • Omit service_name on iMessage sends. Passing it can trigger AppleScript error -1728.

Related

Release files for apple-messages-mcp 1.0.3

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for apple-messages-mcp 1.0.3
File Size Uploaded
apple_messages_mcp-1.0.3.tar.gz 17.5 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for apple-messages-mcp 1.0.3
File Interpreter ABI Platform
apple_messages_mcp-1.0.3-py3-none-any.whl Python 3 none any Details

Total release size: 33.2 kB

Release files / apple_messages_mcp-1.0.3.tar.gz

Download URL apple_messages_mcp-1.0.3.tar.gz
Size 17.5 kB
Tags Source
SHA-256 checksum
How to use checksums
938e2cb29b165522cea46eb69c748a1262e1833e56834d35c2cc83124b803565
BLAKE2b-256 checksum
How to use checksums
e1e2ecabb9553dbb5f11703b7acd05dc179fb81aca64652ecb52db702eee61a2
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 1, 2026.

Transparency log

Release files / apple_messages_mcp-1.0.3-py3-none-any.whl

Download URL apple_messages_mcp-1.0.3-py3-none-any.whl
Size 15.7 kB
Tags Python 3
SHA-256 checksum
How to use checksums
1650e0472b60060f0218d0590ad81ad007a36976b5bca2755c86e069bdcf696e
BLAKE2b-256 checksum
How to use checksums
064b7837f8d148952d37a34b6ccdeb7c1e9b6ca8429efba510c0283c6215722f
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 1, 2026.

Transparency log

Release history Release notifications | RSS feed

1.0.4

2 release files

This release

1.0.3 This release

2 release files

1.0.2

2 release files

1.0.1

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page