Skip to main content

Apple Messages MCP

MCP server for Apple Messages on macOS.

Provides access to message history, conversation search, and sending via Messages.app. Requires Full Disk Access for history and Automation access for sending.

When to use

  • Messages-only workflows
  • Message history and sending without the all-in-one server
  • Tighter app-level separation for permissions

What It Does

  • List conversations with pagination
  • Search messages and view attachment metadata
  • Send and reply to messages
  • Tool discovery helpers search_tools and get_tool_info for context-constrained clients
  • Unread and recent conversation resources
  • Health checks that separate history access from automation failures
  • Permission recovery: messages_permission_guide, messages_recheck_permissions

Install On This Mac

Quick start (uvx, from PyPI)

With uv installed:

uvx apple-messages-mcp

No clone, no venv management.

From a clone
git clone https://github.com/JonathanRReed/Apple-MCPs.git
cd Apple-MCPs
uv sync --all-packages

This builds one workspace environment with every server's entry point in .venv/bin (for example .venv/bin/apple-messages-mcp). You can also point an MCP client at AppleMessages-MCP/start.sh, which prefers uv run and falls back to a plain venv bootstrap (Python 3.11+ required).

Install In AI Agents

Generic MCP client config
{
  "mcpServers": {
    "apple-messages": {
      "command": "uvx",
      "args": ["apple-messages-mcp"],
      "env": {
        "APPLE_MESSAGES_MCP_SAFETY_MODE": "full_access"
      }
    }
  }
}

Running from a clone instead? Use /path/to/Apple-MCPs/AppleMessages-MCP/start.sh as the command with empty args.

Claude Code example
claude mcp add --transport stdio --scope project apple-messages -- uvx apple-messages-mcp

Transport

stdio is the default and recommended transport. Set APPLE_MESSAGES_MCP_TRANSPORT=streamable-http (with optional APPLE_MESSAGES_MCP_HOST and APPLE_MESSAGES_MCP_PORT) to serve Streamable HTTP instead.

macOS Permissions

  • Automation access to Messages is required for send and reply
  • Full Disk Access is required for history, search, and attachment metadata from ~/Library/Messages/chat.db
  • messages_health reports both permission surfaces separately, so agents can tell whether send, history, or both are blocked

Launch Checklist

  • Add uvx apple-messages-mcp (or a clone's AppleMessages-MCP/start.sh) to your MCP client
  • Reload or reconnect the client so the Messages tool surface is loaded into context
  • Call messages_health first
  • If either permission surface is blocked, call messages_permission_guide
  • After changing macOS permissions, call messages_recheck_permissions

Prompting Notes

  • tools/list returns the full Messages tool surface. Context-constrained clients can use search_tools first, then get_tool_info for the Messages tool they need.
  • Resolve the recipient via Contacts before any send or reply when the user names a person.
  • Confirm the intended person if Contacts returns multiple matches.
  • Omit service_name on iMessage sends. Passing it can trigger AppleScript error -1728.

Release files for apple-messages-mcp 1.0.5

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for apple-messages-mcp 1.0.5
File Size Uploaded
apple_messages_mcp-1.0.5.tar.gz 17.6 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for apple-messages-mcp 1.0.5
File Interpreter ABI Platform
apple_messages_mcp-1.0.5-py3-none-any.whl Python 3 none any Details

Total release size: 33.3 kB

Release files / apple_messages_mcp-1.0.5.tar.gz

Download URL apple_messages_mcp-1.0.5.tar.gz
Size 17.6 kB
Tags Source
SHA-256 checksum
How to use checksums
a9e64931d0e893522eb6fbb2d6edceb5b1da7d3f7192b2108d58c6cac181772f
BLAKE2b-256 checksum
How to use checksums
d5691209d0b9506e8a5ac9287292b558b9fcd6decb5c4cc05e533f81bef45bb6
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 25, 2026.

Transparency log

Release files / apple_messages_mcp-1.0.5-py3-none-any.whl

Download URL apple_messages_mcp-1.0.5-py3-none-any.whl
Size 15.8 kB
Tags Python 3
SHA-256 checksum
How to use checksums
daa4f342ae99bb66971fc33851b4183f20a9bbd584d02baaeb5b3585cd27857b
BLAKE2b-256 checksum
How to use checksums
03b3ddcddaa94a616ff7f21cd96534f0a3b43ea7f91a83808697bf67edb4593e
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 25, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

1.0.5 This release

2 release files

1.0.4

2 release files

1.0.3

2 release files

1.0.2

2 release files

1.0.1

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page