PluginBench
MCP Server
Active
MIT

Apple Tools (Unified) MCP Server

io.github.JonathanRReed/apple-tools-mcp

Control Apple apps from Claude and Cursor—Mail, Calendar, Notes, Messages, Reminders, and more on your Mac.

What is the Apple Tools (Unified) MCP server?

The Apple Tools MCP server is a unified interface that lets AI clients like Claude and Cursor interact with macOS applications including Mail, Calendar, Notes, Messages, Reminders, Contacts, Shortcuts, Files, System tools, and Maps. It runs locally on your Mac and enables tasks like sending messages, checking calendars, searching mail, creating reminders, and managing files through natural language.

Apple Tools MCP gives AI agents direct access to your Mac's built-in productivity apps. You can automate workflows across Mail, Calendar, Notes, Messages, and other Apple services—all controlled through your AI client. The server runs locally on macOS and respects app-level permissions you configure.

How to install Apple Tools (Unified)

Copy-paste configuration for popular MCP clients.

transport: stdio
Config generated by PluginBench — verify against the source before use.
Environment / auth
  • APPLE_MAIL_MCP_SAFETY_PROFILE

    Safety mode for the Mail domain: safe_readonly, safe_manage, or full_access.

  • APPLE_CALENDAR_MCP_SAFETY_MODE

    Safety mode for the Calendar domain: safe_readonly, safe_manage, or full_access.

  • APPLE_REMINDERS_MCP_SAFETY_MODE

    Safety mode for the Reminders domain: safe_readonly, safe_manage, or full_access.

  • APPLE_FILES_MCP_SAFETY_MODE

    Safety mode for the Files domain: safe_readonly, safe_manage, or full_access.

  • APPLE_FILES_MCP_ALLOWED_ROOTS

    Comma-separated directories file tools may access. Defaults to Desktop, Documents, Downloads, and iCloud Drive.

  • APPLE_SYSTEM_MCP_SAFETY_MODE

    Safety mode for the System domain: safe_readonly, safe_manage, or full_access.

  • APPLE_CONTACTS_MCP_SAFETY_MODE

    Safety mode for the Contacts domain: safe_readonly, safe_manage, or full_access.

  • APPLE_NOTES_MCP_SAFETY_MODE

    Safety mode for the Notes domain: safe_readonly, safe_manage, or full_access.

  • APPLE_MESSAGES_MCP_SAFETY_MODE

    Safety mode for the Messages domain: safe_readonly, safe_manage, or full_access.

  • APPLE_SHORTCUTS_MCP_SAFETY_MODE

    Safety mode for the Shortcuts domain: safe_readonly, safe_manage, or full_access.

  • APPLE_MAIL_MCP_ALLOWED_ATTACHMENT_ROOT

    Directory containing files that Mail may attach. Unset disables attachments.

~/Library/Application Support/Claude/claude_desktop_config.json
{
  "mcpServers": {
    "apple-tools-mcp": {
      "command": "uvx",
      "args": [
        "apple-tools-mcp"
      ],
      "env": {
        "APPLE_MAIL_MCP_SAFETY_PROFILE": "<YOUR_APPLE_MAIL_MCP_SAFETY_PROFILE>",
        "APPLE_CALENDAR_MCP_SAFETY_MODE": "<YOUR_APPLE_CALENDAR_MCP_SAFETY_MODE>",
        "APPLE_REMINDERS_MCP_SAFETY_MODE": "<YOUR_APPLE_REMINDERS_MCP_SAFETY_MODE>",
        "APPLE_FILES_MCP_SAFETY_MODE": "<YOUR_APPLE_FILES_MCP_SAFETY_MODE>",
        "APPLE_FILES_MCP_ALLOWED_ROOTS": "<YOUR_APPLE_FILES_MCP_ALLOWED_ROOTS>",
        "APPLE_SYSTEM_MCP_SAFETY_MODE": "<YOUR_APPLE_SYSTEM_MCP_SAFETY_MODE>",
        "APPLE_CONTACTS_MCP_SAFETY_MODE": "<YOUR_APPLE_CONTACTS_MCP_SAFETY_MODE>",
        "APPLE_NOTES_MCP_SAFETY_MODE": "<YOUR_APPLE_NOTES_MCP_SAFETY_MODE>",
        "APPLE_MESSAGES_MCP_SAFETY_MODE": "<YOUR_APPLE_MESSAGES_MCP_SAFETY_MODE>",
        "APPLE_SHORTCUTS_MCP_SAFETY_MODE": "<YOUR_APPLE_SHORTCUTS_MCP_SAFETY_MODE>",
        "APPLE_MAIL_MCP_ALLOWED_ATTACHMENT_ROOT": "<YOUR_APPLE_MAIL_MCP_ALLOWED_ATTACHMENT_ROOT>"
      }
    }
  }
}

Tools & capabilities

Tools this server exposes to the agent.

  • mail_search — Search email by sender, subject, or wildcard query
  • mail_get_thread — Retrieve a mail conversation thread
  • mail_reply_latest_in_thread — Reply to the latest message in a mail thread
  • mail_archive_thread — Archive a mail conversation
  • calendar_health — Check Calendar app health and permissions
  • reminders_health — Check Reminders app health and permissions
  • messages_health — Check Messages app health and permissions
  • contacts_health — Check Contacts app health and permissions
  • notes_health — Check Notes app health and permissions
  • shortcuts_health — Check Shortcuts app health and permissions
  • files_health — Check Files tool health and permissions
  • system_health — Check System tools health and permissions
  • maps_health — Check Maps app health and permissions
  • apple_health — Check overall Apple Tools MCP health and permissions
  • apple_permission_guide — Get guidance on setting up required macOS permissions
  • apple_recheck_permissions — Re-verify app permissions
  • search_tools — Search available tools by name, description, or alias
  • get_tool_info — Get detailed schema and examples for a specific tool
  • apple_generate_daily_briefing — Generate a daily briefing from your communications and calendar
  • apple_generate_weekly_briefing — Generate a weekly briefing from your communications and calendar

Use cases

  • Search and reply to emails, manage mail threads, and organize your inbox through natural conversation
  • Check your calendar, create events, and manage your schedule without opening Calendar
  • Send iMessages and SMS through Messages app automation
  • Create and manage reminders with due dates and timezone support
  • Search and organize notes across your Notes app
  • Retrieve contact information and route messages to the right recipients

Apple Tools (Unified) MCP server FAQ

What is Apple Tools MCP?

It's an MCP server that runs on your Mac and gives AI clients like Claude and Cursor access to Apple apps (Mail, Calendar, Notes, Messages, Reminders, Contacts, Shortcuts, Files, System, and Maps) through natural language commands.

Is it free?

Yes. Apple Tools MCP is open-source under the MIT license.

How do I install it in Claude or Cursor?

For Claude: run `claude mcp add --transport stdio --scope project apple-tools -- uvx apple-tools-mcp`. For Cursor or other stdio clients, add the server to your MCP configuration JSON. You need Python 3.11+ and macOS. Alternatively, download a `.mcpb` bundle from Releases and double-click it in Claude Desktop.

What permissions does it need?

The server requires macOS app-level permissions (Automation, Full Disk Access, Contacts, Calendar, etc.) which you approve in System Settings or via macOS prompts. Mail attachments are disabled by default; enable them by setting `APPLE_MAIL_MCP_ALLOWED_ATTACHMENT_ROOT` to a dedicated directory. Files tools only access directories you explicitly allow via `APPLE_FILES_MCP_ALLOWED_ROOTS`.

Does my data stay private?

The server runs locally on your Mac, but returned data may be sent to your AI client's model provider (e.g., Anthropic for Claude). Apple apps may also sync through iCloud or other accounts. Review your client's privacy policy.

Can I use just one app instead of all ten?

Yes. The repository includes standalone servers for Mail, Calendar, Reminders, Messages, Contacts, Notes, Shortcuts, Files, System, and Maps. Use the unified Apple-Tools-MCP for all apps, or install individual servers to limit what your client can access.

README (reference)

Source of truth, from the repository.

Apple-MCPs

CI Python 3.11+ macOS

MCP servers that let an AI client use Apple apps and macOS tools. Create reminders, send messages, check calendars, search mail, manage files, and get directions.

The servers run on your Mac. Your MCP client may send returned data to its model provider, and Apple apps may sync through iCloud or another account. Local execution does not mean the data stays local.

Requires Python 3.11+ and macOS. Uses MCP specification 2026-07-28 and Python SDK 2.x, with support for older client protocol revisions. MIT license.

Install

Install uv, then register the unified server with your client.

Claude Code:

claude mcp add --transport stdio --scope project apple-tools -- uvx apple-tools-mcp

Codex:

codex mcp add apple-tools -- uvx apple-tools-mcp

Other stdio clients:

{
  "mcpServers": {
    "apple-tools": {
      "command": "uvx",
      "args": ["apple-tools-mcp"]
    }
  }
}

Run uvx apple-tools-mcp to start the server directly. Standalone servers use the same approach, such as uvx apple-mcp-mail or uvx apple-calendar-mcp.

Restart your client after installing or upgrading. Call search_tools with calendar health to check discovery without reading app data.

For Claude Desktop, download a server's .mcpb bundle from Releases and double-click it.

Set app-specific safety modes and directories in your client's env settings. The configuration guide lists defaults and options. Mail attachments are disabled until you set APPLE_MAIL_MCP_ALLOWED_ATTACHMENT_ROOT to a dedicated directory. Files tools only access APPLE_FILES_MCP_ALLOWED_ROOTS; macOS may impose further restrictions.

Choose a server

Start with Apple-Tools-MCP. It combines all ten apps and tools below, plus saved defaults, contact routing, Mail thread helpers, undo, briefings, and cross-app workflows.

Choose a standalone server to expose fewer apps to your client:

ServermacOS accessHealth toolPermission help
MailAutomation access to Mailmail_healthmail_permission_guide, mail_recheck_permissions
CalendarCalendar accesscalendar_healthcalendar_permission_guide, calendar_recheck_permissions
RemindersReminders accessreminders_healthreminders_permission_guide, reminders_recheck_permissions
MessagesAutomation; Full Disk Access for historymessages_healthmessages_permission_guide, messages_recheck_permissions
ContactsContacts accesscontacts_healthcontacts_permission_guide, contacts_recheck_permissions
NotesAutomation access to Notesnotes_healthnotes_permission_guide, notes_recheck_permissions
ShortcutsUsually no separate promptshortcuts_healthshortcuts_permission_guide, shortcuts_refresh_state
FilesAllowed roots and protected-folder accessfiles_healthfiles_permission_guide
SystemSome actions need System Events, Accessibility, or Automationsystem_healthsystem_permission_guide
MapsNo privacy prompt; Swift helper needs Xcode command line toolsmaps_healthmaps_permission_guide

The unified server uses apple_health, apple_permission_guide, and apple_recheck_permissions. You must approve permissions yourself in the macOS prompt or System Settings.

Find and use tools

MCP tools/list returns each tool's schemas and read or write annotations. Use search_tools to search names, descriptions, and aliases; use get_tool_info for one tool's schema and examples.

Resolve recipients through Contacts before sending, unless you have the exact address. For Mail conversations, use mail_get_thread, mail_reply_latest_in_thread, or mail_archive_thread. Pass an exact sender email in from_account when the sending identity matters.

Mail search requires a query: a sender, subject fragment, or *. Reminders due_date requires a timezone offset, such as yyyy-MM-ddTHH:mm:ss-08:00. Omit service_name when sending iMessages.

The unified server also provides apple_generate_daily_briefing, apple_generate_weekly_briefing, and apple_triage_communications_task. Clients without prompt support can use apple_list_prompts, apple_get_prompt, and their per-server equivalents.

For calls from Python, use the metadata in generated/tool_catalogs/ and wrappers in generated/tool_wrappers/python/. See code-mode.md.

Transport and stored state

stdio is the default. To use Streamable HTTP, set APPLE_<DOMAIN>_MCP_TRANSPORT=streamable-http and the matching _HOST and _PORT variables.

HTTP must bind to 127.0.0.1, ::1, or localhost. The servers have no remote authentication and reject network and wildcard binds. Do not expose them through a tunnel or public proxy.

Apple-Tools-MCP stores defaults in ~/.apple-tools-mcp/preferences.json, configurable through APPLE_AGENT_MCP_STATE_FILE. It stores recent actions in ~/.apple-tools-mcp/actions.json for audit and undo.

Develop

git clone https://github.com/JonathanRReed/Apple-MCPs.git
cd Apple-MCPs
uv sync --all-packages

The uv workspace installs every server into .venv/bin. Each server folder also has a start.sh for clients; it uses uv when available and otherwise creates a virtual environment. Root pyproject.toml defines workspace members, and uv.lock pins dependencies.

PathContents
Apple-Tools-MCP/Unified server; module apple_agent_mcp, environment prefix APPLE_AGENT_MCP_*
Apple<Domain>-MCP/Standalone servers; Calendar uses Apple-Calendar-MCP
AppleMCPCommon/Shared discovery and search, published as apple-mcp-common
generated/Tool catalogs and Python wrappers
scripts/Installation, checks, generation, and bundle builds
docs/Project and launch documentation

Run smoke checks:

bash scripts/inspector_smoke.sh
uv run python scripts/protocol_smoke.py

For the official conformance suite, start the server in a separate terminal:

APPLE_AGENT_MCP_TRANSPORT=streamable-http \
APPLE_AGENT_MCP_PORT=8765 \
APPLE_AGENT_MCP_CONFORMANCE_MODE=1 \
./Apple-Tools-MCP/start.sh
npx -y @modelcontextprotocol/conformance@0.2.0-alpha.11 server --url http://127.0.0.1:8765/mcp --requirements 2026-07-28

Conformance mode registers test fixtures. Use it only for protocol validation. CI runs lint, macOS and Linux tests, generated-file checks, Inspector smoke checks, and conformance tests.

Documentation

Contributing · Security · Troubleshooting · MCP compatibility · Publishing · Changelog · Trademark notice · Launch docs

Related MCP servers

List, create, update, and delete events in Apple Calendar on macOS via MCP.

9
Python
MIT
View repository →

Search and inspect Apple Contacts on macOS, resolve contacts into message-ready recipients.

9
Python
MIT
View repository →
APApple Files logo

Inspect and manage local files and folders on macOS with AI assistance.

9
Python
MIT
View repository →
APApple Maps logo

Search places, estimate routes, and build Apple Maps links on macOS via MCP.

9
Python
MIT
View repository →

Vectorize images to SVG and export to PDF, EPS, DXF, PNG, JPG, or WEBP via Vectorise.Me.

View repository →

Shared memory for AI coding agents. Save once, reuse from Cursor, Claude Code, Codex.