io.github.chrischall/apple-icloud-mcp MCP Server
io.github.chrischall/apple-icloud-mcp
What is the io.github.chrischall/apple-icloud-mcp MCP server?
Unofficial: Apple Music, iCloud Calendar/Contacts/Mail, Apple Maps and WeatherKit, no Mac needed
How to install io.github.chrischall/apple-icloud-mcp
Copy-paste configuration for popular MCP clients.
APPLE_TEAM_IDYour Apple Developer Team ID (10 characters). Needed for Apple Music (official API), Apple Maps and WeatherKit.
APPLE_KEY_IDKey ID of a private key created in Certificates, Identifiers & Profiles → Keys with Media Services (MusicKit), MapKit JS and/or WeatherKit enabled.
APPLE_PRIVATE_KEYsecretContents of that key's .p8 file (PEM; one-line values with \n escapes and base64 are accepted).
APPLE_PRIVATE_KEY_PATHLocal installs only: a path to the .p8 file instead of APPLE_PRIVATE_KEY.
APPLE_MUSIC_KEY_IDOptional per-service override of APPLE_KEY_ID for Apple Music (pair with APPLE_MUSIC_PRIVATE_KEY).
APPLE_MUSIC_PRIVATE_KEYsecretOptional per-service override of APPLE_PRIVATE_KEY for Apple Music.
APPLE_MAPS_KEY_IDOptional per-service override of APPLE_KEY_ID for Apple Maps.
APPLE_MAPS_PRIVATE_KEYsecretOptional per-service override of APPLE_PRIVATE_KEY for Apple Maps.
APPLE_WEATHERKIT_KEY_IDOptional per-service override of APPLE_KEY_ID for WeatherKit.
APPLE_WEATHERKIT_PRIVATE_KEYsecretOptional per-service override of APPLE_PRIVATE_KEY for WeatherKit.
APPLE_WEATHERKIT_SERVICE_IDWeatherKit only: the Services ID registered for WeatherKit (e.g. com.example.weather).
APPLE_MUSIC_DEVELOPER_TOKENsecretOptional: a pre-minted Apple Music developer token (JWT) instead of signing one from the key above.
APPLE_MUSIC_USER_TOKENsecretMusic User Token for your library (official API), from a one-time MusicKit sign-in: `npx apple-icloud-mcp music-auth`. Without the Apple Developer key, ask the owner for a developer token (music-auth --print-developer-token) and run it with APPLE_MUSIC_DEVELOPER_TOKEN set. Lasts ~6 months.
APPLE_MUSIC_WEB_USER_TOKENsecretOpt-in web-player mode (no developer account needed; unlocks rename/delete/remove/reorder): the media-user-token cookie from a signed-in music.apple.com tab.
APPLE_MUSIC_WEB_DEVELOPER_TOKENsecretOptional override for the web-player developer token (normally read automatically from music.apple.com).
APPLE_MUSIC_STOREFRONTTwo-letter Apple Music storefront (e.g. us, gb). Default: your account's storefront, else us.
ICLOUD_USERNAMEYour Apple ID email, for iCloud Calendar, Contacts and Mail.
ICLOUD_APP_PASSWORDsecretAn app-specific password from appleid.apple.com → Sign-In and Security → App-Specific Passwords (NOT your Apple ID password).
ICLOUD_MAIL_ADDRESSYour @icloud.com address, only if your Apple ID email is not an iCloud address (needed for Mail).
ICLOUD_DEFAULT_CALENDARCalendar new events go to when none is named (default: the first writable event calendar).
APPLE_WRITE_MODE"none" = read-only tools; "additive" = also create/append, never modify, delete or send; "all" = everything (default). Unrecognized values fail closed to "none".
APPLE_SERVICESComma-separated services to enable (music, calendar, contacts, mail, maps, weather, itunes). Default: all.
DISPLAY_TZIANA time zone (e.g. America/New_York) for displayed times and for dates you give without an offset. Set this on a hosted server, which runs in UTC.
APPLE_UNITS"metric" (default) or "imperial" units for weather (Maps distances always show both).
APPLE_STATE_CACHESet to false to write nothing under $MCP_DATA_DIR/.apple-icloud-mcp: no web-player token or iCloud discovery cache, and the rejected-password latch and spent confirmation tokens then last only as long as the process.
APPLE_REQUEST_TIMEOUT_MSPer-request timeout in milliseconds (default 30000).
APPLE_DEBUG_LOGSet to 1 to log every upstream request line to stderr (credentials redacted).
MCP_CONFIRM_MODEHow confirm-gated writes (send mail, deletes, removing tracks, invitations) behave on a client with no prompt, like claude.ai: "ask-user" (default: preview + confirmToken, the model must get your OK), "auto", or "refuse". Unknown values mean refuse.
MCP_CONFIRM_TTL_SECONDSLifetime of a confirmToken in seconds (default 600).
MCP_CONFIRM_SECRETsecretSigning key for confirmTokens. Random per process by default; set it so a token issued just before a restart or redeploy still works (spent tokens are recorded on disk, so none can be replayed).
Related MCP servers
Parent/fan access to Artsonia student-art portfolios, comments, and fans (AI-built).

Booli.se real estate for Claude: search listings, sold prices, areas & market stats
Canvas LMS (Instructure) for Claude — courses, grades, assignments, planner, files
Charlotte On The Cheap MCP — free and cheap Charlotte events, deals and local guides

Compass real-estate for Claude — search, property details, photos, price history, compare
Credit Karma transactions for Claude — spending by category, merchant, and account summary