PluginBench
MCP Server
Active
Apache-2.0

io.github.cyanheads/ntfy-mcp-server MCP Server

io.github.cyanheads/ntfy-mcp-server

Send, manage, and replay ntfy push notifications via MCP with full publish, update, and message management.

What is the io.github.cyanheads/ntfy-mcp-server MCP server?

The ntfy-mcp-server is an MCP server that enables sending, updating, and managing push notifications on ntfy topics via the ntfy pub/sub HTTP API. It provides tools to publish messages with rich formatting and actions, manage notification state, fetch message history, and search emoji tags, running as either a stdio process or local HTTP server.

This server wraps ntfy's HTTP API to let AI agents publish and manage push notifications on ntfy topics. Use it to send alerts, update notifications, replay missed messages, and manage notification state—useful for integrating ntfy notifications into AI workflows, automating alert delivery, or auditing topic activity.

How to install io.github.cyanheads/ntfy-mcp-server

Copy-paste configuration for popular MCP clients.

transport: stdio
Config generated by PluginBench — verify against the source before use.
Environment / auth
  • NTFY_SERVERS

    JSON array of `{ baseUrl, authToken? | authUsername?+authPassword? }` entries — one per ntfy server. First entry is the default base. Auth is scoped to the entry's `baseUrl`; per-call `base_url` overrides that match a registered base forward that server's auth. Takes precedence over the single-server NTFY_BASE_URL / NTFY_AUTH_* shorthand.

  • NTFY_BASE_URL

    Single-server shorthand — base URL of the ntfy server (no trailing slash). Used when NTFY_SERVERS is unset.

  • NTFY_DEFAULT_TOPIC

    Topic used when a tool call omits `topic`. Treat the topic name as a secret — anyone who knows it can publish or subscribe.

  • NTFY_AUTH_TOKEN

    Bearer access token (`tk_…`) for the single-server shorthand. Mutually exclusive with NTFY_AUTH_USERNAME / NTFY_AUTH_PASSWORD.

  • NTFY_AUTH_USERNAME

    Basic-auth username for the single-server shorthand — must be set together with NTFY_AUTH_PASSWORD.

  • NTFY_AUTH_PASSWORD

    Basic-auth password for the single-server shorthand — must be set together with NTFY_AUTH_USERNAME.

  • NTFY_REQUEST_TIMEOUT_MS

    Per-request HTTP timeout in milliseconds.

  • NTFY_MAX_RETRIES

    Max retry attempts for transient upstream failures (5xx, network, 429).

  • NTFY_BLOCK_PRIVATE_HOSTS

    When true, a per-call `base_url` override must resolve to a public address and its redirects are not followed. Servers registered under NTFY_SERVERS / NTFY_BASE_URL are exempt. Turn it on where callers you do not control can reach the server.

  • MCP_LOG_LEVEL

    Sets the minimum log level for output (e.g., 'debug', 'info', 'warn').

  • LOGS_DIR

    Directory for file-based logs (Node only; ignored on Workers).

  • OTEL_ENABLED

    Enable OpenTelemetry instrumentation (spans, metrics, completion logs).

  • MCP_SESSION_MODE

    HTTP session model: 'auto', 'stateful', or 'stateless'. This server requires 'stateful' over HTTP — the consent prompt on destructive and outbound calls is a multi-round-trip request that a 2025-era HTTP client can only complete over a live session — so an HTTP start with 'stateless' is refused. 'auto' resolves to 'stateful'; stdio ignores the setting.

  • MCP_HTTP_HOST

    The hostname for the HTTP server.

  • MCP_HTTP_PORT

    The port to run the HTTP server on.

  • MCP_HTTP_ENDPOINT_PATH

    The endpoint path for the MCP server.

  • MCP_AUTH_MODE

    Authentication mode to use: 'none', 'jwt', or 'oauth'.

~/Library/Application Support/Claude/claude_desktop_config.json
{
  "mcpServers": {
    "ntfy-mcp-server": {
      "command": "bun",
      "args": [
        "-y",
        "ntfy-mcp-server",
        "run",
        "start:stdio"
      ],
      "env": {
        "NTFY_SERVERS": "<YOUR_NTFY_SERVERS>",
        "NTFY_BASE_URL": "<YOUR_NTFY_BASE_URL>",
        "NTFY_DEFAULT_TOPIC": "<YOUR_NTFY_DEFAULT_TOPIC>",
        "NTFY_AUTH_TOKEN": "<YOUR_NTFY_AUTH_TOKEN>",
        "NTFY_AUTH_USERNAME": "<YOUR_NTFY_AUTH_USERNAME>",
        "NTFY_AUTH_PASSWORD": "<YOUR_NTFY_AUTH_PASSWORD>",
        "NTFY_REQUEST_TIMEOUT_MS": "<YOUR_NTFY_REQUEST_TIMEOUT_MS>",
        "NTFY_MAX_RETRIES": "<YOUR_NTFY_MAX_RETRIES>",
        "NTFY_BLOCK_PRIVATE_HOSTS": "<YOUR_NTFY_BLOCK_PRIVATE_HOSTS>",
        "MCP_LOG_LEVEL": "<YOUR_MCP_LOG_LEVEL>",
        "LOGS_DIR": "<YOUR_LOGS_DIR>",
        "OTEL_ENABLED": "<YOUR_OTEL_ENABLED>",
        "MCP_SESSION_MODE": "<YOUR_MCP_SESSION_MODE>",
        "MCP_HTTP_HOST": "<YOUR_MCP_HTTP_HOST>",
        "MCP_HTTP_PORT": "<YOUR_MCP_HTTP_PORT>",
        "MCP_HTTP_ENDPOINT_PATH": "<YOUR_MCP_HTTP_ENDPOINT_PATH>",
        "MCP_AUTH_MODE": "<YOUR_MCP_AUTH_MODE>"
      }
    }
  }
}

Tools & capabilities

Tools this server exposes to the agent.

  • ntfy_publish_message — Send or update a push notification on an ntfy topic with support for title, priority, tags, action buttons, attachments, and more; update existing messages by sequence_id.
  • ntfy_manage_message — Clear or delete a previously-sent notification by sequence_id; clear marks it read and dismisses it, delete removes it from the drawer.
  • ntfy_fetch_messages — Poll cached messages from one or more topics with optional filters by since, priority, tags, id, title, and message content; supports pagination and truncation reporting.
  • ntfy_search_emoji_tags — Look up ntfy emoji tag short codes for use in publish message tags; supports substring matching and pagination.

Use cases

  • Send alert notifications from AI workflows to ntfy topics with custom titles, priorities, and action buttons
  • Update or replace previously-sent notifications by sequence_id to reflect changing status
  • Fetch and replay missed notifications from topic history to confirm delivery or audit activity
  • Search and insert emoji tags into notifications for visual categorization
  • Manage notification state by clearing read notifications or deleting them from the drawer

io.github.cyanheads/ntfy-mcp-server MCP server FAQ

What is the ntfy-mcp-server?

It's an MCP server that integrates ntfy push notifications into AI agents, allowing them to publish, update, manage, and query notifications on ntfy topics via a pub/sub HTTP API.

Is it free to use?

Yes. The public ntfy.sh service requires no account. Self-hosted ntfy instances and protected topics may require bearer tokens or basic-auth credentials, which you configure via environment variables.

How do I install it in Claude Desktop or Cursor?

Use the one-click install buttons in the GitHub releases, or add the server to your MCP client config with `command: npx` and `args: ["-y", "ntfy-mcp-server@latest"]`, setting `NTFY_DEFAULT_TOPIC` in env.

Does it require authentication?

No authentication is required for public ntfy.sh topics. For protected topics or self-hosted servers, configure bearer tokens or basic-auth credentials via `NTFY_AUTH_TOKEN` or `NTFY_AUTH_USERNAME`/`NTFY_AUTH_PASSWORD`.

What transport modes does it support?

It runs as a stdio process (default) or as a local Streamable HTTP server; configure via `MCP_TRANSPORT_TYPE` environment variable.

Does it ask for confirmation before sending notifications?

Yes—publishes carrying email, call, or broadcast/http action buttons, and all clear/delete operations, require user confirmation before executing to prevent unintended side effects.

README (reference)

Source of truth, from the repository.

<div align="center"> <h1>ntfy-mcp-server</h1> <p><b>Send, manage, and replay ntfy push notifications via MCP. STDIO or Streamable HTTP.</b> <div>4 Tools • 1 Resource</div> </p> </div> <div align="center">

npm Version Framework MCP SDK

License TypeScript Bun

</div> <div align="center">

Install in Claude Desktop Install in Cursor Install in VS Code

</div>

Overview

Push notifications over the ntfy pub/sub HTTP API. Publish, update, and manage notifications, poll cached topic history, and look up emoji short codes for tags from any MCP client. Runs as a stdio process or a local Streamable HTTP server.

Tools

ToolDescription
ntfy_publish_messageSend or update a push notification on an ntfy topic.
ntfy_manage_messageClear or delete a previously-sent notification by sequence_id.
ntfy_fetch_messagesPoll cached messages from one or more topics with optional filters.
ntfy_search_emoji_tagsLook up ntfy emoji tag short codes for use in tags.

Resources

ResourceDescription
ntfy://{topic}Snapshot of a topic — latest 20 messages from the past hour, plus the topic's browser URL.

ntfy_fetch_messages covers the same topic data with custom windows and filters when the resource's fixed defaults aren't enough.

Capability reference

ntfy_publish_message <sub>tool</sub>

  • Topics are created on first publish — treat the topic name as a secret; anyone who knows it can publish or subscribe
  • Full publish-parameter coverage — title, priority (1–5), tags, click, attach, icon, filename, markdown, delay, email, call, cache, firebase; message body capped at 4096 bytes (non-ASCII characters cost more), empty body defaults server-side to triggered
  • Up to three discriminated action buttons (view, broadcast, http, copy) per message
  • Update or replace a previously-sent message by passing the original sequence_id
  • Per-call base_url override forwards credentials only when it matches a registered server (NTFY_BASE_URL or an NTFY_SERVERS entry); otherwise the request goes out unauthenticated
  • Publishes carrying email, call, or a broadcast/http action button ask the user to confirm the specific target first — the call returns a confirmation request, and sends only once reissued with the answer

ntfy_manage_message <sub>tool</sub>

  • operation: clear marks the notification read & dismisses it (subscribers see message_clear); delete removes it from the drawer (subscribers see message_delete)
  • Append-only — the original message stays in cache; re-issuing the same operation is safe, though a fresh event fires each call
  • Every call asks the user to confirm the topic, sequence_id, and operation before the event fires — the first call returns that confirmation request, and declining fails with consent_declined
  • ntfy.sh accepts an unknown sequence_id without error; stricter ntfy deployments return a not_found failure instead

ntfy_fetch_messages <sub>tool</sub>

  • Returns a snapshot, not a live stream — use it to confirm delivery, replay missed alerts, or audit topic activity
  • Comma-separated multi-topic queries (e.g. alerts,backups,phil_alerts)
  • Filter by since (duration / timestamp / message ID / all / latest), priority, tags, id, title, message, scheduled-only
  • Default window 10m, default limit 20 messages per response, hard cap 100 — over-limit windows keep the newest limit messages, listed oldest-first
  • Long bodies truncated to ~500 chars with messageTruncated reporting the dropped count; refetch with a message id to read that one in full

ntfy_search_emoji_tags <sub>tool</sub>

  • Substring match against tag names, case-insensitive; omit query to list the reference from the start in its documented order
  • limit default 25, max 200; offset pages past the cap using the returned totalCount
  • Returned tag strings plug directly into ntfy_publish_message's tags field

ntfy://{topic} <sub>resource</sub>

  • Fixed snapshot — latest 20 messages from the past 1 hour, plus the topic's browser URL; same normalized message shape as ntfy_fetch_messages (ISO 8601 timestamps, ~500-char body truncation)
  • For custom windows, filters, or replay, use ntfy_fetch_messages instead

Features

Built on @cyanheads/mcp-ts-core: stdio and Streamable HTTP transports, pluggable auth (none / jwt / oauth), swappable storage (in-memory, filesystem, Supabase, Cloudflare KV/R2/D1), structured logging with optional OpenTelemetry tracing.

ntfy-specific:

  • Wraps ntfy's HTTP API with a retry-aware client (withRetry + per-request timeout)
  • Per-server scoped auth — credentials bind to each registered base URL (NTFY_BASE_URL or an NTFY_SERVERS entry); mutually-exclusive bearer-token / basic-auth modes validated at config load; a per-call base_url override forwards auth only when it matches a registered server
  • User confirmation before side effects that leave the notification drawer — a clear/delete, or a publish carrying email, call, or a broadcast/http action button — enforced on both stdio and Streamable HTTP
  • Optional SSRF guard on base_url overrides (NTFY_BLOCK_PRIVATE_HOSTS) — blocks loopback, RFC 1918, RFC 6598 mesh, link-local, and IPv6 equivalents, then refuses redirects; registered servers are exempt
  • Bundled emoji-tag reference, regenerated from upstream docs/ntfy/emojis.md via scripts/build-emoji-tags.ts

Agent-friendly output:

  • Provenance — ntfy_publish_message and ntfy_manage_message echo back the resolved topic, ID, and timestamp; ntfy_fetch_messages also echoes the resolved since and applied filters
  • Discriminated outputs — typed reason codes (consent_declined, forbidden_topic, rate_limited, not_found, payload_too_large, and more) on every tool's error contract let callers branch on failure mode instead of parsing error text
  • Truncation and paging guidance — ntfy_fetch_messages and ntfy_search_emoji_tags report a truncated flag plus a notice naming the exact next step (widen since, raise limit, advance offset) instead of silently dropping results

Getting started

Add the following to your MCP client configuration file. Public ntfy.sh works out of the box without an account; for protected topics, generate an access token at https://ntfy.sh/account.

{
  "mcpServers": {
    "ntfy-mcp-server": {
      "type": "stdio",
      "command": "bunx",
      "args": ["ntfy-mcp-server@latest"],
      "env": {
        "MCP_TRANSPORT_TYPE": "stdio",
        "MCP_LOG_LEVEL": "info",
        "NTFY_DEFAULT_TOPIC": "your-topic-name"
      }
    }
  }
}

Or with npx (no Bun required):

{
  "mcpServers": {
    "ntfy-mcp-server": {
      "type": "stdio",
      "command": "npx",
      "args": ["-y", "ntfy-mcp-server@latest"],
      "env": {
        "MCP_TRANSPORT_TYPE": "stdio",
        "MCP_LOG_LEVEL": "info",
        "NTFY_DEFAULT_TOPIC": "your-topic-name"
      }
    }
  }
}

Or with Docker:

{
  "mcpServers": {
    "ntfy-mcp-server": {
      "type": "stdio",
      "command": "docker",
      "args": [
        "run", "-i", "--rm",
        "-e", "MCP_TRANSPORT_TYPE=stdio",
        "-e", "NTFY_DEFAULT_TOPIC=your-topic-name",
        "ghcr.io/cyanheads/ntfy-mcp-server:latest"
      ]
    }
  }
}

For Streamable HTTP, set the transport and start the server:

MCP_TRANSPORT_TYPE=http MCP_HTTP_PORT=3010 NTFY_DEFAULT_TOPIC=your-topic bun run start:http
# Server listens at http://127.0.0.1:3010/mcp

Prerequisites

  • Bun v1.4.0 or higher (or Node.js v24+).
  • A topic name on an ntfy server. Public ntfy.sh requires no account; self-hosted instances and protected topics may need a bearer token or basic-auth credentials.

Installation

  1. Clone the repository:
git clone https://github.com/cyanheads/ntfy-mcp-server.git
  1. Navigate into the directory:
cd ntfy-mcp-server
  1. Install dependencies:
bun install
  1. Configure environment:
cp .env.example .env
# edit .env and set NTFY_DEFAULT_TOPIC (and auth, if needed)

Configuration

VariableDescriptionDefault
NTFY_SERVERSJSON array of { baseUrl, authToken? | authUsername?+authPassword? } entries — one per ntfy server. First entry is the default base. Auth is scoped to the entry's baseUrl; per-call base_url overrides that match a registered base forward that server's auth. Use this when you need more than one authenticated server in a single process; it takes precedence over the single-server vars below.—
NTFY_BASE_URLSingle-server shorthand — base URL of the ntfy server (no trailing slash). Used when NTFY_SERVERS is unset.https://ntfy.sh
NTFY_DEFAULT_TOPICTopic used when a tool call omits topic.—
NTFY_AUTH_TOKENBearer access token (tk_…) for the single-server shorthand. Mutually exclusive with NTFY_AUTH_USERNAME / NTFY_AUTH_PASSWORD.—
NTFY_AUTH_USERNAMEBasic-auth username for the single-server shorthand — required together with NTFY_AUTH_PASSWORD.—
NTFY_AUTH_PASSWORDBasic-auth password for the single-server shorthand — required together with NTFY_AUTH_USERNAME.—
NTFY_REQUEST_TIMEOUT_MSPer-request HTTP timeout in milliseconds.15000
NTFY_MAX_RETRIESMax retry attempts for transient upstream failures (5xx, network, 429).3
NTFY_BLOCK_PRIVATE_HOSTSWhen true, a per-call base_url override must resolve to a public address, and its redirects are not followed. Servers registered under NTFY_SERVERS / NTFY_BASE_URL are exempt, so a deliberate LAN target still works. Turn it on where callers you don't control can reach the server.false
MCP_TRANSPORT_TYPETransport: stdio or http.stdio
MCP_SESSION_MODEHTTP session model: auto, stateful, or stateless. This server requires stateful over HTTP — the consent prompt on destructive and outbound calls is a multi-round-trip request that a 2025-era HTTP client can only complete over a live session — so an HTTP start with stateless is refused. auto resolves to stateful; stdio ignores the setting.stateful
MCP_HTTP_HOSTHTTP host.127.0.0.1
MCP_HTTP_PORTHTTP port.3010
MCP_HTTP_ENDPOINT_PATHHTTP endpoint path./mcp
MCP_AUTH_MODEAuth mode: none, jwt, or oauth.none
MCP_LOG_LEVELLog level (RFC 5424).info
LOGS_DIRDirectory for file-based logs (Node only; ignored on Workers)../logs
OTEL_ENABLEDEnable OpenTelemetry instrumentation (spans, metrics, completion logs).false

See .env.example for the full list of optional overrides.

Running the server

Local development

  • Build and run:

    # One-time build
    bun run rebuild
    
    # Run the built server
    bun run start:stdio
    # or
    bun run start:http
    
  • Run checks and tests:

    bun run devcheck     # Lint, format, typecheck, security, changelog sync
    bun run test         # Vitest test suite
    bun run lint:mcp     # Validate MCP definitions against spec
    

Docker

docker build -t ntfy-mcp-server .
docker run --rm -e NTFY_DEFAULT_TOPIC=your-topic -p 3010:3010 ntfy-mcp-server

The Dockerfile defaults to HTTP transport, stateful session mode, and logs to /var/log/ntfy-mcp-server. OpenTelemetry peer dependencies are installed by default — build with --build-arg OTEL_ENABLED=false to omit them.

Project structure

DirectoryPurpose
src/index.tscreateApp() entry point — registers tools and resources, initializes services.
src/configServer-specific environment variable parsing (NTFY_*) with Zod.
src/mcp-server/toolsTool definitions (*.tool.ts).
src/mcp-server/resourcesResource definitions (*.resource.ts).
src/services/ntfyntfy HTTP client, types, and error classifier.
src/services/emoji-tagsBundled emoji short-code reference and lookup service.
docs/ntfyMirrored upstream ntfy API docs (pinned commit in SOURCES.md).
tests/Unit and integration tests mirroring src/.

Development guide

See CLAUDE.md for development guidelines and architectural rules. The short version:

  • Handlers throw, framework catches — no try/catch in tool logic
  • Use ctx.log for request-scoped logging, ctx.state for tenant-scoped storage
  • Wrap external API calls: validate raw → normalize to domain type → return output schema; never fabricate missing fields
  • Per-tool errors[] contracts stay inline — repetition is intended for locality

Contributing

Issues are welcome. Run checks and tests before submitting:

bun run devcheck
bun run test

License

Apache-2.0 — see LICENSE for details.

Related MCP servers

Get US weather forecasts, active alerts, and current observations.

1
TypeScript
Apache-2.0
View repository →

Read, write, search, and surgically edit Obsidian notes, tags, and frontmatter via MCP.

611
TypeScript
Apache-2.0
View repository →

Search and query 1,500+ OECD statistical datasets via SDMX. Keyless.

1
TypeScript
Apache-2.0
View repository →

Real-time transit stops, routes, arrivals, vehicle positions, and schedules via OneBusAway APIs.

1
TypeScript
Apache-2.0
View repository →

Global weather via Open-Meteo: forecast, historical, marine, air quality, geocoding, elevation.

2
TypeScript
Apache-2.0
View repository →

Access the OpenAlex academic research catalog — 270M+ publications.

7
TypeScript
Apache-2.0
View repository →