nblm-mcp
nblm-mcp
AIエージェントにGoogle NotebookLM(2026年7月にGemini Notebookへ改名)へのアクセスを提供するMCPサーバーです。ノートブックの一覧表示・作成、ソースの管理、それらのソースからの引用付き回答を得る質問、オーディオ概要・ブリーフィングドキュメント・クイズ・マインドマップなどのStudioアーティファクト生成を行います。
ポイントは「根拠に基づくこと」です。NotebookLMは与えた素材だけから回答するため、askを呼び出せるエージェントは、推測ではなく自分のドキュメントから引用付きの回答を得られます。しかも、Geminiがサーバー側で読むため、自分のコンテキストのトークンを消費しません。
⚠️ 非公式 — 最初にお読みください
GoogleにはNotebookLMの公開コンシューマーAPIはありません。 このサーバーは、notebooklm.google.comのUIが呼び出すのと同じ非公開Webエンドポイントを、MITライセンスの
notebooklm-pyライブラリを介して、自分のブラウザセッションCookieで認証して操作します。
Googleとは提携・承認されていません。
内部APIは予告なく変更され、このサーバーが壊れる可能性があります。
Googleアカウントのレート制限と1日のStudioクォータが適用されます。
自動化しても問題ないアカウントを使用してください。個人プロジェクト、研究、プロトタイプに最適です。
GoogleはGemini Notebook Enterprise向けの公式APIを文書化しています。その機能を持つWorkspace/Cloud組織をお持ちの場合は、こちらを優先してください。
インストール
まだPyPIには公開されていません — このリポジトリから直接インストールします。uvxが必要に応じてビルドして実行するため、手動で更新するものはありません:
uvx --from git+https://github.com/Diego-Dev-Moros/nblm-mcp nblm-mcpRelated MCP server: NotebookLM MCP Server
一度ログインする
ログインにはauthエクストラ(Playwright)とキーボードの前の人間が必要です:
uvx --from "nblm-mcp[auth] @ git+https://github.com/Diego-Dev-Moros/nblm-mcp" nblm-mcp-loginブラウザウィンドウが開くので、通常どおりNotebookLMにサインインします。セッションCookieは~/.notebooklm/に保存されます(notebooklm-pyが使用するのと同じプロファイル構成なので、既存のnotebooklm loginも機能します)。MCPサーバーは単独ではログインしません — インタラクティブなブラウザが必要であり、MCPホストはそれを提供できないためです。
Playwrightにブラウザがまだない場合は、最初にplaywright install chromiumを実行してください。
Cookieは期限切れになります。期限が切れると、ツールは認証エラーを返し始めるので、ログインコマンドを再度実行してください。
クライアントに接続する
Claude Code — -s userを指定すると、すべてのプロジェクトで利用可能になります:
claude mcp add notebooklm -s user -- \
uvx --from git+https://github.com/Diego-Dev-Moros/nblm-mcp nblm-mcpClaude Desktop — これをclaude_desktop_config.jsonに追加してアプリを再起動します(macOS: ~/Library/Application Support/Claude/、Windows: %APPDATA%\Claude\、Linux: ~/.config/Claude/):
{
"mcpServers": {
"notebooklm": {
"command": "uvx",
"args": ["--from", "git+https://github.com/Diego-Dev-Moros/nblm-mcp", "nblm-mcp"]
}
}
}Claude DesktopはGUIから起動するため、シェルのPATHを継承しません。そこでサーバーが起動しない場合は、"uvx"を絶対パス(which uvx、通常は~/.local/bin/uvx)に置き換えてください。
どちらの場合も、エージェントにauth_statusを呼び出させることで動作を確認できます。
ツール
ツール | 機能 |
| 保存されたセッションを実際のリクエストで検証し、再ログインが必要かどうかを通知します。 |
| アカウントがアクセスできるすべてのノートブックを、IDとソース数とともに表示します。 |
| 1つのノートブックとそのソースを取得します。オプションでNotebookLM自身の要約も取得します。 |
| 空のノートブックを作成します。 |
| ノートブックとその中のすべてを削除します。 |
| ノートブック内のソースとその処理ステータスを表示します。 |
| URL(Web、YouTube、Drive)、貼り付けたテキスト、またはローカルファイルから1つのソースを追加します。 |
| ソースを削除します。 |
| ノートブックに質問し、回答とソースタイトルに解決された引用を返します。 |
| ノートブックの会話における過去の質問/回答ターンを表示します。 |
| 生成されたStudioアーティファクトとそのステータス — 実行中の生成をポーリングする方法でもあります。 |
| オーディオ、ビデオ、レポート、study_guide、quiz、flashcards、infographic、slide_deck、またはmind_mapを生成します。 |
| 完了したアーティファクトをサーバーが実行されているマシンのファイルにダウンロードします。 |
動作に関する注意
破壊的なツールはゲート付きです。
delete_notebookとdelete_sourceはconfirm=trueなしでは実行を拒否するため、誤ったツール呼び出しでノートブックを破壊することはありません。生成は遅く、クォータに制限されます。
generate_artifactはジョブがキューに入るとすぐに返り(wait=false、デフォルト)、エージェントにlist_artifactsをポーリングするよう指示します。代わりにブロックするにはwait=trueを渡します。NBLM_GENERATION_TIMEOUT秒まで待機します。ファイルパスはサーバー側です。
add_source(file_path=...)とdownload_artifactは、MCPサーバーが実行されているホスト上で読み書きします。これはユーザーのチャットクライアントが実行されている場所と同じとは限りません。
設定
すべてオプションです — .env.exampleを参照してください。作業ディレクトリに.envがあれば読み込まれます。
変数 | デフォルト | 目的 |
| アクティブプロファイル | 複数のGoogleアカウント用に、使用する保存済みログインを指定します。 |
| プロファイルから解決 |
|
|
|
|
|
|
|
|
| 新しいソースの処理完了を待つ秒数。 |
開発
uv venv && uv pip install -e ".[dev]"
uv run pytest
uv run ruff check src testsテストスイートはインメモリのフェイククライアントに対してツールを実行します — Googleには一切アクセスしないため、どこでも安全かつ高速に実行できます。
先行技術
notebooklm-pyが難しい部分 — 非公開のbatchexecuteプロトコルのリバースエンジニアリングと保守 — を担当し、独自のより大きなMCPサーバーを提供しています。このプロジェクトは、そのライブラリの上に構築された、より小さく、意見が反映されたツールサーフェスです。ツールが少なく、破壊的操作には確認ゲートがあり、引用が解決された回答を提供します。
ライセンス
MIT — LICENSEを参照してください。
Available Tools
13 toolsadd_sourceA
Add one source to a notebook, from a URL, pasted text, or a local file.
Pass exactly one of url, text, or file_path.
| Name | Required | Description | Default |
|---|---|---|---|
| url | No | Web page, YouTube video, or Google Docs/Slides link to ingest. | |
| text | No | Raw text to paste as a source. Requires `title`. | |
| wait | No | Block until the source finishes processing so it is usable immediately. Turn off for bulk imports and poll list_sources. | |
| title | No | Display title. Required for `text`, optional otherwise. | |
| file_path | No | Absolute path to a local file (PDF, txt, md, audio...). Read from the machine running this server, not the user's client. | |
| notebook_id | Yes | Notebook to add the source to. |
Output Schema
| Name | Required | Description |
|---|---|---|
No output parameters | ||
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
No annotations are provided, so the description carries the full burden and it only partially does so. It implies a mutation on a notebook but says nothing about permissions, duplicate handling, or processing latency; the wait/blocking behavior is documented only in the schema description, not the tool description.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Two short sentences, purpose first then the critical constraint, with zero filler. Every sentence earns its place.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
With a full schema and an output schema present, the description need not cover return values or parameter formats, and it covers the core action plus the exclusivity rule. It leaves gaps only around invocation behavior (latency, permissions) that a no-annotation mutation tool arguably warrants.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema coverage is 100%, so the baseline is 3, but the description contributes the mutual-exclusion constraint among url/text/file_path that the schema itself does not encode. That is real added meaning beyond the per-parameter descriptions.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
States a specific verb (add) and resource (source to a notebook) and enumerates the three accepted input modalities (URL, pasted text, local file). This cleanly separates it from sibling list_sources and delete_source without needing to name them.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The instruction 'Pass exactly one of url, text, or file_path' is a genuine usage rule that is not enforced by the schema (which only sets additionalProperties: false and does not declare a oneOf), so it adds value. However, there is no guidance on when to choose this tool over siblings, nor when to prefer one input modality over another.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
askA
Ask a notebook a question and get an answer grounded in its sources.
The answer comes from Gemini reading the notebook's own sources, with citations back to them — use this instead of summarizing the sources yourself when a notebook already holds the material.
| Name | Required | Description | Default |
|---|---|---|---|
| question | Yes | Natural-language question. Specific questions cite better than broad ones. | |
| source_ids | No | Restrict the answer to these sources. Omit to use all. | |
| notebook_id | Yes | The notebook to query. | |
| conversation_id | No | Continue a specific conversation. Omit to continue the notebook's current one, matching the web UI. |
Output Schema
| Name | Required | Description |
|---|---|---|
No output parameters | ||
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations, the description must carry the behavioral burden, and it does disclose the key mechanism: the answer is produced by Gemini reading the notebook's own sources and is returned with citations. It says nothing about latency, cost, persistence of the Q&A, or auth requirements, so it is only partially transparent for a query tool with no annotation coverage.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Two short sentences, front-loaded with the action and immediately followed by the grounding/citation guarantee and the when-to-use rule. No filler or repetition.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
An output schema exists, so return-value explanation is unnecessary, and the description covers the mechanism, grounding, and citations an agent needs to trust the result. Only minor gaps remain around cost/latency and whether the interaction is persisted.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 100%, so the schema already explains notebook_id, source_ids scoping, conversation_id continuation, and the 'specific questions cite better' hint. The description adds no parameter meaning beyond that, so the baseline of 3 is appropriate.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description names a specific verb ('ask') and resource ('a notebook'), plus states the output is an answer 'grounded in its sources' with citations, which is concrete and distinguishable from sibling listing/generation tools like list_sources or generate_artifact. It stops short of naming any sibling it competes with, so the differentiation is implied rather than explicit.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
It gives a clear usage condition — 'use this instead of summarizing the sources yourself when a notebook already holds the material' — which tells the agent when this beats doing the work manually. No explicit exclusions or named alternative tools are provided, so it lands at 'clear context, no exclusions' rather than full routing guidance.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
auth_statusA
Check whether this server has a working NotebookLM session.
Call this first when any other tool reports an auth problem. It performs a real (cheap) request, so it distinguishes "no cookies stored" from "cookies stored but expired".
| Name | Required | Description | Default |
|---|---|---|---|
No parameters | |||
Output Schema
| Name | Required | Description |
|---|---|---|
No output parameters | ||
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations, the description carries the full burden and does disclose meaningful behavior: it makes a real (cheap) network request and can distinguish 'no cookies stored' from 'cookies stored but expired'. It does not mention permissions, rate limits, or failure modes, but for a diagnostic probe this is substantive disclosure.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Three short sentences, front-loaded with the purpose before the routing advice and the behavioral caveat. Every sentence adds information; nothing is padded.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
An output schema exists, so return values need no explanation. For a zero-parameter diagnostic tool, the description supplies everything needed to call it correctly: what it checks, when to call it, and that it costs a real request.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The tool takes zero parameters, so there is nothing for the description to disambiguate; the 4 baseline applies. The prose adds no parameter detail, but none is needed.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
States a specific verb and resource: checks whether the server has a working NotebookLM session. It is unmistakably distinct from every sibling (which act on notebooks, sources, artifacts, or chat), so an agent can identify it without opening a schema.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Gives an explicit trigger condition: call it first when any other tool reports an auth problem. It does not state the inverse (e.g., that it need not be called before routine operations), so it is clear context without full when-not guidance.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
chat_historyB
Read past question/answer turns for a notebook's current conversation.
| Name | Required | Description | Default |
|---|---|---|---|
| limit | No | Maximum number of turns to return, newest conversation first. | |
| notebook_id | Yes | The notebook whose conversation to read. |
Output Schema
| Name | Required | Description |
|---|---|---|
No output parameters | ||
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
No annotations are provided, so the description carries the full behavioral burden, and it supplies almost nothing beyond the word "Read." It does not state read-only guarantees, auth/permission requirements, ordering behavior, or what happens when the conversation is empty.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
A single front-loaded sentence with no filler; the resource and scope are stated in the first few words and nothing is wasted.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
With an output schema present, return values need not be described, and both parameters are documented. The only shortfall is the absence of any safety/behavioral note, which matters more here because there are no annotations to lean on.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 100%, with both notebook_id and limit fully documented in-schema (including the newest-first ordering), so the baseline is 3. The description's "current conversation" phrasing adds only marginal scope nuance over the schema.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description pairs a specific verb ("Read") with a specific resource ("past question/answer turns") scoped to "a notebook's current conversation." That is enough to distinguish it from siblings like ask or get_notebook, though it never names a sibling explicitly.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Usage is only implied: the "current conversation" framing suggests using it alongside ask to recover prior turns, but there is no explicit when-to-use, when-not-to-use, or named alternative. An agent must infer the trigger condition.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
create_notebookA
Create an empty notebook.
A notebook with no sources cannot answer questions — follow up with add_source before calling ask.
| Name | Required | Description | Default |
|---|---|---|---|
| title | Yes | Display title for the new notebook. |
Output Schema
| Name | Required | Description |
|---|---|---|
No output parameters | ||
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations, the description carries the full burden and does disclose a non-obvious behavioral trait: the created notebook starts empty and is functionally useless for answering questions until sources are added. It omits any mention of permissions/auth or duplicate-title behavior, but the key post-condition is stated.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Two short sentences with zero filler; the operation is stated first and the follow-up prerequisite second. Every sentence earns its place.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
An output schema exists, so return values need not be explained, and the description covers the essential behavior for a simple one-parameter creation tool. The only missing pieces are permission/error context, which is minor at this complexity.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
There is a single parameter (title) and schema description coverage is 100%, so the schema already explains it fully. The description adds no format, length, or uniqueness constraints beyond the schema, which is the baseline-3 situation.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
States a specific verb+resource ('Create an empty notebook') and immediately qualifies the result as empty, which tells an agent what state the object will be in. It does not name a sibling to contrast with, but the purpose is unambiguous.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Provides clear context: an empty notebook cannot answer questions, so call add_source before ask. That is real workflow guidance tying this tool to the next step. It lacks an explicit 'when not to use' clause or a comparison against list_notebooks/get_notebook, so it falls just short of a 5.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
delete_notebookA
Permanently delete a notebook and everything in it.
This cannot be undone and deletes the notebook's sources, chats, and generated artifacts along with it.
| Name | Required | Description | Default |
|---|---|---|---|
| confirm | No | Must be true. The guard exists so a mistaken tool call cannot destroy a notebook; ask the user before setting it. | |
| notebook_id | Yes | The notebook to delete. |
Output Schema
| Name | Required | Description |
|---|---|---|
No output parameters | ||
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations, the description carries the full burden and does well: it explicitly says the deletion is permanent, cannot be undone, and cascades to sources, chats, and generated artifacts. It omits permissions/authorization requirements and the confirmation ceremony, though the latter is covered by the schema.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Two short sentences, both front-loaded, with the irreversible nature placed immediately after the core action. No filler or repetition.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
An output schema exists, so return values need not be explained, and the destructive scope is fully described. The only gap is the absence of any authorization or prerequisite context for a permanently destructive operation.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 100%, so the schema already documents both notebook_id and the confirm guard, including the instruction to ask the user. The description adds no parameter-level detail beyond what structured fields provide, making the baseline 3 appropriate.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
Names a precise verb and resource ('delete_notebook') and specifies the blast radius ('everything in it', enumerated as sources, chats, and generated artifacts). This is enough to separate it from delete_source without opening either schema.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description states no conditions for when to use this tool, no prerequisites, and never points to alternatives such as delete_source for removing a single source. It conveys only that the action is destructive, which is informational rather than guidance.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
delete_sourceC
Remove a source from a notebook.
| Name | Required | Description | Default |
|---|---|---|---|
| confirm | No | Must be true. Removing a source also drops the citations that point at it, so ask the user first. | |
| source_id | Yes | The source to remove, from list_sources. | |
| notebook_id | Yes | The notebook holding the source. |
Output Schema
| Name | Required | Description |
|---|---|---|
No output parameters | ||
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
No annotations are provided, so the description carries the full burden. It says 'Remove' but omits that citations pointing at the source are dropped and that confirmation is required; those details live only in the schema's confirm parameter.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
A single front-loaded sentence with no wasted words. It is appropriately sized, though for a destructive action it is perhaps under-specified.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
An output schema exists and the input schema covers the required confirm flag and its consequences, so an agent has key operational details. However, the description itself adds almost no usage or behavioral context for a destructive removal tool.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 100%, and the parameters are richly documented (including the confirm requirement and citation consequence), so the baseline is 3. The description adds no additional parameter meaning.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
States a specific verb and resource with its scope: removing a source from a notebook. This distinguishes it from the sibling add_source, though it does not explicitly name alternatives.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description offers no when-to-use guidance or alternatives. The schema's confirm parameter says to ask the user first, but the description itself gives none of that routing context.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
download_artifactB
Download a completed Studio artifact to a file on the server host.
| Name | Required | Description | Default |
|---|---|---|---|
| artifact_id | Yes | The artifact to download, from list_artifacts. | |
| notebook_id | Yes | The notebook holding the artifact. | |
| output_path | No | Destination path. A bare filename lands in the configured download directory; omit it to name the file after the artifact. |
Output Schema
| Name | Required | Description |
|---|---|---|
No output parameters | ||
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations, the description carries the full burden. It usefully discloses the key behavioral trait that the file is written to the server host rather than returned to the caller, but says nothing about overwrite behavior, required permissions, or error handling for incomplete artifacts.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
A single front-loaded sentence with no filler; the action and destination are both established immediately.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
An output schema exists, so return values need no explanation, and the parameters are fully documented. However, for a tool with no annotations that writes a file to a host, the description omits permission requirements and overwrite semantics, leaving gaps an agent would want covered.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 100%, and output_path's path-resolution rules are already documented in the schema. The description adds only the 'server host' framing, so the baseline 3 applies.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
States a specific verb (Download) and resource (Studio artifact) plus the destination (a file on the server host). It clearly separates itself from list_artifacts and generate_artifact, though it never names a sibling explicitly.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The word 'completed' hints that only finished artifacts are downloadable, but there is no explicit when-to-use, prerequisite, or alternative (e.g., list_artifacts to find the artifact) guidance. Usage must be inferred.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
generate_artifactA
Generate a Studio artifact (podcast, report, quiz, mind map...).
Generation runs server-side and is slow — an audio overview commonly takes several minutes — and it consumes the account's daily Studio quota. Prefer the default wait=false and poll with list_artifacts.
| Name | Required | Description | Default |
|---|---|---|---|
| kind | Yes | One of audio, video, report, study_guide, quiz, flashcards, infographic, slide_deck, mind_map. | |
| wait | No | Block until the artifact is ready (or the configured timeout elapses) instead of returning as soon as it is queued. | |
| language | No | BCP-47 language code for the output, e.g. "en", "es". | en |
| quantity | No | quiz/flashcards only — fewer, standard, or more. | |
| difficulty | No | quiz/flashcards only — easy, medium, or hard. | |
| source_ids | No | Restrict generation to these sources. Omit to use all. | |
| notebook_id | Yes | Notebook whose sources feed the generation. | |
| audio_format | No | audio only — deep_dive, brief, critique, or debate. | |
| audio_length | No | audio only — short, default, or long. | |
| instructions | No | Free-text steer for the output ("focus on the pricing section", "explain it for beginners"). | |
| report_format | No | report only — briefing_doc, study_guide, or blog_post. |
Output Schema
| Name | Required | Description |
|---|---|---|
No output parameters | ||
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations, the description carries the full behavioral burden and does well: it discloses that generation is server-side, slow (audio can take minutes), and consumes the account's daily Studio quota. It stops short of covering auth requirements or failure behavior when the quota is exhausted.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Four tight sentences: purpose first, then cost/latency, then the recommended call pattern. Every sentence carries load and nothing is repeated from the schema.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
An output schema exists so return values needn't be explained, and all 11 parameters are schema-documented; the description supplies the missing quota and latency context plus the preferred invocation pattern. Only auth/prerequisite and failure-mode details are absent.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 100%, so every parameter (including wait, kind, and the kind-conditional options) is already documented in the schema. The description adds meaning to wait by pairing it with the polling workflow, but adds nothing else beyond the schema.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
States a specific verb (Generate) and resource (Studio artifact) and enumerates concrete artifact types (podcast, report, quiz, mind map), which lets an agent distinguish it from sibling read tools like list_artifacts and download_artifact.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Gives explicit operational guidance: prefer wait=false and poll with list_artifacts rather than blocking. It names the alternative tool and the condition that selects it, but says nothing about when NOT to use this tool (e.g., versus ask).
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
get_notebookC
Get one notebook with its sources.
| Name | Required | Description | Default |
|---|---|---|---|
| notebook_id | Yes | The notebook id, as returned by list_notebooks. | |
| include_summary | No | Also fetch NotebookLM's own generated summary of the notebook. Costs an extra round-trip and can be slow on large notebooks, so it is off by default. |
Output Schema
| Name | Required | Description |
|---|---|---|
No output parameters | ||
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
No annotations are provided, so the description carries the full behavioral burden, and it says almost nothing: no permission requirements, no error behavior for an invalid or missing notebook_id, no mention that the sources payload may be large. 'With its sources' hints at return content, but the output schema already covers that.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
A single, front-loaded sentence with no filler. It is efficient, though arguably under-specified rather than genuinely well-structured.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a low-complexity read tool with a full output schema and 100%-covered parameters, the description is minimally sufficient. The missing piece is routing guidance against list_notebooks/list_sources and any note on behavior when the id is unknown.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 100%: notebook_id is tied to list_notebooks output and include_summary's cost/latency tradeoff is fully documented in the schema. The description adds nothing for either parameter, so the baseline 3 applies.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description states a specific verb and resource ('Get one notebook') and adds scope detail ('with its sources') that distinguishes it from list_notebooks. It stops short of naming the sibling explicitly, but the singular 'one' makes the contrast inferable.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
No indication of when to use this tool versus list_notebooks, list_sources, or ask. The only implicit guidance is that a notebook_id must already be known, which is not stated in the description itself.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
list_artifactsA
List generated Studio artifacts in a notebook.
Use this to poll a generation started with wait=false: the artifact reports
status: completed when it is ready to download.
| Name | Required | Description | Default |
|---|---|---|---|
| kind | No | Filter by type — audio, video, report, quiz, flashcards, mind_map, infographic, slide_deck, or data_table. | |
| notebook_id | Yes | The notebook to inspect. |
Output Schema
| Name | Required | Description |
|---|---|---|
No output parameters | ||
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
No annotations are provided, so the description carries the burden. It helpfully discloses that artifacts expose a status field that flips to 'completed' — a real behavioral detail beyond the schema. However, it omits any mention of pagination, ordering, or permission requirements for a list endpoint.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Two short sentences, front-loaded with the core action and followed immediately by the polling use case. Every sentence earns its place with no filler.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a two-parameter list tool with a full output schema and 100% schema coverage, the description supplies the key missing operational context (the polling workflow). It is close to complete; only ordering/pagination expectations are unstated.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 100%: both notebook_id and the kind filter's enumerated values are documented in the schema itself. The description adds nothing about parameter meaning, so the baseline 3 applies.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description opens with a specific verb+resource+scope: listing generated Studio artifacts within a notebook. It naturally separates itself from siblings like generate_artifact and download_artifact by virtue of the 'list' verb and the notebook scoping.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
It gives a concrete usage scenario — polling a generation started with wait=false — and explains the readiness signal to look for. This is clear context, but it does not state when NOT to use it or point to alternatives (e.g. download_artifact once status is completed).
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
list_notebooksA
List the notebooks reachable by the signed-in Google account.
Returns id, title, and source count for each. Use the ids with every other tool — NotebookLM has no lookup by title.
| Name | Required | Description | Default |
|---|---|---|---|
No parameters | |||
Output Schema
| Name | Required | Description |
|---|---|---|
No output parameters | ||
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations, the description carries the full behavioral burden. It implies a read-only, account-scoped listing and previews the returned fields, but says nothing about pagination, result limits, or ordering, which matters for a list tool that may return many notebooks.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Three short sentences, front-loaded with the core action and followed by the return summary and the key routing rule. No filler and the most decision-relevant fact (ids are mandatory elsewhere) is kept.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a zero-parameter read tool with an output schema present, the description supplies everything needed to select and invoke it: what it lists, whose scope, what comes back, and why the result matters downstream.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The schema has zero parameters, so there is no parameter semantics to clarify; the baseline for a parameterless tool applies. Nothing in the description misleads about inputs.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
States a specific verb and resource ('List the notebooks') plus scope ('reachable by the signed-in Google account'). It also implicitly separates itself from get_notebook and other id-based siblings by noting that ids are the required handle throughout the toolset.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
'Use the ids with every other tool' tells the agent exactly when this tool is needed as a prerequisite step. It also rules out the title-based alternative ('NotebookLM has no lookup by title'), though it doesn't give explicit when-not-to-use conditions.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
list_sourcesB
List the sources in a notebook, with their processing status.
A source that is not ready is still being ingested and will not ground
answers yet.
| Name | Required | Description | Default |
|---|---|---|---|
| notebook_id | Yes |
Output Schema
| Name | Required | Description |
|---|---|---|
No output parameters | ||
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations, the description carries the full behavioral burden. It usefully discloses the meaning of processing status (non-ready sources do not ground answers), but it omits permissions, ordering, and pagination details for a read operation.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Two sentences, front-loaded, with no filler. The second sentence efficiently explains the status semantics.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given an existing output schema and a single self-evident notebook_id parameter, the description covers the tool's core purpose and status behavior sufficiently for correct invocation. The main gap is the undocumented notebook_id.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The only parameter, notebook_id, has 0% schema description coverage, and the description merely says 'in a notebook' without defining the identifier format or where to obtain it. It adds almost no semantic meaning beyond the parameter name.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
States a specific verb ('List') and resource ('sources in a notebook') plus the processing-status dimension. It does not explicitly contrast itself with siblings like list_notebooks or add_source, but the scope is distinct.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description implies usage by explaining that non-ready sources are still being ingested and will not ground answers. However, it does not say when to prefer this over alternatives or what a caller should do with the returned statuses.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections.
13 tool updates
v0.1.0- First observed
add_source - First observed
ask - First observed
auth_status - First observed
chat_history - First observed
create_notebook - First observed
delete_notebook - First observed
delete_source - First observed
download_artifact - First observed
generate_artifact - First observed
get_notebook - First observed
list_artifacts - First observed
list_notebooks - First observed
list_sources
TDQS
Scored across 13 tools
Most tools target a distinct resource+action (notebook CRUD, source add/delete/list, artifact generate/list/download, ask, auth). Minor overlap between get_notebook (returns notebook with sources) and list_sources (sources with processing status), but descriptions clarify the difference.
Strong verb_noun pattern for most tools (add_source, list_notebooks, create_notebook, list_artifacts, generate_artifact, download_artifact). A few deviations—ask (bare verb), chat_history and auth_status (noun phrases)—but overall readable and predictable.
13 tools is well-scoped for the NotebookLM domain, cleanly grouped into notebooks, sources, artifacts, and query/auth concerns. Each tool earns its place with no filler.
Good CRUD/lifecycle coverage: notebook create/get/list/delete, source add/delete/list, artifact generate/list/download, plus ask, chat_history, and auth_status. Minor gaps like notebook rename/update and source update, but core workflows are covered.
Maintenance
Related MCP Connectors
Google NotebookLM via natural language: create notebooks, add sources (PDF, URL, YouTube) and ask gr
- backrowOAuthai.backrow
Turn any recording or document into notes, flashcards and quizzes your agent can read and act on
Cited, versioned knowledge for agents: retrieve sourced passages and propose owner-approved fixes.
- KnowtisOAuthapp.knowtis
Create, search and manage Knowtis collaborative notes from AI assistants.
Related MCP Servers
- FlicenseAqualityDmaintenanceEnables AI agents to query and interact with Google NotebookLM notebooks to retrieve citation-backed information. It provides tools for listing notebooks, accessing source data, and asking natural language questions.11-
- AlicenseNot gradedqualityDmaintenanceEnables AI agents to programmatically access Google NotebookLM through browser automation for managing notebooks, sources, and chat interactions. It supports automated content generation including audio overviews, study guides, and quizzes directly within AI workflows.381 npmMIT
- AlicenseBqualityBmaintenanceEnables AI agents to interact with Google NotebookLM for grounded, hallucination-free answers through notebook management, source management, research, and generation tools.29381 npm39MIT
- AlicenseBqualityAmaintenanceEnables AI assistants to programmatically interact with Google NotebookLM, allowing them to create and manage notebooks, add sources, query content, generate audio/video, and perform research tasks through natural language commands.5319,474 PyPI6,246MIT