Apple Notes MCP Server
Apple Notes MCP サーバー
Apple Notesのネイティブフォーマットをサポートし、Apple Notesの読み書きを行います。
ほとんどのApple Notes MCPサーバーはプレーンテキストしか書き込めませんが、このサーバーはネイティブにフォーマットされたノートを作成します。タイトル、見出し、太字、リストなどは、プレーンテキストではなく、実際のApple Notesのスタイルとしてレンダリングされます。これは、Notes.appに組み込まれているMarkdownインポート機能を活用することで実現しています。
要件: macOS 26 (Tahoe) 以降、Node.js 24以上
セットアップ
1. MCPクライアントに追加する
Claude Desktop — ~/Library/Application Support/Claude/claude_desktop_config.json を編集します:
{
"mcpServers": {
"apple-notes": {
"command": "npx",
"args": ["-y", "@ailenshen/apple-notes-mcp@latest"]
}
}
}Claude Code — ターミナルで実行します:
claude mcp add apple-notes -- npx -y @ailenshen/apple-notes-mcp@latest2. 権限を付与する
ネイティブフォーマットをサポートするため、このサーバーはNotes.appの組み込みMarkdownインポート機能を使用します。これは.mdファイルをNotes.appで開き、インポートダイアログを自動的に確定させるものです。これにはnodeに対して2つのmacOS権限が必要です:
権限 | 有効にする場所 | 理由 |
フルディスクアクセス | システム設定 > プライバシーとセキュリティ > フルディスクアクセス > | ノートのリスト表示と検索のためにデータベースを読み取る |
アクセシビリティ | システム設定 > プライバシーとセキュリティ > アクセシビリティ > | ノート作成時にインポートダイアログを自動確定させる |
初回使用時にmacOSから承認を求められるので、「許可」をクリックしてください。プロンプトを見逃した場合は、上記の設定から手動でnodeをオンにしてください。権限付与後、MCPクライアントを再起動してください。
権限が不足している場合、サーバーがどの権限が必要か、どう修正すべきかを正確に伝えます。
3. 使用を開始する
AIに自然に話しかけるだけです:
「Projectsフォルダにあるすべてのノートをリストアップして」
「ノートから『会議の議題』を検索して」
「『買い物リスト』というノートを読んで」
「Workフォルダに今日のタスク項目を含むノートを作成して」
「『買い物リスト』をこれらの新しい項目で更新して」
「『古いドラフト』という名前のノートを削除して」
Related MCP server: Apple Mail MCP
何ができるか?
ツール | 説明 |
| ノートを閲覧する(フォルダでフィルタリング可能) |
| キーワードでノートを探す |
| 内容をMarkdownとして読み込む |
| Markdownを書き込み、ネイティブフォーマットのノートを作成する |
| フォルダを維持したまま内容を置き換える |
| 「最近削除した項目」に移動する |
NotesでのMarkdownサポート
要素 | 対応状況 |
見出し、太字、斜体、リスト、 | はい |
引用ブロック | 内容は保持されるが、インデントスタイルはなし |
リンク | テキストは保持されるが、URLは失われる |
テーブル、脚注 | いいえ |
リモートアクセス (HTTPモード)
スマートフォンや別のコンピュータからApple Notesにアクセスしたいですか?
npx @ailenshen/apple-notes-mcp@latest --httpこれにより、組み込みシークレットを含むエンドポイントURLが表示されます:
Endpoint: http://localhost:3100/mcp/a3f8b2c9e1d4...リモートのMCPクライアントをこのURLに向けてください。インターネット経由でアクセスするには、トンネル(ngrok、Cloudflare Tunnelなど)を使用してHTTPSの背後に配置してください。
フラグ | デフォルト | 説明 |
| 3100 | ポート番号 |
| ランダム | カスタムURLシークレット |
再起動後も実行し続けるには、wikiのLaunchAgentの例を参照してください。
仕組み
アクション | メソッド | 速度 |
リスト / 検索 | SQLite (読み取り専用) | < 100ms |
読み取り | AppleScript → Markdown | ~1秒 |
作成 | ネイティブMarkdownインポート | ~0.5秒 |
更新 | 削除 + 作成 | ~1.5秒 |
削除 | AppleScript | ~1秒 |
読み取りは、SQLiteを介してNotesデータベースを直接クエリするため、高速かつ安全です。内容はturndownを介してAppleのHTMLからMarkdownに変換されます。
作成はmacOSのネイティブMarkdownインポート(
open -a Notes)を使用するため、フォーマットがネイティブに保持されます。作成中、Notes.appが短時間(約0.5秒)表示されます。更新は古いノートを削除して新しいノートを作成し、元のフォルダを自動的に保持します。
削除は手動で行うのと同様に、ノートを「最近削除した項目」に移動します。
既知の制限事項
ノートの部分編集(例:「この段落だけ修正して」)はサポートされていません。
update_noteは常に内容全体を置き換えます。これはNotesがコンテンツを公開する方法の根本的な制限です。AppleScriptインターフェースは元のMarkdownではなくHTMLを返すため、クリーンな「読み取り→編集→書き込み」の往復は現在不可能です。ノート作成中にNotesが短時間表示されます。MarkdownインポートフローではNotes.appのダイアログを自動確定させる必要があり、その際に一時的に前面に表示されることがあります。
これらの制限は、AppleがAppleScriptにMarkdownのインポート/エクスポートを追加するか、公式のNotes APIを公開すれば解消されます。どちらも将来のmacOSリリースに向けて追跡されています。
ビジョン
Apple Notesは、Appleデバイス上で個人の知識を保持するための最も自然な場所です。同期はどこでも行われ、高速で、プライベートです。しかし、APIのない「壁に囲まれた庭」でもあります。
このプロジェクトは、Apple NotesをAIにとってのファーストクラスのデータソースにします。長期的な目標は、Mac、スマートフォン、Webなど、どこでAIと対話していても、Apple Notesに常にアクセスでき、読み書きできるようにすることです。
ライセンス
MIT
Available Tools
6 toolscreate_noteA
Create a new note in Apple Notes from Markdown content. The first line becomes the title. Optionally specify a target folder (defaults to 'Notes').
| Name | Required | Description | Default |
|---|---|---|---|
| folder | No | Target folder name (e.g. 'Projects'). Defaults to 'Notes'. | |
| markdown | Yes | Markdown content for the note. First line (with or without #) becomes the title. |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
No annotations provided, so the description carries full burden. It discloses title extraction and folder defaults but omits behavioral details like side effects, irreversibility, authentication needs, or what happens on failure. For a mutation tool, this is insufficient.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Two sentences with no wasted words. The first sentence states the core action, the second explains important details (title extraction, folder). Efficient and well-structured.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a simple creation tool with two parameters and no output schema, the description covers the essential behavior and key defaults. It lacks mention of return value or confirmation, but given the simplicity, it is largely sufficient.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema coverage is 100%, but the description adds value: it explains that the first line of markdown becomes the title, which is not in the schema. The folder parameter default is also reiterated, but schema already includes that. Overall, description enhances parameter understanding.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the verb 'create', the resource 'note', and the source 'Markdown content'. It explains that the first line becomes the title and mentions optional folder with default. This distinguishes it from sibling tools like delete_note, get_note, etc.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description does not explicitly guide when to use this tool versus alternatives (e.g., update_note). It implies usage for creating new notes but lacks explicit exclusions or conditions, leaving it to the agent to infer from sibling names.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
delete_noteA
Delete a note from Apple Notes by title. Optionally specify folder to disambiguate. The note is moved to Recently Deleted.
| Name | Required | Description | Default |
|---|---|---|---|
| title | Yes | Title of the note to delete | |
| folder | No | Folder name to scope the search |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations, the description provides key behavioral context: the note is moved to Recently Deleted (not permanently erased), which is important for decision-making. However, it does not detail side effects, permission requirements, or recovery timeframe.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Extremely concise at two sentences, with the most critical information first. No unnecessary words or repetition.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a delete operation without output schema, the description adequately covers the action and its immediate consequence. It could mention that the note enters a recoverable state, but the core behavior is clear.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The schema already describes both parameters (title required, folder optional). The description adds meaning by clarifying that title is the primary identifier and folder is for disambiguation, which is not redundant with schema.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the verb (delete), resource (note), and method (by title). It also distinguishes from siblings like update_note by specifying the action and the consequence ('moved to Recently Deleted').
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
It implies when to use the folder parameter for disambiguation but lacks explicit guidance on when to choose delete_note over other tools like search_notes or update_note. No prerequisites or exclusions are mentioned.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
get_noteA
Get the full content of a note by its title, returned as Markdown. Optionally specify folder to disambiguate.
| Name | Required | Description | Default |
|---|---|---|---|
| title | Yes | Note title (exact match) | |
| folder | No | Folder name to scope the search |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
No annotations are provided, so the description carries the full burden. It states the output format (Markdown) but does not disclose error behavior (e.g., note not found), authentication requirements, or rate limits. Basic behavioral info is present, but significant gaps remain for a read operation.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is a single sentence with no wasted words. It front-loads the core purpose and output format, then adds the optional parameter. Perfectly concise for a simple tool.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given the tool's simplicity (two params, no output schema, no nested objects), the description covers the essentials: what it does, required input, output format, and optional disambiguation. Missing error handling details, but overall adequate for a straightforward retrieval tool.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 100%, so the schema already documents both parameters. The description adds minimal value: 'by its title' and 'Optionally specify folder to disambiguate' reinforce but don't extend the schema. Baseline 3 is appropriate.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states 'Get the full content of a note by its title, returned as Markdown.' It uses a specific verb and resource, and implicitly distinguishes from siblings (create, delete, list, search, update) by focusing on retrieval. Could be improved by noting it returns a single note, not a list.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description mentions 'Optionally specify folder to disambiguate,' providing a clear use case for the folder parameter. However, it offers no guidance on when not to use this tool versus alternatives, nor does it suggest using search_notes when the title is unknown. The sibling context helps but is not integrated.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
list_notesB
List notes from Apple Notes. Returns title, folder, dates, pinned status, snippet. Optionally filter by folder name and limit results.
| Name | Required | Description | Default |
|---|---|---|---|
| limit | No | Max number of notes to return | |
| folder | No | Filter by folder name |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
No annotations are present, so the description carries the full burden. It discloses the return fields and optional filters, but does not mention default behavior (e.g., sort order, default limit), potential side effects, or authentication requirements. This is adequate for a simple read tool but leaves gaps.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Two sentences are used, containing only relevant information. No redundant or extraneous text. The key purpose and options are front-loaded.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given the lack of output schema, the description adequately describes the return format. The tool is simple with only two optional parameters. However, it does not mention pagination or default limit behavior, which are common for listing tools. Still, it is mostly complete for its complexity.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The input schema provides descriptions for both parameters (limit and folder), and the description reiterates these options. Since schema coverage is 100%, the description adds minimal value beyond summarizing the schema. Baseline 3 is appropriate.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the action (list notes), the source (Apple Notes), and the returned fields (title, folder, dates, pinned status, snippet). It distinguishes from siblings like create_note and delete_note by focusing on listing, but does not explicitly differentiate from search_notes, which might offer more advanced filtering.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
No guidance is provided on when to use this tool versus alternatives like search_notes. There is no mention of prerequisites, limitations, or when not to use it. The description assumes the agent will infer usage from context.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
search_notesA
Search Apple Notes by keyword. Searches in title and snippet. Returns matching notes with metadata.
| Name | Required | Description | Default |
|---|---|---|---|
| limit | No | Max number of results | |
| query | Yes | Search keyword |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
No annotations are present, so the description bears full responsibility for behavioral disclosure. It mentions returns metadata but does not explain behavior for no matches, pagination, rate limits, or authentication needs.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Two concise sentences, front-loaded with the action, and no extraneous information. Every word adds value.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given no output schema and simple parameters, the description covers the basic functionality. However, it lacks details about default limit, ordering of results, or what specific metadata is returned, leaving some gaps.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema coverage is 100%, but the description adds value by specifying that 'query' searches in title and snippet, which is beyond the schema's 'Search keyword' description. This clarifies the scope of the parameter.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
Description clearly states the tool searches Apple Notes by keyword in title and snippet, and returns matching notes with metadata. This distinguishes it from sibling tools like list_notes (listing all) and get_note (single note retrieval).
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description implies usage for keyword-based search but does not explicitly state when to use this tool versus alternatives like list_notes or get_note. No when-to-use or when-not-to-use guidance is provided.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
update_noteA
Update an existing note in Apple Notes. Deletes the old note and creates a new one with the given Markdown content, preserving the original folder.
| Name | Required | Description | Default |
|---|---|---|---|
| title | Yes | Title of the existing note to update | |
| folder | No | Folder name to scope the search for the existing note | |
| markdown | Yes | New Markdown content for the note. First line (with or without #) becomes the title. |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
The description explicitly discloses the critical behavioral trait: 'Deletes the old note and creates a new one', which is essential because a user might assume in-place modification. This transparency is high. No annotations are present to conflict.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is only two sentences, front-loading the main action and then adding the important behavioral detail. Every part is informative, with no redundancy or extraneous text.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given the straightforward nature (3 parameters, no output schema), the description covers the core functionality and behavioral change. It lacks mention of error conditions or prerequisites (e.g., note must exist), but is otherwise sufficient for usage.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 100%, but the description adds value by clarifying that the first line of markdown becomes the title (with or without #), which is not in the schema. This extends understanding beyond the parameter descriptions.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states 'Update an existing note in Apple Notes', specifying the verb (update), resource (note), and system (Apple Notes). It distinguishes from siblings like create_note and delete_note by describing that this tool deletes the old note and creates a new one, making it a unique replacement operation.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description implies when to use the tool (to update content while preserving folder) but does not explicitly state when not to use it or mention alternative tools. Sibling tools are provided in context but not referenced in the description.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections. Dates show when Glama detected each change.
6 tool updates
v1.2.5- Removed
create_note - Removed
delete_note - Removed
get_note - Removed
list_notes - Removed
search_notes - Removed
update_note
6 tool updates
v1.3.1- Added
create_note - Added
delete_note - Added
get_note - Added
list_notes - Added
search_notes - Added
update_note
6 tool updates
v1.2.3- Removed
create_note - Removed
delete_note - Removed
get_note - Removed
list_notes - Removed
search_notes - Removed
update_note
6 tool updates
v0.1.0- First observed
create_note - First observed
delete_note - First observed
get_note - First observed
list_notes - First observed
search_notes - First observed
update_note
TDQS
Each tool targets a distinct operation on notes (create, delete, get, list, search, update) with clear differences between getting full content, listing metadata, and searching by keyword. No two tools have overlapping purposes.
All tool names follow the verb_noun pattern with appropriate singular/plural forms (e.g., create_note, list_notes). Verbs accurately describe the action, and naming is consistent throughout.
Six tools cover the essential CRUD operations plus listing and searching for an Apple Notes server. Each tool has a clear purpose, and the count is well-scoped for the domain.
The set covers CRUD, listing, and search comprehensively. However, the update tool re-creates the note, potentially losing metadata like creation date and pin status, and there is no direct move/folder change operation. These are minor gaps that agents can work around.
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Connectors
Convert documents and web pages to clean Markdown: PDF, DOCX, XLSX, EPUB, scanned files, any URL.
Convert PDF, DOCX, HTML, and URLs to clean, LLM-ready markdown with tables preserved
Search, read, and write your Apple Notes from ChatGPT/Claude via a local Mac agent + MCP relay.
- mcpOAuthcom.mdtidy
Clean, repair, and convert AI-generated Markdown to HTML/PDF/DOCX/PNG; save and share documents.
Related MCP Servers
- MIT
- AlicenseAqualityAmaintenanceA high-performance MCP server for Apple Mail that uses optimized JavaScript for Automation (JXA) to search and manage emails. It enables users to list accounts, fetch mailboxes, and retrieve today's, unread, or flagged messages with significantly improved speed through batch property fetching.763GPL 3.0
- AlicenseNot gradedqualityDmaintenanceEnables AI assistants to save well-organized technical articles to Apple Notes and local Markdown files simultaneously.433MIT
- FlicenseNot gradedqualityDmaintenanceEnables LLMs to read, write, and manage Apple Notes directly via markdown, including listing, fetching, creating, and appending notes.41-
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/ailenshen/apple-notes-mcp'
If you have feedback or need assistance with the MCP directory API, please join our Discord server