Skip to main content
Glama
ailenshen

Apple Notes MCP Server

by ailenshen

Apple Notes MCP 服务器

读取和写入 Apple Notes,支持 Apple Notes 原生格式

apple-notes-mcp MCP server

大多数 Apple Notes MCP 服务器只能写入纯文本。本服务器可以创建原生格式的笔记——标题、字号、粗体、列表等都会渲染为真正的 Apple Notes 样式,而非纯文本。这是通过利用 Notes.app 内置的 Markdown 导入功能实现的。

要求: macOS 26 (Tahoe) 或更高版本,Node.js 24+

设置

1. 添加到你的 MCP 客户端

Claude Desktop — 编辑 ~/Library/Application Support/Claude/claude_desktop_config.json

{
  "mcpServers": {
    "apple-notes": {
      "command": "npx",
      "args": ["-y", "@ailenshen/apple-notes-mcp@latest"]
    }
  }
}

Claude Code — 在终端运行:

claude mcp add apple-notes -- npx -y @ailenshen/apple-notes-mcp@latest

2. 授予权限

为了支持原生格式,服务器使用了 Notes.app 内置的 Markdown 导入功能——它会用 Notes.app 打开 .md 文件并自动确认导入对话框。这需要为 node 授予两个 macOS 权限:

权限

启用位置

原因

完全磁盘访问权限

系统设置 > 隐私与安全性 > 完全磁盘访问权限 > 启用 node

读取笔记数据库以进行列出和搜索

辅助功能

系统设置 > 隐私与安全性 > 辅助功能 > 启用 node

创建笔记时自动确认导入对话框

首次使用时,macOS 会提示你批准——只需点击“允许”。如果你错过了提示,请前往上述设置手动开启 node。授予权限后,重启你的 MCP 客户端。

如果缺少权限,服务器会明确告知你缺少哪一项以及如何修复。

3. 开始使用

像平时一样与 AI 对话即可:

  • “列出我在 Projects 文件夹中的所有笔记”

  • “在我的笔记中搜索‘会议议程’”

  • “读取我的购物清单笔记”

  • “在 Work 中创建一个包含今日待办事项的笔记”

  • “用这些新项目更新我的购物清单”

  • “删除名为‘旧草稿’的笔记”

Related MCP server: Apple Mail MCP

它能做什么?

工具

描述

list_notes

浏览笔记,可选择按文件夹过滤

search_notes

按关键词查找笔记

get_note

以 Markdown 格式读取完整内容

create_note

写入 Markdown → 原生格式笔记

update_note

替换内容,保留文件夹位置

delete_note

移至“最近删除”

Notes 中的 Markdown 支持

元素

是否支持?

标题、粗体斜体、列表、inline code

引用块

保留内容,无缩进样式

链接

保留文本,丢失 URL

表格、脚注

远程访问(HTTP 模式)

想要从手机或其他电脑访问你的 Apple Notes 吗?

npx @ailenshen/apple-notes-mcp@latest --http

这将打印一个带有内置密钥的端点 URL:

Endpoint: http://localhost:3100/mcp/a3f8b2c9e1d4...

将你的远程 MCP 客户端指向此 URL。若要通过互联网访问,请使用隧道(ngrok、Cloudflare Tunnel 等)将其置于 HTTPS 之后。

标志

默认值

描述

--port <number>

3100

端口号

--secret <string>

随机

自定义 URL 密钥

若要使其在重启后保持运行,请参阅 wiki 中的 LaunchAgent 示例。

工作原理

操作

方法

速度

列出 / 搜索

SQLite (只读)

< 100ms

读取

AppleScript → Markdown

~1s

创建

原生 Markdown 导入

~0.5s

更新

删除 + 创建

~1.5s

删除

AppleScript

~1s

  • 读取:通过 SQLite 直接查询笔记数据库——快速且安全。内容通过 turndown 从 Apple 的 HTML 转换为 Markdown。

  • 创建:使用 macOS 原生的 Markdown 导入功能 (open -a Notes),因此原生保留了格式。创建过程中 Notes.app 会短暂出现(约 0.5 秒)。

  • 更新:删除旧笔记并创建一个新笔记,自动保留原始文件夹。

  • 删除:将笔记移至“最近删除”,与手动操作相同。

已知限制

  • 不支持部分笔记编辑(例如“只修改这一段”)。update_note 总是替换全部内容。这是 Notes 暴露内容方式的根本限制——其 AppleScript 接口返回的是 HTML 而非原始 Markdown,因此目前无法实现干净的“读取→编辑→写入”循环。

  • 创建笔记时 Notes 会短暂出现。Markdown 导入流程需要在 Notes.app 中自动确认对话框,这可能会使其瞬间置于前台。

如果 Apple 在 AppleScript 中添加 Markdown 导入/导出功能,或开放官方 Notes API,这些限制将会解除——目前这两个方向都在关注未来的 macOS 版本。

愿景

Apple Notes 是在 Apple 设备上保存个人知识最自然的地方——它随处同步、快速且私密。但它是一个没有 API 的封闭花园。

本项目使 Apple Notes 成为 AI 的一流数据源。长期目标是:无论你在哪里与 AI 对话——在 Mac 上、手机上还是网页上——你的 Apple Notes 始终是可访问、可读且可写的。

许可证

MIT

Available Tools

6 tools
create_noteA

Create a new note in Apple Notes from Markdown content. The first line becomes the title. Optionally specify a target folder (defaults to 'Notes').

ParametersJSON Schema
NameRequiredDescriptionDefault
folderNoTarget folder name (e.g. 'Projects'). Defaults to 'Notes'.
markdownYesMarkdown content for the note. First line (with or without #) becomes the title.

TDQS

A3.8/5.0
Behavior2/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

No annotations provided, so the description carries full burden. It discloses title extraction and folder defaults but omits behavioral details like side effects, irreversibility, authentication needs, or what happens on failure. For a mutation tool, this is insufficient.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Two sentences with no wasted words. The first sentence states the core action, the second explains important details (title extraction, folder). Efficient and well-structured.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a simple creation tool with two parameters and no output schema, the description covers the essential behavior and key defaults. It lacks mention of return value or confirmation, but given the simplicity, it is largely sufficient.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100%, but the description adds value: it explains that the first line of markdown becomes the title, which is not in the schema. The folder parameter default is also reiterated, but schema already includes that. Overall, description enhances parameter understanding.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly states the verb 'create', the resource 'note', and the source 'Markdown content'. It explains that the first line becomes the title and mentions optional folder with default. This distinguishes it from sibling tools like delete_note, get_note, etc.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description does not explicitly guide when to use this tool versus alternatives (e.g., update_note). It implies usage for creating new notes but lacks explicit exclusions or conditions, leaving it to the agent to infer from sibling names.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

delete_noteA

Delete a note from Apple Notes by title. Optionally specify folder to disambiguate. The note is moved to Recently Deleted.

ParametersJSON Schema
NameRequiredDescriptionDefault
titleYesTitle of the note to delete
folderNoFolder name to scope the search

TDQS

A4.2/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With no annotations, the description provides key behavioral context: the note is moved to Recently Deleted (not permanently erased), which is important for decision-making. However, it does not detail side effects, permission requirements, or recovery timeframe.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Extremely concise at two sentences, with the most critical information first. No unnecessary words or repetition.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a delete operation without output schema, the description adequately covers the action and its immediate consequence. It could mention that the note enters a recoverable state, but the core behavior is clear.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

The schema already describes both parameters (title required, folder optional). The description adds meaning by clarifying that title is the primary identifier and folder is for disambiguation, which is not redundant with schema.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly states the verb (delete), resource (note), and method (by title). It also distinguishes from siblings like update_note by specifying the action and the consequence ('moved to Recently Deleted').

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

It implies when to use the folder parameter for disambiguation but lacks explicit guidance on when to choose delete_note over other tools like search_notes or update_note. No prerequisites or exclusions are mentioned.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

get_noteA

Get the full content of a note by its title, returned as Markdown. Optionally specify folder to disambiguate.

ParametersJSON Schema
NameRequiredDescriptionDefault
titleYesNote title (exact match)
folderNoFolder name to scope the search

TDQS

A3.6/5.0
Behavior3/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

No annotations are provided, so the description carries the full burden. It states the output format (Markdown) but does not disclose error behavior (e.g., note not found), authentication requirements, or rate limits. Basic behavioral info is present, but significant gaps remain for a read operation.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is a single sentence with no wasted words. It front-loads the core purpose and output format, then adds the optional parameter. Perfectly concise for a simple tool.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Given the tool's simplicity (two params, no output schema, no nested objects), the description covers the essentials: what it does, required input, output format, and optional disambiguation. Missing error handling details, but overall adequate for a straightforward retrieval tool.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100%, so the schema already documents both parameters. The description adds minimal value: 'by its title' and 'Optionally specify folder to disambiguate' reinforce but don't extend the schema. Baseline 3 is appropriate.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly states 'Get the full content of a note by its title, returned as Markdown.' It uses a specific verb and resource, and implicitly distinguishes from siblings (create, delete, list, search, update) by focusing on retrieval. Could be improved by noting it returns a single note, not a list.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description mentions 'Optionally specify folder to disambiguate,' providing a clear use case for the folder parameter. However, it offers no guidance on when not to use this tool versus alternatives, nor does it suggest using search_notes when the title is unknown. The sibling context helps but is not integrated.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

list_notesB

List notes from Apple Notes. Returns title, folder, dates, pinned status, snippet. Optionally filter by folder name and limit results.

ParametersJSON Schema
NameRequiredDescriptionDefault
limitNoMax number of notes to return
folderNoFilter by folder name

TDQS

B3.4/5.0
Behavior3/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

No annotations are present, so the description carries the full burden. It discloses the return fields and optional filters, but does not mention default behavior (e.g., sort order, default limit), potential side effects, or authentication requirements. This is adequate for a simple read tool but leaves gaps.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Two sentences are used, containing only relevant information. No redundant or extraneous text. The key purpose and options are front-loaded.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Given the lack of output schema, the description adequately describes the return format. The tool is simple with only two optional parameters. However, it does not mention pagination or default limit behavior, which are common for listing tools. Still, it is mostly complete for its complexity.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

The input schema provides descriptions for both parameters (limit and folder), and the description reiterates these options. Since schema coverage is 100%, the description adds minimal value beyond summarizing the schema. Baseline 3 is appropriate.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly states the action (list notes), the source (Apple Notes), and the returned fields (title, folder, dates, pinned status, snippet). It distinguishes from siblings like create_note and delete_note by focusing on listing, but does not explicitly differentiate from search_notes, which might offer more advanced filtering.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines2/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

No guidance is provided on when to use this tool versus alternatives like search_notes. There is no mention of prerequisites, limitations, or when not to use it. The description assumes the agent will infer usage from context.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

search_notesA

Search Apple Notes by keyword. Searches in title and snippet. Returns matching notes with metadata.

ParametersJSON Schema
NameRequiredDescriptionDefault
limitNoMax number of results
queryYesSearch keyword

TDQS

A3.7/5.0
Behavior2/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

No annotations are present, so the description bears full responsibility for behavioral disclosure. It mentions returns metadata but does not explain behavior for no matches, pagination, rate limits, or authentication needs.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Two concise sentences, front-loaded with the action, and no extraneous information. Every word adds value.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness3/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Given no output schema and simple parameters, the description covers the basic functionality. However, it lacks details about default limit, ordering of results, or what specific metadata is returned, leaving some gaps.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100%, but the description adds value by specifying that 'query' searches in title and snippet, which is beyond the schema's 'Search keyword' description. This clarifies the scope of the parameter.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

Description clearly states the tool searches Apple Notes by keyword in title and snippet, and returns matching notes with metadata. This distinguishes it from sibling tools like list_notes (listing all) and get_note (single note retrieval).

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description implies usage for keyword-based search but does not explicitly state when to use this tool versus alternatives like list_notes or get_note. No when-to-use or when-not-to-use guidance is provided.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

update_noteA

Update an existing note in Apple Notes. Deletes the old note and creates a new one with the given Markdown content, preserving the original folder.

ParametersJSON Schema
NameRequiredDescriptionDefault
titleYesTitle of the existing note to update
folderNoFolder name to scope the search for the existing note
markdownYesNew Markdown content for the note. First line (with or without #) becomes the title.

TDQS

A4.4/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

The description explicitly discloses the critical behavioral trait: 'Deletes the old note and creates a new one', which is essential because a user might assume in-place modification. This transparency is high. No annotations are present to conflict.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is only two sentences, front-loading the main action and then adding the important behavioral detail. Every part is informative, with no redundancy or extraneous text.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Given the straightforward nature (3 parameters, no output schema), the description covers the core functionality and behavioral change. It lacks mention of error conditions or prerequisites (e.g., note must exist), but is otherwise sufficient for usage.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100%, but the description adds value by clarifying that the first line of markdown becomes the title (with or without #), which is not in the schema. This extends understanding beyond the parameter descriptions.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly states 'Update an existing note in Apple Notes', specifying the verb (update), resource (note), and system (Apple Notes). It distinguishes from siblings like create_note and delete_note by describing that this tool deletes the old note and creates a new one, making it a unique replacement operation.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description implies when to use the tool (to update content while preserving folder) but does not explicitly state when not to use it or mention alternative tools. Sibling tools are provided in context but not referenced in the description.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Tool Schema Changelog

Recent tool additions, removals, and schema changes observed during successful MCP inspections. Dates show when Glama detected each change.

  1. 6 tool updatesv1.2.5
    • Removedcreate_note
    • Removeddelete_note
    • Removedget_note
    • Removedlist_notes
    • Removedsearch_notes
    • Removedupdate_note
  2. 6 tool updatesv1.3.1
    • Addedcreate_note
    • Addeddelete_note
    • Addedget_note
    • Addedlist_notes
    • Addedsearch_notes
    • Addedupdate_note
  3. 6 tool updatesv1.2.3
    • Removedcreate_note
    • Removeddelete_note
    • Removedget_note
    • Removedlist_notes
    • Removedsearch_notes
    • Removedupdate_note
  4. 6 tool updatesv0.1.0
    • First observedcreate_note
    • First observeddelete_note
    • First observedget_note
    • First observedlist_notes
    • First observedsearch_notes
    • First observedupdate_note

TDQS

A4/5.0
Disambiguation5/5

Each tool targets a distinct operation on notes (create, delete, get, list, search, update) with clear differences between getting full content, listing metadata, and searching by keyword. No two tools have overlapping purposes.

Naming Consistency5/5

All tool names follow the verb_noun pattern with appropriate singular/plural forms (e.g., create_note, list_notes). Verbs accurately describe the action, and naming is consistent throughout.

Tool Count5/5

Six tools cover the essential CRUD operations plus listing and searching for an Apple Notes server. Each tool has a clear purpose, and the count is well-scoped for the domain.

Completeness4/5

The set covers CRUD, listing, and search comprehensively. However, the update tool re-creates the note, potentially losing metadata like creation date and pin status, and there is no direct move/folder change operation. These are minor gaps that agents can work around.

Maintenance

ActivityInactive
ResponsivenessSyncing

Resources

Unclaimed servers have limited discoverability.

Looking for Admin?

If you are the server author, to access and configure the admin panel.

Related MCP Connectors

Related MCP Servers

  • A
    license
    A
    quality
    A
    maintenance
    A high-performance MCP server for Apple Mail that uses optimized JavaScript for Automation (JXA) to search and manage emails. It enables users to list accounts, fetch mailboxes, and retrieve today's, unread, or flagged messages with significantly improved speed through batch property fetching.
    7
    63
    GPL 3.0
  • A
    license
    Not graded
    quality
    D
    maintenance
    Enables AI assistants to save well-organized technical articles to Apple Notes and local Markdown files simultaneously.
    1,440
    MIT
  • F
    license
    Not graded
    quality
    D
    maintenance
    Enables LLMs to read, write, and manage Apple Notes directly via markdown, including listing, fetching, creating, and appending notes.
    41
    -

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/ailenshen/apple-notes-mcp'

If you have feedback or need assistance with the MCP directory API, please join our Discord server