notes-mcp
This server acts as a virtual sticky notes manager, allowing you to create, store, search, and manage plain Markdown notes on your local machine via an MCP client. Key capabilities include:
Add notes (
add_note): Save a note with a title, optional Markdown body, and optional tags.List notes (
list_notes): View a summary of notes (IDs, titles, tags, and a blurb), sorted by most recently updated; optionally filter by a specific tag.Search notes (
search_notes): Find notes by case-insensitive text search in titles/bodies, combined with tag filters; you can require matching all tags or any of them (match_all).Read a note (
get_note): Retrieve the full Markdown content of a note by its ID.Delete notes (
delete_note): Permanently remove a note by ID; the ID is freed for future reuse.Browse resources: Access all notes as an index (
notes://all), a tag usage summary (notes://tags), or the full source of an individual note (note://{note_id}).Summarize notes (prompt): Use
summarize_notesto gather notes (optionally filtered by tag), group them by theme, and extract tasks or open questions.
Notes are stored locally as plain Markdown files ({id}.md) in ~/.notes-mcp/notes/ (or a configurable directory) with secure file permissions (0600). The server validates note IDs to prevent directory traversal attacks, though notes are not encrypted. This setup enables direct access and editing of notes outside the server as well.
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@notes-mcpsave a note about the project meeting tomorrow"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
notes-mcp: Virtual Sticky Notes
for Mac
An MCP server that keeps notes on your own machine, stored as plain Markdown files. Connect it to Claude Code or Claude Desktop and you can say "save a note about this" or "what did I write down about the migration?" in the middle of a conversation.
What it exposes
MCP servers offer three kinds of things to a client. This one uses all three, because they do different jobs:
Tools are verbs. They are actions the model decides to take. Writing and deleting notes belongs here.
Resources are nouns. They are content the client can pull into context, addressed by URI. The model does not have to "decide" to call them; you or the client can attach them directly.
Prompts are reusable message templates the user invokes deliberately, usually from a menu.
Tools
Tool | Arguments | Returns |
|
| The new note's id |
|
| A Markdown table: id, title, tags, and a short blurb |
|
| Matching notes with a short snippet |
|
| One note in full, including its body |
|
| Confirmation |
search_notes matches query against note titles and bodies, case-insensitively, and ANDs that
with the tag filter. match_all decides whether a note needs every tag listed or just one of them.
Resources
URI | Contents |
| An index of every note: id, title, tags |
| Every tag in use, with how many notes carry it |
| One note's full Markdown source |
note://{note_id} is a resource template — the client fills in {note_id} to read a specific
note, rather than the server listing all of them up front. Since ids are small integers, that
means note://5 for the fifth note.
Prompt
summarize_notes(tag) gathers your notes, groups them by theme, and pulls out anything that looks
like a task or an open question. Pass a tag to narrow it, or leave it empty for everything.
Related MCP server: MCP Notes Server
Setup
Requires uv and Python 3.10+.
git clone https://github.com/pdegner/notes-mcp.git
cd notes-mcp
uv syncClaude Code
claude mcp add notes -- uv --directory /full/path/to/notes-mcp run notes-mcpClaude Desktop
Add this to claude_desktop_config.json:
{
"mcpServers": {
"notes": {
"command": "uv",
"args": ["--directory", "/full/path/to/notes-mcp", "run", "notes-mcp"]
}
}
}Where your virtual sticky notes live
In ~/.notes-mcp/notes/, one Markdown file per note, named {id}.md. Set NOTES_MCP_DIR to put
them elsewhere.
---
id: '5'
title: Dentist appointment
tags:
- errands
- health
created: '2026-07-30T17:19:20Z'
updated: '2026-07-30T17:19:20Z'
---
Tuesday 3pm, Dr. Okafor.Ids are assigned in order starting from 1. Deleting a note frees its number, and the next note
you write gets the lowest free number rather than the next-highest — so if you delete note 3 out
of five notes, the next note you add becomes the new 3, not 6.
Because a note is just a Markdown file, you can read, edit, grep, or back it up without this
server involved. Hand-edited files are read back fine, including a tags: work, urgent shorthand
instead of a YAML list.
Your notes stay on this machine. They live outside this repository, so git never sees them and
they are never committed or pushed — the repo holds code only. The notes directory is created
0700 and each note file 0600, so other accounts on the machine cannot read them.
They are stored as plain text, not encrypted. That protects against other local users and against accidentally publishing them; it does not protect against anyone who has your login, admin access to the machine, or a backup that copies your home directory. Treat them like sticky notes on your desk, and don't put passwords in them.
Design notes
A few decisions worth explaining:
List and search return metadata, not bodies. Only get_note returns note text. If
list_notes returned full bodies, a directory of a few hundred notes would flood the model's
context on a single call. Search returns a short snippet around the match instead, which is enough
for the model to pick the right note and then ask for it.
Note ids are validated before they touch the filesystem. Ids arrive as tool arguments, which
means they come from a model and are untrusted input. Every id is checked against
^[a-z0-9][a-z0-9-]*$ before it is turned into a path, so ../../etc/passwd is rejected rather
than resolved. That pattern is broader than the plain integers the server assigns on purpose: a
hand-named file dropped into the notes directory stays readable even though the server would never
generate an id like that itself. Writes go to a temp file and are then atomically renamed, so an
interrupted write can't truncate an existing note.
A note's id never changes for as long as it exists. These are meant to work like sticky notes:
you write one down, and if you end up checking it often, note://5 is a fixed address you can
always go back to, not something that drifts as other notes come and go. Ids are only ever handed
out at creation, so nothing renumbers a note out from under you. Deleting a note frees its number
for the next note written after it, rather than leaving a permanent gap; the store scans
existing filenames on every add_note call and picks the smallest positive integer not already in
use (an O(n) scan, fine for a personal notes directory, not for thousands of notes). That reuse is
what keeps ids low and memorable instead of growing forever, but it only ever assigns a freed
number to a brand-new note, never to one that's still around.
Nothing prints to stdout. On the stdio transport, file descriptor 1 carries the JSON-RPC
message stream, so anything else written there corrupts the framing. The Python SDK does defend
against this — mcp.server.stdio claims fd 1 for the transport and repoints the process's own
stdout at stderr — but that only happens when the SDK opens the stream itself, and other MCP
implementations don't all do it. Treating stdout as reserved and sending logs to stderr is the
portable discipline rather than a workaround for one library's behavior.
Development
uv run pytest # 59 tests
uv run ruff check . # lint
uv run ruff format . # formatLicense
MIT
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Servers
- FlicenseAqualityBmaintenanceA local MCP server for managing Markdown notes, enabling create, list, read, search, summarize, and delete operations through natural language.61
- AlicenseNot gradedqualityBmaintenanceA beginner-friendly MCP server for managing personal notes. Enables Claude to create, list, read, search, update, and delete notes saved as Markdown files.MIT
- AlicenseAqualityCmaintenanceA note-taking MCP server for Claude-based agents that provides persistent markdown files for easily referable notes, supporting create, read, update, append, and delete operations.5Apache 2.0
- AlicenseAqualityAmaintenanceMCP server that gives Claude Code and other MCP clients persistent memory using plain Markdown notes stored on your disk and optionally synced to cloud storage (iCloud, OneDrive, Google Drive, Dropbox).361MIT
Related MCP Connectors
Serve a folder of Markdown notes as an MCP server: hybrid search, reading, and sourced answers.
Markdown-first MCP server for Notion API with 8 composite tools and 39 actions.
Search, read, and write your Apple Notes from ChatGPT/Claude via a local Mac agent + MCP relay.
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/pdegner/notes-mcp'
If you have feedback or need assistance with the MCP directory API, please join our Discord server