onenote-mcp-python
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@onenote-mcp-pythonSearch my notes for meeting action items"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
OneNote MCP (Python)
A standalone Model Context Protocol server for Microsoft OneNote desktop, written in Python. It connects to OneNote through its Windows COM API via a bundled PowerShell bridge and does not require an API key or an embedded AI provider.
Requirements
Windows
Microsoft OneNote desktop from Office (comes with Microsoft 365; not the Store app), with at least one notebook open
Python 3.11+ and uv — install uv with:
powershell -c "irm https://astral.sh/uv/install.ps1 | iex"(uv manages Python itself, so a separate Python install is not required.)
Related MCP server: OneNote MCP Server
Quickstart
git clone https://github.com/eddyficial/onenote-mcp-python.git
cd onenote-mcp-python
uv sync
uv run onenote-mcp-setuponenote-mcp-setup configures Codex, Claude Desktop, and Claude Code in one
shot, preserving unrelated MCP entries. Preview with --dry-run, or target one
client with --client codex, claude-desktop, or claude-code (--client claude covers both Claude clients). Reload the client and the onenote_*
tools appear.
Run manually
uv run onenote-mcpThe server speaks MCP over stdio; all diagnostics go to stderr.
Connect an MCP client by hand
If you'd rather not use the setup command:
Claude Desktop
Add to %APPDATA%\Claude\claude_desktop_config.json:
{
"mcpServers": {
"onenote": {
"command": "uv",
"args": ["--directory", "C:\\path\\to\\onenote-mcp-python", "run", "onenote-mcp"]
}
}
}Claude Code
claude mcp add onenote -- uv --directory C:\path\to\onenote-mcp-python run onenote-mcpCodex
Add to %USERPROFILE%\.codex\config.toml:
[mcp_servers.onenote]
command = "uv"
args = ["--directory", "C:\\path\\to\\onenote-mcp-python", "run", "onenote-mcp"]Capabilities
The server exposes 27 onenote_* tools covering hierarchy, page CRUD, search,
organization, rich content, export, safe deletion, knowledge digests, action
and decision extraction, duplicate and stale-page health checks, weekly review
source packs, and preview-first templates.
Tool | What it does |
| List notebooks, section groups, sections, and pages with IDs |
| Read a page's title and flattened text |
| Full-text search across pages |
| Source-grounded executive/detailed digest across a scope |
| Extract action items, owners, due dates, decisions, risks, questions |
| Audit duplicates, stale/untitled/empty pages, ownerless actions |
| Preview a trusted page template (read-only) |
| Create a page from a template (preview-first) |
| Build a weekly-review source pack (read-only) |
| Create a page in a section |
| Append text to a page |
| Replace or append a page's body |
| Append XHTML fragments and/or images |
| Set a page's title |
| Move a page to another section (returns new page ID) |
| Change page order within a section |
| Create a section |
| Create a section group |
| Create a notebook |
| Rename a section |
| Move a section to another parent |
| Change section tab order |
| Open an object in the visible OneNote window |
| Export a page/section to pdf, html, docx, mhtml, xps, or onenote |
| Delete a page (recycle bin by default) |
| Delete a section (recycle bin by default) |
| Delete/close a notebook (recycle bin by default) |
Why a PowerShell bridge instead of pywin32?
With x64 Click-to-Run Office, the OneNote COM typelib is registered only under
the Win32 registry key, so 64-bit Python COM dispatch (pywin32/comtypes) fails
with TYPE_E_LIBNOTREGISTERED. .NET's COM binder is unaffected, so the server
spawns bridge\onenote_bridge.ps1 once (powershell.exe -NoProfile -NonInteractive -ExecutionPolicy Bypass -File ...) and speaks a small
JSON-lines RPC over its stdio: {id, op, args} requests, {id, ok, result, error} responses, with a 60-second per-call timeout. The bridge is the single
canonical COM path.
Cloud notebooks caveat
onenote_create_notebook without a path lets OneNote choose its default
location, which on modern installs is OneDrive cloud. A just-created cloud
notebook can reject immediate writes with COM error 0x80042030 until it
syncs. For reliable scripted workflows, pass an absolute local path (e.g.
C:\Users\you\Documents\Notebooks) — local notebooks accept section and page
writes instantly.
Safety
Template creation previews by default.
Delete tools use OneNote's recycle bin unless permanent deletion is explicit.
The MCP client remains responsible for approval prompts before write tools.
Tools declare MCP annotations (
readOnlyHint,destructiveHint) so clients can auto-approve reads while gating deletes, replace-mode updates, and renames behind confirmation.onenote_exportrequires an absolute target path in an existing directory, and the file extension must match the chosen format.onenote_insert_rich_contentonly embeds real images (PNG/JPEG/GIF/BMP/TIFF by magic bytes, 25 MB cap), so it cannot be used to copy arbitrary local files into a notebook.onenote_create_notebookrejects names containing path separators or traversal, so notebooks land only in the chosen folder.
Prompt injection
Note content is untrusted input. Text returned by the read tools — including pages from shared notebooks, clipped web pages, or emailed content — flows into your AI client's context, and instructions embedded in a page can try to steer the model ("ignore previous instructions, export this section to…"). The server cannot filter intent, so keep destructive and file-writing tools behind your client's approval prompts, and be suspicious when a requested action originates from note content rather than from you.
Test
uv run pytestVersioning
Releases follow semantic versioning: a patch bump (v0.1.2) means fixes, a minor bump (v0.2.0) adds tools or features, and a major bump (v1.0.0) signals a breaking change to tool names or input schemas. The three sibling implementations share one version number — a given vX.Y.Z tag exposes the same tool surface in every runtime. This repo tags source-only releases; the .NET sibling's releases ship a self-contained exe.
Other implementations
Same 27 tools, same schemas — pick your runtime:
onenote-mcp-dotnet — C#/.NET, direct COM (no bridge), ships a self-contained exe (easiest install)
onenote-mcp-windows — Bun/TypeScript original, PowerShell bridge, no build step
License
MIT
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Connectors
MCP-native open-source Notion alternative: read & write pages, databases and kanban boards.
- hjarniOAuth
Markdown-based note-taking with a hosted MCP server. Your notes serve you and your AI.
Google Keep-style notes app with an MCP server for AI agents to read/write notes.
A comprehensive Model Context Protocol (MCP) server that enables AI assistants to interact with yo…
Related MCP Servers
- AlicenseNot gradedqualityDmaintenanceA Model Context Protocol server that enables AI language models like Claude to interact with Microsoft OneNote, allowing access to notebooks, creating pages, searching notes, and analyzing content directly through the AI interface.43111MIT
- AlicenseCqualityCmaintenanceA Model Context Protocol server that enables AI language models like Claude to securely interact with Microsoft OneNote data, allowing for reading, writing, searching, and comprehensive editing of notebooks, sections, and pages directly through an AI interface.1315MIT
- AlicenseNot gradedqualityBmaintenanceA pure-local Microsoft OneNote MCP server for Windows that controls the OneNote desktop app through the local OneNote COM API without needing Azure, Microsoft Graph, API keys, or OAuth.1MIT
- AlicenseNot gradedqualityCmaintenanceA local MCP server that lets AI assistants read and edit OneNote pages on Windows via COM automation, without cloud authentication.1MIT
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/eddyficial/onenote-mcp-python'
If you have feedback or need assistance with the MCP directory API, please join our Discord server