google-keep-mcp
google-keep-mcp
An MCP server for Google Keep, built on gkeepapi (an unofficial, reverse-engineered client — there is no official Google Keep API for consumer accounts).
Tools
16 tools across three groups:
Notes & lists — search_notes, get_note, create_note, create_list, update_note, trash_note, restore_note, delete_note
Checklist items — add_list_item, update_list_item, delete_list_item
Labels — list_labels, create_label, delete_label, add_label_to_note, remove_label_from_note
Auth
gkeepapi authenticates with an email + master token (not your Google password, not an app password long-term). Get one:
uv run python scripts/get_master_token.pyThis trades a Google App Password (requires 2FA on the account) for a master token via gpsoauth, one time. It also pins a random device ID so the server doesn't rely on the host machine's MAC address for its device identity — needed since this runs in a container, not on a fixed physical device.
Required env vars:
GOOGLE_KEEP_EMAIL=you@gmail.com
GOOGLE_KEEP_MASTER_TOKEN=...
GOOGLE_KEEP_DEVICE_ID=...
# optional: cache Keep state to disk for faster startup
GOOGLE_KEEP_STATE_PATH=./.keep_state.jsonSee .env.example.
Quick Start
uv sync
# Run locally (stdio)
uv run python -m google_keep_mcp.server
# Run as HTTP server
uv run python -m google_keep_mcp.server --transport streamable-http --host 0.0.0.0 --port 8080Docker
Pre-built multi-arch images (amd64/arm64) are published to GHCR on every push to main:
docker pull ghcr.io/suckerfish/google_keep_mcp:latestOr docker compose up using compose.yaml. Health check at GET /health.
Deployment
Runs on ampere via Komodo (stack: google-keep-mcp-ampere), registered in MetaMCP's main-namespace as google-keep-mcp (port 8082). Credentials are injected via Komodo secret variables ([[GOOGLE_KEEP_EMAIL]], [[GOOGLE_KEEP_MASTER_TOKEN]], [[GOOGLE_KEEP_DEVICE_ID]]) — never stored in the stack config or this repo. GOOGLE_KEEP_STATE_PATH points at a mounted volume so the Keep state cache survives container restarts.
Pushing to main rebuilds the image; redeploy the stack via Komodo to pick it up (auto_pull: true, but a fresh deploy still needs to be triggered — it doesn't auto-redeploy on push).
A note on stability
gkeepapi is unofficial and periodically breaks when Google changes its login flow or adds new Keep content types — see its CHANGELOG and issue tracker. If this server suddenly starts failing with LoginException or similar, it's very likely a gkeepapi compatibility issue, not something wrong in this repo. Check upstream before debugging locally.
Tech Stack
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/suckerfish/google_keep_mcp'
If you have feedback or need assistance with the MCP directory API, please join our Discord server