google-keep-mcp
Exposes Google Keep notes as MCP tools, letting an agent list, read, create, and manage notes in a Google Keep account via the unofficial gkeepapi client.
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@google-keep-mcplist my recent Google Keep notes"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
google-keep-mcp
An MCP server that exposes Google Keep notes as tools, so an MCP client (Claude Code, Claude Desktop, etc.) can work with them.
Google Keep has no official public API. This project talks to Keep through
gkeepapi, an unofficial client — expect
it to break whenever Google changes the private endpoints.
Tools
Tool | Does |
| Search the account's notes. Filters: |
| Move a note to the trash by id, or delete it outright with |
Both tools sync with Google on every call, so results reflect the account's current state and deletions are pushed immediately.
Related MCP server: NotesKeep MCP Server
Requirements
Python 3.13+
Setup
uv sync
cp .env.example .env # then fill in your credentialsCredentials
gkeepapi authenticates with a Google master token, not your password.
Obtain one once (see the gkeepapi docs),
then set GOOGLE_KEEP_EMAIL and GOOGLE_KEEP_MASTER_TOKEN — see
.env.example.
A master token grants full access to the account. Treat it like a password: keep it out of version control and out of shell history.
Running
The server speaks MCP over stdio:
uv run google-keep-mcpRegister it with a client — for Claude Code:
claude mcp add google-keep -- uv run --directory /path/to/google-keep-mcp google-keep-mcpCredentials are read from the process environment, falling back to a .env
file in the working directory. To pass them through the client config instead,
add --env GOOGLE_KEEP_EMAIL=... --env GOOGLE_KEEP_MASTER_TOKEN=... to the
command above. Sign-in is deferred until the first tool call, so a
misconfigured server still starts and reports the problem in the tool result.
Development
uv run ruff check . # lint
uv run ruff format . # format
uv run pytest # testsLicense
MIT — see LICENSE.
Available Tools
2 toolsdelete_noteDelete noteADestructiveIdempotent
Move a Google Keep note to the trash, or delete it permanently.
| Name | Required | Description | Default |
|---|---|---|---|
| note_id | Yes | Note id, as returned by list_notes. | |
| permanent | No | Delete the note outright instead of moving it to the trash. Permanent deletion cannot be undone. |
Output Schema
| Name | Required | Description |
|---|---|---|
| id | Yes | |
| title | Yes | |
| permanent | Yes | True if the note was deleted outright, False if it was moved to the trash. |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare destructiveHint=true, so the description is not required to repeat that. It adds valuable context by distinguishing between the reversible trash action and the irreversible permanent deletion, explicitly warning that permanent deletion cannot be undone. This goes beyond the annotations without contradicting them.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is a single, front-loaded sentence that captures both behaviors with no extraneous words. It is optimally concise and readable.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
The tool has a simple interface with two well-documented parameters and an output schema, so the description does not need to explain return values. The description, combined with annotations and schema, gives the agent everything needed to call the tool correctly. It could optionally mention that the note must exist or that trash is reversible, but the schema covers the id, and the irreversibility warning is sufficient.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema coverage is 100% and both parameters have clear descriptions. The tool description restates the two modes but adds little beyond the schema's own explanation of the permanent parameter. The description does not introduce any new semantic details about note_id or permanent beyond what the schema already provides, so a baseline of 3 is appropriate.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description states a specific verb and resource: 'Move a Google Keep note to the trash, or delete it permanently.' It clearly distinguishes the two deletion modes and is unambiguous about what the tool does. The sibling list_notes is obviously for listing, so there is no confusion about purpose.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description clearly implies this tool is for deleting notes, and the sibling list_notes is for retrieval, so the alternative is obvious. The schema reinforces the workflow by noting note_id comes from list_notes. However, there is no explicit 'when not to use' or conditional guidance beyond the two modes, which are explained in the parameter descriptions.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
list_notesList notesARead-only
Search the Google Keep account and return the matching notes.
| Name | Required | Description | Default |
|---|---|---|---|
| limit | No | Maximum notes to return. | |
| query | No | Text to match against note titles and bodies. Omit to match all. | |
| labels | No | Label names a note must all carry, e.g. ['todo']. | |
| pinned | No | Filter by pinned state. | |
| trashed | No | List trashed notes instead of live ones. | |
| archived | No | Filter by archived state. |
Output Schema
| Name | Required | Description |
|---|---|---|
| result | Yes |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare readOnlyHint=true and openWorldHint=true, so the safety profile is covered. The description adds the account-wide search scope but otherwise mostly restates the retrieval behavior. No contradiction with annotations.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is a single, focused sentence with no filler. The action and resource are front-loaded, making it immediately scannable.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
With an output schema, full parameter descriptions, and annotations, the definition is complete enough for an agent to call the tool correctly. It could have explicitly mentioned default live-note behavior, but the schema already documents the trashed parameter default.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The input schema has 100% description coverage for all six optional parameters, so the schema carries the semantic weight. The description adds no parameter-level detail, which is acceptable given the strong schema.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly identifies the action ('Search') and resource ('Google Keep notes'), and specifies the scope ('Google Keep account'). It is easy to distinguish from the sibling delete_note since this tool is retrieval-focused.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The context is clear: use this tool when you need to find or list notes. It does not explicitly mention delete_note or state when not to use it, but the sibling's destructive purpose makes the distinction obvious. An explicit alternative note would have made this a 5.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections.
2 tool updates
v0.1.0- First observed
delete_note - First observed
list_notes
TDQS
Scored across 2 tools
list_notes and delete_note target completely distinct actions with no overlap. An agent can easily choose the right tool based on the operation needed.
Both tools follow a consistent verb_noun pattern (list_notes, delete_note). The naming is predictable and uniform.
With only 2 tools, the server feels thin for a Google Keep integration. The count is borderline but not absurdly small.
The surface lacks essential operations like creating, updating, or fetching a single note by ID. Only list and delete are supported, leaving significant workflow gaps.
Maintenance
Related MCP Connectors
Google Keep-style notes app with an MCP server for AI agents to read/write notes.
Google Keep MCP, read and edit your notes, lists, labels and collaborators. Connect with your Google
- TaprootOAuthcom.taproothq
Persistent memory layer for AI tools. Save and recall notes across Claude and other MCP clients.
Search, read, and write your Apple Notes from ChatGPT/Claude via a local Mac agent + MCP relay.
Related MCP Servers
- AlicenseBqualityAmaintenanceEnables interaction with Google Keep notes through an MCP server, allowing users to search, create, update, and delete notes via natural language commands.23104MIT
- AlicenseCqualityDmaintenanceEnables users to manage their notes on NotesKeep directly through Claude Code or other MCP clients. It supports creating, updating, and organizing both text and checklist notes using natural language commands.1410 npm1MIT
- FlicenseAqualityDmaintenanceEnables AI-powered management of Google Keep notes, including search, create, update, delete, archive, and label operations.1611-
- FlicenseBqualityDmaintenanceA Model Context Protocol server that connects Google Keep to Claude, enabling full note management capabilities including search, CRUD, checklists, labels, and more.20-