Apple Notes MCP server
Last verified: 2026-09
Read local Apple Notes on macOS.
Community Files & knowledge No API key Claude Desktop, Cursor, Windsurf, Claude Code, VS Code
What it does
Read-only window into macOS Notes. It can list, open, and search notes. It cannot create or edit them, and it cannot open password-protected notes.
It sits in Files & knowledge: These servers put the model inside a folder, a notes vault, or a Drive.
Good for
- List Notes on this Mac and open one by title.
- Search note bodies for a flight number or address.
- Pull text out of Notes into a markdown file via Filesystem (read here, write there).
- Find an old note without opening the Notes app.
Tools
- get-all-notes — List notes the app can see.
- read-note — Open one note's text.
- search-notes — Search note bodies.
Config (Claude Desktop / Cursor / Windsurf)
Paste the JSON below. Same mcpServers shape. Replace placeholder paths and secrets.
Windows paths look like C:\\Users\\you\\project, not /path/to.
Host-side steps →
Claude Desktop
| OS | Config file |
|---|---|
| macOS | ~/Library/Application Support/Claude/claude_desktop_config.json |
| Windows | %APPDATA%\Claude\claude_desktop_config.json
(usually C:\Users\<you>\AppData\Roaming\Claude\) |
| Linux | ~/.config/Claude/claude_desktop_config.json |
Cursor
| Scope | macOS / Linux | Windows |
|---|---|---|
| This project | .cursor/mcp.json in the repo root | |
| This user | ~/.cursor/mcp.json |
%USERPROFILE%\.cursor\mcp.json |
Windsurf
| OS | Config file |
|---|---|
| macOS / Linux | ~/.codeium/windsurf/mcp_config.json |
| Windows | %USERPROFILE%\.codeium\windsurf\mcp_config.json |
{
"mcpServers": {
"apple_notes": {
"command": "npx",
"args": [
"-y",
"apple-notes-mcp"
]
}
}
}
Windsurf remote MCP: use serverUrl instead of url if the block below is HTTP.
One-liner: npx -y apple-notes-mcp
Secrets it wants: none — uses macOS permissions
How to get started
- macOS only. Grant the host disk/Notes permissions when the OS prompts.
- Paste the JSON and restart. Ask it to list notes.
- Do not expect create/edit — those are listed as missing in the repo.
Access risk
Anything in Notes that is not encrypted can be sent to the model. No write path, but the read is still private mail, 2FA backups, and health notes if you keep them there.
When to skip it
Skip it if you already dump notes to a folder or Obsidian. Windows/Linux cannot run it.
Instead: Obsidian, Filesystem, Notion.
Vs alternatives
| Server | Official? | Needs a secret? | Best for |
|---|---|---|---|
| Apple Notes | No | No | Read local Apple Notes on macOS. |
| Obsidian | No | Yes | Read and search a local Obsidian vault. |
| Filesystem | Yes | No | Read and write files inside a folder you choose. |
| Notion | No | Yes | Search and update Notion pages. |
More in Files & knowledge
FAQ
Can it create or edit notes?
No. The current server is read-only. Encrypted notes and attachments are also out of scope.
Does it run on Windows?
No. It uses macOS Notes storage and needs disk/Notes permission.
Will it see iCloud notes?
It sees what the local Notes database has. iCloud sync status is listed as a missing feature.
Safer than Filesystem on ~/Library?
Yes, because it only walks Notes. Still: anything unencrypted in Notes can go to the model.