AirMCP
AirMCP is a comprehensive MCP server that connects AI assistants to the Apple ecosystem on macOS, enabling automation and control across virtually all Apple apps and system functions.
Apple App Automation
Notes: List, search, create, update, delete, move notes; manage folders; bulk scan and compare notes
Reminders: Full CRUD on reminders and lists; search, filter, complete, and create recurring reminders (macOS 26+ Swift bridge)
Calendar: List/search/create/update/delete events; view attendees; recurring events (macOS 26+ Swift bridge)
Contacts, Mail, Messages: Read/send mail and messages; manage contacts
Music, Photos, TV, Podcasts: Playback control, import/delete photos, manage media
Finder & Safari: File and browser automation
System Control
Clipboard, volume, mute, dark/light mode, display brightness, screen info
Screenshots (full screen, window, or selection) and screen recording
WiFi toggle/status, Bluetooth device listing, battery status
Running app management, system notifications, Do Not Disturb/Focus mode
UI Automation
Open apps, simulate clicks, type text, send key combos, scroll, read accessibility trees
Siri Shortcuts
List, search, run, create, delete, export, import, duplicate, and edit shortcuts
Apple Intelligence (macOS 26+ / Apple Silicon)
On-device text summarization, rewriting, proofreading, generation, structured output, content tagging, and multi-turn AI chat
Semantic Search
Build a local vector index from Notes, Calendar, Reminders, and Mail
Search by meaning across apps; find semantically related items by ID
Apple Maps
Search locations, get directions, drop pins, search nearby places, share locations
Live Data via MCP Resources
Real-time access to recent notes, today's events, overdue reminders, now-playing music, clipboard content, unread mail counts
Pre-built AI Workflows (Prompts)
Multi-step tasks: daily/weekly reviews, meeting prep, note/reminder organization, developer sessions (debug-loop, idea-to-task), Safari research integration
Safety & Configuration
Human-in-the-loop (HITL) approval for destructive operations
Safety annotations (readOnly, destructive, idempotent) on all tools
Module-level enable/disable control
Stdio (local) and HTTP/SSE (remote/multi-client) transport modes
Interactive setup wizard, one-click permission setup, native menubar app; compatible with Claude Desktop, Cursor, and Windsurf
Enables programmatic access to core Apple ecosystem applications including Notes, Reminders, Calendar, Contacts, and Mail.
Provides tools for controlling playback, searching tracks, and managing playlists within Apple Music.
Allows interaction with the Apple TV app and related ecosystem components.
Provides capabilities for interacting with the Apple Messages app to manage communications.
Offers comprehensive system-level tools for macOS, including Finder operations, clipboard management, and system settings control.
Enables browser automation for Safari, allowing users to list tabs, read page content, and execute JavaScript.
AirMCP
Your AI assistant can use the Mac apps you already use. Ask for something in plain language and AirMCP does it in the real Notes, Mail, Calendar, Reminders, Messages, Photos, Safari, Finder, and Shortcuts on your machine — your actual data, not a copy and not a sandbox. The macOS runtime is available today; the iOS runtime is in preview.
"Brief me on today's calendar, overdue reminders, and unread mail."
"For my next meeting, pull up the related notes, contacts, files, and reminders."
"Search my Safari tabs for that article and save a summary to Notes."
"Draft replies to the urgent mail, but ask me before sending anything."
"Run my Morning Routine shortcut."Start on macOS with Node.js 20+:
npx airmcp initThen ask your client. Works with Claude, Codex, Cursor, Raycast, Xcode agents, and any other MCP client. Nothing reads or changes a client's settings until you opt in.
More to try: Common Workflows · every tool · Quick Start
It does not act behind your back
AirMCP is the connector and control layer, not another agent. Destructive calls
preview before they run, approval is per-call, and the audit chain is
tamper-evident and verifiable by you — read airmcp://trust and check it
yourself. Details in Safety Model.
Multi-language project page: heznpc.github.io/AirMCP
What You Get
Apple workspace tools for Notes, Reminders, Calendar, Contacts, Mail, Messages, Music, Finder, Safari, Photos, Shortcuts, system control, screen capture, Weather, Maps, Location, Bluetooth, and more.
Google Workspace tools for Gmail, Drive, Sheets, Calendar, Docs, Tasks, People, and raw
gwsCLI access.Profiles and progressive exposure so clients start with a small front door instead of every loaded tool.
Skills DSL workflows with
parallel,loop,retry,on_error, runtime inputs, and event triggers.App Intent action bridge generated from the MCP manifest for macOS Shortcuts, with an iOS-only App Shortcuts provider and destructive intents gated separately.
Native Swift bridge for EventKit, PhotoKit, HealthKit, Vision, on-device semantic search, and FoundationModels preview builds. AirMCP.app embeds the normal bridge; it is optional for npm and MCPB users, who can build it separately when needed.
Dual transport: stdio for standard MCP clients, HTTP/SSE for shared local runtimes, browser clients, registries, and always-on hosts.
Related MCP server: apple-mcp
Apple Platform Direction
AirMCP is one governed action layer with platform-specific roles, rather than a copy of the full Mac runtime on every device.
Platform | Status | Role |
macOS | Available | Full local MCP runtime and broad Apple app and system integration. |
iOS / iPadOS | Preview | Native Calendar, Reminders, Contacts, Health, and Location actions, plus in-process AppIntents. |
visionOS | Roadmap | Spatial interaction and native actions, with Mac routing for Mac-only automation. |
watchOS | Roadmap | Commands, notifications, and per-call approval through a paired iPhone runtime. |
The shared Swift and AppIntents layers are the portability boundary. Platform sandboxing and lifecycle rules still determine which actions run locally and which route to a paired Mac or iPhone.
Quick Start
Claude Desktop one-click
Download
airmcp-<version>.mcpbfrom Releases.Drag it onto Claude Desktop, or use Settings -> Extensions -> Install from file....
Choose modules in the install form and finish setup.
Full guide: docs/mcpb.md.
CLI wizard
Install Node.js 20+, then run:
npx airmcp initThe wizard selects a profile and stores preferences in
~/.config/airmcp/config.json. Client registration is a separate consent
step whose default is No; no Claude, Codex, Cursor, or Windsurf setting is
read or changed until you opt in.
For Codex, Claude Code, Cursor, Windsurf, and other stdio clients, use the
direct runtime unless the matching GitHub Release includes a signed
AirMCP-<version>.zip:
npx airmcp init --no-clients
npx airmcp connect-clients --client-runtime direct --dry-run
npx airmcp connect-clients --client-runtime directThe app-owned runtime is available only after installing that signed app ZIP and explicitly choosing Start Local Runtime. Do not configure a client to wait for AirMCP.app when the release does not include the app asset.
Non-interactive examples:
npx airmcp init --profile starter --yes
npx airmcp init --profile communications-safe --yes
npx airmcp init --profile productivity --yes
npx airmcp init --profile productivity --yes --connect-clients
npx airmcp init --profile productivity --yes --connect-clients --client-runtime directCheck the install:
npx airmcp doctorCommon Workflows
Once connected, ask your MCP client in natural language:
"Tell me today's calendar events and overdue reminders. Do not change anything."
"Brief me on today's calendar, overdue reminders, unread mail, and recent notes."
"Turn today's meetings into a prep checklist."
"Draft replies for urgent mail, but ask before sending anything."
"For my next meeting, find related notes, contacts, files, and reminders."
"Search my Safari tabs for that article and save the summary to Notes."
"Run my Morning Routine shortcut."
"Take a screenshot and save it to my Desktop."
More workflow examples live in docs/workflows.md.
Runtime Model
AirMCP is designed to keep a large local capability surface usable without dumping the full catalog into every client context.
The complete generated catalog currently contains 297 tools across 32 modules. Profiles and progressive exposure keep clients from loading it all at once.
Profiles:
starter,communications-safe,productivity,full, orcustom.Tool exposure:
progressive,profile, orfull.Module packs: enable only the packs you want with
npx airmcp modulesorAIRMCP_MODULE_PACKS=core,productivity.Task sessions:
start_tool_session,discover_tools, andrun_toolallow a broad runtime to behave like a narrow task-specific toolbelt.Opt-in network modules:
webhooksandpowerautomatestay off in every profile until explicitly enabled.
Useful commands:
npx airmcp modules
npx airmcp modules enable productivity --install
npx airmcp --full
npx airmcp workflows
npx airmcp workflows --readiness
npx airmcp workflows today-overview --prompttoday-overview is the starter-safe first workflow: it reads only Calendar
and Reminders and never writes data. Paste the printed prompt into a connected
MCP client for a governed first run with client authorization and AirMCP audit
coverage.
workflows <id> --preview is a separate local diagnostic. It reads Apple apps
directly, bypasses the MCP governance path, and creates no AirMCP audit entry;
do not use it as the first-success workflow. Broader diagnostics such as
daily-briefing --preview report missing modules before reading live data.
The complete generated tool manifest is in docs/tool-manifest.json.
Current generated surfaces: 233 App Intent action types, 85 Interactive Snippet views, 14 AppEnum pickers, and an iOS-only provider with 8 read-only App Shortcuts that match the preview runtime. The sessionless discovery card uses MCP schema version 2025-11-25.
Safety Model
AirMCP treats local app access as a governed action layer, not a blind shell for agents.
The claim is verifiable, not marketing: read the first-party airmcp://trust
resource for a live governed verdict composed from the tamper-evident audit
chain, the active HITL level, the rate-limit / emergency-stop state, and the
audit key grade — available before any tool access is widened. Preview any
destructive call with preview_action to see exactly what it would record and
whether it would be gated, without running it.
Per-call human approval for destructive and sensitive actions at the default
sensitive-onlyHITL level.HMAC-chained audit log at
~/.airmcp/audit.jsonl, with tamper detection covered by tests.Native Trust Center for governed-run timelines, approval state, audit integrity, emergency controls, permission probes, and redacted local export. Audit history is never read in the background: Load or Refresh makes one explicit
audit_logrequest, and the effective HITL policy may require approval for that call.Rate limits: 60/min globally and 10 destructive/hr.
Emergency stop:
touch ~/.config/airmcp/emergency-stopblocks destructive tools without restarting the server.Inbound HTTP policy through
AIRMCP_ALLOW_NETWORK: loopback-only by default, with token, origin, or OAuth modes available for wider exposure.OAuth 2.1 + Resource Indicators for HTTP runtimes that need scoped access control, with RS256/ES256 JWT verification.
Environment variables are indexed in docs/environment.md. HTTP policy details are in RFC 0002, and OAuth details are in RFC 0005.
Client Setup
When the matching GitHub Release includes a signed AirMCP.app ZIP, the
app-owned desktop pattern keeps one local runtime behind every connected
client. A per-install token is created only by an explicit action: Start
Local Runtime in AirMCP.app, or an opted-in app-runtime client connection
such as --connect-clients / connect-clients. It is stored at:
~/Library/Application Support/AirMCP/http-tokenThe macOS Setup window is consent-driven: it appears automatically once and resumes its last step when reopened. Merely opening or moving through Setup does not start the runtime or edit a client, and first-run Finish Later with no runtime saves the selection only. If an app-owned runtime is already running and the selection changed, Finish Setup may stop and restart that exact owned generation so the persisted and effective scopes match. Start Local Runtime creates the token and opts into automatic startup; each client is registered only after its own Connect action and a fresh scope/readiness check.
Existing Codex registrations can be inspected or disabled without deleting their settings:
npx airmcp codex status
npx airmcp codex disableThe npx airmcp codex commands follow their child Codex CLI's active user
config root: AIRMCP_CODEX_CONFIG_PATH first, then
$CODEX_HOME/config.toml, then ~/.codex/config.toml. The explicit override
is resolved against the invoking working directory and must be named
config.toml.
Stdio clients can proxy into the app-owned HTTP runtime:
npx -y airmcp connect --url http://127.0.0.1:3847/mcpSet AIRMCP_HTTP_TOKEN to the token value when using that proxy.
Examples:
claude mcp add --env AIRMCP_HTTP_TOKEN=<token> airmcp -- npx -y airmcp connect --url http://127.0.0.1:3847/mcp
codex mcp add --env AIRMCP_HTTP_TOKEN=<token> airmcp -- npx -y airmcp connect --url http://127.0.0.1:3847/mcpDirect stdio mode still works for development or isolated client-owned runtimes:
npx -y airmcpBrowser-based MCP clients should use HTTP mode with token and origin checks. See docs/oauth-browser-pkce.md for the browser/OAuth path.
App Intents and Shortcuts
AirMCP generates App Intent actions from the same MCP tool manifest. On macOS,
those actions are available in the Shortcuts action library; Apple does not
support the AppShortcutsProvider phrase surface on macOS. iOS preview builds
can additionally compile the workflow-first App Shortcuts provider.
Destructive intent source generation is opt-in at build/codegen time with
AIRMCP_APPINTENTS_DESTRUCTIVE=true; setting it beside an already-built app
does not expand that binary's intent surface.
AskAirMCPIntent and FoundationModels-backed Apple Intelligence paths are
preview-only and require explicit Swift builds.
Guide: docs/shortcuts.md. Architecture: RFC 0007.
Local Development
git clone https://github.com/heznpc/AirMCP.git
cd AirMCP
npm install
npm run build
node dist/index.jsUseful checks:
npm test
npm run mcp:validate
npm run dev:test -- notes
npm run dev:test:changedSwift bridge:
npm run swift-buildFoundationModels preview builds require macOS 26+, Apple Silicon, a compatible SDK, and the explicit compile flag:
cd swift
swift build -c release -Xswiftc -DAIRMCP_ENABLE_FOUNDATION_MODELSLocal build artifacts can grow after Swift or app builds. To inspect or reclaim ignored artifacts:
npm run clean:local
npm run clean:local:apply
npm run size:checkTesting guide: docs/testing.md.
Requirements
macOS for the server runtime.
Node.js 20 or newer.
macOS Automation, Accessibility, Full Disk Access, Location, Bluetooth, or Photos permissions as required by the modules you enable.
The self-contained AirMCP.app distribution embeds its fixed Node runtime and the normal Swift bridge. The npm package and
.mcpbdo not embed the Swift binary; users of those artifacts build it from source for Swift-backed tools.FoundationModels-backed Apple Intelligence preview requires macOS 26+, Apple Silicon, and
AIRMCP_ENABLE_FOUNDATION_MODELS.
The macOS runtime is the current supported release. The iOS runtime is a preview; visionOS and watchOS are roadmap targets, not released products.
Documentation
Tool manifest: generated list of registered tools.
Workflows: target workflows and prompt catalog.
Skills DSL: YAML workflow syntax and built-ins.
Shortcuts: macOS App Intent actions and the iOS-only App Shortcuts surface.
Environment variables: all runtime knobs.
MCPB install: Claude Desktop extension package.
OAuth browser PKCE: browser client setup.
RFC index: design records and architecture notes.
Testing: development test workflow.
Project direction: product direction and positioning.
Contributing
See CONTRIBUTING.md for development setup, code style, and PR guidelines.
First-time contributors can look for
good first issue.
Community
License
MIT
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Servers
- AlicenseBqualityCmaintenanceA macOS MCP server that provides AI agents with secure access to Calendar, Reminders, Notes, and Health data via native Apple APIs.Last updated3017MIT
- AlicenseBqualityFmaintenanceMCP server for macOS Apple apps. Enables read/write access to Notes, Reminders, Calendar, Contacts, and Safari using SQLite and JXA, all running locally.Last updated28172MIT
- AlicenseAqualityCmaintenanceMCP server for privacy-gated local Apple data access including Mail, Messages, Notes, Calendar, Contacts, Photos, Reminders, Voice Memos, and iCloud Drive.Last updated301MIT
- Alicense-qualityAmaintenanceA collection of MCP servers for Apple macOS apps (Mail, Contacts, Notes, Memory, Messages, Calendar, Reminders) enabling AI assistants to read, search, create, and update data via JXA, SQLite, and EventKit.Last updated12MIT
Related MCP Connectors
Search, read, and write your Apple Notes from ChatGPT/Claude via a local Mac agent + MCP relay.
MCP connector for Apple Reminders — search, create, complete, and edit via your own Mac.
MCP connector that lets ChatGPT list, search, and run your Apple Shortcuts via a local Mac agent
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/heznpc/AirMCP'
If you have feedback or need assistance with the MCP directory API, please join our Discord server