Skip to content
mcp/skillhub

Apple Icloud MCP Server

by chrischallio.github.chrischall/apple-icloud-mcpv0.3.3

Unofficial: Apple Music, iCloud Calendar/Contacts/Mail, Apple Maps and WeatherKit, no Mac needed

0Node.jsstdioofficial registry

context tax

queued

security

queued

cold start

queued

freshness

Active3d ago

Install Apple Icloud MCP server

Install in Claude Code

claude mcp add apple-icloud -e APPLE_PRIVATE_KEY='<apple-private-key>' -e APPLE_MUSIC_PRIVATE_KEY='<apple-music-private-key>' -e APPLE_MAPS_PRIVATE_KEY='<apple-maps-private-key>' -e APPLE_WEATHERKIT_PRIVATE_KEY='<apple-weatherkit-private-key>' -e APPLE_MUSIC_DEVELOPER_TOKEN='<apple-music-developer-token>' -e APPLE_MUSIC_USER_TOKEN='<apple-music-user-token>' -e APPLE_MUSIC_WEB_USER_TOKEN='<apple-music-web-user-token>' -e APPLE_MUSIC_WEB_DEVELOPER_TOKEN='<apple-music-web-developer-token>' -e ICLOUD_APP_PASSWORD='<icloud-app-password>' -e MCP_CONFIRM_SECRET='<mcp-confirm-secret>' -- npx -y apple-icloud-mcp

Configuration

VariableRequiredSecretDescription
APPLE_TEAM_ID——Your Apple Developer Team ID (10 characters). Needed for Apple Music (official API), Apple Maps and WeatherKit.
APPLE_KEY_ID——Key ID of a private key created in Certificates, Identifiers & Profiles → Keys with Media Services (MusicKit), MapKit JS and/or WeatherKit enabled.
APPLE_PRIVATE_KEY—yesContents of that key's .p8 file (PEM; one-line values with \n escapes and base64 are accepted).
APPLE_PRIVATE_KEY_PATH——Local installs only: a path to the .p8 file instead of APPLE_PRIVATE_KEY.
APPLE_MUSIC_KEY_ID——Optional per-service override of APPLE_KEY_ID for Apple Music (pair with APPLE_MUSIC_PRIVATE_KEY).
APPLE_MUSIC_PRIVATE_KEY—yesOptional per-service override of APPLE_PRIVATE_KEY for Apple Music.
APPLE_MAPS_KEY_ID——Optional per-service override of APPLE_KEY_ID for Apple Maps.
APPLE_MAPS_PRIVATE_KEY—yesOptional per-service override of APPLE_PRIVATE_KEY for Apple Maps.
APPLE_WEATHERKIT_KEY_ID——Optional per-service override of APPLE_KEY_ID for WeatherKit.
APPLE_WEATHERKIT_PRIVATE_KEY—yesOptional per-service override of APPLE_PRIVATE_KEY for WeatherKit.
APPLE_WEATHERKIT_SERVICE_ID——WeatherKit only: the Services ID registered for WeatherKit (e.g. com.example.weather).
APPLE_MUSIC_DEVELOPER_TOKEN—yesOptional: a pre-minted Apple Music developer token (JWT) instead of signing one from the key above.
APPLE_MUSIC_USER_TOKEN—yesMusic User Token for your library (official API), from a one-time MusicKit sign-in: `npx apple-icloud-mcp music-auth`. Without the Apple Developer key, ask the owner for a developer token (music-auth --print-developer-token) and run it with APPLE_MUSIC_DEVELOPER_TOKEN set. Lasts ~6 months.
APPLE_MUSIC_WEB_USER_TOKEN—yesOpt-in web-player mode (no developer account needed; unlocks rename/delete/remove/reorder): the media-user-token cookie from a signed-in music.apple.com tab.
APPLE_MUSIC_WEB_DEVELOPER_TOKEN—yesOptional override for the web-player developer token (normally read automatically from music.apple.com).
APPLE_MUSIC_STOREFRONT——Two-letter Apple Music storefront (e.g. us, gb). Default: your account's storefront, else us.
ICLOUD_USERNAME——Your Apple ID email, for iCloud Calendar, Contacts and Mail.
ICLOUD_APP_PASSWORD—yesAn app-specific password from appleid.apple.com → Sign-In and Security → App-Specific Passwords (NOT your Apple ID password).
ICLOUD_MAIL_ADDRESS——Your @icloud.com address, only if your Apple ID email is not an iCloud address (needed for Mail).
ICLOUD_DEFAULT_CALENDAR——Calendar new events go to when none is named (default: the first writable event calendar).
APPLE_WRITE_MODE——"none" = read-only tools; "additive" = also create/append, never modify, delete or send; "all" = everything (default). Unrecognized values fail closed to "none".
APPLE_SERVICES——Comma-separated services to enable (music, calendar, contacts, mail, maps, weather, itunes). Default: all.
DISPLAY_TZ——IANA time zone (e.g. America/New_York) for displayed times and for dates you give without an offset. Set this on a hosted server, which runs in UTC.
APPLE_UNITS——"metric" (default) or "imperial" units for weather (Maps distances always show both).
APPLE_STATE_CACHE——Set to false to write nothing under $MCP_DATA_DIR/.apple-icloud-mcp: no web-player token or iCloud discovery cache, and the rejected-password latch and spent confirmation tokens then last only as long as the process.
APPLE_REQUEST_TIMEOUT_MS——Per-request timeout in milliseconds (default 30000).
APPLE_DEBUG_LOG——Set to 1 to log every upstream request line to stderr (credentials redacted).
MCP_CONFIRM_MODE——How confirm-gated writes (send mail, deletes, removing tracks, invitations) behave on a client with no prompt, like claude.ai: "ask-user" (default: preview + confirmToken, the model must get your OK), "auto", or "refuse". Unknown values mean refuse.
MCP_CONFIRM_ELICITATION——"off" never shows a confirmation prompt, so every client gets the MCP_CONFIRM_MODE flow. Set it for a client that says it can prompt but never does (the gated call hangs, e.g. opencode 2.0.x). Any other value stays "on" (with a stderr warning).
MCP_CONFIRM_TTL_SECONDS——Lifetime of a confirmToken in seconds (default 600).
MCP_CONFIRM_SECRET—yesSigning key for confirmTokens. Random per process by default; set it so a token issued just before a restart or redeploy still works (spent tokens are recorded on disk, so none can be replayed).

Freshness

Active — last maintenance signal 3d ago. The newest of the signals below sets the band.

  1. Last commit (default branch)

    2026-10-07 · 3d ago · GitHub

  2. Latest release

    2026-10-07 · 3d ago · GitHub · v0.3.3

  3. Package published

    no data · npm/PyPI

  4. Registry entry updated

    2026-10-07 · 3d ago · official registry · v0.3.3

FAQ

›How do I install the Apple Icloud MCP server in Claude Code?

Run: claude mcp add apple-icloud -e APPLE_PRIVATE_KEY='<apple-private-key>' -e APPLE_MUSIC_PRIVATE_KEY='<apple-music-private-key>' -e APPLE_MAPS_PRIVATE_KEY='<apple-maps-private-key>' -e APPLE_WEATHERKIT_PRIVATE_KEY='<apple-weatherkit-private-key>' -e APPLE_MUSIC_DEVELOPER_TOKEN='<apple-music-developer-token>' -e APPLE_MUSIC_USER_TOKEN='<apple-music-user-token>' -e APPLE_MUSIC_WEB_USER_TOKEN='<apple-music-web-user-token>' -e APPLE_MUSIC_WEB_DEVELOPER_TOKEN='<apple-music-web-developer-token>' -e ICLOUD_APP_PASSWORD='<icloud-app-password>' -e MCP_CONFIRM_SECRET='<mcp-confirm-secret>' -- npx -y apple-icloud-mcp. For Cursor, VS Code, Claude Desktop and Windsurf, use the install tabs above.

›Does Apple Icloud require an API key?

Yes. It expects APPLE_PRIVATE_KEY, APPLE_MUSIC_PRIVATE_KEY, APPLE_MAPS_PRIVATE_KEY, APPLE_WEATHERKIT_PRIVATE_KEY, APPLE_MUSIC_DEVELOPER_TOKEN, APPLE_MUSIC_USER_TOKEN, APPLE_MUSIC_WEB_USER_TOKEN, APPLE_MUSIC_WEB_DEVELOPER_TOKEN, ICLOUD_APP_PASSWORD, MCP_CONFIRM_SECRET, of which 10 are secrets.

›Can I use Apple Icloud as a remote (hosted) MCP server?

No hosted endpoint is published; it runs locally over stdio.

›Is Apple Icloud in the official MCP registry?

Yes, as io.github.chrischall/apple-icloud-mcp.

Alternatives to Apple Icloud

Other calendar & scheduling MCP servers.

View all