Apple Icloud MCP Server
by chrischallio.github.chrischall/apple-icloud-mcpv0.3.3
Unofficial: Apple Music, iCloud Calendar/Contacts/Mail, Apple Maps and WeatherKit, no Mac needed
context tax
queued
security
queued
cold start
queued
freshness
Active3d ago
Install Apple Icloud MCP server
Install in Claude Code
claude mcp add apple-icloud -e APPLE_PRIVATE_KEY='<apple-private-key>' -e APPLE_MUSIC_PRIVATE_KEY='<apple-music-private-key>' -e APPLE_MAPS_PRIVATE_KEY='<apple-maps-private-key>' -e APPLE_WEATHERKIT_PRIVATE_KEY='<apple-weatherkit-private-key>' -e APPLE_MUSIC_DEVELOPER_TOKEN='<apple-music-developer-token>' -e APPLE_MUSIC_USER_TOKEN='<apple-music-user-token>' -e APPLE_MUSIC_WEB_USER_TOKEN='<apple-music-web-user-token>' -e APPLE_MUSIC_WEB_DEVELOPER_TOKEN='<apple-music-web-developer-token>' -e ICLOUD_APP_PASSWORD='<icloud-app-password>' -e MCP_CONFIRM_SECRET='<mcp-confirm-secret>' -- npx -y apple-icloud-mcpInstall in Cursor
{
"mcpServers": {
"apple-icloud": {
"command": "npx",
"args": [
"-y",
"apple-icloud-mcp"
],
"env": {
"APPLE_PRIVATE_KEY": "<apple-private-key>",
"APPLE_MUSIC_PRIVATE_KEY": "<apple-music-private-key>",
"APPLE_MAPS_PRIVATE_KEY": "<apple-maps-private-key>",
"APPLE_WEATHERKIT_PRIVATE_KEY": "<apple-weatherkit-private-key>",
"APPLE_MUSIC_DEVELOPER_TOKEN": "<apple-music-developer-token>",
"APPLE_MUSIC_USER_TOKEN": "<apple-music-user-token>",
"APPLE_MUSIC_WEB_USER_TOKEN": "<apple-music-web-user-token>",
"APPLE_MUSIC_WEB_DEVELOPER_TOKEN": "<apple-music-web-developer-token>",
"ICLOUD_APP_PASSWORD": "<icloud-app-password>",
"MCP_CONFIRM_SECRET": "<mcp-confirm-secret>"
}
}
}
}Add to ~/.cursor/mcp.json (global) or .cursor/mcp.json (project).
Install in Claude Desktop
{
"mcpServers": {
"apple-icloud": {
"command": "npx",
"args": [
"-y",
"apple-icloud-mcp"
],
"env": {
"APPLE_PRIVATE_KEY": "<apple-private-key>",
"APPLE_MUSIC_PRIVATE_KEY": "<apple-music-private-key>",
"APPLE_MAPS_PRIVATE_KEY": "<apple-maps-private-key>",
"APPLE_WEATHERKIT_PRIVATE_KEY": "<apple-weatherkit-private-key>",
"APPLE_MUSIC_DEVELOPER_TOKEN": "<apple-music-developer-token>",
"APPLE_MUSIC_USER_TOKEN": "<apple-music-user-token>",
"APPLE_MUSIC_WEB_USER_TOKEN": "<apple-music-web-user-token>",
"APPLE_MUSIC_WEB_DEVELOPER_TOKEN": "<apple-music-web-developer-token>",
"ICLOUD_APP_PASSWORD": "<icloud-app-password>",
"MCP_CONFIRM_SECRET": "<mcp-confirm-secret>"
}
}
}
}Settings → Developer → Edit Config (claude_desktop_config.json), then restart.
Install in VS Code
{
"servers": {
"apple-icloud": {
"type": "stdio",
"command": "npx",
"args": [
"-y",
"apple-icloud-mcp"
],
"env": {
"APPLE_PRIVATE_KEY": "<apple-private-key>",
"APPLE_MUSIC_PRIVATE_KEY": "<apple-music-private-key>",
"APPLE_MAPS_PRIVATE_KEY": "<apple-maps-private-key>",
"APPLE_WEATHERKIT_PRIVATE_KEY": "<apple-weatherkit-private-key>",
"APPLE_MUSIC_DEVELOPER_TOKEN": "<apple-music-developer-token>",
"APPLE_MUSIC_USER_TOKEN": "<apple-music-user-token>",
"APPLE_MUSIC_WEB_USER_TOKEN": "<apple-music-web-user-token>",
"APPLE_MUSIC_WEB_DEVELOPER_TOKEN": "<apple-music-web-developer-token>",
"ICLOUD_APP_PASSWORD": "<icloud-app-password>",
"MCP_CONFIRM_SECRET": "<mcp-confirm-secret>"
}
}
}
}Add to .vscode/mcp.json in your workspace.
Install in Windsurf
{
"mcpServers": {
"apple-icloud": {
"command": "npx",
"args": [
"-y",
"apple-icloud-mcp"
],
"env": {
"APPLE_PRIVATE_KEY": "<apple-private-key>",
"APPLE_MUSIC_PRIVATE_KEY": "<apple-music-private-key>",
"APPLE_MAPS_PRIVATE_KEY": "<apple-maps-private-key>",
"APPLE_WEATHERKIT_PRIVATE_KEY": "<apple-weatherkit-private-key>",
"APPLE_MUSIC_DEVELOPER_TOKEN": "<apple-music-developer-token>",
"APPLE_MUSIC_USER_TOKEN": "<apple-music-user-token>",
"APPLE_MUSIC_WEB_USER_TOKEN": "<apple-music-web-user-token>",
"APPLE_MUSIC_WEB_DEVELOPER_TOKEN": "<apple-music-web-developer-token>",
"ICLOUD_APP_PASSWORD": "<icloud-app-password>",
"MCP_CONFIRM_SECRET": "<mcp-confirm-secret>"
}
}
}
}Add to ~/.codeium/windsurf/mcp_config.json.
Configuration
| Variable | Required | Secret | Description |
|---|---|---|---|
| APPLE_TEAM_ID | — | — | Your Apple Developer Team ID (10 characters). Needed for Apple Music (official API), Apple Maps and WeatherKit. |
| APPLE_KEY_ID | — | — | Key ID of a private key created in Certificates, Identifiers & Profiles → Keys with Media Services (MusicKit), MapKit JS and/or WeatherKit enabled. |
| APPLE_PRIVATE_KEY | — | yes | Contents of that key's .p8 file (PEM; one-line values with \n escapes and base64 are accepted). |
| APPLE_PRIVATE_KEY_PATH | — | — | Local installs only: a path to the .p8 file instead of APPLE_PRIVATE_KEY. |
| APPLE_MUSIC_KEY_ID | — | — | Optional per-service override of APPLE_KEY_ID for Apple Music (pair with APPLE_MUSIC_PRIVATE_KEY). |
| APPLE_MUSIC_PRIVATE_KEY | — | yes | Optional per-service override of APPLE_PRIVATE_KEY for Apple Music. |
| APPLE_MAPS_KEY_ID | — | — | Optional per-service override of APPLE_KEY_ID for Apple Maps. |
| APPLE_MAPS_PRIVATE_KEY | — | yes | Optional per-service override of APPLE_PRIVATE_KEY for Apple Maps. |
| APPLE_WEATHERKIT_KEY_ID | — | — | Optional per-service override of APPLE_KEY_ID for WeatherKit. |
| APPLE_WEATHERKIT_PRIVATE_KEY | — | yes | Optional per-service override of APPLE_PRIVATE_KEY for WeatherKit. |
| APPLE_WEATHERKIT_SERVICE_ID | — | — | WeatherKit only: the Services ID registered for WeatherKit (e.g. com.example.weather). |
| APPLE_MUSIC_DEVELOPER_TOKEN | — | yes | Optional: a pre-minted Apple Music developer token (JWT) instead of signing one from the key above. |
| APPLE_MUSIC_USER_TOKEN | — | yes | Music User Token for your library (official API), from a one-time MusicKit sign-in: `npx apple-icloud-mcp music-auth`. Without the Apple Developer key, ask the owner for a developer token (music-auth --print-developer-token) and run it with APPLE_MUSIC_DEVELOPER_TOKEN set. Lasts ~6 months. |
| APPLE_MUSIC_WEB_USER_TOKEN | — | yes | Opt-in web-player mode (no developer account needed; unlocks rename/delete/remove/reorder): the media-user-token cookie from a signed-in music.apple.com tab. |
| APPLE_MUSIC_WEB_DEVELOPER_TOKEN | — | yes | Optional override for the web-player developer token (normally read automatically from music.apple.com). |
| APPLE_MUSIC_STOREFRONT | — | — | Two-letter Apple Music storefront (e.g. us, gb). Default: your account's storefront, else us. |
| ICLOUD_USERNAME | — | — | Your Apple ID email, for iCloud Calendar, Contacts and Mail. |
| ICLOUD_APP_PASSWORD | — | yes | An app-specific password from appleid.apple.com → Sign-In and Security → App-Specific Passwords (NOT your Apple ID password). |
| ICLOUD_MAIL_ADDRESS | — | — | Your @icloud.com address, only if your Apple ID email is not an iCloud address (needed for Mail). |
| ICLOUD_DEFAULT_CALENDAR | — | — | Calendar new events go to when none is named (default: the first writable event calendar). |
| APPLE_WRITE_MODE | — | — | "none" = read-only tools; "additive" = also create/append, never modify, delete or send; "all" = everything (default). Unrecognized values fail closed to "none". |
| APPLE_SERVICES | — | — | Comma-separated services to enable (music, calendar, contacts, mail, maps, weather, itunes). Default: all. |
| DISPLAY_TZ | — | — | IANA time zone (e.g. America/New_York) for displayed times and for dates you give without an offset. Set this on a hosted server, which runs in UTC. |
| APPLE_UNITS | — | — | "metric" (default) or "imperial" units for weather (Maps distances always show both). |
| APPLE_STATE_CACHE | — | — | Set to false to write nothing under $MCP_DATA_DIR/.apple-icloud-mcp: no web-player token or iCloud discovery cache, and the rejected-password latch and spent confirmation tokens then last only as long as the process. |
| APPLE_REQUEST_TIMEOUT_MS | — | — | Per-request timeout in milliseconds (default 30000). |
| APPLE_DEBUG_LOG | — | — | Set to 1 to log every upstream request line to stderr (credentials redacted). |
| MCP_CONFIRM_MODE | — | — | How confirm-gated writes (send mail, deletes, removing tracks, invitations) behave on a client with no prompt, like claude.ai: "ask-user" (default: preview + confirmToken, the model must get your OK), "auto", or "refuse". Unknown values mean refuse. |
| MCP_CONFIRM_ELICITATION | — | — | "off" never shows a confirmation prompt, so every client gets the MCP_CONFIRM_MODE flow. Set it for a client that says it can prompt but never does (the gated call hangs, e.g. opencode 2.0.x). Any other value stays "on" (with a stderr warning). |
| MCP_CONFIRM_TTL_SECONDS | — | — | Lifetime of a confirmToken in seconds (default 600). |
| MCP_CONFIRM_SECRET | — | yes | Signing key for confirmTokens. Random per process by default; set it so a token issued just before a restart or redeploy still works (spent tokens are recorded on disk, so none can be replayed). |
Freshness
Active — last maintenance signal 3d ago. The newest of the signals below sets the band.
Last commit (default branch)
2026-10-07 · 3d ago · GitHub
Latest release
2026-10-07 · 3d ago · GitHub · v0.3.3
Package published
no data · npm/PyPI
Registry entry updated
2026-10-07 · 3d ago · official registry · v0.3.3
FAQ
›How do I install the Apple Icloud MCP server in Claude Code?
Run: claude mcp add apple-icloud -e APPLE_PRIVATE_KEY='<apple-private-key>' -e APPLE_MUSIC_PRIVATE_KEY='<apple-music-private-key>' -e APPLE_MAPS_PRIVATE_KEY='<apple-maps-private-key>' -e APPLE_WEATHERKIT_PRIVATE_KEY='<apple-weatherkit-private-key>' -e APPLE_MUSIC_DEVELOPER_TOKEN='<apple-music-developer-token>' -e APPLE_MUSIC_USER_TOKEN='<apple-music-user-token>' -e APPLE_MUSIC_WEB_USER_TOKEN='<apple-music-web-user-token>' -e APPLE_MUSIC_WEB_DEVELOPER_TOKEN='<apple-music-web-developer-token>' -e ICLOUD_APP_PASSWORD='<icloud-app-password>' -e MCP_CONFIRM_SECRET='<mcp-confirm-secret>' -- npx -y apple-icloud-mcp. For Cursor, VS Code, Claude Desktop and Windsurf, use the install tabs above.
›Does Apple Icloud require an API key?
Yes. It expects APPLE_PRIVATE_KEY, APPLE_MUSIC_PRIVATE_KEY, APPLE_MAPS_PRIVATE_KEY, APPLE_WEATHERKIT_PRIVATE_KEY, APPLE_MUSIC_DEVELOPER_TOKEN, APPLE_MUSIC_USER_TOKEN, APPLE_MUSIC_WEB_USER_TOKEN, APPLE_MUSIC_WEB_DEVELOPER_TOKEN, ICLOUD_APP_PASSWORD, MCP_CONFIRM_SECRET, of which 10 are secrets.
›Can I use Apple Icloud as a remote (hosted) MCP server?
No hosted endpoint is published; it runs locally over stdio.
›Is Apple Icloud in the official MCP registry?
Yes, as io.github.chrischall/apple-icloud-mcp.
Alternatives to Apple Icloud
Other calendar & scheduling MCP servers.