An MCP server that securely interfaces with your iMessage database via the Model Context Protocol (MCP), allowing LLMs to query and analyze iMessage conversations. It includes robust phone number validation, attachment processing, contact management, group chat handling, and full
SaferSkills independently audited mac_messages_mcp (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
A Python bridge for interacting with the macOS Messages app using MCP (Multiple Context Protocol).
<a href="https://glama.ai/mcp/servers/gxvaoc9znc"> <img width="380" height="200" src="https://glama.ai/mcp/servers/gxvaoc9znc/badge" /> </a>
Click the button above to automatically add Mac Messages MCP to Cursor
See the Integration section below for setup instructions.
tool_get_chats to read one group conversation chronologicallyAttachment access uses progressive disclosure — discovery is cheap, fetching is deliberate:
tool_get_recent_messages and tool_fuzzy_search_messages annotate messages that have attachments with a compact summary like [attachments: #42 image/jpeg (invitation.jpg)]. The id lets you fetch the file later.tool_search_attachments(start_date, end_date, contact, mime_type, limit) returns metadata only (id, MIME type, filename, size, sender) — useful for "find all images Elizabeth sent in April 2026" without scanning message text.tool_get_attachment(attachment_id) returns the file. Image MIME types come back inline (HEIC is converted to PNG so it can be viewed directly). PDFs, video, and audio come back as a filesystem path the agent can read with its own tools. Inline image bytes are capped at 5MB by default to avoid context blowup; oversized images fall back to path return.Stickers, link-preview "balloon" payloads, and .pluginPayloadAttachment containers are filtered out by default.
For direct sends, E.164 phone numbers with a leading + are the most reliable format, such as +14155551234. Bare digit phone numbers with a country code are normalized before sending, and 10-digit US numbers are sent as +1.... tool_find_contact returns phone matches in the same send-ready format.
If you're on Mac, install uv using Homebrew:
brew install uvOtherwise, follow the installation instructions on the uv website.
⚠️ Do not proceed before installing uv
⚠️ This application requires Full Disk Access permission for your terminal or application to access the Messages database.
To grant Full Disk Access:
#### Option 1: Claude Desktop Extension
This repo includes an MCPB-compatible manifest.json for Claude Desktop's one-click extension flow.
yarn global add @anthropic-ai/mcpb
mcpb packInstall the generated .mcpb file from Claude Desktop Settings > Extensions > Advanced settings > Install Extension....
Claude Desktop, or the terminal used to package/run the extension, still needs Full Disk Access to read Messages.
Building the extension
Build the .mcpb with the build script:
python scripts/build_mcpb.py # build for the host architecture
python scripts/build_mcpb.py --arch x86_64 # build for Intel macsBy default it vendors a uv binary into the bundle (bin/uv) so the extension also runs on machines without uv installed — that binary is architecture specific (build one .mcpb per arch) and downloads Python and dependencies on first launch (network required once). Pass --no-bundle to pack against the system uv instead; see python scripts/build_mcpb.py --help for all options.
#### Option 2: Manual Config
{
"mcpServers": {
"messages": {
"command": "uvx",
"args": [
"mac-messages-mcp"
]
}
}
}#### Option 1: One-Click Install (Recommended)
#### Option 2: Manual Setup
Go to Cursor Settings > MCP and paste this as a command:
uvx mac-messages-mcp⚠️ Only run one instance of the MCP server (either on Cursor or Claude Desktop), not both
If you need to connect to mac-messages-mcp from a Docker container, you'll need to use the mcp-proxy package to bridge the stdio-based server to HTTP.
This repository also includes a Dockerfile for catalog checks and container builds:
docker build -t mac-messages-mcp .Messages.app automation is macOS-only and will not work inside a Linux container. Container use is primarily for MCP catalog compatibility and read-only database experiments with mounted data.
#### Setup Instructions
npm install -g mcp-proxy# Using the published version
npx mcp-proxy uvx mac-messages-mcp --port 8000 --host 0.0.0.0
# Or using local development (if you encounter issues)
npx mcp-proxy uv run python -m mac_messages_mcp.server --port 8000 --host 0.0.0.0Your Docker container can now connect to:
http://host.docker.internal:8000/mcp (on macOS/Windows)http://<host-ip>:8000/mcp (on Linux)version: '3.8'
services:
your-app:
image: your-image
environment:
MCP_MESSAGES_URL: "http://host.docker.internal:8000/mcp"
extra_hosts:
- "host.docker.internal:host-gateway" # For Linux hosts# Terminal 1 - Messages MCP on port 8001
npx mcp-proxy uvx mac-messages-mcp --port 8001 --host 0.0.0.0
# Terminal 2 - Another MCP server on port 8002
npx mcp-proxy uvx another-mcp-server --port 8002 --host 0.0.0.0Note: Binding to 0.0.0.0 exposes the service to all network interfaces. In production, consider using more restrictive host bindings and adding authentication.
uv pip install mac-messages-mcp# Clone the repository
git clone https://github.com/carterlasalle/mac_messages_mcp.git
cd mac_messages_mcp
# Install dependencies
uv install -e .Mac Messages MCP automatically handles message delivery across different platforms:
# Send to iPhone user - uses iMessage
send_message("+1234567890", "Hey! This goes via iMessage")
# Send to Android user - automatically uses SMS
send_message("+1987654321", "Hey! This goes via SMS")
# Check delivery method before sending
check_imessage_availability("+1234567890") # Returns availability statusfrom mac_messages_mcp import get_recent_messages, send_message
# Get recent messages
messages = get_recent_messages(hours=48)
print(messages)
# Send a message (automatically chooses iMessage or SMS)
result = send_message(recipient="+1234567890", message="Hello from Mac Messages MCP!")
print(result) # Shows whether sent via iMessage or SMS# Run the MCP server directly
mac-messages-mcpThis project uses semantic versioning. See VERSIONING.md for details on how the versioning system works and how to release new versions.
To bump the version:
python scripts/bump_version.py [patch|minor|major]This application accesses the Messages database directly, which contains personal communications. Please use it responsibly and ensure you have appropriate permissions.
MIT
Contributions are welcome! Please feel free to submit a Pull Request.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.