Skip to content
verify mcp Beta VerifyMCP is currently in beta. If you notice any issues, get in touch and we’ll put it right.

io.github.chrischall/apple-icloud-mcp

NPM · APPLE-ICLOUD-MCP · SCANNED OCT 2

Unofficial: Apple Music, iCloud Calendar/Contacts/Mail, Apple Maps and WeatherKit, no Mac needed

Available components

81 Trust /100
Trust breakdown (7 categories)

How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. How we score → Why this is hard to score →

Supply Chain Security99
  • No malware found by supply-chain analysis.Pass
  • No known CVEs affecting this package version or its production dependencies.Pass
  • No install/post-install scripts declared.Pass
  • 7 of 35 dependencies flagged as unhealthy. View diagnostics → Partial
Provenance & Transparency97
  • Source repository is publicly reachable at the declared URL. View diagnostics → Pass
  • Cryptographically verified build provenance (signed, bound to chrischall/apple-icloud-mcp). View diagnostics → Pass
  • Clear OSI-approved license (MIT).Pass
  • Actively maintained (last published 2 days ago).Pass
  • Disclosure check failed: no security disclosure policy was found in the source repository. See how to fix → Fail
Schema Quality & AI Usability65
  • AI-judged instruction clarity (excellent).Pass
  • Context-footprint check failed: tool/resource definitions use about 16686 tokens (~282/item across 59 items; 59 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
  • Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management17
  • Stability observed for 5 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage100
  • 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
  • 100% of tool parameters carry a description.Pass
Tool Safety100
  • No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
  • All 7 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation.Pass
  • An AI judge read all 59 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
  • Implements a current MCP spec version (2026-07-28).Pass
Install

How do I install the io.github.chrischall/apple-icloud-mcp server?

io.github.chrischall/apple-icloud-mcp runs locally as an npm package, launched with npx -y apple-icloud-mcp. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

npm · apple-icloud-mcp

# add to Claude Code
claude mcp add chrischall-apple-icloud-mcp -- npx -y apple-icloud-mcp
// .cursor/mcp.json
{
  "mcpServers": {
    "chrischall-apple-icloud-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "apple-icloud-mcp"
      ]
    }
  }
}
// .vscode/mcp.json
{
  "servers": {
    "chrischall-apple-icloud-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "apple-icloud-mcp"
      ]
    }
  }
}
# add to Codex CLI
codex mcp add chrischall-apple-icloud-mcp -- npx -y apple-icloud-mcp
// opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "chrischall-apple-icloud-mcp": {
      "type": "local",
      "command": [
        "npx",
        "-y",
        "apple-icloud-mcp"
      ],
      "enabled": true
    }
  }
}
# add to OpenClaw
openclaw mcp add chrischall-apple-icloud-mcp --command npx --arg -y --arg apple-icloud-mcp
# ~/.hermes/config.yaml
mcp_servers:
  chrischall-apple-icloud-mcp:
    command: "npx"
    args: ["-y", "apple-icloud-mcp"]
// ~/.netclaw/config/netclaw.json
{
  "McpServers": {
    "chrischall-apple-icloud-mcp": {
      "Transport": "stdio",
      "Command": "npx",
      "Arguments": [
        "-y",
        "apple-icloud-mcp"
      ]
    }
  }
}
# add to Vellum
assistant mcp add chrischall-apple-icloud-mcp -t stdio -c npx -a -y apple-icloud-mcp
// mcp.json
{
  "mcpServers": {
    "chrischall-apple-icloud-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "apple-icloud-mcp"
      ]
    }
  }
}
Changelog

Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.

  • 1 Oct 26 +16
    • Malware scan: unverified → pass ▲ security
  • 30 Sept 26 −15
    • Malware scan: pass → unverified ▼ security
    • Package version: 0.2.1 → 0.3.0 functional
  • 29 Sept 26 +16
    • Malware scan: unverified → pass ▲ security
  • 28 Sept 26 −15
    • Malware scan: pass → unverified ▼ security
    • Tool safety: pass → unverified ▼ security
    • Stability: Stability not yet verified: we do not have a sandbox capture of the MCP schema this version of the package serves yet. security
    • Capabilities: pass → unverified ▼ functional
    • Tool coverage: 100 → unverified ▼ functional
    • Stability: unverified → 0.03 ▲ functional
    • First check of Schema quality: unverified functional
    • Package version: 0.1.0 → 0.2.1 functional
    • Package version: 0.1.0 → 0.2.0 functional
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 27 Sept 26 79

    First indexed and scored.

Diagnostics

Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.

Captured 2 Oct 2026 · Analysed npm/apple-icloud-mcp@0.3.0

Provenance Verified

A signed build attestation was found and verified, binding this exact artifact to the source repository it claims to come from.

Result Verified
Ecosystem npm
Reason Verified
Discovered via Registry attestation endpoint
Source repo chrischall/apple-icloud-mcp
Certificate issuer https://token.actions.githubusercontent.com
Certificate SAN https://github.com/chrischall/apple-icloud-mcp/.github/workflows/release-please.yml@refs/heads/main
Rekor log index 3008557783
Predicate type SLSA build provenance https://slsa.dev/provenance/v1
Subject digest sha512:3af786cd6e9fd3e76f9e394faea66083b1d0e588a4ef8ebf6be4479abad8878c6758067abc5ba70eec83069244b60b8e307e87ec97806a5f0d0b0c340

Background: How many MCP packages publish verified provenance →

Dependencies 35 packages
Packages resolved 35
Stale 7
Tree resolution Complete

Background: SBOMs and build attestations, explained →

MCP tools · 59 exposed · ~16,686 tokens

The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →

Tool Tokens
apple_music_move_playlist ~103

Move one of your library playlists into a playlist folder, or back to the top level ("root"). Checks the folder exists and verifies the playlist appears in it. Uses Apple's web-player API (unofficial; needs APPLE_MUSIC_WEB_USER_TOKEN).

NameTypeReqDescription
folderIdstringyesDestination folder id (p.… from apple_music_list_folders), or "root" for the top level.
playlistIdstringyesLibrary playlist id (p.…).

No output schema declared.

No examples provided.

apple_music_remove_favorites ~168

Remove the favorite (star) from catalog songs, albums, playlists, artists or music videos, by catalog id, up to 100 per type. Apple answers only "accepted" and offers no way to read favorites back. Uses Apple's web-player API (unofficial; needs APPLE_MUSIC_WEB_USER_TOKEN).

NameTypeReqDescription
albumsarray–Catalog albums ids (up to 100) — numeric.
artistsarray–Catalog artists ids (up to 100) — numeric.
musicVideosarray–Catalog music-videos ids (up to 100) — numeric.
playlistsarray–Catalog playlists ids (up to 100) — pl.….
songsarray–Catalog songs ids (up to 100) — numeric.

No output schema declared.

No examples provided.

apple_music_remove_from_library ~243

Remove songs, albums, music videos or playlists from your Apple Music library by LIBRARY id (i.…, l.…, p.… from apple_music_list_library / apple_music_search_library), up to 50 at a time; the preview names each item. Uses Apple's web-player API (unofficial; needs APPLE_MUSIC_WEB_USER_TOKEN). Asks the user to confirm first: a confirmation prompt where the client supports one; otherwise the first call performs NO write and returns a preview of exactly what would happen plus a confirmToken, and only a repeat call with that token proceeds (see MCP_CONFIRM_MODE).

NameTypeReqDescription
confirmTokenstring–ONLY for the two-step confirmation fallback (a client without MCP elicitation). The confirmToken from this same tool's phase-1 "confirmation-required" response, passed back ONLY after the user has se…
idsarrayyesLibrary ids (up to 50).
typestringyesWhat the ids are.

No output schema declared.

No examples provided.

apple_music_remove_playlist_tracks ~354

Remove tracks from one of your library playlists by library track id and/or 1-based position (from apple_music_get_playlist). Apple removes EVERY copy of a track, so removing one copy of a duplicate is refused (use apple_music_reorder_playlist). Takes expectedRevision, returns the new revision. Uses Apple's web-player API (unofficial; needs APPLE_MUSIC_WEB_USER_TOKEN). Asks the user to confirm first: a confirmation prompt where the client supports one; otherwise the first call performs NO write and returns a preview of exactly what would happen plus a confirmToken, and only a repeat call with that token proceeds (see MCP_CONFIRM_MODE).

NameTypeReqDescription
confirmTokenstring–ONLY for the two-step confirmation fallback (a client without MCP elicitation). The confirmToken from this same tool's phase-1 "confirmation-required" response, passed back ONLY after the user has se…
expectedRevisionstring–The playlist revision you expect: from apple_music_get_playlist (a complete read) or from the previous change's result. Refused if the playlist no longer reads as that revision. (A change is also ref…
playlistIdstringyesLibrary playlist id (p.…).
positionsarray–1-based positions of tracks to remove (as listed by apple_music_get_playlist).
trackIdsarray–Library ids of the tracks to remove (every copy of each).

No output schema declared.

No examples provided.

apple_music_reorder_playlist ~472

Reorder one of your library playlists: move tracks, sort (name, artist, album, release date, duration, date added), reverse, dedupe (keep the first copy of each song), or replace with a complete new order of its track ids (can drop tracks). Takes expectedRevision, returns the new revision. Uses Apple's web-player API (unofficial; needs APPLE_MUSIC_WEB_USER_TOKEN). Asks the user to confirm first: a confirmation prompt where the client supports one; otherwise the first call performs NO write and returns a preview of exactly what would happen plus a confirmToken, and only a repeat call with that token proceeds (see MCP_CONFIRM_MODE).

NameTypeReqDescription
bystring–sort: the key (dateAdded is when the song entered your library; Apple often omits it on playlist tracks, and a key no track has is refused).
confirmTokenstring–ONLY for the two-step confirmation fallback (a client without MCP elicitation). The confirmToken from this same tool's phase-1 "confirmation-required" response, passed back ONLY after the user has se…
countinteger–move: how many consecutive tracks to move (default 1).
descendingboolean–sort: largest/latest/Z first (default false).
expectedRevisionstring–The playlist revision you expect: from apple_music_get_playlist (a complete read) or from the previous change's result. Refused if the playlist no longer reads as that revision. (A change is also ref…
fromPositioninteger–move: 1-based position of the first track to move.
operationstringyesWhat to do.
playlistIdstringyesLibrary playlist id (p.…).
toPositioninteger–move: 1-based position the first moved track should end up at.
trackIdsarray–replace: the complete new order as library track ids from apple_music_get_playlist; ids left out are removed.

No output schema declared.

No examples provided.

apple_music_search_catalog ~312

Search Apple Music's catalog by text for songs, albums, artists, playlists, music videos or stations. Results are grouped by type, each group with its own returned/hasMore/nextOffset, and carry catalog ids other tools take (e.g. to add songs to a playlist). Up to 25 per type per call. Needs an Apple Developer key (APPLE_TEAM_ID, APPLE_KEY_ID, APPLE_PRIVATE_KEY) or web-player mode (APPLE_MUSIC_WEB_USER_TOKEN).

NameTypeReqDescription
limitinteger–Results per type (default 10, max 25).
offsetinteger–Skip this many results per type (use a group's nextOffset).
storefrontstring–Two-letter Apple Music storefront (country catalog), e.g. us, gb, jp. Default: APPLE_MUSIC_STOREFRONT, else your account's storefront, else us.
termstringyesWhat to search for, e.g. "bohemian rhapsody queen". Prefer "title artist" over "title - artist".
typesarray–Which kinds of results (default songs, albums, artists, playlists).
viewstring–Response shape: "compact" (default) drops fields the response already carries elsewhere; "full" returns every field this server understands. compact keeps ids (library and catalog), names, artist/alb…

No output schema declared.

No examples provided.

apple_music_search_library ~219

Search YOUR Apple Music library (not the whole catalog) by text for songs, albums, artists, playlists or music videos. Results are grouped by type with library ids (i.… songs, l.… albums, p.… playlists) and each group's returned/hasMore/nextOffset. Up to 25 per type. Needs APPLE_MUSIC_USER_TOKEN or web-player mode.

NameTypeReqDescription
limitinteger–Results per type (default 10, max 25).
offsetinteger–Skip this many results per type.
termstringyesWhat to search for in your library.
typesarray–Kinds of items (default songs, albums, artists, playlists).
viewstring–Response shape: "compact" (default) drops fields the response already carries elsewhere; "full" returns every field this server understands. compact keeps ids (library and catalog), names, artist/alb…

No output schema declared.

No examples provided.

apple_music_set_rating ~133

Set your rating on a song, album, playlist, music video or station (catalog or library id): love, dislike, or none to clear it. Always sends the rating (Apple's reads can lag its writes); returns the previous rating as read and verifies the new one. Needs APPLE_MUSIC_USER_TOKEN or web-player mode.

NameTypeReqDescription
idstringyesThe item id.
ratingstringyeslove, dislike, or none to remove your rating.
typestringyesWhat the id is: catalog types (songs, albums, …) or library-* types for library ids.

No output schema declared.

No examples provided.

apple_music_update_playlist ~149

Rename one of your Apple Music library playlists, change its description, or make it public/private. Returns the previous values and verifies the change. Refused while Apple does not show your last change to the playlist yet (the update sends every field back, so it would undo it). Uses Apple's web-player API (unofficial; needs APPLE_MUSIC_WEB_USER_TOKEN).

NameTypeReqDescription
descriptionstring–New description ("" clears it).
isPublicboolean–Show it on your Apple Music profile (true) or not (false).
namestring–New name.
playlistIdstringyesLibrary playlist id (p.…) from apple_music_list_playlists.

No output schema declared.

No examples provided.

apple_weather_get ~582

Weather forecast for a place from Apple Weather (WeatherKit): current conditions, hourly (up to 240 h), daily (up to 10 days), next-hour rain, severe-weather alerts (need countryCode). Returns temperature, feels-like, rain/snow chance and amount, wind, humidity, UV, sunrise/sunset. Takes latitude/longitude — use apple_maps_geocode first to turn a place name into coordinates. Days roll over in timeZone: pass the place's own zone when it differs from yours. Needs APPLE_TEAM_ID, APPLE_KEY_ID, APPLE_PRIVATE_KEY and APPLE_WEATHERKIT_SERVICE_ID. Show the returned attribution with the data.

NameTypeReqDescription
countryCodestring–Two-letter ISO country code of the location (e.g. US, GB). Required for severe-weather alerts; without it alerts are skipped, with a note.
dataSetsarray–What to fetch (default current, hourly, daily, alerts): current = conditions now; hourly = hour by hour; daily = day by day; nextHour = minute-level precipitation for the next hour (some regions only…
daysinteger–Days of daily forecast starting today in timeZone (default 7, max 10). Needs "daily" in dataSets.
hoursinteger–Hours of hourly forecast from the current hour (default 24, max 240). Needs "hourly" in dataSets.
langstring–Language of alert descriptions, as a BCP 47 tag such as en, en-GB, fr or ja (default en). Condition words are always English.
latitudenumberyesLatitude in decimal degrees, -90 to 90 (e.g. 40.7128).
longitudenumberyesLongitude in decimal degrees, -180 to 180 (e.g. -74.006).
timeZonestring–IANA time zone (e.g. America/New_York) that times are shown in and that days roll over in. Default: the server's display zone (DISPLAY_TZ). For a place in another zone pass that place's zone.
unitsstring–metric (°C, km/h, mm, hPa, km) or imperial (°F, mph, in, inHg, mi). Default: APPLE_UNITS, else metric.
viewstring–Response shape: "compact" (default) drops fields the response already carries elsewhere; "full" returns every field this server understands. compact converts units, rounds, turns fractions into perce…

No output schema declared.

No examples provided.

apple_weather_get_alert ~264

Get one severe-weather alert's full official text from Apple Weather (WeatherKit), unmodified, by its id (the alerts[].id from apple_weather_get called with countryCode). Returns the issuing agency (source), severity, effective/expiry times, detailsUrl and the messages verbatim. Apple serves an alert only while it is active; an expired one is NOT_FOUND. Needs APPLE_TEAM_ID, APPLE_KEY_ID, APPLE_PRIVATE_KEY and APPLE_WEATHERKIT_SERVICE_ID.

NameTypeReqDescription
alertIdstringyesThe alert id (a UUID), from alerts[].id in an apple_weather_get result.
langstring–Language of the alert text, as a BCP 47 tag such as en, en-GB, fr or ja (default en).
timeZonestring–IANA time zone (e.g. America/New_York) the alert's times are shown in. Default: the server's display zone (DISPLAY_TZ).
viewstring–Response shape: "compact" (default) drops fields the response already carries elsewhere; "full" returns every field this server understands. compact drops the alert area geometry (GeoJSON) and bookke…

No output schema declared.

No examples provided.

Common questions

What is the io.github.chrischall/apple-icloud-mcp server?

io.github.chrischall/apple-icloud-mcp is listed in the public MCP registry as io.github.chrischall/apple-icloud-mcp. Unofficial: Apple Music, iCloud Calendar/Contacts/Mail, Apple Maps and WeatherKit, no Mac needed. This page covers its npm package (apple-icloud-mcp).

Is the io.github.chrischall/apple-icloud-mcp server safe to use?

io.github.chrischall/apple-icloud-mcp scores 81 out of 100 on VerifyMCP. We found no known CVEs affecting it as of 2 October 2026. It declares no install or post-install scripts. Its build provenance is signed and verified. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

What tools does the io.github.chrischall/apple-icloud-mcp server expose?

io.github.chrischall/apple-icloud-mcp exposes 59 tools: apple_healthcheck, apple_music_search_catalog, apple_music_get_catalog_items, apple_music_get_charts, apple_music_list_playlists, and 54 more. Their descriptions and schemas cost roughly 16,686 tokens of context every time the server is loaded.

Is the io.github.chrischall/apple-icloud-mcp server still maintained?

io.github.chrischall/apple-icloud-mcp is still listed as active in the MCP registry. We last reached this channel on 2 October 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.

What licence is the io.github.chrischall/apple-icloud-mcp server under?

io.github.chrischall/apple-icloud-mcp declares the MIT licence, which is OSI-approved. That covers the source only, and says nothing about the cost of any service it calls.