CalDAV MCP Server
A Model Context Protocol server for managing iCloud Calendar events, supporting multiple alarms and both stdio and Streamable HTTP transports.
README
CalDAV MCP Server
CalDAV MCP Server is a Model Context Protocol server for managing iCloud Calendar
events, including native support for multiple VALARM reminders on one event.
iCloud Calendar is the only provider officially supported and manually validated in the
first release. The server works with any MCP client that supports stdio or Streamable
HTTP.
This independent project is not affiliated with, authorized, sponsored, or approved by Apple Inc. Apple and iCloud are trademarks of their respective owner.
Navigation
- About
- Features
- MCP tools
- Tech stack
- Installation
- Configuration
- MCP client setup
- Verification
- Limitations
- Contributing
About
The server connects one configured account to iCloud through CalDAV. It discovers the account's calendars and exposes normalized read and write operations through MCP.
Updates preserve the complete iCalendar resource, including unknown properties, Apple
extensions, VTIMEZONE, recurrence exceptions, and alarms omitted from a patch. Writes
use opaque resource identifiers and ETags instead of assuming that a CalDAV filename
matches an event UID.
Calendar resources are processed in memory. The server has no telemetry and no application database, and raw iCalendar is returned only when explicitly requested.
Features
- Discovers calendars available to the configured iCloud account.
- Lists events in semi-open time ranges and expands recurring occurrences.
- Creates timed, all-day, and recurring events.
- Supports zero, one, or multiple display alarms per event.
- Emits the Apple alarm extensions expected by iCloud Calendar.
- Reads events by opaque resource ID or by calendar ID and UID.
- Applies partial updates while preserving omitted and unknown iCalendar data.
- Uses ETags for optimistic concurrency on updates and deletions.
- Rejects isolated recurrence mutations instead of changing the complete series.
- Redacts credentials, raw calendar content, and CalDAV paths from logs and errors.
- Runs as a non-root container with a read-only root filesystem configuration.
- Supports
stdioand Streamable HTTP MCP transports.
MCP tools
list_calendars
Lists the calendars discovered for the configured account. Each result includes an
opaque calendar_id, display name, description, timezone, and best-effort write status.
list_events
Lists events in a semi-open interval and expands recurring occurrences. The maximum range is 366 days, the default page size is 100, and the maximum page size is 500.
Example input:
{
"calendar_id": "opaque-calendar-id",
"start": "2026-09-01T00:00:00Z",
"end": "2026-10-01T00:00:00Z",
"timezone": "Europe/Berlin",
"limit": 100
}
get_event
Reads an event by resource_id, or by a calendar_id and UID pair. Raw iCalendar is
excluded by default and can be requested with include_raw_ical: true for controlled
diagnostics.
create_event
Creates an event and reads back the representation stored by the server.
Timed event with two alarms:
{
"calendar_id": "opaque-calendar-id",
"summary": "Buy Shinkansen tickets",
"start": {
"date_time": "2026-09-06T03:00:00+02:00",
"timezone": "Europe/Berlin"
},
"end": {
"date_time": "2026-09-06T03:30:00+02:00",
"timezone": "Europe/Berlin"
},
"description": "Smart-EX",
"location": null,
"alarms": [
{ "minutes_before": 1440, "action": "DISPLAY" },
{ "minutes_before": 0, "action": "DISPLAY" }
],
"rrule": null
}
All-day event with an exclusive end date:
{
"calendar_id": "opaque-calendar-id",
"summary": "Trip",
"start": { "date": "2026-09-06" },
"end": { "date": "2026-09-08" },
"alarms": []
}
Recurring events accept an RFC 5545 rule without the RRULE: prefix:
{
"calendar_id": "opaque-calendar-id",
"summary": "Weekly planning",
"start": {
"date_time": "2026-09-07T09:00:00+02:00",
"timezone": "Europe/Berlin"
},
"end": {
"date_time": "2026-09-07T09:30:00+02:00",
"timezone": "Europe/Berlin"
},
"rrule": "FREQ=WEEKLY;BYDAY=MO;COUNT=10"
}
update_event
Patches an event or complete recurring series. Omitted fields are preserved, null
removes a nullable field, and alarms: [] removes all alarms. An optional
expected_etag prevents overwriting a newer server version.
delete_event
Deletes an event or complete recurring series, optionally requiring an observed ETag. Deleting a single expanded occurrence is not supported in the current release.
Tech stack
- Node.js 24+
- TypeScript with strict project rules
- Model Context Protocol TypeScript SDK
- tsdav
- ical.js
- Zod
- Vitest
- pnpm
- Docker
Installation
Prerequisites
- An iCloud account with Calendar enabled.
- Two-factor authentication enabled for the Apple Account.
- An app-specific password.
- Docker and Docker Compose for container deployment, or Node.js 24+ and pnpm for a local installation.
Docker Compose
The recommended installation uses the published multi-architecture image:
ghcr.io/lukegskw/caldav-mcp:latest
Download the Compose example:
curl -O https://raw.githubusercontent.com/lukegskw/caldav-mcp/main/compose.example.yaml
Provide the Apple Account email and app-specific password, then start the service:
export CALDAV_USERNAME='user@example.com'
export CALDAV_PASSWORD='xxxx-xxxx-xxxx-xxxx'
docker compose -f compose.example.yaml up -d
To publish a different host port, set:
export CALDAV_MCP_PUBLISHED_PORT=18100
docker compose -f compose.example.yaml up -d
The latest tag follows the newest successful build from the default branch. For a
controlled deployment or rollback, replace it in the Compose file with a published
version or immutable sha-* tag.
The Streamable HTTP endpoint will be available at:
http://<host>:8100/mcp
The host port can change without changing port 8100 inside the container. No
persistent volume is required; calendar data remains in iCloud.
Docker run
The same hardened container configuration can be started directly:
docker run -d \
--name caldav-mcp \
--restart unless-stopped \
--read-only \
--user 10001:10001 \
--cap-drop ALL \
--security-opt no-new-privileges:true \
--tmpfs /tmp:size=16m,mode=1777 \
-e CALDAV_PROVIDER=icloud \
-e CALDAV_USERNAME \
-e CALDAV_PASSWORD \
-e CALDAV_MCP_TRANSPORT=streamable-http \
-e CALDAV_MCP_HOST=0.0.0.0 \
-p 8100:8100 \
ghcr.io/lukegskw/caldav-mcp:latest
Build the container from source
Building locally is optional. Prefer the published image unless you need to modify or audit the container build.
git clone https://github.com/lukegskw/caldav-mcp.git
cd caldav-mcp
docker buildx build --load -t caldav-mcp:local .
Local Node.js installation
git clone https://github.com/lukegskw/caldav-mcp.git
cd caldav-mcp
pnpm install --frozen-lockfile
cp .env.example .env
pnpm build
pnpm start -- --transport stdio
In stdio mode, stdout is reserved exclusively for MCP messages. To run Streamable HTTP
locally:
CALDAV_MCP_TRANSPORT=streamable-http pnpm start
Configuration
All settings use the CALDAV_ or CALDAV_MCP_ prefix.
| Variable | Required | Default | Description |
|---|---|---|---|
CALDAV_PROVIDER |
No | icloud |
Provider policy. iCloud is the supported profile. |
CALDAV_URL |
No | https://caldav.icloud.com |
CalDAV discovery URL. |
CALDAV_USERNAME |
Yes | None | Apple Account email. |
CALDAV_PASSWORD |
Yes | None | App-specific password, not the account password. |
CALDAV_MCP_TRANSPORT |
No | stdio |
stdio or streamable-http. |
CALDAV_MCP_HOST |
No | 0.0.0.0 |
HTTP bind address. |
CALDAV_MCP_PORT |
No | 8100 |
HTTP listening port. |
CALDAV_MCP_LOG_LEVEL |
No | INFO |
Application log level. |
CALDAV_MCP_REQUEST_TIMEOUT_MS |
No | 30000 |
CalDAV request timeout. |
The core retains an experimental generic provider policy and configurable URL to keep
Apple extensions isolated from the shared iCalendar implementation. No compatibility
with other providers is currently claimed.
Secrets must be supplied through the deployment platform or environment. Never commit
.env, pass credentials as MCP tool arguments, or include them in diagnostic reports.
MCP client setup
For any MCP client that accepts Streamable HTTP server definitions, configure the URL:
mcp_servers:
caldav:
url: http://<host>:8100/mcp
If the client shares the Compose network, use the service name and internal port:
mcp_servers:
caldav:
url: http://caldav-mcp:8100/mcp
For clients that launch local stdio servers, configure the command to run
node /absolute/path/to/caldav-mcp/dist/main.js with the required environment
variables.
Configuration formats differ between MCP clients. Consult the client's documentation for its exact schema and reload or restart it after changing the server definition.
Verification
Check the container state and logs:
docker compose -f compose.example.yaml ps
docker compose -f compose.example.yaml logs caldav-mcp
The container should report healthy. The TCP healthcheck validates the server process,
not iCloud credentials.
Run the repository verification suite:
pnpm install --frozen-lockfile
pnpm format:check
pnpm lint
pnpm typecheck
pnpm test:unit
pnpm test:integration
pnpm build
Finally, connect with an MCP client and confirm that all six tools are listed. Before a release, run the dedicated iCloud manual validation against a test calendar.
Limitations
- One iCloud account is configured per server process or container.
- The Streamable HTTP endpoint has no authentication in the current release. Restrict it to a trusted LAN, VPN, or private container network; do not expose it directly to the internet.
- Individual recurrence occurrences are read-only. Updating or deleting the complete series is supported.
- Only
ACTION:DISPLAYalarms are created. - Individual iCalendar resources are limited to 5 MiB.
- Event list ranges are limited to 366 days and pages to 500 results.
- Events may contain at most 20 alarms.
- Attendee scheduling is outside the current scope.
- Providers other than iCloud are not officially supported.
See troubleshooting for discovery, authentication, ETag, and Apple extension guidance. Review SECURITY.md before reporting a security issue or attaching diagnostics.
Contributing
Contributions are welcome. Before opening a pull request:
pnpm install --frozen-lockfile
pnpm format:check
pnpm lint
pnpm typecheck
pnpm test
pnpm build
docker buildx build --load -t caldav-mcp:test .
Changes to CalDAV writes or iCalendar serialization must preserve ETag checks, opaque
resource boundaries, unknown properties, recurrence exceptions, and alarms omitted from
patches. TypeScript changes must continue to satisfy the rules in
.codex/rules/typescript.md.
License
MIT. See LICENSE.
推荐服务器
Baidu Map
百度地图核心API现已全面兼容MCP协议,是国内首家兼容MCP协议的地图服务商。
Playwright MCP Server
一个模型上下文协议服务器,它使大型语言模型能够通过结构化的可访问性快照与网页进行交互,而无需视觉模型或屏幕截图。
Magic Component Platform (MCP)
一个由人工智能驱动的工具,可以从自然语言描述生成现代化的用户界面组件,并与流行的集成开发环境(IDE)集成,从而简化用户界面开发流程。
Audiense Insights MCP Server
通过模型上下文协议启用与 Audiense Insights 账户的交互,从而促进营销洞察和受众数据的提取和分析,包括人口统计信息、行为和影响者互动。
VeyraX
一个单一的 MCP 工具,连接你所有喜爱的工具:Gmail、日历以及其他 40 多个工具。
graphlit-mcp-server
模型上下文协议 (MCP) 服务器实现了 MCP 客户端与 Graphlit 服务之间的集成。 除了网络爬取之外,还可以将任何内容(从 Slack 到 Gmail 再到播客订阅源)导入到 Graphlit 项目中,然后从 MCP 客户端检索相关内容。
Kagi MCP Server
一个 MCP 服务器,集成了 Kagi 搜索功能和 Claude AI,使 Claude 能够在回答需要最新信息的问题时执行实时网络搜索。
e2b-mcp-server
使用 MCP 通过 e2b 运行代码。
Neon MCP Server
用于与 Neon 管理 API 和数据库交互的 MCP 服务器
Exa MCP Server
模型上下文协议(MCP)服务器允许像 Claude 这样的 AI 助手使用 Exa AI 搜索 API 进行网络搜索。这种设置允许 AI 模型以安全和受控的方式获取实时的网络信息。