NotesBridge
MCP server enabling ChatGPT to search, read, and write Apple Notes via a local Mac agent with a privacy-preserving relay.
README
<div align="center">
📝 NotesBridge
Use your Apple Notes from ChatGPT — search, read, and write, powered by your own Mac.
</div>
NotesBridge is a Model Context Protocol (MCP) connector that lets ChatGPT work with your Apple Notes. It never uploads your notes to a third party — every action runs on your own Mac through a tiny local agent. The cloud piece is only a stateless relay that shuttles requests between ChatGPT and your Mac.
ChatGPT ──OAuth──► NotesBridge relay ──job queue──► apple-notes-agent ──► Apple Notes.app
(connector) (Vercel, stateless) (your Mac, polls & executes) (on your Mac)
Your Mac is the only place your notes are ever read or written. The relay stores only short-lived job payloads and your account record; it never sees a note unless a job is in flight, and jobs expire in seconds.
For users — 3 steps
1. Create your account at notesbridge.vercel.app and generate a pairing code.
2. Install the Mac agent (needs Node 18+):
npx apple-notes-agent pair <YOUR-CODE> # link this Mac to your account
npx apple-notes-agent install # keep it running on every restart
The first time it touches Notes, macOS asks "Terminal wants to control Notes" — click OK (one time).
3. Connect ChatGPT: Settings → Plugins → turn on Developer mode (Security & login) → Create a custom plugin → paste the MCP Server URL https://notesbridge.vercel.app/mcp → Authentication OAuth → sign in & Allow.
That's it. In a new chat: "Search my Apple Notes for the Q3 planning note" or "Create a note titled Groceries with milk, eggs, coffee."
Your Mac must be awake with the agent running.
npx apple-notes-agent installmakes it start automatically at login and restart if it ever crashes.
Managing the agent
npx apple-notes-agent status # is it paired & reachable?
npx apple-notes-agent logs # recent activity
npx apple-notes-agent uninstall # stop auto-start
What ChatGPT can do
| Tool | Action |
|---|---|
search |
Search notes by keyword |
fetch / get_note |
Read a note's full content |
list_folders |
List folders with note counts |
list_notes |
List notes (optionally by folder) |
create_note |
Create a new note |
append_to_note |
Append text to a note |
update_note |
Rewrite a note (destructive — ChatGPT confirms first) |
Self-hosting
You can run your own relay so nothing depends on the hosted instance.
Prereqs: a Vercel account and a Supabase project (free tiers are fine).
- Storage — in your Supabase project's SQL editor, run
supabase/schema.sql. It creates a tiny Redis-shaped KV + queue surface (nb_*functions) with RLS on. - Deploy the
server/directory to Vercel. - Set env vars (see
server/.env.example):SUPABASE_URL,SUPABASE_SERVICE_ROLE_KEY— your project + service-role keyJWT_SECRET—openssl rand -hex 32
- Verify:
curl https://YOUR-APP.vercel.app/api/health→redisConfigured,redisOk,jwtSecretSetalltrue. - Point the agent at it:
npx apple-notes-agent pair <CODE> --server https://YOUR-APP.vercel.app.
How it works
- Auth — OAuth 2.1 with PKCE and Dynamic Client Registration (RFC 7591). ChatGPT registers itself, the user signs in on the NotesBridge consent page, and ChatGPT gets a scoped MCP access token. JWTs are HMAC-signed; three kinds (
session,agent,mcp) with distinct privileges. Optional email verification via Resend (RESEND_API_KEY); off unless configured, and enforcement is opt-in (REQUIRE_EMAIL_VERIFICATION). - Relay — MCP tool call → job pushed to
jobs:<user>(TTL ≤ the caller's wait window, so an abandoned job can't run late) → the Mac agent (holding a hanging long-poll) is handed the job within ~200ms, executes it, pushes the result → the MCP handler returns it. The long-poll means jobs are delivered on arrival rather than on a fixed interval, so relay overhead is ~300ms instead of ~1s. The agent is considered "online" only while it's actively connected. - Agent — a dependency-free Node CLI. Tools run via JXA (
osascript -l JavaScript) against Notes.app; arguments are passed as JSON over argv (never shell-interpolated). A macOS LaunchAgent keeps it alive across logins and crashes.
Repository layout
server/ Vercel functions: OAuth + MCP endpoint + relay (deploy this)
agent/ apple-notes-agent — the npm-published Mac CLI (users npx this)
kit/ Browser automations: register the dev-mode connector AND
fill the OpenAI directory submission (see kit/README.md)
supabase/ schema.sql for self-hosting the storage
test/ end-to-end OAuth + MCP integration test
Development
# server
cd server && cp .env.example .env.local # fill in, then: vercel dev
# end-to-end test against a live deployment (reads ../.env.local)
node test/e2e-oauth.mjs
# agent unit tests
node --test agent/test-agent-unit.mjs
Security & privacy
- Notes are read/written only on your Mac. The relay never persists note content — job payloads live in Redis-shaped storage with a short TTL and are deleted on delivery.
- The agent token is stored at
~/.notesbridge-agent.json(mode600). - No secrets are committed; see
.gitignoreand the.env.examplefiles. - Write tools are marked destructive so ChatGPT asks before overwriting.
License
MIT © Isaiah Dupree
推荐服务器
Baidu Map
百度地图核心API现已全面兼容MCP协议,是国内首家兼容MCP协议的地图服务商。
Playwright MCP Server
一个模型上下文协议服务器,它使大型语言模型能够通过结构化的可访问性快照与网页进行交互,而无需视觉模型或屏幕截图。
Magic Component Platform (MCP)
一个由人工智能驱动的工具,可以从自然语言描述生成现代化的用户界面组件,并与流行的集成开发环境(IDE)集成,从而简化用户界面开发流程。
Audiense Insights MCP Server
通过模型上下文协议启用与 Audiense Insights 账户的交互,从而促进营销洞察和受众数据的提取和分析,包括人口统计信息、行为和影响者互动。
VeyraX
一个单一的 MCP 工具,连接你所有喜爱的工具:Gmail、日历以及其他 40 多个工具。
graphlit-mcp-server
模型上下文协议 (MCP) 服务器实现了 MCP 客户端与 Graphlit 服务之间的集成。 除了网络爬取之外,还可以将任何内容(从 Slack 到 Gmail 再到播客订阅源)导入到 Graphlit 项目中,然后从 MCP 客户端检索相关内容。
Kagi MCP Server
一个 MCP 服务器,集成了 Kagi 搜索功能和 Claude AI,使 Claude 能够在回答需要最新信息的问题时执行实时网络搜索。
e2b-mcp-server
使用 MCP 通过 e2b 运行代码。
Neon MCP Server
用于与 Neon 管理 API 和数据库交互的 MCP 服务器
Exa MCP Server
模型上下文协议(MCP)服务器允许像 Claude 这样的 AI 助手使用 Exa AI 搜索 API 进行网络搜索。这种设置允许 AI 模型以安全和受控的方式获取实时的网络信息。