Unofficial MCP server for Apple's services — Apple Music playlists and library, iCloud Calendar, Contacts and Mail, Apple Maps, WeatherKit and iTunes search — that runs anywhere, no Mac needed. Not affiliated with Apple. Developed and maintained by AI (Cl
Inferred from the transports this listing declares (stdio). A client not listed here hasn’t been ruled out — it just isn’t something Forge can confirm.
APPLE_PRIVATE_KEYAPI keyoptionalContents of that key's .p8 file (PEM; one-line values with \n escapes and base64 are accepted).
APPLE_MUSIC_PRIVATE_KEYAPI keyoptionalOptional per-service override of APPLE_PRIVATE_KEY for Apple Music.
APPLE_MAPS_PRIVATE_KEYAPI keyoptionalOptional per-service override of APPLE_PRIVATE_KEY for Apple Maps.
APPLE_WEATHERKIT_PRIVATE_KEYAPI keyoptionalOptional per-service override of APPLE_PRIVATE_KEY for WeatherKit.
APPLE_MUSIC_DEVELOPER_TOKENAPI keyoptionalOptional: a pre-minted Apple Music developer token (JWT) instead of signing one from the key above.
APPLE_MUSIC_USER_TOKENAPI keyoptionalMusic User Token for your library (official API), from a one-time MusicKit sign-in: `npx apple-icloud-mcp music-auth`. Without the Apple Developer key, ask the owner for a developer token (music-auth…
APPLE_MUSIC_WEB_USER_TOKENAPI keyoptionalOpt-in web-player mode (no developer account needed; unlocks rename/delete/remove/reorder): the media-user-token cookie from a signed-in music.apple.com tab.
APPLE_MUSIC_WEB_DEVELOPER_TOKENAPI keyoptionalOptional override for the web-player developer token (normally read automatically from music.apple.com).
ICLOUD_APP_PASSWORDAPI keyoptionalAn app-specific password from appleid.apple.com → Sign-In and Security → App-Specific Passwords (NOT your Apple ID password).
MCP_CONFIRM_SECRETAPI keyoptionalSigning key for confirmTokens. Random per process by default; set it so a token issued just before a restart or redeploy still works (spent tokens are recorded on disk, so none can be replayed).
Declared by the author in the official MCP registry. Forge does not store, broker, or ever see these values — the config below is scaffolded with placeholders you fill in locally.
Verification confirms publisher identity (repo ownership), not code safety. The security scan covers known CVEs and suspicious install scripts.
Read out of the source npm actually ships, at scan time. The package was never executed. Tools registered dynamically at runtime, or hidden inside bundled or minified code, can be missed — so this is a floor on the tool surface, not a complete census of it.
apple_calendar_list_calendarsList your iCloud calendars (event calendars only): id, name, color, whether you can add events to it, whether it isList your iCloud calendars (event calendars only): id, name, color, whether you can add events to it, whether it is
No input schema was published for this tool.
apple_calendar_list_eventsList iCloud Calendar events (appointments, meetings) in a date window, recurring events expanded into occurrences,List iCloud Calendar events (appointments, meetings) in a date window, recurring events expanded into occurrences,
No input schema was published for this tool.
apple_calendar_search_eventsSearch iCloud Calendar events by text (case-insensitive match in title, location or notes) within a date window:Search iCloud Calendar events by text (case-insensitive match in title, location or notes) within a date window:
No input schema was published for this tool.
apple_calendar_get_eventGet one iCloud Calendar event in full (notes untruncated, attendees, alerts, recurrence rule in plain English) by theGet one iCloud Calendar event in full (notes untruncated, attendees, alerts, recurrence rule in plain English) by the
No input schema was published for this tool.
apple_calendar_create_eventCreate an iCloud Calendar event: title, startDate/endDate (timed default 1 hour; all-day endDate = last day),Create an iCloud Calendar event: title, startDate/endDate (timed default 1 hour; all-day endDate = last day),
No input schema was published for this tool.
apple_calendar_update_eventChange an iCloud Calendar event: title, startDate/endDate, isAllDay, location, notes, url ("" clears), alarms,Change an iCloud Calendar event: title, startDate/endDate, isAllDay, location, notes, url ("" clears), alarms,
No input schema was published for this tool.
apple_calendar_delete_eventprivilegedDelete an iCloud Calendar event. Recurring: span thisEvent (default; the one occurrence an "#occ=" id names),Delete an iCloud Calendar event. Recurring: span thisEvent (default; the one occurrence an "#occ=" id names),
No input schema was published for this tool.
apple_calendar_find_free_timeFind free time in your iCloud calendars: open slots per day within working hours (workdayStart/workdayEnd, defaultFind free time in your iCloud calendars: open slots per day within working hours (workdayStart/workdayEnd, default
No input schema was published for this tool.
8 of 8 tools published a description.
Tool names and descriptions are written by the publisher and shown verbatim as inert text. They are the strings an MCP client passes to a model, so Forge scans them for prompt-injection patterns — any finding appears with the security scan above. “Privileged” is a keyword match on the tool name, not an audit of what the tool does: a benign-sounding name can still do anything.
Unofficial MCP server for Apple's services — Apple Music playlists and library, iCloud Calendar, Contacts and Mail, Apple Maps, WeatherKit and iTunes search — that runs anywhere, no Mac needed. Not affiliated with Apple. Developed and maintained by AI (Cl
Linked names open Forge’s index of every entry observed exposing that tool. Browse all indexed tools.
11 more resolved packages are not drawn here (display cap: 24). Every dependency carrying an advisory is drawn regardless of the cap. Full inventory (CycloneDX SBOM)
Not followed: peerDependencies. This tree covers runtime dependencies only, so anything those pull in was never resolved.