The Apple Notes MCP server bridges an agent to the Notes app on macOS using AppleScript. Apple Notes is where an enormous amount of personal thinking ends up precisely because it is frictionless, and it has historically been a closed box as far as any other tool is concerned.
What it actually does
The server talks to the local Notes app. The agent can list notes and folders, read note content, search across them, and create new notes. Everything runs on your machine through macOS automation, with no API key and no cloud service in between.
Practical patterns:
- ‘Search my notes for anything about this project and summarise what I already decided.’
- ‘Create a note with the summary of this conversation in my Ideas folder.’
- ‘Which notes have I not touched in a year that still mention active work?‘
Why use it
Notes accumulates fragments: half-formed ideas, meeting scraps, things typed on a phone and never revisited. That is genuinely valuable context and it is unreachable, because Notes has no useful search and no integration story. Making it readable turns a pile of fragments into something an agent can draw on when you ask what you have already thought about a topic.
Gotchas
The permissions step is what trips people up. macOS requires explicit automation permission for one app to control another, and until you grant it in System Settings the server fails quietly rather than helpfully. It is macOS only and needs the app present, so no Windows and no headless use. Locked notes are not accessible, correctly. And AppleScript bridges are slow on large libraries, so a search across thousands of notes takes noticeably longer than you would expect.