An MCP server that securely interfaces with your iMessage database via the Model Context Protocol (MCP), allowing LLMs to query and analyze iMessage conversations. It includes robust phone number validation, attachment processing, contact management, group chat handling, and full support for sending and receiving messages.
# Add to your Claude Code skills
git clone https://github.com/carterlasalle/mac_messages_mcpGuides for using mcp servers skills like mac_messages_mcp.
Last scanned: 5/30/2026
{
"issues": [],
"status": "PASSED",
"scannedAt": "2026-05-30T15:06:33.846Z",
"npmAuditRan": true,
"pipAuditRan": true
}See how mac_messages_mcp compares with popular alternatives.
mac_messages_mcp is an open-source mcp servers skill for AI coding assistants such as Claude Code, Codex CLI, and ChatGPT, built by carterlasalle. An MCP server that securely interfaces with your iMessage database via the Model Context Protocol (MCP), allowing LLMs to query and analyze iMessage conversations. It includes robust phone number validation, attachment processing, contact management, group chat handling, and full support for sending and receiving messages. It has 331 GitHub stars.
Yes. mac_messages_mcp passed SkillsLLM's automated security scan — a dependency vulnerability audit plus prompt-injection heuristics — with no high-severity issues. You can read the full report in the Security Report section on this page.
Clone the repository with "git clone https://github.com/carterlasalle/mac_messages_mcp" and add it to your Claude Code skills directory (see the Installation section above).
mac_messages_mcp is primarily written in Python. It is open-source under carterlasalle on GitHub, so you can review or fork the full source.
Yes. SkillsLLM lists many other MCP Servers skills you can browse and compare side by side. Open the MCP Servers category from the badge at the top of this page, or use the Related Skills and comparison links further down to weigh mac_messages_mcp against similar tools.
No comments yet. Be the first to share your thoughts!
Top skills in this category by stars
⚠️ Third-Party Software Notice
This skill is third-party open-source software developed and hosted independently on GitHub. SkillsLLM is an informational directory and does not control or maintain the underlying repository.
Any security checks, ratings, or warnings displayed by SkillsLLM are automated and limited in scope. They do not constitute a security certification or guarantee that the software is safe, error-free, or free from malicious code, vulnerabilities, compromised dependencies, or prompt-injection risks.
Review the source code, permissions, dependencies, and configuration before installing or running any third-party skill. Use is at your own risk. To the maximum extent permitted by applicable law, SkillsLLM is not liable for losses arising from third-party software.
Read, search, and send macOS Messages from any local MCP client.
Quick start · Available tools · Agent skill · Command-line interface · Security · Changelog
Use Claude, Codex, Cursor, VS Code, or any local MCP client to search, read, and send messages through the macOS Messages app.
Mac Messages MCP runs locally on your Mac. It opens the Messages and Contacts databases read-only, returns only the data a client asks for, and uses Messages.app automation only when the client explicitly calls the send tool.
[!IMPORTANT] This server is macOS-only. Reading messages requires Full Disk Access. Sending requires a Mac signed into Messages plus permission for the launching app to automate Messages.
flowchart LR
A[MCP client] -->|stdio| B[mac-messages-mcp]
B --> C{Tool call}
C -->|read tools| D[(chat.db read-only)]
C -->|read tools| E[(AddressBook read-only)]
C -->|send tools| F[Messages.app]
F --> G[Recipient]
D --> H[Untrusted-output boundary]
E --> H
H --> A
Everything the client reads comes from the local SQLite databases, opened read-only. Everything that leaves the machine goes out through Messages.app, under an explicit send tool call. Message- and contact-derived text is fenced as untrusted data on the way back to the model.
| Area | What Mac Messages MCP provides |
|---|---|
| Reading | Recent messages across all conversations or filtered by contact, group chat, date range, or unread state; paging with limit/offset and forward-cursor reads |
| Conversations | Every conversation (1:1, business, and group) with kind, message and unread counts, last activity, and a blocking wait for new messages |
| Search | Fuzzy message-body search across a time window or all history, scoped to a contact or conversation |
| Context | Per-message service (iMessage/SMS/RCS), unread and delivery state, tapbacks, and threaded replies |
| Contacts | Fuzzy contact lookup by approximate name, send-ready phone numbers, and contact creation |
| Group chats | Named group chat discovery with stable chat IDs reused for reads and sends |
| Sending | iMessage with SMS/RCS fallback, file attachments, optional human approval through MCP elicitation, and iMessage reachability checks |
| Scheduling | Queue a message for later delivery while the server process stays alive |
| Attachments | Metadata search, best-effort text/PDF content search, inline images (HEIC converted to PNG), and local paths for larger or non-image files |
| Diagnostics | Messages and Contacts database permission checks from inside the MCP client |
| Privacy | Read-only SQLite access, no message archive of its own, and a structural untrusted-output boundary |
uvbrew install uv
Confirm that the launcher is available:
uvx --version
Python 3.10 or newer is required. uvx can provision a compatible Python and
installs Mac Messages MCP in an isolated environment, so you do not need to
create a virtual environment first.
Open System Settings → Privacy & Security → Full Disk Access and enable the app that will launch the MCP server:
Quit and reopen the app after changing Full Disk Access. On the first contact lookup or send, macOS may separately ask for access to Contacts or permission to control Messages. Allow those prompts.
Also make sure Messages.app is open, signed in, and already able to send a normal message.
The server command is the same everywhere:
uvx mac-messages-mcp
Choose your client below.
Open Claude → Settings → Developer → Edit Config, then add:
{
"mcpServers": {
"mac-messages": {
"command": "uvx",
"args": ["mac-messages-mcp"]
}
}
}
Preserve any other servers already in claude_desktop_config.json, save the
file, and restart Claude Desktop.
Claude Desktop also supports installable .mcpb extensions. See
Build the Claude Desktop extension if you
want to package this repository as one.
Add it once at user scope so it is available in every project:
claude mcp add --transport stdio --scope user mac-messages -- uvx mac-messages-mcp
Verify it:
claude mcp get mac-messages
Inside Claude Code, run /mcp to inspect the connection and tools.
Codex clients on the same Mac share MCP configuration. Add the server with:
codex mcp add mac-messages -- uvx mac-messages-mcp
Then verify it:
codex mcp list
You can also add it directly to ~/.codex/config.toml:
[mcp_servers.mac-messages]
command = "uvx"
args = ["mac-messages-mcp"]
Restart the desktop app or IDE extension after changing the configuration. In
Codex CLI, use /mcp to view the active server.
Or open Cursor Settings → Tools & MCP → New MCP Server and use:
{
"mcpServers": {
"mac-messages": {
"command": "uvx",
"args": ["mac-messages-mcp"]
}
}
}
Restart the server from Cursor's MCP settings after saving.
Open the Command Palette and run MCP: Add Server. Choose Command
(stdio), enter uvx as the command, add mac-messages-mcp as the argument,
and install it globally.
Or add it from a terminal:
code --add-mcp '{"name":"mac-messages","command":"uvx","args":["mac-messages-mcp"]}'
The equivalent user or workspace mcp.json entry is:
{
"servers": {
"mac-messages": {
"type": "stdio",
"command": "uvx",
"args": ["mac-messages-mcp"]
}
}
}
[!NOTE] VS Code uses a top-level
serversobject. Claude Desktop and Cursor usemcpServers.
Use this generic server definition:
{
"command": "uvx",
"args": ["mac-messages-mcp"]
}
If a GUI client reports that uvx cannot be found, run which uvx in Terminal
and replace "uvx" with the returned absolute path. Homebrew commonly installs
it at /opt/homebrew/bin/uvx on Apple silicon and /usr/local/bin/uvx on Intel
Macs.
Ask your client to call tool_check_db_access, then tool_check_addressbook.
Once both succeed, try prompts such as:
Show me my messages from the last two hours.
Find messages from Carter about dinner in the last 30 days.
Find PDFs sent to me this month, but do not open any yet.
Find Jordan in my contacts and draft a message saying I am running 10 minutes
late. Do not send it until I confirm.
The first uvx launch can take longer while it downloads and caches Python
dependencies.
Phone numbers written in national format (06 39 98 00 01, (415) 555-1234)
have to be expanded to E.164 before they can be matched against the Messages
database, and that expansion needs to know which country they belong to. The
server reads your Mac's own region setting for this, so on a correctly
configured Mac there is nothing to do.
Set MAC_MESSAGES_REGION to an ISO 3166-1 alpha-2 code when your
numbers belong to a different region than your Mac is configured for — a French
SIM on a Mac set to en_US, say:
{
"mcpServers": {
"mac-messages": {
"command": "uvx",
"args": ["mac-messages-mcp"],
"env": { "MAC_MESSAGES_REGION": "FR" }
}
}
}
For Claude Code:
claude mcp add --transport stdio --scope user \
--env MAC_MESSAGES_REGION=FR \
mac-messages -- uvx mac-messages-mcp
The region is resolved once at startup, so restart the server after changing
it. Resolution order: MAC_MESSAGES_REGION, then the macOS AppleLocale
preference, then LC_ALL / LC_CTYPE / LANG, then US. Numbers already
written in E.164 (+33639980001) are never reinterpreted and need none of
this.
| Tool | Purpose | Side effect |
|---|---|---|
tool_get_recent_messages |
Read recent messages, filtered by contact, group chat ID, date range, or unread state; page with limit/offset |
Read-onl |