---
bezeichner: "io.github.chrischall/apple-icloud-mcp"
art: "mcp_server"
slug: "io-github-chrischall-apple-icloud-mcp"
paketkoordinate: "npm:apple-icloud-mcp"
status: "aktiv"
homepage: "https://github.com/chrischall/apple-icloud-mcp"
erhebungsstand: "2026-10-10T01:17:01.464Z"
namensraum: "io.github.chrischall"
registerseite: "https://tracevero.com/mcp/io-github-chrischall-apple-icloud-mcp"
abgerufen_am: "2026-10-10"
zugangsdaten_erforderlich: false
ausfuehrungsort: "lokal"
dateisystem_pfadargument: false
quelloffen_einsehbar: true
einsatzgebiet: "audio"
roh_beschreibung: "Unofficial: Apple Music, iCloud Calendar/Contacts/Mail, Apple Maps and WeatherKit, no Mac needed"
version: "0.3.4"
roh_umgebungsvariablen: "APPLE_TEAM_ID, APPLE_KEY_ID, APPLE_PRIVATE_KEY, APPLE_PRIVATE_KEY_PATH, APPLE_MUSIC_KEY_ID, APPLE_MUSIC_PRIVATE_KEY, APPLE_MAPS_KEY_ID, APPLE_MAPS_PRIVATE_KEY, APPLE_WEATHERKIT_KEY_ID, APPLE_WEATHERKIT_PRIVATE_KEY, APPLE_WEATHERKIT_SERVICE_ID, APPLE_MUSIC_DEVELOPER_TOKEN, APPLE_MUSIC_USER_TOKEN, APPLE_MUSIC_WEB_USER_TOKEN, APPLE_MUSIC_WEB_DEVELOPER_TOKEN, APPLE_MUSIC_STOREFRONT, ICLOUD_USERNAME, ICLOUD_APP_PASSWORD, ICLOUD_MAIL_ADDRESS, ICLOUD_DEFAULT_CALENDAR, APPLE_WRITE_MODE, APPLE_SERVICES, DISPLAY_TZ, APPLE_UNITS, APPLE_STATE_CACHE, APPLE_REQUEST_TIMEOUT_MS, APPLE_DEBUG_LOG, MCP_CONFIRM_MODE, MCP_CONFIRM_ELICITATION, MCP_CONFIRM_TTL_SECONDS, MCP_CONFIRM_SECRET"
roh_geheime_pflichtvariablen: ""
roh_transportarten: "stdio"
roh_pfadargumente: ""
roh_repository_url: "https://github.com/chrischall/apple-icloud-mcp"
roh_paketquellen: "npm"
roh_geheime_pflichtkopfzeilen: ""
roh_pfad_umgebungsvariablen: ""
roh_remote_adressen: ""
roh_remote_hosts: ""
roh_statusmeldung: ""
roh_veroeffentlicht_am: "2026-10-09"
roh_aktualisiert_am: "2026-10-09"
roh_schemafassung: "https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json"
roh_bereitstellungsform: "paket"
roh_repository_quelle: "github"
roh_repository_unterordner: ""
roh_paketbezeichner: "apple-icloud-mcp"
roh_paketversionen: "0.3.4"
roh_laufzeithinweise: ""
roh_umgebungsformate: "string"
roh_umgebungsbeschreibungen: "APPLE_DEBUG_LOG=Set to 1 to log every upstream request line to stderr (credentials redacted). · APPLE_KEY_ID=Key ID of a private key created in Certificates, Identifiers & Profiles → Keys with Media Services (MusicKit), MapKit JS and/or WeatherKit enabled. · APPLE_MAPS_KEY_ID=Optional per-service override of APPLE_KEY_ID for Apple Maps. · APPLE_MAPS_PRIVATE_KEY=Optional per-service override of APPLE_PRIVATE_KEY for Apple Maps. · APPLE_MUSIC_DEVELOPER_TOKEN=Optional: a pre-minted Apple Music developer token (JWT) instead of signing one from the key above. · APPLE_MUSIC_KEY_ID=Optional per-service override of APPLE_KEY_ID for Apple Music (pair with APPLE_MUSIC_PRIVATE_KEY). · APPLE_MUSIC_PRIVATE_KEY=Optional per-service override of APPLE_PRIVATE_KEY for Apple Music. · APPLE_MUSIC_STOREFRONT=Two-letter Apple Music storefront (e.g. us, gb). Default: your account's storefront, else us. · APPLE_MUSIC_USER_TOKEN=Music User Token for your library (official API), from a one-time MusicKit sign-in: `npx apple-icloud-mcp music-auth`. Without the Apple Developer key, ask the owner for a developer token (music-auth --print-developer-token) and run it with APPLE_MUSIC_DEVELOPER_TOKEN set. Lasts ~6 months. · APPLE_MUSIC_WEB_DEVELOPER_TOKEN=Optional override for the web-player developer token (normally read automatically from music.apple.com). · APPLE_MUSIC_WEB_USER_TOKEN=Opt-in web-player mode (no developer account needed; unlocks rename/delete/remove/reorder): the media-user-token cookie from a signed-in music.apple.com tab. · APPLE_PRIVATE_KEY=Contents of that key's .p8 file (PEM; one-line values with \\n escapes and base64 are accepted). · APPLE_PRIVATE_KEY_PATH=Local installs only: a path to the .p8 file instead of APPLE_PRIVATE_KEY. · APPLE_REQUEST_TIMEOUT_MS=Per-request timeout in milliseconds (default 30000). · APPLE_SERVICES=Comma-separated services to enable (music, calendar, contacts, mail, maps, weather, itunes). Default: all. · APPLE_STATE_CACHE=Set to false to write nothing under $MCP_DATA_DIR/.apple-icloud-mcp: no web-player token or iCloud discovery cache, and the rejected-password latch and spent confirmation tokens then last only as long as the process. · APPLE_TEAM_ID=Your Apple Developer Team ID (10 characters). Needed for Apple Music (official API), Apple Maps and WeatherKit. · APPLE_UNITS=\"metric\" (default) or \"imperial\" units for weather (Maps distances always show both). · APPLE_WEATHERKIT_KEY_ID=Optional per-service override of APPLE_KEY_ID for WeatherKit. · APPLE_WEATHERKIT_PRIVATE_KEY=Optional per-service override of APPLE_PRIVATE_KEY for WeatherKit. · APPLE_WEATHERKIT_SERVICE_ID=WeatherKit only: the Services ID registered for WeatherKit (e.g. com.example.weather). · APPLE_WRITE_MODE=\"none\" = read-only tools; \"additive\" = also create/append, never modify, delete or send; \"all\" = everything (default). Unrecognized values fail closed to \"none\". · DISPLAY_TZ=IANA time zone (e.g. America/New_York) for displayed times and for dates you give without an offset. Set this on a hosted server, which runs in UTC. · ICLOUD_APP_PASSWORD=An app-specific password from appleid.apple.com → Sign-In and Security → App-Specific Passwords (NOT your Apple ID password). · ICLOUD_DEFAULT_CALENDAR=Calendar new events go to when none is named (default: the first writable event calendar). · ICLOUD_MAIL_ADDRESS=Your @icloud.com address, only if your Apple ID email is not an iCloud address (needed for Mail). · ICLOUD_USERNAME=Your Apple ID email, for iCloud Calendar, Contacts and Mail. · MCP_CONFIRM_ELICITATION=\"off\" never shows a confirmation prompt, so every client gets the MCP_CONFIRM_MODE flow. Set it for a client that says it can prompt but never does (the gated call hangs, e.g. opencode 2.0.x). Any other value stays \"on\" (with a stderr warning). · MCP_CONFIRM_MODE=How confirm-gated writes (send mail, deletes, removing tracks, invitations) behave on a client with no prompt, like claude.ai: \"ask-user\" (default: preview + confirmToken, the model must get your OK), \"auto\", or \"refuse\". Unknown values mean refuse. · MCP_CONFIRM_SECRET=Signing key for confirmTokens. Random per process by default; set it so a token issued just before a restart or redeploy still works (spent tokens are recorded on disk, so none can be replayed). · MCP_CONFIRM_TTL_SECONDS=Lifetime of a confirmToken in seconds (default 600)."
roh_symbolformate: ""
roh_verbindungswege: "{\"packages\":[{\"registryType\":\"npm\",\"identifier\":\"apple-icloud-mcp\",\"version\":\"0.3.4\",\"transport\":\"stdio\",\"environment\":[{\"name\":\"APPLE_TEAM_ID\",\"description\":\"Your Apple Developer Team ID (10 characters). Needed for Apple Music (official API), Apple Maps and WeatherKit.\",\"format\":\"string\",\"required\":false,\"secret\":false},{\"name\":\"APPLE_KEY_ID\",\"description\":\"Key ID of a private key created in Certificates, Identifiers & Profiles → Keys with Media Services (MusicKit), MapKit JS and/or WeatherKit enabled.\",\"format\":\"string\",\"required\":false,\"secret\":false},{\"name\":\"APPLE_PRIVATE_KEY\",\"description\":\"Contents of that key's .p8 file (PEM; one-line values with \\\\n escapes and base64 are accepted).\",\"format\":\"string\",\"required\":false,\"secret\":true},{\"name\":\"APPLE_PRIVATE_KEY_PATH\",\"description\":\"Local installs only: a path to the .p8 file instead of APPLE_PRIVATE_KEY.\",\"format\":\"string\",\"required\":false,\"secret\":false},{\"name\":\"APPLE_MUSIC_KEY_ID\",\"description\":\"Optional per-service override of APPLE_KEY_ID for Apple Music (pair with APPLE_MUSIC_PRIVATE_KEY).\",\"format\":\"string\",\"required\":false,\"secret\":false},{\"name\":\"APPLE_MUSIC_PRIVATE_KEY\",\"description\":\"Optional per-service override of APPLE_PRIVATE_KEY for Apple Music.\",\"format\":\"string\",\"required\":false,\"secret\":true},{\"name\":\"APPLE_MAPS_KEY_ID\",\"description\":\"Optional per-service override of APPLE_KEY_ID for Apple Maps.\",\"format\":\"string\",\"required\":false,\"secret\":false},{\"name\":\"APPLE_MAPS_PRIVATE_KEY\",\"description\":\"Optional per-service override of APPLE_PRIVATE_KEY for Apple Maps.\",\"format\":\"string\",\"required\":false,\"secret\":true},{\"name\":\"APPLE_WEATHERKIT_KEY_ID\",\"description\":\"Optional per-service override of APPLE_KEY_ID for WeatherKit.\",\"format\":\"string\",\"required\":false,\"secret\":false},{\"name\":\"APPLE_WEATHERKIT_PRIVATE_KEY\",\"description\":\"Optional per-service override of APPLE_PRIVATE_KEY for WeatherKit.\",\"format\":\"string\",\"required\":false,\"secret\":true},{\"name\":\"APPLE_WEATHERKIT_SERVICE_ID\",\"description\":\"WeatherKit only: the Services ID registered for WeatherKit (e.g. com.example.weather).\",\"format\":\"string\",\"required\":false,\"secret\":false},{\"name\":\"APPLE_MUSIC_DEVELOPER_TOKEN\",\"description\":\"Optional: a pre-minted Apple Music developer token (JWT) instead of signing one from the key above.\",\"format\":\"string\",\"required\":false,\"secret\":true},{\"name\":\"APPLE_MUSIC_USER_TOKEN\",\"description\":\"Music User Token for your library (official API), from a one-time MusicKit sign-in: `npx apple-icloud-mcp music-auth`. Without the Apple Developer key, ask the owner for a developer token (music-auth --print-developer-token) and run it with APPLE_MUSIC_DEVELOPER_TOKEN set. Lasts ~6 months.\",\"format\":\"string\",\"required\":false,\"secret\":true},{\"name\":\"APPLE_MUSIC_WEB_USER_TOKEN\",\"description\":\"Opt-in web-player mode (no developer account needed; unlocks rename/delete/remove/reorder): the media-user-token cookie from a signed-in music.apple.com tab.\",\"format\":\"string\",\"required\":false,\"secret\":true},{\"name\":\"APPLE_MUSIC_WEB_DEVELOPER_TOKEN\",\"description\":\"Optional override for the web-player developer token (normally read automatically from music.apple.com).\",\"format\":\"string\",\"required\":false,\"secret\":true},{\"name\":\"APPLE_MUSIC_STOREFRONT\",\"description\":\"Two-letter Apple Music storefront (e.g. us, gb). Default: your account's storefront, else us.\",\"format\":\"string\",\"required\":false,\"secret\":false},{\"name\":\"ICLOUD_USERNAME\",\"description\":\"Your Apple ID email, for iCloud Calendar, Contacts and Mail.\",\"format\":\"string\",\"required\":false,\"secret\":false},{\"name\":\"ICLOUD_APP_PASSWORD\",\"description\":\"An app-specific password from appleid.apple.com → Sign-In and Security → App-Specific Passwords (NOT your Apple ID password).\",\"format\":\"string\",\"required\":false,\"secret\":true},{\"name\":\"ICLOUD_MAIL_ADDRESS\",\"description\":\"Your @icloud.com address, only if your Apple ID email is not an iCloud address (needed for Mail).\",\"format\":\"string\",\"required\":false,\"secret\":false},{\"name\":\"ICLOUD_DEFAULT_CALENDAR\",\"description\":\"Calendar new events go to when none is named (default: the first writable event calendar).\",\"format\":\"string\",\"required\":false,\"secret\":false},{\"name\":\"APPLE_WRITE_MODE\",\"description\":\"\\\"none\\\" = read-only tools; \\\"additive\\\" = also create/append, never modify, delete or send; \\\"all\\\" = everything (default). Unrecognized values fail closed to \\\"none\\\".\",\"format\":\"string\",\"required\":false,\"secret\":false},{\"name\":\"APPLE_SERVICES\",\"description\":\"Comma-separated services to enable (music, calendar, contacts, mail, maps, weather, itunes). Default: all.\",\"format\":\"string\",\"required\":false,\"secret\":false},{\"name\":\"DISPLAY_TZ\",\"description\":\"IANA time zone (e.g. America/New_York) for displayed times and for dates you give without an offset. Set this on a hosted server, which runs in UTC.\",\"format\":\"string\",\"required\":false,\"secret\":false},{\"name\":\"APPLE_UNITS\",\"description\":\"\\\"metric\\\" (default) or \\\"imperial\\\" units for weather (Maps distances always show both).\",\"format\":\"string\",\"required\":false,\"secret\":false},{\"name\":\"APPLE_STATE_CACHE\",\"description\":\"Set to false to write nothing under $MCP_DATA_DIR/.apple-icloud-mcp: no web-player token or iCloud discovery cache, and the rejected-password latch and spent confirmation tokens then last only as long as the process.\",\"format\":\"string\",\"required\":false,\"secret\":false},{\"name\":\"APPLE_REQUEST_TIMEOUT_MS\",\"description\":\"Per-request timeout in milliseconds (default 30000).\",\"format\":\"string\",\"required\":false,\"secret\":false},{\"name\":\"APPLE_DEBUG_LOG\",\"description\":\"Set to 1 to log every upstream request line to stderr (credentials redacted).\",\"format\":\"string\",\"required\":false,\"secret\":false},{\"name\":\"MCP_CONFIRM_MODE\",\"description\":\"How confirm-gated writes (send mail, deletes, removing tracks, invitations) behave on a client with no prompt, like claude.ai: \\\"ask-user\\\" (default: preview + confirmToken, the model must get your OK), \\\"auto\\\", or \\\"refuse\\\". Unknown values mean refuse.\",\"format\":\"string\",\"required\":false,\"secret\":false},{\"name\":\"MCP_CONFIRM_ELICITATION\",\"description\":\"\\\"off\\\" never shows a confirmation prompt, so every client gets the MCP_CONFIRM_MODE flow. Set it for a client that says it can prompt but never does (the gated call hangs, e.g. opencode 2.0.x). Any other value stays \\\"on\\\" (with a stderr warning).\",\"format\":\"string\",\"required\":false,\"secret\":false},{\"name\":\"MCP_CONFIRM_TTL_SECONDS\",\"description\":\"Lifetime of a confirmToken in seconds (default 600).\",\"format\":\"string\",\"required\":false,\"secret\":false},{\"name\":\"MCP_CONFIRM_SECRET\",\"description\":\"Signing key for confirmTokens. Random per process by default; set it so a token issued just before a restart or redeploy still works (spent tokens are recorded on disk, so none can be replayed).\",\"format\":\"string\",\"required\":false,\"secret\":true}],\"additional_arguments_declared\":false}],\"remotes\":[]}"
---

# io.github.chrischall/apple-icloud-mcp

## Measured values

| Property | Value | Source | Collected on | Level of trust | Raw declaration |
| --- | --- | --- | --- | --- | --- |
| Required secrets declared | false | MCP-Register | 2026-09-28T01:17:01.494Z | abgeleitet | roh_geheime_pflichtvariablen: ; roh_geheime_pflichtkopfzeilen: |
| Execution location | lokal | MCP-Register | 2026-09-28T01:17:01.494Z | abgeleitet | roh_transportarten: stdio |
| Path argument present | false | MCP-Register | 2026-09-28T01:17:01.494Z | abgeleitet | roh_pfadargumente: ; roh_pfad_umgebungsvariablen: |
| Repository URL listed | true | MCP-Register | 2026-09-28T01:17:01.494Z | abgeleitet | roh_repository_url: https://github.com/chrischall/apple-icloud-mcp |
| Field of use, derived from the vendor description | audio | MCP-Register | 2026-09-28T01:17:01.494Z | abgeleitet | roh_beschreibung: Unofficial: Apple Music, iCloud Calendar/Contacts/Mail, Apple Maps and WeatherKit, no Mac needed |
| Description (raw) | Unofficial: Apple Music, iCloud Calendar/Contacts/Mail, Apple Maps and WeatherKit, no Mac needed | MCP-Register | 2026-09-28T01:17:01.494Z | selbstauskunft |  |
| Declared version | 0.3.4 | MCP-Register | 2026-10-10T01:17:01.464Z | selbstauskunft |  |
| Environment variables (raw) | APPLE_TEAM_ID, APPLE_KEY_ID, APPLE_PRIVATE_KEY, APPLE_PRIVATE_KEY_PATH, APPLE_MUSIC_KEY_ID, APPLE_MUSIC_PRIVATE_KEY, APPLE_MAPS_KEY_ID, APPLE_MAPS_PRIVATE_KEY, APPLE_WEATHERKIT_KEY_ID, APPLE_WEATHERKIT_PRIVATE_KEY, APPLE_WEATHERKIT_SERVICE_ID, APPLE_MUSIC_DEVELOPER_TOKEN, APPLE_MUSIC_USER_TOKEN, APPLE_MUSIC_WEB_USER_TOKEN, APPLE_MUSIC_WEB_DEVELOPER_TOKEN, APPLE_MUSIC_STOREFRONT, ICLOUD_USERNAME, ICLOUD_APP_PASSWORD, ICLOUD_MAIL_ADDRESS, ICLOUD_DEFAULT_CALENDAR, APPLE_WRITE_MODE, APPLE_SERVICES, DISPLAY_TZ, APPLE_UNITS, APPLE_STATE_CACHE, APPLE_REQUEST_TIMEOUT_MS, APPLE_DEBUG_LOG, MCP_CONFIRM_MODE, MCP_CONFIRM_ELICITATION, MCP_CONFIRM_TTL_SECONDS, MCP_CONFIRM_SECRET | MCP-Register | 2026-10-08T01:17:01.893Z | selbstauskunft |  |
| Required secret variables (raw) |  | MCP-Register | 2026-09-28T01:17:01.494Z | selbstauskunft |  |
| Transports (raw) | stdio | MCP-Register | 2026-09-28T01:17:01.494Z | selbstauskunft |  |
| Path arguments (raw) |  | MCP-Register | 2026-09-28T01:17:01.494Z | selbstauskunft |  |
| Repository (raw) | https://github.com/chrischall/apple-icloud-mcp | MCP-Register | 2026-09-28T01:17:01.494Z | selbstauskunft |  |
| Package registries (raw) | npm | MCP-Register | 2026-09-28T01:17:01.494Z | selbstauskunft |  |
| Required secret headers (raw) |  | MCP-Register | 2026-09-28T01:17:01.494Z | selbstauskunft |  |
| Path environment variables (raw) |  | MCP-Register | 2026-09-28T01:17:01.494Z | selbstauskunft |  |
| Remote URLs (raw) |  | MCP-Register | 2026-09-28T01:17:01.494Z | selbstauskunft |  |
| Remote hosts (raw) |  | MCP-Register | 2026-09-28T01:17:01.494Z | selbstauskunft |  |
| Registry status message (raw) |  | MCP-Register | 2026-09-28T01:17:01.494Z | selbstauskunft |  |
| First listed in the registry (raw) | 2026-10-09 | MCP-Register | 2026-10-10T01:17:01.464Z | selbstauskunft |  |
| Last changed in the registry (raw) | 2026-10-09 | MCP-Register | 2026-10-10T01:17:01.464Z | selbstauskunft |  |
| Schema version of the raw record (raw) | https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json | MCP-Register | 2026-09-28T01:17:01.494Z | selbstauskunft |  |
| Delivery form (raw) | paket | MCP-Register | 2026-09-28T01:17:01.494Z | selbstauskunft |  |
| Repository platform (raw) | github | MCP-Register | 2026-09-28T01:17:01.494Z | selbstauskunft |  |
| Repository subfolder (raw) |  | MCP-Register | 2026-09-28T01:17:01.494Z | selbstauskunft |  |
| Package identifiers (raw) | apple-icloud-mcp | MCP-Register | 2026-09-28T01:17:01.494Z | selbstauskunft |  |
| Package versions (raw) | 0.3.4 | MCP-Register | 2026-10-10T01:17:01.464Z | selbstauskunft |  |
| Runtime hints (raw) |  | MCP-Register | 2026-09-28T01:17:01.494Z | selbstauskunft |  |
| Environment variable formats (raw) | string | MCP-Register | 2026-09-28T01:17:01.494Z | selbstauskunft |  |
| Environment variable descriptions (raw) | APPLE_DEBUG_LOG=Set to 1 to log every upstream request line to stderr (credentials redacted). · APPLE_KEY_ID=Key ID of a private key created in Certificates, Identifiers & Profiles → Keys with Media Services (MusicKit), MapKit JS and/or WeatherKit enabled. · APPLE_MAPS_KEY_ID=Optional per-service override of APPLE_KEY_ID for Apple Maps. · APPLE_MAPS_PRIVATE_KEY=Optional per-service override of APPLE_PRIVATE_KEY for Apple Maps. · APPLE_MUSIC_DEVELOPER_TOKEN=Optional: a pre-minted Apple Music developer token (JWT) instead of signing one from the key above. · APPLE_MUSIC_KEY_ID=Optional per-service override of APPLE_KEY_ID for Apple Music (pair with APPLE_MUSIC_PRIVATE_KEY). · APPLE_MUSIC_PRIVATE_KEY=Optional per-service override of APPLE_PRIVATE_KEY for Apple Music. · APPLE_MUSIC_STOREFRONT=Two-letter Apple Music storefront (e.g. us, gb). Default: your account's storefront, else us. · APPLE_MUSIC_USER_TOKEN=Music User Token for your library (official API), from a one-time MusicKit sign-in: `npx apple-icloud-mcp music-auth`. Without the Apple Developer key, ask the owner for a developer token (music-auth --print-developer-token) and run it with APPLE_MUSIC_DEVELOPER_TOKEN set. Lasts ~6 months. · APPLE_MUSIC_WEB_DEVELOPER_TOKEN=Optional override for the web-player developer token (normally read automatically from music.apple.com). · APPLE_MUSIC_WEB_USER_TOKEN=Opt-in web-player mode (no developer account needed; unlocks rename/delete/remove/reorder): the media-user-token cookie from a signed-in music.apple.com tab. · APPLE_PRIVATE_KEY=Contents of that key's .p8 file (PEM; one-line values with \\n escapes and base64 are accepted). · APPLE_PRIVATE_KEY_PATH=Local installs only: a path to the .p8 file instead of APPLE_PRIVATE_KEY. · APPLE_REQUEST_TIMEOUT_MS=Per-request timeout in milliseconds (default 30000). · APPLE_SERVICES=Comma-separated services to enable (music, calendar, contacts, mail, maps, weather, itunes). Default: all. · APPLE_STATE_CACHE=Set to false to write nothing under $MCP_DATA_DIR/.apple-icloud-mcp: no web-player token or iCloud discovery cache, and the rejected-password latch and spent confirmation tokens then last only as long as the process. · APPLE_TEAM_ID=Your Apple Developer Team ID (10 characters). Needed for Apple Music (official API), Apple Maps and WeatherKit. · APPLE_UNITS="metric" (default) or "imperial" units for weather (Maps distances always show both). · APPLE_WEATHERKIT_KEY_ID=Optional per-service override of APPLE_KEY_ID for WeatherKit. · APPLE_WEATHERKIT_PRIVATE_KEY=Optional per-service override of APPLE_PRIVATE_KEY for WeatherKit. · APPLE_WEATHERKIT_SERVICE_ID=WeatherKit only: the Services ID registered for WeatherKit (e.g. com.example.weather). · APPLE_WRITE_MODE="none" = read-only tools; "additive" = also create/append, never modify, delete or send; "all" = everything (default). Unrecognized values fail closed to "none". · DISPLAY_TZ=IANA time zone (e.g. America/New_York) for displayed times and for dates you give without an offset. Set this on a hosted server, which runs in UTC. · ICLOUD_APP_PASSWORD=An app-specific password from appleid.apple.com → Sign-In and Security → App-Specific Passwords (NOT your Apple ID password). · ICLOUD_DEFAULT_CALENDAR=Calendar new events go to when none is named (default: the first writable event calendar). · ICLOUD_MAIL_ADDRESS=Your @icloud.com address, only if your Apple ID email is not an iCloud address (needed for Mail). · ICLOUD_USERNAME=Your Apple ID email, for iCloud Calendar, Contacts and Mail. · MCP_CONFIRM_ELICITATION="off" never shows a confirmation prompt, so every client gets the MCP_CONFIRM_MODE flow. Set it for a client that says it can prompt but never does (the gated call hangs, e.g. opencode 2.0.x). Any other value stays "on" (with a stderr warning). · MCP_CONFIRM_MODE=How confirm-gated writes (send mail, deletes, removing tracks, invitations) behave on a client with no prompt, like claude.ai: "ask-user" (default: preview + confirmToken, the model must get your OK), "auto", or "refuse". Unknown values mean refuse. · MCP_CONFIRM_SECRET=Signing key for confirmTokens. Random per process by default; set it so a token issued just before a restart or redeploy still works (spent tokens are recorded on disk, so none can be replayed). · MCP_CONFIRM_TTL_SECONDS=Lifetime of a confirmToken in seconds (default 600). | MCP-Register | 2026-10-08T01:17:01.893Z | selbstauskunft |  |
| Icon formats (raw) |  | MCP-Register | 2026-09-28T01:17:01.494Z | selbstauskunft |  |
| Connection paths (source structure) | {"packages":[{"registryType":"npm","identifier":"apple-icloud-mcp","version":"0.3.4","transport":"stdio","environment":[{"name":"APPLE_TEAM_ID","description":"Your Apple Developer Team ID (10 characters). Needed for Apple Music (official API), Apple Maps and WeatherKit.","format":"string","required":false,"secret":false},{"name":"APPLE_KEY_ID","description":"Key ID of a private key created in Certificates, Identifiers & Profiles → Keys with Media Services (MusicKit), MapKit JS and/or WeatherKit enabled.","format":"string","required":false,"secret":false},{"name":"APPLE_PRIVATE_KEY","description":"Contents of that key's .p8 file (PEM; one-line values with \\\\n escapes and base64 are accepted).","format":"string","required":false,"secret":true},{"name":"APPLE_PRIVATE_KEY_PATH","description":"Local installs only: a path to the .p8 file instead of APPLE_PRIVATE_KEY.","format":"string","required":false,"secret":false},{"name":"APPLE_MUSIC_KEY_ID","description":"Optional per-service override of APPLE_KEY_ID for Apple Music (pair with APPLE_MUSIC_PRIVATE_KEY).","format":"string","required":false,"secret":false},{"name":"APPLE_MUSIC_PRIVATE_KEY","description":"Optional per-service override of APPLE_PRIVATE_KEY for Apple Music.","format":"string","required":false,"secret":true},{"name":"APPLE_MAPS_KEY_ID","description":"Optional per-service override of APPLE_KEY_ID for Apple Maps.","format":"string","required":false,"secret":false},{"name":"APPLE_MAPS_PRIVATE_KEY","description":"Optional per-service override of APPLE_PRIVATE_KEY for Apple Maps.","format":"string","required":false,"secret":true},{"name":"APPLE_WEATHERKIT_KEY_ID","description":"Optional per-service override of APPLE_KEY_ID for WeatherKit.","format":"string","required":false,"secret":false},{"name":"APPLE_WEATHERKIT_PRIVATE_KEY","description":"Optional per-service override of APPLE_PRIVATE_KEY for WeatherKit.","format":"string","required":false,"secret":true},{"name":"APPLE_WEATHERKIT_SERVICE_ID","description":"WeatherKit only: the Services ID registered for WeatherKit (e.g. com.example.weather).","format":"string","required":false,"secret":false},{"name":"APPLE_MUSIC_DEVELOPER_TOKEN","description":"Optional: a pre-minted Apple Music developer token (JWT) instead of signing one from the key above.","format":"string","required":false,"secret":true},{"name":"APPLE_MUSIC_USER_TOKEN","description":"Music User Token for your library (official API), from a one-time MusicKit sign-in: `npx apple-icloud-mcp music-auth`. Without the Apple Developer key, ask the owner for a developer token (music-auth --print-developer-token) and run it with APPLE_MUSIC_DEVELOPER_TOKEN set. Lasts ~6 months.","format":"string","required":false,"secret":true},{"name":"APPLE_MUSIC_WEB_USER_TOKEN","description":"Opt-in web-player mode (no developer account needed; unlocks rename/delete/remove/reorder): the media-user-token cookie from a signed-in music.apple.com tab.","format":"string","required":false,"secret":true},{"name":"APPLE_MUSIC_WEB_DEVELOPER_TOKEN","description":"Optional override for the web-player developer token (normally read automatically from music.apple.com).","format":"string","required":false,"secret":true},{"name":"APPLE_MUSIC_STOREFRONT","description":"Two-letter Apple Music storefront (e.g. us, gb). Default: your account's storefront, else us.","format":"string","required":false,"secret":false},{"name":"ICLOUD_USERNAME","description":"Your Apple ID email, for iCloud Calendar, Contacts and Mail.","format":"string","required":false,"secret":false},{"name":"ICLOUD_APP_PASSWORD","description":"An app-specific password from appleid.apple.com → Sign-In and Security → App-Specific Passwords (NOT your Apple ID password).","format":"string","required":false,"secret":true},{"name":"ICLOUD_MAIL_ADDRESS","description":"Your @icloud.com address, only if your Apple ID email is not an iCloud address (needed for Mail).","format":"string","required":false,"secret":false},{"name":"ICLOUD_DEFAULT_CALENDAR","description":"Calendar new events go to when none is named (default: the first writable event calendar).","format":"string","required":false,"secret":false},{"name":"APPLE_WRITE_MODE","description":"\\"none\\" = read-only tools; \\"additive\\" = also create/append, never modify, delete or send; \\"all\\" = everything (default). Unrecognized values fail closed to \\"none\\".","format":"string","required":false,"secret":false},{"name":"APPLE_SERVICES","description":"Comma-separated services to enable (music, calendar, contacts, mail, maps, weather, itunes). Default: all.","format":"string","required":false,"secret":false},{"name":"DISPLAY_TZ","description":"IANA time zone (e.g. America/New_York) for displayed times and for dates you give without an offset. Set this on a hosted server, which runs in UTC.","format":"string","required":false,"secret":false},{"name":"APPLE_UNITS","description":"\\"metric\\" (default) or \\"imperial\\" units for weather (Maps distances always show both).","format":"string","required":false,"secret":false},{"name":"APPLE_STATE_CACHE","description":"Set to false to write nothing under $MCP_DATA_DIR/.apple-icloud-mcp: no web-player token or iCloud discovery cache, and the rejected-password latch and spent confirmation tokens then last only as long as the process.","format":"string","required":false,"secret":false},{"name":"APPLE_REQUEST_TIMEOUT_MS","description":"Per-request timeout in milliseconds (default 30000).","format":"string","required":false,"secret":false},{"name":"APPLE_DEBUG_LOG","description":"Set to 1 to log every upstream request line to stderr (credentials redacted).","format":"string","required":false,"secret":false},{"name":"MCP_CONFIRM_MODE","description":"How confirm-gated writes (send mail, deletes, removing tracks, invitations) behave on a client with no prompt, like claude.ai: \\"ask-user\\" (default: preview + confirmToken, the model must get your OK), \\"auto\\", or \\"refuse\\". Unknown values mean refuse.","format":"string","required":false,"secret":false},{"name":"MCP_CONFIRM_ELICITATION","description":"\\"off\\" never shows a confirmation prompt, so every client gets the MCP_CONFIRM_MODE flow. Set it for a client that says it can prompt but never does (the gated call hangs, e.g. opencode 2.0.x). Any other value stays \\"on\\" (with a stderr warning).","format":"string","required":false,"secret":false},{"name":"MCP_CONFIRM_TTL_SECONDS","description":"Lifetime of a confirmToken in seconds (default 600).","format":"string","required":false,"secret":false},{"name":"MCP_CONFIRM_SECRET","description":"Signing key for confirmTokens. Random per process by default; set it so a token issued just before a restart or redeploy still works (spent tokens are recorded on disk, so none can be replayed).","format":"string","required":false,"secret":true}],"additional_arguments_declared":false}],"remotes":[]} | MCP-Register | 2026-10-10T01:17:01.464Z | selbstauskunft |  |

## Links

- Namespace: [[namensraum/io-github-chrischall|io.github.chrischall]]

---

- Registry page: <https://tracevero.com/mcp/io-github-chrischall-apple-icloud-mcp>
- Retrieved on: 2026-10-10
