iMessage MCP Server & CLI
A free, open source iMessage MCP server and CLI that lets Claude Code, Codex, Cursor and other AI agents catch you up, search your history and send messages, on your Mac.
This free iMessage MCP server and CLI gives your AI real access to your Messages history on your Mac, and the Messages app itself. It keeps an inbox that remembers what you've already seen, searches your full history, looks people up in Contacts, sends messages and files, and transcribes voice notes.
It's one install with 2 ways in. Claude, Codex, Cursor or any other MCP app calls its 10 tools for you, and the same tools work as a CLI that agents like Claude Code, Codex and OpenCode run, or that you type yourself.
Here's what the iMessage MCP server and CLI is, how to set it up in each app, and every tool it has.
What is the iMessage MCP server & CLI?
The iMessage MCP server & CLI is a free, open source program that lets AI agents read, search and send your iMessages for you, in 2 ways. The MCP server is what an AI app like Claude, Codex or Cursor connects to, through MCP (Model Context Protocol), the open standard AI apps use to call outside tools.
You ask in plain language. Your AI picks the right tool, and the server makes the call to the Messages database right on your Mac.
The CLI is the same program as commands. imessage-cli inbox runs the same code your AI runs when you ask what you missed, whether an agent like Claude Code runs it or you do.
What can you ask it?
Once it's set up, you ask the way you'd ask an assistant. These are real prompts it handles:
Try askingWhat did I miss?
What did Mike say about the invoice last month?
Text Anna that I'm running fifteen minutes late.
Transcribe that voice note.
Who have I not replied to this week?
Find the address someone sent me in March.
The first one shows why this is useful. The inbox keeps its place on disk, so it covers everything since you last asked, even while nothing was running.
How to install the iMessage MCP server
Pick your app in the box at the top of this page. Each one is a single command or a pasted block, and there's no account or key to add.
Watch out: It can read every conversation in your Messages database, and a message it sends comes from your own account and can't be unsent. Connect it only to an AI app you trust with your messages.
Give it access to your messages
There's no sign-in. macOS asks twice, at different moments.
The first time it sends anything, macOS asks whether that app may control Messages. Allow it. That prompt appears once, and only if you send.
Check that it works
Run the doctor. It checks the database, your contacts, the inbox cursor and the voice note tools.
npx -y @thenavidm/imessage-mcp-cli doctorIf the database line fails, Full Disk Access is missing for the app that runs it, and remember the Cmd+Q.
Use the iMessage CLI
The CLI is the same 10 tools as commands. AI agents that run commands, like Claude Code, Codex and OpenCode, use it on their own, and you can type the same commands in a terminal or a script.
Every tool name becomes a command with dashes, so search_messages runs as imessage-cli search-messages.
npm install -g @thenavidm/imessage-mcp-cli
imessage-cli
imessage-cli inbox --peek
imessage-cli search-messages --query "invoice" --limit 10
imessage-cli resolve-contact --name "Sarah"The bare imessage-cli lists every command, and imessage-cli <command> --help shows what a command takes. Sending asks for --confirm first, like it does for your AI.
These flags work on every command:
| Flag | What it does |
|---|---|
--json | Prints JSON |
--compact | Prints the JSON on one line |
--agent | Machine mode: JSON, compact, no prompts and no color |
--select a,b.c | Keeps only those fields, and a dotted path goes deeper |
--confirm | Lets a write that asks first go ahead |
A script can branch on the exit code:
| Exit code | What it means |
|---|---|
| 0 | It worked |
| 2 | The command was typed wrong, or a send needed --confirm |
| 3 | It wasn't found |
| 4 | macOS refused access, so turn on Full Disk Access or allow Automation for Messages |
| 5 | Messages or a transcription service failed |
MCP server or CLI: which one?
Both are the same program with the same 10 tools. The difference is when your AI pays for them, in the tokens it reads.
- MCP server
- 1,600 tokens
- CLI
- Nothing
- MCP server
- 110 tokens
- CLI
- Nothing
- MCP server
- Nothing more, or in Claude Code the tools it picks
- CLI
- 2,100 tokens, once
- MCP server
- 33,000 tokens
- CLI
- 2,100 tokens
- MCP server
- Yes
- CLI
- No, there's no terminal there
- MCP server
- No
- CLI
- Yes
An app that loads every tool up front sends the full list with every message, whether you mention iMessage or not. Claude Code doesn't by default: its tool search sends only the tool names and the server's instructions, and loads a tool's full definition when your AI reaches for it.
The CLI costs nothing until iMessage comes up. Then your agent reads its skill file once and runs the commands it needs. With the skill added, Claude Code also lists its one-line description with every message, about 90 tokens.
When the whole conversation is about iMessage, the gap closes. Then the MCP server is the better experience, because you ask in plain language and your AI never has to look up a command.
How to spend less
In Claude Code, leave tool search on, which it is unless you've set ENABLE_TOOL_SEARCH=false.
Turn the server off when you aren't using it, with your AI app's own switch.
Or install the CLI and connect the server later, on the days it earns its place. Every tool stays in reach, and the standing cost drops to nothing.
Every number here was measured on September 27, 2026 in Claude Code 2.1.257 with Claude Opus 5. It's the same one-line prompt with and without the server connected, once with tool search off so every tool loads, and once with Claude Code's default. The skill was measured the same way, and other apps and models count tokens a little differently.
The inbox remembers where you were
The inbox keeps its place in ~/.imessage-mcp/state.json, so you can close everything, come back two days later and ask what you missed. It's written safely, so a crash can't make it skip or repeat messages.
The first call returns nothing, because it starts at the end of your history rather than dumping years of messages. It includes your own sends, which makes note-to-self work, and includeFromMe: false leaves them out.
Voice notes
Transcription has 4 providers, and only one keeps the audio on your Mac.
- What it is
- Whisper on Groq's servers, the default and the cheapest
- Audio leaves your Mac
- Yes
- What it is
- Whisper on your own Mac, with a whisper command installed
- Audio leaves your Mac
- No
- What it is
- Whisper on OpenAI's servers
- Audio leaves your Mac
- Yes
- What it is
- ElevenLabs' Scribe model, strongest across languages
- Audio leaves your Mac
- Yes
Set IMESSAGE_TRANSCRIBE to choose, and put the provider's key in its environment variable. ffmpeg is needed for every provider.
Every iMessage tool
All 10 tools, grouped the way the README groups them. 6 only read, and the rest send, speak or move the inbox's place.
The inbox
inbox- What it does
- Messages that have arrived since this tool last ran.
- Kind
- Writes
Reading
search_messages- What it does
- Search message history by text, sender, chat, or date range.
- Kind
- Reads
list_conversations- What it does
- List chats by most recent activity, with resolved contact names and participants.
- Kind
- Reads
get_conversation- What it does
- Read one conversation in order, oldest first.
- Kind
- Reads
Contacts
resolve_contact- What it does
- Look up a person in Contacts by name and return their sendable handles.
- Kind
- Reads
Sending
send_message- What it does
- Send a message to a phone number, email, or chat GUID.
- Kind
- Asks first
send_file- What it does
- Send a file by absolute path.
- Kind
- Asks first
Voice
transcribe_voice_note- What it does
- Transcribe an audio attachment to text.
- Kind
- Reads
speak- What it does
- Turn text into speech with ElevenLabs and return the audio file path, optionally sending it.
- Kind
- Asks first
Status
server_status- What it does
- Database reachability, cursor position, contact count, and which optional tools are installed.
- Kind
- Reads
Is the iMessage MCP server safe?
Reading changes nothing. Sending is the one thing to be careful with, because a message goes to a real person from your own account and can't be unsent, so every send asks first.
send_message, send_file and speak with a recipient refuse to run without a confirm check, marked Asks first in the tool tables above. The refusal names the recipient and the text, so your AI can show you exactly what would go before it asks again.
Make it read-only
Set IMESSAGE_READ_ONLY=1 and the 3 sending tools disappear from the list, so an agent that should only read never sees them. The inbox still works, because the only thing it writes is its own place on disk.
Keep a log of every write
Set IMESSAGE_AUDIT_LOG to a file path. The server writes one line per attempted write, allowed or blocked.
Watch out: Anyone who can text you can put words in front of your AI. Treat instructions inside messages as hostile, and check who you're about to text, because matching on the last 7 digits of a number can collide across countries.
Your data
Nothing leaves your Mac, except in 2 cases. Voice transcription uploads the audio unless the provider is local, and speak sends its text to ElevenLabs.
The only thing this server writes is ~/.imessage-mcp/state.json, which holds one number and a timestamp. No message is copied, cached or indexed. Whatever your AI reads goes to its own model provider, like anything you paste into a chat.
iMessage MCP server settings
Every setting is optional, as an environment variable in your app's config.
IMESSAGE_DB- Default
~/Library/Messages/chat.db- What it does
- Points at another copy of the database
IMESSAGE_STATE_DIR- Default
~/.imessage-mcp- What it does
- Sets where the inbox keeps its place
IMESSAGE_READ_ONLY- Default
- off
- What it does
1takes the sending tools away. Reading and the inbox still work
IMESSAGE_AUDIT_LOG- Default
- none
- What it does
- Names a file that gets one line per send attempt, with the recipient but never the words
IMESSAGE_TRANSCRIBE- Default
groq- What it does
- Picks the transcription provider:
groq,local,openaiorelevenlabs
GROQ_API_KEY- Default
- none
- What it does
- Holds the key for the default provider
OPENAI_API_KEY- Default
- none
- What it does
- Holds the key for
openai
ELEVENLABS_API_KEY- Default
- none
- What it does
- Holds the key for
speakand forelevenlabstranscription
ELEVENLABS_VOICE_ID- Default
- none
- What it does
- Sets the voice
speakuses
Troubleshooting
Run the doctor first. It names the step that failed and the fix.
| What you see | What to do |
|---|---|
| Every tool says it can't read chat.db | Turn on Full Disk Access for the app that runs it, then quit it with Cmd+Q |
| The inbox returns nothing on a fresh install | That's expected. The first call starts at the end, so send yourself a message and ask again |
| Sends fail with no error | Messages must be open and signed in. Try one message by hand first |
| Contacts show as raw numbers | That person isn't in Contacts, or the number differs beyond the last 7 digits |
| Transcription fails | Run the doctor, which names the provider and what it's missing |
If the server doesn't show up in your app at all, run the command your app runs, in a terminal, and read the error.
More free tools for staying in touch
Make a QR code that opens a chat, or tag the links you send so you can see which ones people open.
iMessage MCP Server FAQs
Here are the questions people ask most about the iMessage MCP server and CLI.
The iMessage MCP server & CLI is a free, open source program that lets an AI app like Claude, Codex or Cursor read, search and send your iMessages.
It has 10 tools for your inbox, search, contacts, sending and voice notes, and the same tools run as a CLI that agents like Claude Code and Codex use, or that you type yourself.
An MCP server is a standard way to give an AI app real access to a tool, so it can act instead of guessing.
MCP stands for Model Context Protocol, and Claude, Codex, Cursor and many other AI apps speak it.
The iMessage CLI is the same program as the iMessage MCP server, run as commands.
AI agents like Claude Code, Codex and OpenCode run them for you, and you can type them in a terminal or a script.
Use the iMessage MCP server in an AI app with no terminal, like Claude Desktop's chat, and the CLI in a terminal, a script or a cron job.
In an AI app that can run commands, like Claude Code, Codex or Cursor, the CLI is the lighter choice, because it costs nothing until it runs.
Yes, the iMessage MCP server is free and open source under the MIT license, with no account and no key.
Voice note transcription can use a paid provider, or run free on your Mac.
Yes, the iMessage MCP server reads the whole Messages database on your Mac, groups included.
There's no per-chat allowlist, so connect it only to an AI app you trust with your messages.
Yes, every send needs a confirm check first, because it goes from your own account and can't be unsent.
The refusal names the recipient and the text, so your AI can show you before it sends.
No, the iMessage MCP server only runs on a Mac, because the Messages database exists nowhere else.
No, the iMessage MCP server reads the history your Mac already synced through iCloud, and sends through the Messages app on your Mac.
The iMessage MCP server works with any app that speaks MCP.
That includes Claude Code, Claude Desktop, Codex, Cursor, VS Code, GitHub Copilot CLI, Gemini CLI, OpenCode, OpenClaw, Antigravity and Hermes, on your Mac.
Navid.me is reader-supported. When you buy through links on this site, I may earn an affiliate commission. Learn more.
More MCP servers & CLIs
The most actionable AI newsletter for founders
Every week, get proven AI strategies, curated tools, and step-by-step systems to grow your audience, create better content, and build a profitable creator business.
No fluff, no filler, no BS. Just five minutes each week that might level up your online business and life.
P.S. Sign up now to get free access to my ultimate AI tools guide for creators.


