
Security News
Happy Birthday, Shai-Hulud
It has been one year since Shai-Hulud made its first appearance on npm.
icloud-calendar-mcp
Advanced tools
An MCP server for managing iCloud Calendar.
English · 简体中文
Requirements:
Add the server to your MCP client:
{
"mcpServers": {
"icloud-calendar": {
"command": "npx",
"args": ["-y", "icloud-calendar-mcp"],
"env": {
"ICLOUD_USERNAME": "you@example.com",
"ICLOUD_APP_PASSWORD": "xxxx-xxxx-xxxx-xxxx"
}
}
}
}
Use an app-specific password, not your Apple Account password.
| Tool | Purpose |
|---|---|
list_calendars | List calendars |
list_events | List events in a time range |
get_event | Get an event |
create_event | Create an event |
update_event | Update an event |
delete_event | Delete an event |
find_conflicts | Find overlapping events |
free_busy | Return busy time ranges |
Events can include time zones, all-day dates, recurrence rules, alarms, locations, descriptions, URLs, and attendees.
Once the server is connected, you can ask your MCP client:
Show my calendars.
What is on my calendar next week in Asia/Shanghai time?
Add a project review to my Work calendar tomorrow from 2:00 PM to 3:00 PM, with a reminder 15 minutes before.
Do I have any conflicts on Friday between 9:00 AM and noon?
Move the project review to 4:00 PM and change the location to Meeting Room B.
Add an all-day event called “Company holiday” on October 1.
Delete the project review event.
For ambiguous requests, include the calendar, date, time, and time zone when possible.
2026-08-18 to 2026-08-19.request_id for safe retries.See tool contracts for complete inputs, outputs, and error codes.
stdio is the default transport. Streamable HTTP is optional:
ICLOUD_MCP_TRANSPORT=http \
ICLOUD_MCP_HTTP_TOKEN='replace-with-a-long-random-token' \
ICLOUD_MCP_HTTP_PORT=3000 \
npx -y icloud-calendar-mcp
HTTP mode requires a bearer token and listens on loopback by default. See security before exposing it through a proxy.
pnpm install
pnpm check
See architecture, contributing, and releasing.
FAQs
Reliable Apple iCloud Calendar MCP server over CalDAV
The npm package icloud-calendar-mcp receives a total of 118 weekly downloads. As such, icloud-calendar-mcp popularity was classified as not popular.
We found that icloud-calendar-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
It has been one year since Shai-Hulud made its first appearance on npm.

Research
/Security News
Operators behind PolinRider used a compromised GitHub account to plant malware in four development versions of a Packagist package with 700,000+ downloads.

Security News
GitHub Actions now supports cache-mode, a least-privilege control on the Actions cache aimed at the cache poisoning technique behind recent compromises.