RaindropCAUTION
Raindrop MCP Server
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://smithery.ai/server/@adeze/raindrop-mcp) [](https://www.npmjs.com/package/@adeze/raindrop-mcp) [](https://github.com/adeze/raindrop-mcp/releases)
Connect Raindrop.io to your AI assistant with a simple MCP server. Use it to organize, search, and manage bookmarks with natural language.
Raindrop.io now also offers a hosted Streamable HTTP MCP endpoint (https://api.raindrop.io/rest/v2/ai/mcp) in beta for Pro users. Use that when its hosted toolset is sufficient; use this package for local stdio, self-hosted HTTP, and its additional library-management tools.What it can do
- Create, update, and delete collections and bookmarks
- Search bookmarks by tags, domain, type, date, and more
- Manage tags (list, rename, merge, delete)
- Read highlights from bookmarks
- Bulk edit bookmarks in a collection
- Audit broken links and duplicates, and manage trash
Tools
- diagnostics - Server diagnostic information and library health metrics
- collection_list - List all collections as a flat list
- get_collection_tree - Hierarchical view of collections with full breadcrumb paths
- collection_manage - Create, update, or delete collections
- bookmark_search - Advanced search with filters, tags, and pagination
- bookmark_manage - Create, update, or delete bookmarks
- get_raindrop - Fetch a single bookmark by ID
- list_raindrops - List bookmarks for a collection with pagination
- get_suggestions - AI-powered organization advice (tags/collections) for a URL or bookmark
- suggest_tags - Suggest relevant tags from bookmark metadata using AI-assisted analysis
- bulk_edit_raindrops - Bulk update, move, or remove bookmarks in a specific collection
- tag_manage -
127d7d00b8d6OBSERVED · 2026-10-06Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add raindrop-mcp --env RAINDROP_ACCESS_TOKEN=${RAINDROP_ACCESS_TOKEN} --env RAINDROP_CLIENT_SECRET=${RAINDROP_CLIENT_SECRET} -- npx -y @adeze/[email protected]{
"mcpServers": {
"raindrop-mcp": {
"command": "npx",
"args": [
"-y",
"@adeze/[email protected]"
],
"env": {
"RAINDROP_ACCESS_TOKEN": "${RAINDROP_ACCESS_TOKEN}",
"RAINDROP_CLIENT_SECRET": "${RAINDROP_CLIENT_SECRET}"
}
}
}
}Exposed tools (21)
17 read · 0 write · 4 destructive. Blast radius: 4 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
bookmark_manage | read | Creates, updates, or deletes bookmarks. Use the operation parameter to specify the action. |
bookmark_search | read | Searches bookmarks with advanced filters, tags, and full-text search. |
bulk_edit_raindrops | destructive | Bulk update, move, or remove bookmarks in a specific collection. |
cleanup_collections | destructive | Remove all collections that do not contain any bookmarks. Requires |
collection_list | read | Lists all Raindrop.io collections as a flat list. |
collection_manage | read | Creates, updates, or deletes a collection. Use the operation parameter to specify the action. |
diagnostics | read | Diagnostics resource and runtime metadata. |
empty_trash | destructive | Permanently delete all bookmarks currently in the trash collection. Requires |
export_markdown | read | Render bookmarks as Markdown list with title, link, tags, and excerpt. |
find_duplicates | read | Identify potential duplicate bookmarks using URL + title similarity. |
get_collection_tree | read | Returns a hierarchical view of all collections with full breadcrumb paths. |
get_raindrop | read | Fetch a single Raindrop.io bookmark by ID. |
get_suggestions | read | Get AI-powered suggestions for tags and collections for a specific URL or existing bookmark. |
highlight_manage | read | Creates, updates, or deletes highlights. Use the operation parameter to specify the action. |
library_audit | read | Scans the entire library for broken links and duplicate bookmarks. |
list_raindrops | read | List Raindrop.io bookmarks for a collection with pagination. |
organize_by_topic | read | Analyze titles/excerpts and suggest collections + tags for organization. |
remove_duplicates | destructive | Optimized duplicate deletion pattern. Scans all collections and removes duplicates in batches of 50 to minimize round-trips. Supports dry run to report counts without deleting. |
suggest_tags | read | Uses AI to suggest relevant tags based on bookmark metadata (title, URL, description). |
tag_manage | read | Renames, merges, or deletes tags. Use the operation parameter to specify the action. |
test_tool | read | A test tool |
Trust audit
CAUTIONgrade B · trust 87/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (3 observation(s))
- Network
- declared (1 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (14)
/.env" ... fetch(
bulk_edit_raindrops, cleanup_collections, empty_trash, remove_duplicates
.mcpbignore
.prettierignore
.prettierrc.json
.releaserc.json
.nojekyll
import pkg from "../../package.json";
import pkg from "../../package.json";
window.hierarchyData = "eJyV0D1rwzAQgOH/cvMl9YdsFG0d2qntUGiXEIqwFSyqDyOdhxL834tJW+QujiaBuFfPoQsE7ymCONa8OCEEdTaqI+1dBHGBmhfL4aRVIOC5Gx9C8AEQPrXrQZQVR5iCAQGdkTGqeEdfo4of9mcy7n+b/UDWAF7nQADFfrc8srteIHSD
window.navigationData = "eJytmV1v1DgUhv9L2MtSaCns0jt2WATa6W7VdrlBaORxPIk1jm3FTumC+O8omST+iH1splx1NHnPc15/HPtk+ulbocmDLi4LykvyUJwUEum6uCwaUXaMqGfD16e1blhxUuwpL4vL85MC15SVLeHF5acZ0CDKTfyu41hTwSdC/9TFvLr
window.searchData = "eJy9XV2T2zay/S/yfZzYavDbb1knqXXd+G4qTvZlKpWiJYzEMiVqScpx1uX/fguAKDaApqbFDz95yiKaB+BBo9GnCX5Z1dVfzer145fVx+K4Xb0WD6tjfpCr16viuJWfVw+rc12uXq8O1fZcyuaV/t+X+/ZQrh5WmzJvGtmsXq9WXx86C3F
@modelcontextprotocol/client, @modelcontextprotocol/node, @modelcontextprotocol/server, axios, dotenv, esm, express, keyv
docs/interfaces/types_raindrop.schema.operations.html
Gates applied: no_behavioural_pass.
127d7d00b8d6full audit observations/trust-audit/mcp-server/adeze__raindrop.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-06 | 127d7d00b8d6 | CAUTION | B | 87 | first audit |
Questions
What is the Raindrop MCP server?
Raindrop MCP Server
What tools does Raindrop expose?
21 in total: 17 read-only, 0 that write, and 4 that can delete or overwrite (bulk_edit_raindrops, cleanup_collections, empty_trash, remove_duplicates). Every one is listed on this page with its risk.
Is Raindrop safe to connect to an agent?
With care. The audit graded it B (87/100) and found 14 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 4 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Raindrop need?
It reads RAINDROP_ACCESS_TOKEN and RAINDROP_CLIENT_SECRET from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Raindrop run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as @adeze/raindrop-mcp at 2.4.5.
How current is this page?
The grade is for one exact copy of the source (127d7d00b8d6), read on 2026-10-06. The repository is watched and re-audited when it changes.