JoplinCAUTION
MCP server for the Joplin note taking app
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
A FastMCP-based Model Context Protocol (MCP) server for Joplin note-taking application via its Python API joppy, enabling AI assistants to interact with your Joplin notes, notebooks, and tags through a standardized interface.
Table of Contents
- What You Can Do
- Quick Start
- Supported Clients
- Example Usage
- Tool Permissions
- Notebook Allowlist
- Advanced Configuration
- Docker
- Project Structure
- Testing
- Complete Tool Reference
- Changelog
What You Can Do
This MCP server provides 26 optimized tools for comprehensive Joplin integration:
Note Management
- Find & Search:
find_notes(supportstrash=Truefor trashed notes),find_notes_with_tag,find_notes_in_notebook,get_all_notes - CRUD Operations:
get_note,get_note_resources(read OCR text from attached images/PDFs),get_links,create_note,update_note,edit_note,delete_note
Notebook Management
- Organize:
list_notebooks,create_notebook,update_notebook,delete_notebook
Tag Management
- Categorize:
list_tags,create_tag,update_tag,delete_tag,get_tags_by_note - Link:
tag_note,untag_note
Trash Management
- Recover:
restore_from_trash- Restore soft-deleted notes or notebooks
Import
- File Import:
import_from_file- Import Markdown, HTML, CSV, TXT, JEX files and directories
System
- Health:
ping_joplin
Quick Start
- Open Joplin Desktop → Tools → Options → Web Clipper
- Enable the Web Clipper service
- Copy the Authorization token
- Set up your preferred cl
caf52debfd3eOBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add joplin-mcp --env JOPLIN_TOKEN=${JOPLIN_TOKEN} -- None joplin-mcp==0.10.0Trust audit
CAUTIONgrade C · trust 73/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (3 observation(s))
- Shell
- declared (1 observation(s))
- Dependencies
- pinned
- Secrets in source
- found
Findings (13)
module = __import__(f"joplin_mcp.importers.{module_name}", fromlist=[class_name])token="test_token_for_allowlist",
config = JoplinMCPConfig(token="test-token-1234567890")
token="test-token-1234567890",
config = JoplinMCPConfig(token="test-token-1234567890")
token="test-token-1234567890",
await fn(title="Family", emoji="👨👩👧")
assert json.loads(call_kwargs["icon"])["emoji"] == "👨👩👧"
kiss = "👩🏽❤️💋👨🏿" # 10 codepoints
line = _format_notebook_icon('{"type":1,"emoji":"👨👩👧","name":""}')assert line == " emoji: 👨👩👧"
### 3. Full Access Configuration
Gates applied: no_behavioural_pass.
caf52debfd3efull audit observations/trust-audit/mcp-server/alondmnt__joplin-4.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | caf52debfd3e | CAUTION | C | 73 | first audit |
Questions
What is the Joplin MCP server?
MCP server for the Joplin note taking app
Is Joplin safe to connect to an agent?
With care. The audit graded it C (73/100) and found 13 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does Joplin need?
It reads JOPLIN_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Joplin run?
It speaks sse, stdio and streamable-http, so it runs as a local process your client starts. It is published on PyPI as joplin-mcp.
How current is this page?
The grade is for one exact copy of the source (caf52debfd3e), read on 2026-10-07. The repository is watched and re-audited when it changes.