Atlas / MCP servers / ccabanillas / Notion

NotionCAUTION

mcp/ccabanillas/notion-4

A Model Context Protocol (MCP) server implementation for Notion integration, providing a standardized interface for interacting with Notion's API.

Verdict
CAUTION
Grade
B
Trust score
88 /100
Exposed tools
7 5r · 2w · 0d
Transport
stdio
License
MIT
Stars
111
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://smithery.ai/server/@ccabanillas/notion-mcp)

A Model Context Protocol (MCP) server implementation for Notion integration, providing a standardized interface for interacting with Notion's API. Compatible with Claude Desktop and other MCP clients.

Features

  • List and query Notion databases
  • Create and update pages
  • Search across Notion workspace
  • Get database details and block children
  • Full async/await support with httpx
  • Type-safe with Pydantic v2 models
  • Proper error handling with detailed logging
  • Compatibility with MCP 1.6.0

Installation

Installing via Smithery

To install Notion Integration Server for Claude Desktop automatically via Smithery:

npx -y @smithery/cli install @ccabanillas/notion-mcp --client claude

Manual Installation

  1. Clone the repository:
git clone https://github.com/ccabanillas/notion-mcp.git
cd notion-mcp
  1. Create a virtual environment and install dependencies (using uv):
uv venv
source .venv/bin/activate  # On Windows: .venv\Scripts\activate
uv pip install -e .

Alternatively, using standard venv:

python -m venv venv
source venv/bin/activate  # On Windows: venv\Scripts\activate
pip install -e .
  1. Create a .env file in the project root:
NOTION_API_KEY=your_notion_integration_token

Usage

  1. Test the server (it should run without errors):
python -m notion_mcp
  1. To use it with Claude Desktop, adjust your claude_desktop_config.json file (located at ~/Library/Application Support/Claude/claude_desktop_config.json on macOS):
{
"servers": {
"notion-mcp": {
"command": "/Users/username/Projects/notion-mcp/.venv/bin/python",
"args": ["-m", "notion_mcp"],
"cwd": "/Users/username/Projects/notion-mcp"
}
}
}

Be sure to replace /Users/username/ with

Read from source at commit d147ce4ee908OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add notion-mcp --env NOTION_API_KEY=${NOTION_API_KEY} -- uvx notion-mcp
claude-desktop
{
  "mcpServers": {
    "notion-mcp": {
      "command": "uvx",
      "args": [
        "notion-mcp"
      ],
      "env": {
        "NOTION_API_KEY": "${NOTION_API_KEY}"
      }
    }
  }
}
03

Exposed tools (7)

5 read · 2 write · 0 destructive.

ToolRiskDescription
create_pagewriteCreate a new page in a database
get_block_childrenreadGet the children blocks of a block
get_databasereadGet details about a specific Notion database
list_databasesreadList all accessible Notion databases
query_databasereadQuery items from a Notion database
searchreadSearch Notion content
update_pagewriteUpdate an existing page
04

Trust audit

CAUTIONgrade B · trust 88/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (5 observation(s))
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (5)

MEDIUMInventory / provenance · inv.binary · CWE-1104
src/notion_mcp/__pycache__/__init__.cpython-311.pyc
__init__.cpython-311.pyc
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
src/notion_mcp/__pycache__/__init__.cpython-313.pyc
__init__.cpython-313.pyc
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
src/notion_mcp/__pycache__/__main__.cpython-311.pyc
__main__.cpython-311.pyc
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
src/notion_mcp/__pycache__/__main__.cpython-313.pyc
__main__.cpython-313.pyc
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
src/notion_mcp/__pycache__/client.cpython-313.pyc
client.cpython-313.pyc
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha d147ce4ee908full audit observations/trust-audit/mcp-server/ccabanillas__notion-4.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07d147ce4ee908CAUTIONB88first audit
06

Questions

What is the Notion MCP server?

A Model Context Protocol (MCP) server implementation for Notion integration, providing a standardized interface for interacting with Notion's API.

What tools does Notion expose?

7 in total: 5 read-only, 2 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Notion safe to connect to an agent?

With care. The audit graded it B (88/100) and found 5 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does Notion need?

It reads NOTION_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Notion run?

It speaks stdio, so it runs as a local process your client starts. It is published on PyPI as notion-mcp.

How current is this page?

The grade is for one exact copy of the source (d147ce4ee908), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement