NotionCAUTION
A Model Context Protocol (MCP) server implementation for Notion integration, providing a standardized interface for interacting with Notion's API.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://smithery.ai/server/@ccabanillas/notion-mcp)
A Model Context Protocol (MCP) server implementation for Notion integration, providing a standardized interface for interacting with Notion's API. Compatible with Claude Desktop and other MCP clients.
Features
- List and query Notion databases
- Create and update pages
- Search across Notion workspace
- Get database details and block children
- Full async/await support with httpx
- Type-safe with Pydantic v2 models
- Proper error handling with detailed logging
- Compatibility with MCP 1.6.0
Installation
Installing via Smithery
To install Notion Integration Server for Claude Desktop automatically via Smithery:
npx -y @smithery/cli install @ccabanillas/notion-mcp --client claude
Manual Installation
- Clone the repository:
git clone https://github.com/ccabanillas/notion-mcp.git cd notion-mcp
- Create a virtual environment and install dependencies (using uv):
uv venv source .venv/bin/activate # On Windows: .venv\Scripts\activate uv pip install -e .
Alternatively, using standard venv:
python -m venv venv source venv/bin/activate # On Windows: venv\Scripts\activate pip install -e .
- Create a
.envfile in the project root:
NOTION_API_KEY=your_notion_integration_token
Usage
- Test the server (it should run without errors):
python -m notion_mcp
- To use it with Claude Desktop, adjust your
claude_desktop_config.jsonfile (located at~/Library/Application Support/Claude/claude_desktop_config.jsonon macOS):
{
"servers": {
"notion-mcp": {
"command": "/Users/username/Projects/notion-mcp/.venv/bin/python",
"args": ["-m", "notion_mcp"],
"cwd": "/Users/username/Projects/notion-mcp"
}
}
}Be sure to replace /Users/username/ with
d147ce4ee908OBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add notion-mcp --env NOTION_API_KEY=${NOTION_API_KEY} -- uvx notion-mcp{
"mcpServers": {
"notion-mcp": {
"command": "uvx",
"args": [
"notion-mcp"
],
"env": {
"NOTION_API_KEY": "${NOTION_API_KEY}"
}
}
}
}Exposed tools (7)
5 read · 2 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
create_page | write | Create a new page in a database |
get_block_children | read | Get the children blocks of a block |
get_database | read | Get details about a specific Notion database |
list_databases | read | List all accessible Notion databases |
query_database | read | Query items from a Notion database |
search | read | Search Notion content |
update_page | write | Update an existing page |
Trust audit
CAUTIONgrade B · trust 88/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (5 observation(s))
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (5)
__init__.cpython-311.pyc
__init__.cpython-313.pyc
__main__.cpython-311.pyc
__main__.cpython-313.pyc
client.cpython-313.pyc
Gates applied: no_behavioural_pass.
d147ce4ee908full audit observations/trust-audit/mcp-server/ccabanillas__notion-4.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | d147ce4ee908 | CAUTION | B | 88 | first audit |
Questions
What is the Notion MCP server?
A Model Context Protocol (MCP) server implementation for Notion integration, providing a standardized interface for interacting with Notion's API.
What tools does Notion expose?
7 in total: 5 read-only, 2 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Notion safe to connect to an agent?
With care. The audit graded it B (88/100) and found 5 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does Notion need?
It reads NOTION_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Notion run?
It speaks stdio, so it runs as a local process your client starts. It is published on PyPI as notion-mcp.
How current is this page?
The grade is for one exact copy of the source (d147ce4ee908), read on 2026-10-07. The repository is watched and re-audited when it changes.