NotionCAUTION
A simple MCP integration that allows Claude to read and manage a personal Notion todo list
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
A simple Model Context Protocol (MCP) server that integrates with Notion's API to manage my personal todo list through Claude. This is a basic implementation tailored specifically for my minimalist todo list setup in Notion.
Important Note
This is a personal project designed for a very specific use case: my simple Notion todo list that has just three properties:
- Task (title)
- When (select with only two options: "today" or "later")
- Checkbox (marks if completed)
While you can use this as a starting point for your own Notion integration, you'll likely need to modify the code to match your specific database structure and requirements.
Features
- Add new todo items
- View all todos
- View today's tasks
- Check off a task as complete
Prerequisites
- Python 3.10 or higher
- A Notion account
- A Notion integration (API key)
- A Notion database that matches the exact structure described above (or willingness to modify the code for your structure)
Setup
- Clone the repository:
git clone https://github.com/yourusername/notion-mcp.git cd notion-mcp
- Set up Python environment:
python -m venv .venv source .venv/bin/activate # On Windows use: .venv\Scripts\activate uv pip install -e .
- Create a Notion integration:
- Go to https://www.notion.so/my-integrations
- Create new integration
- Copy the API key
- Share your database with the integration:
- Open your todo database in Notion
- Click "..." menu → "Add connections"
- Select your integration
- Create a
.envfile:
NOTION_API_KEY=your-api-key-here NOTION_DATABASE_ID=your-database-id-here
- Configure Claude Desktop:
{
"mcpServers": {
"notion-todo": {
"command": "/path/to/your/.venv/bin/python",
497a4a64123aOBSERVED · 2026-10-06Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add notion_mcp --env NOTION_API_KEY=${NOTION_API_KEY} -- uvx notion_mcp{
"mcpServers": {
"notion_mcp": {
"command": "uvx",
"args": [
"notion_mcp"
],
"env": {
"NOTION_API_KEY": "${NOTION_API_KEY}"
}
}
}
}Exposed tools (4)
3 read · 1 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
add_todo | write | Add a new todo item |
complete_todo | read | Mark a todo item as complete |
show_all_todos | read | Show all todo items from Notion |
show_today_todos | read | Show today |
Trust audit
CAUTIONgrade B · trust 86/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (5 observation(s))
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (8)
.DS_Store
.DS_Store
__init__.cpython-311.pyc
__main__.cpython-311.pyc
server.cpython-311.pyc
.DS_Store
.DS_Store
assets/demo.gif
Gates applied: no_behavioural_pass.
497a4a64123afull audit observations/trust-audit/mcp-server/danhilse__notion-5.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-06 | 497a4a64123a | CAUTION | B | 86 | first audit |
Questions
What is the Notion MCP server?
A simple MCP integration that allows Claude to read and manage a personal Notion todo list
What tools does Notion expose?
4 in total: 3 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Notion safe to connect to an agent?
With care. The audit graded it B (86/100) and found 8 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does Notion need?
It reads NOTION_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Notion run?
It speaks stdio, so it runs as a local process your client starts. It is published on PyPI as notion_mcp.
How current is this page?
The grade is for one exact copy of the source (497a4a64123a), read on 2026-10-06. The repository is watched and re-audited when it changes.