KeeperBLOCK
Calendar sync tool & universal calendar MCP server. Aggregate, sync and control calendars on Google, Outlook, Office 365, iCloud, CalDAV or ICS.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Keeper.sh is a simple & open-source calendar syncing tool. It allows you to pull events from your Google Calendar, Outlook, iCloud, Fastmail, CalDAV server, or remotely hosted iCal and ICS links, and push them to one or many calendars so the time slots can align across them all. Google, Outlook, iCloud, Fastmail, and CalDAV are first-class integrations that can each be used as a source or as a destination, while iCal and ICS links are pull-only. It also serves as a global MCP server and API for you or your agents to manage all your calendars from one convenient interface.
The recommended way to run it is the hosted version at keeper.sh: the same code, minus the server, the domain, the upgrades, the backups and the Google and Microsoft sign-in apps you would otherwise register yourself. Self-hosting is a first-class path and every Pro feature is included when you self-host — that is not a trial, and it is not going away. It costs you the upkeep instead of the $5.
Features
- First-class Google Calendar, Outlook, iCloud, Fastmail, and CalDAV integrations, each usable as a source or a destination
- Pull-only ingestion of remotely hosted iCal and ICS links
- Incremental syncing on Google and Outlook using provider sync tokens rather than refetching everything
- Event content agnostic syncing engine
- Push aggregate events to one or more calendars
- Per-source privacy controls to strip event names, descriptions, and locations, replacing the title with a
{{calendar_name}}or{{event_name}}template - REST API under
/api/v1authenticated with API tokens - MCP (Model Context Protocol) server for AI agent calendar access
- Combined iCal feed you can subscribe to from any calendar app
- Open source under AGPL-3.0
- Easy to self-host
- Easy-to-purge remote events
Bug Reports & Feature Requests
If you encounter a bug or have an idea for a feature, you may [open an issue on Gi
2fc93464d952OBSERVED · 2026-09-25Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add worker -- npx -y @keeper.sh/worker
{
"mcpServers": {
"worker": {
"command": "npx",
"args": [
"-y",
"@keeper.sh/worker"
]
}
}
}Exposed tools (2)
2 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
Free | read | Enough for two calendar accounts and three connections. |
Pro | read | As many calendars as you want, and changes that land within a minute. |
Trust audit
BLOCKgrade F · trust 40/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | FAIL |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (11 observation(s))
- Network
- declared (13 observation(s))
- Shell
- declared (1 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
websocket-payload.ts
eval(script: string, numberOfKeys: number, ...arguments_: string[]): Promise<unknown>;
ENV VITE_API_URL=http://127.0.0.1:3001
ENV VITE_API_URL=http://127.0.0.1:3001
ENV VITE_MCP_URL=http://127.0.0.1:3002
const BYTE_ORDER_MARK = "";
KEEPER_TEST_DATABASE_URL: postgres://postgres:postgres@localhost:5432/postgres
MIGRATION_TEST_DATABASE_URL: postgres://postgres:postgres@localhost:5432/postgres
| Postgres | 5432 | `postgresql://postgres:postgres@localhost:5432/postgres` |
DATABASE_URL=postgres://keeper:keeper@postgres:5432/keeper
DATABASE_URL: postgres://keeper:keeper@postgres:5432/keeper
const SECRET = "test-secret-for-microsoft-sign-in-account-linking";
const SECRET = "test-secret-for-abandoned-unverified-registration-reclaim";
const SECRET = "test-secret-for-outlook-sign-in-email-verification";
const SECRET = "test-secret-for-provider-asserted-email-not-reclaimable";
secret: "test-secret-value-for-signup-reclaim-ownership",
streamable-http
.gitmodules
.oxlintrc.json
.eslintrc.cjs
.env.template
.env.template
websocket-payload.test.ts
eval(script: string, numberOfKeys: number, ...arguments_: string[]): Promise<unknown>;
eval(script: string, numberOfKeys: number, ...arguments_: string[]): Promise<unknown>;
Gates applied: no_behavioural_pass.
2fc93464d952full audit observations/trust-audit/mcp-server/ridafkih__keeper-1.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-25 | 2fc93464d952 | BLOCK | F | 40 | first audit |
Questions
What is the Keeper MCP server?
Calendar sync tool & universal calendar MCP server. Aggregate, sync and control calendars on Google, Outlook, Office 365, iCloud, CalDAV or ICS.
What tools does Keeper expose?
2 in total: 2 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Keeper safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (40/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does Keeper need?
No credential environment variables were found in its source, so it appears to need none.
How does Keeper run?
It speaks streamable-http, so it runs as a service you connect to over the network. It is published on npm as @keeper.sh/worker.
How current is this page?
The grade is for one exact copy of the source (2fc93464d952), read on 2026-09-25. The repository is watched and re-audited when it changes.