NotebookLMBLOCK
Google NotebookLM over MCP + a local HTTP REST API. Citation-backed Q&A, audio/video/content generation, multi-account rotation. For Claude Code, Codex, Cursor, n8n, Zapier, Make.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Automate Google NotebookLM at scale. 33-endpoint HTTP REST API for n8n / Zapier / Make / curl, plus an MCP server for Claude Code / Cursor / Codex. Citation-backed Q&A, full Studio generation (audio · video · infographic · report · presentation · data table), multi-account rotation with auto-reauth across personal and Google Workspace accounts.
v3.2.0 — generated content can finally be deleted (content_delete): the endpoint had been declared and called by nothing since v3, so notebooks accumulated every draft ever asked for. Builds on 3.1.x, where generated content stopped coming back in the wrong language — the interface locale was overriding thelanguageargument on both transports, silently, while reporting success. Also: reading a source's full indexed text (source_read, paginated), working source labels, and RPC refusals reported as refusals instead of as a rotated endpoint id. Built on a dual transport — the internalbatchexecuteRPC API (10-100× faster than scraping, immune to UI rebrands) with the Playwright browser as an automatic fallback, both shipped permanently. Batch-tested on overnight runs of 1 000+ questions. See the changelog. Compare with `PleasePrompto/notebooklm-mcp` for when this project is the right pick (REST API, full Studio, auto-reauth).
Note (July 2026): Google rebranded NotebookLM to Gemini Notebook. It is the same product, existing links redirect, and this project drives the same underlying service — the browser path was updated for the new DOM in v2.3.0 and the RPC path in v3.0.0. Package and repository keep the notebooklm name.[](https://github.com/roomi-fields/notebooklm-mcp/actions/workflows/ci.yml) [
38 read · 9 write · 7 destructive. Blast radius: 7 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
Original | read | Keep this |
Test | read | Test notebook |
add_notebook | write | 🔌 [PROXY] Add notebook to library via HTTP server |
add_source | write | 🔌 [PROXY] Add source/document to notebook via HTTP server |
ask_question | read | Ask a question to NotebookLM |
auto_discover_notebook | read | 🔌 [PROXY] Auto-discover notebook metadata via HTTP server |
batch_to_vault | write | Run a list of questions against a notebook and persist each answer to disk as |
cleanup_data | read | 🔌 [PROXY] Cleanup server data via HTTP server |
close_session | read | 🔌 [PROXY] Close session via HTTP server |
complex_tool | read | A complex tool |
convert_note_to_source | read | Convert a note to a source document in NotebookLM.\n\n |
create_note | write | Create a note in the NotebookLM Studio panel.\n\n |
create_notebook | write | Create a notebook |
de_auth | destructive | 🔌 [PROXY] Logout (clear credentials) via HTTP server |
delete_content | destructive | Delete a generated Studio artifact (audio overview, video, report, infographic, |
delete_notebooks_from_nblm | destructive | Delete one or more notebooks directly from NotebookLM (UI-level deletion, |
delete_source | destructive | Delete a source from the current NotebookLM notebook.\n\n |
download_audio | read | 🔌 [PROXY] Download generated audio file via HTTP server |
download_content | read | Download or export generated content from NotebookLM.\n\n |
generate_audio | read | 🔌 [PROXY] Generate audio overview (podcast) via HTTP server |
generate_content | read | 🔌 [PROXY] Generate content via HTTP server.\n |
generate_mind_map | write | Generate and save a mind map from a notebook’s sources. RPC-backed (no browser). |
generate_study_aid | read | Generate a study aid from a notebook’s sources: flashcards or a quiz. |
get_health | read | Get server health |
get_library_stats | read | 🔌 [PROXY] Get library statistics via HTTP server |
get_note | read | Retrieve the full title and text content of a specific note in the NotebookLM Studio panel. |
get_notebook | read | 🔌 [PROXY] Get notebook details by ID via HTTP server |
list_content | read | 🔌 [PROXY] List sources and generated content via HTTP server |
list_notebooks | read | List all notebooks |
list_notebooks_from_nblm | read | 🔌 [PROXY] Scrape NotebookLM homepage to get real notebook list via HTTP server |
list_notes | read | List all user notes in the NotebookLM Studio panel. Returns note titles, IDs, and timestamps (e.g. details). |
list_sessions | read | 🔌 [PROXY] List active sessions via HTTP server |
list_sources | read | List the sources of a NotebookLM notebook, with their IDs and titles.\n\n |
manage_labels | destructive | Manage a notebook’s source labels (RPC-backed): list them, create one, or delete some. |
my-test-notebook | read | Three word name test. Works correctly. |
n8n-workflow-guide | read | ... |
notebook | read | Single word name test. Works correctly. |
re_auth | read | 🔌 [PROXY] Re-authenticate with different account via HTTP server |
read_source | read | Read a source’s full indexed content — the exact text NotebookLM reasons over, |
remove_notebook | destructive | 🔌 [PROXY] Remove notebook from library via HTTP server |
required | read | All required. Second. |
research_sources | read | Discover web sources for a notebook via NotebookLM Fast Research. RPC-backed. |
reset_session | destructive | 🔌 [PROXY] Reset session history via HTTP server |
retry-test | read | This notebook was discovered after retry. Success on second attempt. |
save_chat_to_note | write | Save the current NotebookLM chat/discussion to a note.\n\n |
search_notebooks | read | 🔌 [PROXY] Search notebooks via HTTP server |
select_notebook | write | 🔌 [PROXY] Set active notebook via HTTP server |
setup_auth | read | 🔌 [PROXY] Setup Google authentication via HTTP server.\n |
share_notebook | read | Read a notebook’s sharing status, or toggle its public link. |
test-name | read | Test description. Second sentence. |
test-notebook | read | This is a test notebook. It contains test data. |
too-many-words-in-name | read | Test description. Second sentence. |
update_notebook | write | 🔌 [PROXY] Update notebook metadata via HTTP server |
valid-name | read | Short description. Second sentence. |
Trust audit
BLOCKgrade F · trust 56/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | FAIL |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (4 observation(s))
- Network
- declared (9 observation(s))
- Shell
- declared (7 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (22)
deletedSourceName = await sourceElement.$eval(
const nameText = await el.$eval(
const titleText = await el.$eval(
const innerContent = await noteElement.$eval(
# NotebookLM MCP HTTP Server - E2E Test Report
$env:API_KEY="my-super-secure-secret-token"
de_auth, delete_content, delete_notebooks_from_nblm, delete_source, manage_labels, remove_notebook, reset_session
.nojekyll
'/root/.ssh/id_rsa',
'/app/data/../../../etc/passwd',
'../../../etc/passwd',
'/app/data/../../etc/shadow',
expect(() => resolveVaultDir('../../etc')).toThrow(/escape/i);import { CONFIG } from '../../src/config.js';curl http://192.168.1.52:3000/health
- **URL:** `http://192.168.1.52:3000/ask`
- URL: `http://192.168.1.52:3000/ask`
- URL: `http://192.168.1.52:3000/ask`
- URL: `http://192.168.1.52:3000/ask`
@modelcontextprotocol/sdk, cors, dotenv, env-paths, express, globby, otplib, patchright
@mdx-js/react, clsx, prism-react-renderer, react, react-dom, @types/react, typescript
The server descriptor read `process.env.npm_package_version`, which is only set
Gates applied: no_behavioural_pass.
28ef8087e99cfull audit observations/trust-audit/mcp-server/roomi-fields__notebooklm-3.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 28ef8087e99c | BLOCK | F | 56 | first audit |
Questions
What is the NotebookLM MCP server?
Google NotebookLM over MCP + a local HTTP REST API. Citation-backed Q&A, audio/video/content generation, multi-account rotation. For Claude Code, Codex, Cursor, n8n, Zapier, Make.
What tools does NotebookLM expose?
54 in total: 38 read-only, 9 that write, and 7 that can delete or overwrite (de_auth, delete_content, delete_notebooks_from_nblm, delete_source, manage_labels). Every one is listed on this page with its risk.
Is NotebookLM safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (56/100) and found 5 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 7 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does NotebookLM need?
It reads GH_TOKEN, GITHUB_TOKEN, LOGIN_PASSWORD and NBLM_ENCRYPTION_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does NotebookLM run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as website at 0.0.0.
How current is this page?
The grade is for one exact copy of the source (28ef8087e99c), read on 2026-10-07. The repository is watched and re-audited when it changes.