ReMarkableCAUTION
MCP server for accessing reMarkable tablet data - sync files, extract text from highlights, and browse your reMarkable cloud
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Access a reMarkable library from MCP clients such as Claude, VS Code Copilot, OpenWebUI, and other compatible tools.
Features
- Browse folders and recent documents.
- Search names, tags, and extracted text.
- Read typed text, PDF and EPUB text, highlights, and annotations.
- Render notebooks and annotated PDFs as PNG or SVG.
- Export one document as a complete PDF or sectioned Markdown resource.
- Run handwriting OCR through Google Vision or Tesseract.
- Upload files and manage folders in supported transports.
- Render Markdown as PDF and upload it to the tablet.
- Open an interactive canvas in clients that support MCP Apps.
- Serve MCP over stdio or local Streamable HTTP.
- Serve MCP
2026-07-28and every earlier SDK-supported revision from one
stable SDK 2.x MCPServer.
Quick Install
Prerequisite: install uv
The commands below use uvx, which is included with `uv`. Page images are rasterized with PyMuPDF; no system Cairo, browser, or graphics runtime needs to be installed on macOS, Linux, or Windows.
macOS and Linux
Use the official standalone installer:
curl -LsSf https://astral.sh/uv/install.sh | sh
Or install with Homebrew:
brew install uv
Windows
Use the official standalone installer from PowerShell:
powershell -ExecutionPolicy ByPass -c "irm https://astral.sh/uv/install.ps1 | iex"
Or install with WinGet:
winget install --id=astral-sh.uv -e
Choose a connection
Start with the first mode that fits your setup.
5cafe21b6245OBSERVED · 2026-10-06Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add remarkable-mcp --env REMARKABLE_TOKEN=${REMARKABLE_TOKEN} -- None remarkable-mcp==0.1.0Exposed tools (14)
11 read · 3 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
my_tool | read | if client_supports_elicitation(ctx): |
remarkable_browse | read | |
remarkable_canvas | read | |
remarkable_export | read | |
remarkable_image | read | |
remarkable_markdown_to_pdf | read | |
remarkable_mkdir | read | |
remarkable_move | write | |
remarkable_read | read | |
remarkable_recent | read | |
remarkable_rename | write | |
remarkable_search | read | |
remarkable_status | read | |
remarkable_upload | write |
Trust audit
CAUTIONgrade C · trust 79/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | FAIL |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (5 observation(s))
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (16)
- **Advanced users:** SSH — Fastest, but requires developer mode enabled
client = SSHClient(key_path="~/.ssh/id_ed25519")
expected_key = os.path.expanduser("~/.ssh/id_ed25519")monkeypatch.setenv("REMARKABLE_SSH_KEY", "~/.ssh/rm_key")assert client.key_path == os.path.expanduser("~/.ssh/rm_key")"~/.ssh/remarkable",
filename="../../Unsafe?.pdf",
- The tablet should be accessible at `http://10.11.99.1`
Then add `http://127.0.0.1:8000/mcp` as the MCP server URL in OpenWebUI. The
proxy_pass http://127.0.0.1:8000;
Open a web browser and go to: [http://10.11.99.1](http://10.11.99.1)
# Change the USB host (default: http://10.11.99.1)
hasher.update(bytes.fromhex(entry["hash"]))
assert base64.b64decode(resource.contents[0].blob).startswith(b"%PDF")
| system `ssh` and `scp` | Direct tablet access; `sshpass` is optional for password auth |
curl -LsSf https://astral.sh/uv/install.sh | sh
Gates applied: instruction_override, no_behavioural_pass.
5cafe21b6245full audit observations/trust-audit/mcp-server/sammorrowdrums__remarkable-1.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-06 | 5cafe21b6245 | CAUTION | C | 79 | first audit |
Questions
What is the ReMarkable MCP server?
MCP server for accessing reMarkable tablet data - sync files, extract text from highlights, and browse your reMarkable cloud
What tools does ReMarkable expose?
14 in total: 11 read-only, 3 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is ReMarkable safe to connect to an agent?
With care. The audit graded it C (79/100) and found 16 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does ReMarkable need?
It reads GOOGLE_VISION_API_KEY, REMARKABLE_SSH_KEY, REMARKABLE_SSH_PASSWORD and REMARKABLE_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does ReMarkable run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on PyPI as remarkable-mcp.
How current is this page?
The grade is for one exact copy of the source (5cafe21b6245), read on 2026-10-06. The repository is watched and re-audited when it changes.