Skip to content
MCP server

ainote

By seunghan91All Ainote servers

Agent-native notes, tasks, dev-docs, vaults, sync & handoffs. MCP + OpenAPI dual surface.

Listed on

First seen 2 Oct 2026. One server, whatever directories list it: each directory listing keeps its own page and history.

2
Directories
1 via MCP Toplist
34
Tools
From an anonymous probe
-
ToolBench grade
Not graded by Arcade
-
GitHub stars
No repository data

Tools

ToolDescriptionBehaviour
assumption_writeCreate or update an assumption under a project (L2 intent layer). Omit `id` to create, pass it to update. There is no delete tool. πŸ”΄ `verdict` is REJECTED with an error if passed β€” verdict is confirmed only through a human judgment decision (see judgment_submit). This tool can only shape the assumption itself: what is being assumed, how critical it is, and what evidence would settle it. Destructive
delete_dev_docSoft-delete a dev document by title or UUID. Reversible from trash. Pass `category` when multiple docs share the same title across subcategories (memory/claude/cursor/env/docs).Destructive
delete_taskSoft-delete a task by ID. Destructive but reversible within 30 days (TaskCleanupJob purges trash daily at 2am KST). Returns 404 if the task does not exist or is not owned by the authenticated user.Destructive
dev_doc_writeCreate or update a dev doc. action: create | update. Deletion is a separate tool (delete_dev_doc). (consolidated surface β€” same handlers as the legacy tools) Required per action β€” create: title, content | update: content.Destructive
dev_docs_readRead dev docs. action: get | list | categories | pull (consolidated surface β€” same handlers as the legacy tools)Read-only
env_sync_readRead env-sync state. action: devices | drift | status | txn_pull. Secret reads are a separate tool (env_sync.secret_pull). (consolidated surface β€” same handlers as the legacy tools)Read-only
env_sync_txn_pushIngest a batched envelope of client-recorded env_sync mutations. HLC-skew gated, partial-success on conflict.Destructive
env_sync_txn_rollbackInverse-apply a prior env_sync transaction. Safety gates: ownership, idempotency, descendant-conflict (force opt-out).Destructive
env_sync_writeNon-destructive env-sync writes. action: enroll | request_share | heartbeat. Secret push/rotate are separate tools. (consolidated surface β€” same handlers as the legacy tools) Required per action β€” enroll: alias, age_pubkey, enrollment_token | request_share: target_device_id, secret_shares, device_id | heartbeat: device_id, installed_skills_hash, installed_hooks_hash.Changes data
env_sync.secret_pullPull an encrypted secret blob. Response is ciphertext_b64 only β€” server never sees and never returns plaintext.Read-only
env_sync.secret_pushPush a new client-encrypted secret. Ciphertext only β€” server never sees plaintext. Recipients must include the pushing device's own pubkey.Changes data
env_sync.secret_rotateRotate a secret: soft-delete the old node, create a new live node with the same alias and the new ciphertext+recipients. 7-day grace before hard delete of old ciphertext bytes.Destructive
get_setup_guideGet instructions for setting up AI Note MCP in Claude Desktop, Cursor, or other MCP clients. No authentication required.Read-only
graph_readRead knowledge-graph nodes. action: get | list (consolidated surface β€” same handlers as the legacy tools)Read-only
graph_soft_deleteSoft-delete an env_sync graph node (sets deleted_at; .live scope hides it from reads). Idempotent β€” re-deleting a deleted node is a no-op success.Destructive
graph_writeAdd or update a graph entity. action: add | update. Deletion is a separate tool (graph_soft_delete). (consolidated surface β€” same handlers as the legacy tools) Required per action β€” add: node_type, alias, payload, device_id | update: node_id, device_id, field_updates.Destructive
handoff_readRead session handoffs. action: get | list (consolidated surface β€” same handlers as the legacy tools) Required per action β€” get: project, topic.Read-only
handoff_saveSave a session handoff note for cross-device / cross-session continuation. Stored at handoffs/{project}-{topic}-{YYYY-MM-DD}.txt in the user's primary vault. Use the optional `time` param (HHMM, KST) to disambiguate multiple handoffs saved on the same day β€” it is appended to the topic slug (e.g. topic='phase-d', time='1555' β†’ handoffs/{project}-phase-d-1555-{date}.txt).Destructive
judgment_listList the authenticated user's own judgments (L3 layer) β€” use this to check your own blocking status (risk_tier 1 pending = execution blocked). Default order matches the /command queue: risk_tier ascending, then arrival order.Read-only
judgment_submitRequest a human judgment (L3 layer) by attaching evidence β€” approval, evidence, or verdict. This is the ONLY door an agent has into the judgment queue. πŸ”΄ `decision` is REJECTED with an error if passed β€” judgments are always created with decision='pending'. Only a human decides them (from the /command queue). Use judgment_list afterwards to check whether this judgment has since been decided. risk_tier controls urgency: 1=destructive (blocks execution until decided), 2=reversible (may auto-proceed after a wait window), 3=informational (auto-expires after 24h). Changes data
list_papersList notes/papers from AI Note. Supports keyword search across title and content, category filtering, pagination, and sorting. Returns id/title/content_preview/category_id/created_at. Use this when the user asks 'find my note about X', 'what did I write on Y', or wants to search their knowledge base.Read-only
memory_readRead agent memory. action: get | search (consolidated surface β€” same handlers as the legacy tools) Required per action β€” get: source | search: query.Read-only
project_readList the authenticated user's projects (L2 intent layer), or fetch one by id. Each entry includes riskiest_assumption β€” the single highest-priority unverified assumption (or, if all are verified, the highest-criticality one).Read-only
project_writeCreate or update a project (L2 intent layer). Omit `id` to create, pass it to update. There is no delete tool β€” use status: 'archived' to retire a project.Destructive
sync_audit_layer5Record the result of a client-side Layer 5 codex review (sync.py merge gate) as a vault_events row. Body of the review is NOT stored β€” only an HMAC digest of the summary so operators can correlate without exposing review content. Opt-in: server skips writes (still returns success) unless ENV['AINOTE_LAYER5_AUDIT']='on' AND a versioned HMAC secret is configured. Used by the sync.py SessionStart hook + merge command to surface 'why was this blocked?' across multi-PC sessions.Changes data
sync_deleteDelete a file from the primary vault. Optional CAS via base_sha to detect concurrent multi-PC writes. Protected paths (global/memory/, global/skills/, global/planning/, global/intent/, global/claude-config/, handoffs/) require base_sha or explicit force:true (audited). Idempotent: deleting a non-existent path returns success with deleted:false.Destructive
sync_pushPush a markdown file into the primary vault. Optional CAS via base_sha to detect concurrent multi-PC writes (Layer 3 of multi-PC sync plan). WAF-bypass tip: large bodies (~10KB+) that get false-positive blocked at Cloudflare can be sent via `content_b64` (base64-encoded) OR `content` prefixed with `__B64__:` instead. When the push CREATES a new .md file, the response may carry `dedup_candidates` β€” existing memory files that look similar (keyword + title similarity, no LLM). It is an advisory, not a rejection: YOU decide to merge into one of them (re-push that path), drop this write as a duplicate (skip), or keep it as a new memory (store).Destructive
sync_push_batchPush MANY files into the primary vault in ONE call. Use this instead of looping sync_push whenever you have more than a couple of changed paths β€” the cost of sync_push is round trips, not bytes. Per-item semantics are identical to sync_push (Layer 3 base_sha CAS, superseded contract, content_b64 WAF fallback). Partial success is normal and returns HTTP 200: read `results[]` and match entries by `path`, NOT by position. A conflict result always carries `remote_sha` + `conflict_reason` so you can go straight to sync_merge. Request-level failures (duplicate paths in one batch, idempotency key reused with a different payload, >200 items, >4MB) return 4xx and apply NOTHING. Each item MUST carry `content_sha` (SHA1 hex of the decoded body, same algorithm as git_sha) β€” it powers both the integrity check and the retry-safe `skipped_identical` result. Newly created .md items may carry `dedup_candidates` (same merge/skip/store advisory as sync_push); a batch creating more than 10 new files skips the check entirely and reports `dedup_skipped: "bulk"`.Destructive
sync_readRead-only vault sync operations. action: list | pull | diff | merge | conflicts. Writes (push/delete) are separate tools β€” they carry CAS semantics. (consolidated surface β€” same handlers as the legacy tools) Required per action β€” diff: path | merge: path, base_text, local_text.Read-only
task_writeCreate or update a task. action: create | update. Deletion is a separate tool (delete_task). (consolidated surface β€” same handlers as the legacy tools) Required per action β€” create: content | update: id.Destructive
tasks_readRead tasks and task categories. action: tasks | categories (consolidated surface β€” same handlers as the legacy tools)Read-only
vault_createCreate a new private vault as a GitHub repository under the user's account. Requires the user to have completed the GitHub App install flow first.Changes data
vault_readRead vault metadata. action: list | clone | status (consolidated surface β€” same handlers as the legacy tools) Required per action β€” clone: name.Read-only
vault_syncWrapper around vault file sync. action=list|pull|push to work against the primary vault. list/pull are paginated β€” narrow with `path`/`since` and follow `next_cursor` instead of pulling the whole vault. For push: WAF-bypass via `content_b64` or `content: '__B64__:...'` prefix (mirrors sync_push).Destructive

Directory listings

DirectoryListingTierFirst seen
Official MCP Registryio.github.seunghan91/ainote-2 Oct 2026
PulseMCPListed there according to MCP Toplist’s dataset; not collected by InvokeRank.
ainote MCP server | InvokeRank