Install
$ agentstack add mcp-dominik1001-carddav-mcp β scanned Β· β verified β works with Claude Code, Cursor, and more.
Security review
β PassedNo issues found. Passed automated security review. Β· v0.1.0 How review works β
- β Prompt-injection patterns
- β Secret / credential exfiltration
- β Dangerous shell & filesystem operations
- β Untrusted network calls
- β Known-malicious package signatures
What it can access
- β Network access Used
- β Filesystem access No
- β Shell / process execution No
- β Environment & secrets Used
- β Dynamic code execution No
From automated source analysis of v0.1.0. βUsedβ means the capability is present in the source β more access means more to trust, not that itβs unsafe.
About
carddav-mcp
π A CardDAV Model Context Protocol (MCP) server to expose contacts and address books as tools for AI assistants.
[](https://github.com/dominik1001/carddav-mcp/actions/workflows/release.yml) [](https://www.npmjs.com/package/carddav-mcp) [](https://choosealicense.com/licenses/mit/) [](https://modelcontextprotocol.io) [](https://github.com/semantic-release/semantic-release)
β¨ Features
- Connect to CardDAV servers
- List address books
- List contacts in an address book
- Get the full details of a single contact
- Create contacts (vCard)
- Update contacts β partial updates that preserve vCard properties written by other clients
- Delete contacts by UID
Setup
{
"mcpServers": {
...,
"contacts": {
"command": "npx",
"args": [
"carddav-mcp"
],
"env": {
"CARDDAV_BASE_URL": "",
"CARDDAV_USERNAME": "",
"CARDDAV_PASSWORD": ""
}
}
}
}
Development
Quick Start
Run the MCP server in development mode with auto-reload:
npm run dev
This will run the TypeScript code directly with watch mode and automatically load environment variables from .env.
Manual Build
Alternatively, you can compile TypeScript to JavaScript and run it:
- Compile:
npx tsc
- Run:
node dist/index.js
Available Tools
list-address-books
List all address books returning both name and URL
Parameters: none
Returns:
- List of all available address books
list-contacts
List all contacts in the address book specified by its URL. Returns a summary per contact; use get-contact for full details.
Parameters:
addressBookUrl: string
Returns:
- A list of contacts, each containing
uid,fn(formatted name),emails, andphones
get-contact
Get the full details of a single contact in the address book specified by its URL
Parameters:
uid: string β Unique identifier of the contact to fetch (obtained from list-contacts)addressBookUrl: string
Returns:
- The contact's parsed fields (
uid,fn,name,emails,phones, and optionallyorg,title,note) plus the raw vCard invcard
create-contact
Creates a contact (vCard) in the address book specified by its URL. If name is omitted, structured name parts are derived from fn.
Parameters:
addressBookUrl: stringfn: string β Formatted display name of the contactname: object (optional) β Structured name parts (family, given, middle, ...)family: string (optional)given: string (optional)middle: string (optional)prefix: string (optional)suffix: string (optional)emails: array of string (optional)phones: array of string (optional)org: string (optional) β Organization / companytitle: string (optional) β Job title or rolenote: string (optional)
Returns:
- The unique ID of the created contact
update-contact
Updates an existing contact in the address book specified by its URL. Only provided fields are changed; emails and phones replace the full list (pass an empty array to clear them, or an empty string to clear org, title, or note). Other vCard properties are preserved.
Parameters:
uid: string β Unique identifier of the contact to update (obtained from list-contacts)addressBookUrl: stringfn: string (optional)name: object (optional)family: string (optional)given: string (optional)middle: string (optional)prefix: string (optional)suffix: string (optional)emails: array of string (optional)phones: array of string (optional)org: string (optional)title: string (optional)note: string (optional)
Returns:
- The unique ID of the updated contact
delete-contact
Deletes a contact in the address book specified by its URL
Parameters:
uid: string β Unique identifier of the contact to delete (obtained from list-contacts)addressBookUrl: string
Returns:
- Confirmation message when the contact is successfully deleted
Smoke Tests
Two complementary end-to-end checks against a real CardDAV server (both read credentials from .env):
npm run smokeβ deterministic SDK harness (scripts/smoke.ts). Spawns the built server over stdio via the MCP client SDK and asserts the create β list β get β update β delete contact round-trip.npm run smoke:agentβ agent-ergonomics harness (scripts/smoke-agent.sh). Drives the server viaclaude -pwith a JSON output schema, validating that tool names, descriptions, schemas, and error messages are usable by an LLM.
License
Source & license
This open-source MCP server is cataloged on AgentStack and links to its original source β we do not rehost the code.
- Author: dominik1001
- Source: dominik1001/carddav-mcp
- License: MIT
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet β be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.