
WWDC MCP
io.github.jabbertones-cloudv0.2.1更新于 Oct 7, 2026
Apple developer intelligence for agents: WWDC26, docs, HIG, Swift, App Review, and app audits.
概览
为编码助手提供本地只读的 Apple 开发者资料索引,涵盖 WWDC 会议、文档、HIG、Swift Evolution 与 App Review 指南。
- 功能
- 将 WWDC20–WWDC26 会议、Apple 开发者文档、教程、人机界面指南、Swift Evolution、The Swift Programming Language 以及 App Store 审核指南索引到本地 SQLite 搜索层。提供 45 个只读工具,用于搜索、文字记录、API 可用性与弃用历史、示例代码、App Review 指南以及有来源依据的应用审计。主推入口 swift_app_audit 会结合 WWDC、HIG、教程与 Swift Evolution 证据,用于仓库级工作。
- 适用场景
- 当助手编写或审查 Swift 与 Apple 平台代码,需要当前 Apple 指南而非过时训练数据时适用。适合回答框架有何变化、某 API 何时引入或弃用、某场 WWDC 讲了什么,或某功能是否符合 App Review 规则。
- 运行要求
- 本地进程:需要 Node.js 22.14 或更高版本以及 npm。查询前须先用 ingest 命令构建索引。可选的本地语义重排会在首次使用时下载 ONNX 嵌入模型。apple_doc_lookup 会实时请求 Apple 文档网络。不需要 Apple 账号凭据。
安装
在 SourceWeft 中
- 打开 控制台中的 WWDC MCP,将其添加到工作区。
- 为需要使用其工具的对话启用该服务。
Desktop only,通过 STDIO。 STDIO 服务会启动本地进程,因此需要 SourceWeft 桌面宿主。
其他 MCP 客户端
参照 仓库 中的启动说明。
README
WWDC MCP — current Apple developer knowledge for coding agents
Ground Codex, Claude, Cursor, VS Code, Windsurf, Zed, and other MCP clients in Apple source material before they change your Swift code.
WWDC MCP indexes WWDC20–WWDC26 sessions, Apple Developer Documentation, tutorials, Human Interface Guidelines, Swift Evolution, The Swift Programming Language, and App Store Review Guidelines into a local SQLite search layer. It exposes 45 read-only MCP tools for search, API history, deprecations, transcripts, source-grounded app audits, and trust metadata.
[CI] [License: MIT] [Node] [MCP] [MCP Registry]
Unofficial community project. Not affiliated with or endorsed by Apple. Apple content remains subject to Apple's terms and source-site availability.
Pick your path
I just want my coding agent to use Apple knowledge
- Install/connect WWDC MCP using the MCP Registry/MCPB release or the client config below.
- Ask: “Use WWDC MCP to audit this app against current Apple guidance before changing code.”
- Let the agent start with
swift_app_audit; you do not need to learn all 45 tools.
I am a power user
Use the focused tools directly for transcripts, API history, HIG, Swift Evolution, App Review, source freshness, and trust metadata. See Agent Guide for recommended tool chains and prompt recipes.
I am an agent working in this repository
Read AGENTS.md first. Client-specific repository instructions are also provided for Cursor and GitHub Copilot.
Why use it?
Coding agents are excellent at writing Swift, but Apple APIs, platform guidance, App Review rules, and WWDC recommendations change quickly. WWDC MCP gives an agent a source-grounded way to answer questions like:
- “What changed in SwiftUI at WWDC26, and which changes matter to this app?”
- “Audit this StoreKit subscription flow against current Apple guidance.”
- “When was this API introduced, is it deprecated, and what replaces it?”
- “Find the exact WWDC chapter that explains this App Intents behavior.”
- “Compare WWDC25 and WWDC26 coverage of Foundation Models.”
- “Check App Store Review Guideline 3.1.1 before I ship.”
- “Audit this macOS app for current SwiftUI, AppKit, concurrency, accessibility, and App Store guidance.”
The promoted entry point for repo-level Apple work is swift_app_audit. The promoted trust entry point is wwdc_security_manifest.
Start here: three high-value workflows
You do not need to learn 45 tool names first. Start with the job you are trying to finish:
- Modernize an Apple app: call
swift_app_auditwith the repo's actual feature/API/problem, then follow its evidence into the focused WWDC, HIG, documentation, and API tools. - Answer “what changed?”: use
wwdc_what_changedorwwdc_searchwith a framework/API and a year range, then open the strongest session/transcript evidence. - Check shipping risk: search
appstore_guidelines_search, API availability/deprecation tools, andwwdc_ingest_statusbefore treating a recommendation as current.
The server instructions teach connected agents this routing automatically; the catalog remains available when you need a narrower source.
What makes this different?
- WWDC26-aware — the default ingest range is 2020–2026 and can be extended with
--year. - Source-grounded app audits —
swift_app_auditcombines WWDC, HIG, tutorials, Swift Evolution, pathways, Apple doc hints, caveats, and validation steps. - API intelligence — availability, deprecation, replacement, introduction history, and WWDC mentions.
- Transcript-native — search complete session transcripts, read them in chunks, and generate timestamped deep links.
- Local-first — SQLite + FTS5 plus optional local ONNX semantic reranking; no separate embedding service or paid API is required for core search.
- Trust-aware — conservative judgment metadata, a content-safety tripwire, and a security manifest help agents distinguish evidence from instructions.
- Two transports — stdio by default, plus authenticated stateless Streamable HTTP for remote/self-hosted use.
- Public-directory ready transport — remote deployments can explicitly set
WWDC_MCP_PUBLIC_READ_ONLY=1to allow anonymous access to the same read-only tool surface; without that flag or bearer auth, HTTP fails closed. - Read-only MCP surface — the 45 tools retrieve and analyze source material; they do not mutate your Apple account or source repo.
Install-path scorecard
Choose the path that matches what you value. Do not confuse “local-first” with “everyone must self-host.”
When the hosted endpoint is live, the intended public URL is:
For ChatGPT/custom remote MCP clients, that removes the local Node/index/config-path requirement. For Cursor, the same remote URL can be placed in mcp.json and can later back a one-click install/deeplink. Local stdio remains a first-class option rather than a fallback.
Friction budget
A newcomer should be able to reach the first source-grounded answer with as few decisions as possible:
- hosted: connect URL → ask the 60-second check;
- Registry/MCPB: install → ask the 60-second check;
- local: install → ingest → configure → ask the 60-second check.
If a new distribution method adds steps before the first useful answer, treat that as an adoption regression unless it buys a clear privacy/security capability.
Local-first quick start
Use this path when you want the corpus and server on your own machine. For hosted/Registry paths, use the scorecard above.
Requirements
- Node.js 22.14 or newer
- npm
Distribution status (October 7, 2026): the official MCP Registry namespace is
io.github.jabbertones-cloud/wwdc, distributed through a GitHub-hosted MCPB release asset. v0.2.1 is the current patch line. npm publication is optional secondary distribution and is not required for Registry or Cursor installs.
1. Clone and build
The release package exposes two executables:
Run the immutable GitHub release package directly:
Clients that support MCP Bundles can use the WWDC-MCP-v0.2.1.mcpb asset from the GitHub v0.2.1 release / official MCP Registry.
2. Build a useful local index
For the full core corpus:
For a faster WWDC26-first setup:
ingest:all covers the core sources: WWDC, tutorials, pathways, HIG, Swift Evolution, Apple docs, Swift Book, and App Store Review Guidelines. Additional optional enrichment sources are documented below.
3. Prove it works before wiring your client
That exercises parser/security checks, all 45 tools over stdio, search regressions, package metadata, and authenticated Streamable HTTP.
4. Add it to an MCP client
Generic stdio configuration:
Then ask your agent:
Use WWDC MCP to audit this app against current Apple guidance before changing code.
Make your agent use it automatically
The highest-leverage setup is a short repository instruction so the agent reaches for WWDC MCP without being reminded every prompt:
Ready-made versions are included in AGENTS.md, Cursor rules, and GitHub Copilot instructions.
60-second connection check
After connecting the server, ask your client to:
A healthy setup should be able to see the wwdc server, call its tools, and return source-grounded results. For repository-level work, follow with:
Remote HTTP deployment modes
The HTTP transport is deliberately fail-closed by default.
Private/self-hosted bearer mode:
Explicit anonymous read-only mode for a public MCP directory/connector:
In public mode, the MCP endpoint exposes the existing 45 read-only tools without requiring a shared bearer token. This mode is opt-in. If neither bearer authentication nor WWDC_MCP_PUBLIC_READ_ONLY=1 is configured, /mcp returns 503 auth_not_configured.
For an internet-facing deployment, put the server behind TLS/reverse-proxy controls, keep the corpus/source policy unchanged, and monitor/rate-limit at the edge. The repo does not claim a hosted public endpoint until one is independently deployed and verified.
Client setup
OpenAI Codex
Codex CLI and the Codex IDE extension share MCP configuration. Add this to ~/.codex/config.toml:
Verify the server appears with:
For reliable tool selection, add a project rule such as this to AGENTS.md:
Claude Desktop
~/Library/Application Support/Claude/claude_desktop_config.json
Claude Code
Use your normal MCP configuration flow and point the server command at:
VS Code
.vscode/mcp.json:
Cursor
~/.cursor/mcp.json:
Windsurf
~/.codeium/windsurf/mcp_config.json:
Zed
.zed/settings.json:
Documentation map
Apple sources
The core index can include:
Most query tools read from the local SQLite index. apple_doc_lookup is intentionally a live Apple Developer Documentation lookup and therefore uses the network.
45 read-only MCP tools
Search and discovery
wwdc_search,apple_search_allwwdc_list_years,wwdc_list_topics,wwdc_list_sessionswwdc_topics_by_year,wwdc_speaker_search,wwdc_what_changedwwdc_list_pathways,wwdc_get_pathway
Sessions, transcripts, and sample code
wwdc_get_session,wwdc_session_summary,wwdc_related_sessionswwdc_transcript_search,wwdc_session_transcript_fullwwdc_session_deep_linkwwdc_list_session_code,wwdc_sample_code_list,wwdc_sample_code_grep
Apple docs, HIG, Swift, and forums
apple_doc_lookup,apple_doc_get,apple_doc_list_frameworkapple_tutorial_getapple_hig_search,apple_hig_listapple_swift_book_getapple_swift_evolution_get,apple_swift_evolution_list,apple_swift_evolution_filterswift_forum_search,apple_forum_search
API and App Store intelligence
wwdc_find_api_introduction,wwdc_sessions_for_apiapple_api_availability,apple_api_deprecation,apple_what_replacedapple_release_notes_searchappstore_guidelines_search,appstore_guideline_get
Audit, graph, status, and trust
swift_app_auditapple_swift_pattern_find,apple_cross_referenceswwdc_ingest_status,wwdc_export_statuswwdc_security_manifest
The test suite asserts that both stdio and Streamable HTTP expose exactly 45 tools.
Search example
wwdc_search supports year ranges, topics, platforms, transcript requirements, output detail, and conservative judgment metadata.
Platform-only queries such as “macOS” intentionally receive conservative judgment. Better audit queries name a framework, API, feature, symptom, or goal.
Ingest
Core sources
Restrict WWDC years by repeating --year:
Optional enrichment
session-summaries is the one optional enrichment lane that uses an external model API. It runs only when ANTHROPIC_API_KEY is set, sends bounded WWDC session metadata/transcript excerpts to Anthropic, and may incur API cost. Core ingest, search, audits, and local semantic reranking do not require that key.
During WWDC week, re-run the WWDC ingest periodically to pick up newly published sessions.
Local semantic search — no Ollama required
FTS5 keyword search works immediately. When semantic reranking is enabled, WWDC MCP lazily loads nomic-ai/nomic-embed-text-v1.5 through @huggingface/transformers and runs the ONNX model locally. The model is cached under ~/.cache/huggingface/hub; the first semantic use may need network access to download model files.
If the model cannot initialize, search falls back to FTS5 for that process. To force keyword-only behavior:
Local/index configuration
Remote Streamable HTTP
Stdio remains the default and simplest local transport. The same 45-tool server can also run as a stateless Streamable HTTP MCP in either private bearer-authenticated mode or an explicitly enabled public read-only mode.
Private bearer-authenticated mode
Routes:
GET /healthzPOST /mcp
For a deliberately public, read-only connector endpoint:
The MCP route fails closed with 503 auth_not_configured unless either bearer authentication is configured or WWDC_MCP_PUBLIC_READ_ONLY=1 is explicitly enabled. Public mode does not add write capabilities: it exposes the same 45 read-only tools.
To mount the service behind a shared reverse proxy without path rewriting:
Routes become /wwdc/healthz and /wwdc/mcp.
The built-in HTTP server does not terminate TLS. If you expose it outside localhost, put it behind a TLS edge/reverse proxy, rate-limit and monitor it, and treat bearer tokens as secrets.
Hosted public endpoint
A Cloudflare-backed public endpoint is being prepared at:
It will be marked live here only after the deployed endpoint passes health, MCP initialize, tool-catalog, and source-grounding verification. Until then, use the GitHub release/MCP Registry or self-hosted modes above.
See docs/DEPLOY.md for the full runbook.
Trust and security model
- All 45 MCP tools are read-only.
- Retrieved web text is treated as untrusted evidence, not executable instruction.
- Search responses can include
content_safetymetadata. wwdc_security_manifestreports the canonical tool surface, manifest hash, read-only posture, and prompt-injection handling.- Remote HTTP fails closed by default. Private mode requires bearer authentication; anonymous access exists only when the operator explicitly enables
WWDC_MCP_PUBLIC_READ_ONLY=1. - The default stdio server opens no network listener.
- Ingest fetches public Apple/Swift sources.
apple_doc_lookupperforms live public Apple documentation requests. - Local semantic reranking uses a Hugging Face Transformers/ONNX model and may download its model files on first use.
- Optional
session-summariessends bounded session metadata/transcript excerpts to Anthropic only whenANTHROPIC_API_KEYis explicitly configured. - No Apple Developer account credentials are required or stored.
For vulnerability reporting and deployment cautions, see SECURITY.md.
Tests and release proof
npm test covers smoke tests, ingest parsing, security evaluation, stdio MCP E2E, search regression, package smoke, and Streamable HTTP MCP E2E.
The protocol tests verify the 45-tool catalog and exercise the trust manifest over both supported transports.
Architecture
- Runtime: Node.js >=22.14, TypeScript
- Default transport: MCP stdio
- Optional transport: authenticated stateless Streamable HTTP
- Storage: SQLite + FTS5
- Semantic reranking: local
nomic-ai/nomic-embed-text-v1.5via Hugging Face Transformers/ONNX - Response budget: bounded tool responses, with compact envelopes for oversized JSON
- Ingest: public Apple/Swift sources with bounded concurrency, retries, and a stable User-Agent
- Safety: content-safety metadata, read-only tool contract, security manifest, fail-closed remote auth
Public project docs
- CHANGELOG.md — implementation and release history
- CONTRIBUTING.md — contribution workflow
- SECURITY.md — security model and vulnerability reporting
- docs/DEPLOY.md — stdio and remote deployment
- docs/RELEASING.md — npm + MCP Registry release checklist
- docs/SOURCE-OF-TRUTH.md — repository truth and verification rules
- docs/SKILL-WIRING.md — agent/skill integration guidance
- docs/APPLE-ENDPOINTS.md — ingest-maintainer notes
From Apple guidance to App Store execution
WWDC MCP is intentionally read-only: it helps your agent understand current Apple APIs, design guidance, platform changes, and App Review requirements without holding App Store Connect credentials.
When the research is done and you need to execute the release workflow, AiSCent is the companion product: App Store Connect automation for release operations such as localization, screenshots, metadata, TestFlight readiness, and submission workflows.
A useful agent workflow:
- Ask WWDC MCP to audit the app against current Apple guidance.
- Fix the code and UX with source-grounded evidence.
- Use AiSCent for the App Store Connect work needed to get the build ready to ship.
WWDC MCP = know what Apple expects. AiSCent = help get the release through App Store Connect.
Contributing
Issues and PRs are welcome. If you change the MCP tool surface, ingest behavior, transport behavior, or public claims, update the matching tests and docs in the same change.
See CONTRIBUTING.md.
License
MIT
来源:README.md,提交 ed1c605
工具
0版本历史
1- v0.2.1最新Oct 7, 2026


