
MustDo
jp.ltngv0.1.0更新於 Oct 8, 2026
Read and write your MustDo (iOS alarm To-Do) tasks in your own iCloud via CloudKit.
概覽
讓助理透過 CloudKit 讀取和寫入你 iCloud 中的 MustDo(iOS 鬧鐘待辦)任務。
- 功能
- 提供列出、新增、更新、完成、延後提醒和軟刪除 MustDo 待辦的工具,以及取得帳號資訊(時區、預設鬧鐘時間等)的 get_me。重複待辦使用 iOS 行事曆風格的規則,以範本加每日 occurrence 的形式回傳。所有工具回傳 JSON,日期為 ISO 8601。僅本機提供 sign_in 工具處理 Apple 登入。
- 適用情境
- 當你希望助理管理與 MustDo iPhone 應用程式相同的鬧鐘待辦時使用,例如在聊天用戶端新增提醒、改期或標記完成。面向將任務保存在 iCloud 的 MustDo 使用者。
- 執行需求
- 可以使用 ltng.jp 上的託管中繼,作為自訂連接器加入,並用與 MustDo 應用程式相同的 Apple ID 登入;或在 macOS 本機執行,需要 Node.js 24 或更新版本、MustDo 應用程式至少同步過一次 iCloud,以及開發者目前未公開分發的 CloudKit API Token。本機設定使用 MUSTDO_CK_API_TOKEN 和 MUSTDO_CK_ENV,認證資訊保存在 ~/.mustdo/auth.json。
安裝
在 SourceWeft 中
- 開啟 儀表板中的 MustDo,將其新增到工作區。
- 為需要使用其工具的對話啟用該服務。
Web executable,透過 Streamable HTTP。 遠端服務在工作區中設定後即可從網頁執行環境執行。
其他 MCP 客戶端
把它新增到你客戶端的 mcpServers 設定中。
{
"mcpServers": {
"mustdo-mcp": {
"type": "http",
"url": "https://ltng.jp/api/mustdo/mcp"
}
}
}README
mustdo-mcp
MCP server for MustDo — the iOS To-Do alarm that keeps ringing until you do it.
It lets Claude (Claude Code, Claude Desktop, claude.ai, the Claude iPhone app) and any other Model Context Protocol client read and write your MustDo To-Dos.
- Your data stays in your iCloud. MustDo has no database of its own for To-Dos. They live in the
CloudKit private database of your Apple ID (container
iCloud.jp.lightning.mustdo, zoneMustDo). This server talks to Apple's CloudKit Web Services and reads/writes the same records as the iPhone app. - The developer never stores your To-Dos. Neither the local server in this repository nor the hosted relay (see below) keeps To-Do content on Lightning LLC servers.
- After a write, CloudKit pushes a silent notification to your iPhone, so the app updates right away.
Two ways to use it
A. Hosted relay — https://ltng.jp/api/mustdo/mcp
- claude.ai → Settings → Connectors → Add custom connector → URL
https://ltng.jp/api/mustdo/mcp(name it "MustDo"). - Click Connect. You will see a consent page on ltng.jp explaining what is stored, then Apple's sign-in page. Sign in with the same Apple ID you use in the MustDo app.
- Done. The same connector is available in the Claude iPhone app.
What the relay keeps, honestly:
- When you sign in, Apple issues a CloudKit sign-in token (
ckWebAuthToken). The relay stores this token encrypted with AWS KMS (AWS Tokyo region) so it can call CloudKit on your behalf on each request. - It also stores hashed OAuth access/refresh tokens for the connector itself.
- It does not store or log your To-Do content, your Apple ID email, your password, or your raw iCloud user ID.
- Disconnect: remove the connector in claude.ai and visit https://ltng.jp/api/mustdo/disconnect.
After confirming with your Apple ID, the stored token is deleted immediately. It is also deleted automatically
when Apple invalidates the sign-in (the tools then return
RECONNECT_REQUIRED; just reconnect).
Full write-up: https://ltng.jp/mustdo/mcp.
B. Run locally (stdio)
Requirements:
- macOS with Node.js 24 or newer
- The MustDo app installed and synced to iCloud at least once (the app creates the zone and the
Accountrecord) - A CloudKit API Token for the MustDo container. It is not currently distributed to the public — see "About the CloudKit API Token" below. Without it, use the hosted relay (A)
Register with Claude Code:
Or put the settings in ~/.mustdo/config.json and register without -e:
Then ask Claude to run the sign_in tool once. The server opens Apple's sign-in page in your browser,
listens on http://localhost:51234/callback, and saves the returned token to ~/.mustdo/auth.json (mode 0600).
About the CloudKit API Token
CloudKit Web Services needs two tokens on every request:
The API Token is container-wide and cannot be created by end users. Lightning LLC does not currently distribute it publicly, so running this server locally is not offered to general users — use the hosted relay (A). The code is published so that you can read exactly what the MCP server does with your data.
For reference, the token for the production environment has its Sign-in Callback set to
https://ltng.jp/api/mustdo/oauth/local-callback, which simply redirects back to http://localhost:51234/callback
without storing or logging anything.
Configuration
Environment variables win over ~/.mustdo/config.json.
auth.json is per environment; switching MUSTDO_CK_ENV requires another sign_in.
Apple expires the session after a while (CloudKit returns HTTP 421); tools then return NOT_SIGNED_IN and you run sign_in again.
Tools
All tools return JSON. Dates in output are ISO 8601 (UTC). Dates in input may be:
YYYY-MM-DD— that day at the account's default time (see below)YYYY-MM-DDTHH:mm— wall-clock time in the account's time zone- Full ISO 8601 with offset
Default time and omitted due
Each account has a default alarm time (Account.defaultTime, HH:mm, set in the app's settings; 09:00 if unset).
add_todowith nodue→ tomorrow (in the account's time zone) at the default time. Month/year boundaries and DST transitions follow the wall clock.due: "2026-10-10"→ that day at the default time.get_mereturnsdefaultTimeanddefaultDueNextso a client can tell the user when the alarm will ring.
Examples:
Repeat rules
Same vocabulary as the iOS Calendar app. Used as input to add_todo / update_todo and returned by list_todos.
Omitted fields take defaults (interval 1, weekdays [], monthly.mode dayOfMonth, end.kind never).
Ranges: interval 1–99, ordinal 1–5 or -1, weekday 1–7, count 1–999. Anything else → INVALID_ARGUMENT.
The legacy shape { "kind", "weekdays", "until" } is still accepted.
Expansion happens in the app, not here. list_todos returns the template plus occurrences
(per-day done / skipped / snooze). Range filtering only drops templates that definitely cannot
fire in range (first occurrence after the range, until before the range, weekly with no matching weekday).
Errors
Failures come back with isError: true and a body of { "code": "...", "message": "...", "details"?: {...} }.
Security model
- Access to your To-Dos is gated by your own Apple ID session (
ckWebAuthToken), issued by Apple's sign-in page. No one — including the developer — can read your private database without it. - The API Token only identifies the container and fixes where Apple may redirect after sign-in. Apple positions it as a client-side token (it is normally embedded in CloudKit JS web pages). By itself it grants no access to any user's private data.
- Locally, the session is stored in
~/.mustdo/auth.json(0600), logs go to stderr as JSON and never include tokens, and the sign-in listener binds to127.0.0.1/::1only. - On the relay, the session is encrypted with AWS KMS per user (envelope encryption with encryption context), OAuth tokens are stored only as peppered SHA-256 hashes, PKCE S256 is mandatory, refresh tokens rotate with reuse detection, and To-Do content is never written to storage or logs.
- Writes use CloudKit
recordChangeTag(optimistic locking) and retry once on conflict; deletes are soft. - Anything you find: see SECURITY.md.
Development
Layout:
dist/core.js (package exports) is the shared core consumed by the hosted relay: everything
except auth.ts, config.ts, index.ts and server.ts. Keep it free of anything that touches the
local file system or a browser.
License
MIT — Copyright (c) 2026 Lightning LLC. See LICENSE.
MustDo is a product of Lightning LLC. Apple, iCloud and CloudKit are trademarks of Apple Inc.
來源:README.md,提交 a2a0e0a
工具
0版本歷史
1- v0.1.0最新Oct 8, 2026
