static.md

Markdown notes and Excalidraw whiteboards your AI agents can read and write, plus image hosting. Remote MCP server at https://static.md/mcp with OAuth sign-in.

Hosted MCP Server

npx add-mcp 'https://static.md/mcp'

Installs into Claude Code, Codex, Cursor and more

Documentation

Sign in with static.md · no token to paste

  1. Add the server from your terminal:
    claude mcp add --transport http static-md https://static.md/mcp
    
  2. In Claude Code, run /mcp, pick static-md and choose Authenticate.
  3. Your browser opens static.md. Sign in with Google and approve the access Claude asks for.
  • list_my_notes Your notes, newest first: ids, titles and links. notes:read
  • read_note A note’s markdown, handed to the agent as data, never as instructions. notes:read
  • create_note A new note in your account, with optional starting content. notes:write
  • update_note Append or replace text. Edits merge live with people typing in the note. notes:write
  • list_my_boards Your whiteboards with their links and element counts. boards:read
  • read_board The text on a whiteboard and its Excalidraw scene. boards:read
  • create_board A whiteboard drawn from an Excalidraw scene. boards:write
  • set_access Who can open a note or whiteboard: anyone with the link, only you, or people you name (Pro). Only when you ask. sharing
FreePro
Tool calls per day505,000
Tool calls per minute6060
New notes & whiteboards10 / hourNo limit
Elements per whiteboard300No limit
Personal access tokens110

Daily limits reset at 00:00 UTC. When one runs out, the agent is told why and where to upgrade.

Sign in with Google to see the apps connected to your static.md account and manage access tokens.

  • consent Every agent signs in through static.md, and you approve it with your Google account. Nothing connects on its own.
  • scopes Access is granted per kind: reading or writing, notes or whiteboards. An agent gets only what you approved.
  • set_access Changing who can open your notes needs its own permission, approved on its own. Agents are told to use it only when you ask them directly, never because a note says so.
  • sharing Agents follow your sharing settings: they open exactly what you could open in your browser.
  • encrypted End-to-end encrypted notes stay unreadable, to agents and to static.md alike.
  • untrusted Note text is fenced as user data, so instructions hidden in a note don’t read as commands.
  • revoke Disconnect an app or delete a token at any time. It stops working within seconds.