static.md
Markdown notes and Excalidraw whiteboards your AI agents can read and write, plus image hosting. Remote MCP server at https://static.md/mcp with OAuth sign-in.
View on static.mdTry this MCPSponsored
Hosted MCP Server
npx add-mcp 'https://static.md/mcp'Installs into Claude Code, Codex, Cursor and more
Documentation
Sign in with static.md · no token to paste
- Add the server from your terminal:
claude mcp add --transport http static-md https://static.md/mcp - In Claude Code, run /mcp, pick static-md and choose Authenticate.
- Your browser opens static.md. Sign in with Google and approve the access Claude asks for.
- list_my_notes Your notes, newest first: ids, titles and links. notes:read
- read_note A note’s markdown, handed to the agent as data, never as instructions. notes:read
- create_note A new note in your account, with optional starting content. notes:write
- update_note Append or replace text. Edits merge live with people typing in the note. notes:write
- list_my_boards Your whiteboards with their links and element counts. boards:read
- read_board The text on a whiteboard and its Excalidraw scene. boards:read
- create_board A whiteboard drawn from an Excalidraw scene. boards:write
- set_access Who can open a note or whiteboard: anyone with the link, only you, or people you name (Pro). Only when you ask. sharing
| Free | Pro | |
|---|---|---|
| Tool calls per day | 50 | 5,000 |
| Tool calls per minute | 60 | 60 |
| New notes & whiteboards | 10 / hour | No limit |
| Elements per whiteboard | 300 | No limit |
| Personal access tokens | 1 | 10 |
Daily limits reset at 00:00 UTC. When one runs out, the agent is told why and where to upgrade.
Sign in with Google to see the apps connected to your static.md account and manage access tokens.
- consent Every agent signs in through static.md, and you approve it with your Google account. Nothing connects on its own.
- scopes Access is granted per kind: reading or writing, notes or whiteboards. An agent gets only what you approved.
- set_access Changing who can open your notes needs its own permission, approved on its own. Agents are told to use it only when you ask them directly, never because a note says so.
- sharing Agents follow your sharing settings: they open exactly what you could open in your browser.
- encrypted End-to-end encrypted notes stay unreadable, to agents and to static.md alike.
- untrusted Note text is fenced as user data, so instructions hidden in a note don’t read as commands.
- revoke Disconnect an app or delete a token at any time. It stops working within seconds.