notion-mcp (snickery/notion-mcp) is an MCP server listed on the M8ven Trust Index. It scores 54 out of 100, grade D. It declares 44 tools. No publisher has claimed this listing.

D
Caution
54/100

notion-mcp

An MCP server for the Notion API, enabling management of pages, databases, files, comments, and users with native markdown support and a full file pipeline.

Caution. Specific findings reduced this grade. They are listed on the page. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.

How we verified

Code Verified⚡ Live Monitored: not connected

Verified is a snapshot. Live keeps it current, and builds your track record.

⚡ Connect GitHub → continuous verification on every pushwhy connect →

Who stands behind it

snickery

Source: Glama

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →

Install from

The grade above is for the source repository. Registries can serve a different version, so we mark the ones we were not able to read.

// key findings
No credential exfiltration, no sensitive file access, no obfuscation
Static analysis found nothing flowing your secrets to unexpected places.
Open source with a license and README
Anyone can audit the code, the license is declared, and the publisher documents what it does.
🔐
You'll be asked for 4 credentials: NOTION_TOKEN, GOOGLE_CLIENT_SECRET, MCP_BEARER_TOKEN, XBERG_VLM_API_KEY
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// tools this server exposes44 tools

These names and descriptions are the publisher's own, read from the source code. We print them as written. Our assessment is the findings above, not this list.

notion_search_pages

Search Notion for pages the integration has access to. Returns titles and page IDs — use these IDs with notion_upload_file / list_files_on_page. The integration only sees pages explicitly shared with it in Notion. in_trash=True searches trashed pages instead of active ones (restore matches with noti

notion_search_databases

Search Notion for databases the integration has access to. Returns titles, IDs, and property schemas. Use the database ID with notion_query_database, notion_describe_database, or notion_create_page (with database_id).

notion_list_files_on_page

List all file/image/pdf/video/audio blocks on a Notion page. Returns block IDs and filenames — use block IDs with notion_download_file.

notion_purge_shared_files

Delete files from the cross-MCP shared mount (SHARED_DIR, /shared inside the container) whose modification time is older than max_age_hours. Use this to clean up attachments handed over from the companion google-accounts-mcp server once they've been uploaded to Notion.

notion_purge_file

Delete a single file from the cross-MCP shared mount by bare filename. Use this after a successful upload to free the shared slot instead of waiting for the daily TTL sweep (or calling notion_purge_shared_files with max_age_hours=0, which would wipe any unrelated in-flight handoffs). Rejects any fil

notion_list_local_files

List files available to notion-mcp by scheme, so the agent can verify a handoff before attaching it to Notion.

notion_upload_file

Upload a file to Notion and attach it as a new block.

notion_replace_file

Replace the file inside an EXISTING file/image/pdf/video/audio block, in place — the block keeps its position on the page. Use this to update a document without re-arranging anything; use notion_upload_file(position=...) to add a new block instead.

notion_import_file_from_url

Import a file into Notion directly from a public HTTPS URL — the bytes go Notion-side, never through this server or MCP parameters.

notion_set_page_visual

Set or remove a Notion page's icon or cover image.

notion_describe_database

Retrieve a Notion database's schema. Returns each property name and type — use this to find the exact files & media column name to pass to notion_upload_file_to_database / notion_add_file_to_row.

notion_upload_file_to_database

Upload a file and create a NEW row in a Notion database with the file attached to the given files & media column.

notion_add_file_to_row

Upload a file and attach it to an EXISTING database row's files & media column.

notion_batch_add_file_to_row

Attach files to many existing Notion rows in one call.

notion_download_file

Download a file from a Notion file/image/pdf/video/audio block.

notion_extract_file_text

Extract text from a PDF anywhere notion-mcp can reach — a file stored in Notion, the shared cross-MCP mount, the private store, or the Drive folder — without moving the bytes over MCP.

notion_render_file_page
notion_read_page

Read a Notion page's properties and content as markdown.

notion_create_page

Create a new Notion page with optional markdown content.

notion_update_page

Update a Notion page's title, icon, or other properties.

notion_append_content

Append markdown content to an existing Notion page.

notion_archive_page

Archive (soft-delete) a Notion page. The page can be restored from the Notion trash within 30 days using notion_restore_page.

notion_restore_page

Restore an archived page from the Notion trash.

notion_update_block

Update an existing block's text content.

notion_delete_block

Delete a block from a Notion page. This removes the block and all its children. The deletion is permanent (blocks cannot be restored).

notion_query_database

Query a Notion database with optional filter, sort, and pagination.

notion_create_database

Create a new Notion database under a page.

notion_update_database

Update a Notion database's title, description, or property schema.

notion_get_property

Retrieve a single property from a Notion page with full pagination.

notion_get_comments

Get all comments on a Notion page.

notion_add_comment

Add a comment to a Notion page or reply to a discussion thread.

notion_update_comment

Edit a comment previously created by this integration (Notion returns 404 for comments created by anyone else).

notion_delete_comment

Delete a comment previously created by this integration (Notion returns 404 for comments created by anyone else).

notion_list_views

List the views defined on a Notion database — name, type, id, and whether each carries a saved filter/sorts. Use the view id with notion_query_view to run a view's saved filter, or with notion_update_view / notion_delete_view to manage it.

notion_query_view

Run a database view's saved filter and sorts, returning the matching rows (title + id + url). Use this instead of notion_query_database when the view already encodes the filter you want — no filter JSON needed.

notion_create_view

Create a view on a Notion database.

notion_update_view

Update a view's name, saved filter, and/or sorts. Only provided fields change (fields left empty are preserved).

notion_delete_view

Delete a view from its database. The database and its rows are untouched — only the saved view configuration is removed.

notion_list_users

List all users in the Notion workspace.

notion_get_user

Get details for a specific Notion user by ID.

notion_read_page_markdown

Read a Notion page's content as native Notion-flavored markdown.

notion_update_page_content

Edit page content using search-and-replace on the page's markdown.

notion_replace_page_content

Replace a page's entire content with new markdown.

notion_move_page

Move a Notion page to a new parent page or database.

// environment variables
To run this server yourself, you supply these values. They go in your own MCP client configuration and stay on your machine. The secret label means the value is sensitive, not that the server mishandles it.
configNOTION_BATCH_CONCURRENCY
configPDF_MAX_CONCURRENCY
🔐 secretNOTION_TOKENexport =ntn_...
configNOTION_API_VERSIONNo 2026-03-11 Notion API version header
configGOOGLE_TOKEN_DB_PATHFor Drive /google-data/tokens.db Path to google-accounts-mcp's SQLite token DB (read-only; the legacy GMAIL_TOKEN_DB_PATH name is still honored)
configGMAIL_TOKEN_DB_PATHGOOGLE_TOKEN_DB_PATH For Drive /google-data/tokens.db Path to google-accounts-mcp's SQLite token DB (read-only; the legacy name is still honored)
configDRIVE_ACCOUNTFor Drive Google account email for Drive access
configDRIVE_FOLDER_NAMEFor Drive mcp-google-accounts Shared Drive folder name
configGOOGLE_CLIENT_IDFor Drive OAuth client ID (same as google-accounts-mcp)
🔐 secretGOOGLE_CLIENT_SECRETFor Drive OAuth client secret
configFILES_DIRlocation string no "files" "files" (the notion-mcp private store, ) or "shared" (the cross-MCP mount, SHARED_DIR, populated by google-accounts-mcp download_attachment(destination='shared'))
configSHARED_DIRlocation string no "files" "files" (the notion-mcp private store, FILES_DIR) or "shared" (the cross-MCP mount, , populated by google-accounts-mcp download_attachment(destination='shared'))
🔐 secretMCP_BEARER_TOKENYes Bearer token for authenticating MCP clients
configXBERG_BASE_URL
configXBERG_TIMEOUT
configXBERG_VLM_MODEL
configXBERG_VLM_BASE_URL
🔐 secretXBERG_VLM_API_KEY
configXBERG_OCR_BACKEND
Deployment configuration, supplied by whoever hosts the server. Users are not asked for these.
deployPORT
// quality suggestions

Tool annotations

No tools have read-only/destructive annotations

Add readOnlyHint or destructiveHint annotations to every tool so hosts can warn users before invoking.

All four hints declared on every tool

44/44 tools missing one or more hints — notion_search_pages (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); notion_search_databases (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); notion_list_files_on_page (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint), +41 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.

For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.

Destructive tools are labelled

2 tools perform destructive updates without destructiveHint — notion_purge_shared_files deletes at line 457 (p.unlink()); notion_purge_file deletes at line 478 (target.unlink())

Add destructiveHint:true to any tool whose handler calls .delete(), .upsert(), .update(), unlink, rm, DELETE, DROP, REPLACE INTO, or any operation that overwrites existing data.

Tool inputs are validated

43/44 tool handlers declare input schemas (98%)

Declare an inputSchema with zod/joi/yup on every tool definition.

Tool handlers catch errors

Only 3/44 tool handlers wrap calls in try/catch (7%)

Wrap each tool handler body in try/catch and return a structured error response.

Tests exist

No test files found

Add tests that exercise each declared tool.

Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.

// full audit trail
The findings above are the summary. The full trail, every check we ran, each deduction, the network hosts observed and the dependency advisories, goes to verified publishers, along with an alert whenever a new one lands. Verified publishers can also review each finding and dispute it in one click. Publisher corrections have sharpened several of our checks this month, because the maintainer knows the codebase better than any scanner.
// improvement guidance — verified publishers only
We have 6 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Verified](https://m8ven.ai/badge/mcp/snickery/notion-mcp?variant=verified)](https://m8ven.ai/mcp/snickery/notion-mcp)
Shows verification status without the grade. Want the grade badge instead? Remove ?variant=verified from the URL.
commit: c2735681f14ca31d410b93822926dac519de2745
code hash: 90fdfe861d6efc03b378c1277018182fe95f67c7c4ce9ce4f13c216ccb3759d6
view raw JSON →
Check MCPs from inside your assistant
Tool Check · MCP

Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.

https://m8ven.ai/api/mcp/tool-check
check_toolsearch_toolscompare_toolsrecommend_alternativescheck_publisherreport_concern
How to add it →Free · no account needed · works in any MCP client