mcpbeat Sign in

three.ws Notifications MCP Server

local only

three.ws Notifications runs on your own machine — the client starts it, so there is no endpoint to ping. 196 installs a week from npm. Last commit 18 Sep 2026.

Read the inbox, mark items read, manage delivery preferences, and register Web Push devices.

Installs per day peak 142 · avg 17 · +579% w/w
a month agotoday
196
Installs / week
npm · @three-ws/notifications-mcp
194
Stars
0 open issues
18 Sep 2026
Last commit
0 releases in 90 days
Apache-2.0
License
JavaScript

What the code does

We read the source, 21 h ago · rules 3dff92dd89df

A tool parameter reaches a dangerous call

A value the model can set ends up inside a file or shell call. That is not a flaw by itself — for a terminal server it is the job — but it is where things go wrong when it is not.

A tool parameter reaches a file or shell call animation_signature.clip → packages/render/bin/tty.js:150, apply_animation.animation → packages/render/bin/tty.js:78
        await fs.writeFile(out, bytes);
Evidence

Things with no honest explanation: a promise that contradicts the code, code that runs at install time while hiding what it does, data leaving the machine.

Reaches cloud metadata service api/_lib/gcp-auth.js:86
        'http://metadata.google.internal/computeMetadata/v1/instance/service-accounts/default/token',
Capabilities

What this server is able to do. For an MCP server this is often the job itself — a terminal server runs commands because that is what it is for. Listed so you know what you are plugging in, not as an accusation.

Builds a file path from a variable api/sitemap/[type].js:76, chat/vite.config.js:18
                return JSON.parse(await readFile(path.join(base, rel), 'utf8'));
Runs an external command herald-sdk/bin/herald.mjs:159
    const child = spawn(command[0], command.slice(1), { stdio: 'inherit', shell: false });
Builds a database query by concatenation packages/motion/src/solve.js:122, pages/marketplace.html:5037
    const drop = STANDING_HIP_HEIGHT * (root.height - 1) + root.rise;
            if (reset) { state.cursor = null; state.total = 0; grid.innerHTML = skeletons(); stateEl.hidden = true; }
        `https://api.telegram.org/bot${cfg.token}/sendMessage`,
Long encoded blob in source api/_lib/x402/ring-catalog.js:56
    'UklGRmQBAABXQVZFZm10IBAAAAABAAEAQB8AAIA+AAACABAAZGF0YUABAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA…
    <script type="module" src="https://three.ws/agent-3d/latest/agent-3d.js"></script>

Is this your server and something here is wrong? Tell us — corrections are free and do not require a plan.

A tool parameter here reaches a dangerous call

That is not a flaw by itself — but it is where things go wrong when it is not the job. We re-read this code on every release. Watch it and you hear from us the day another one appears.

Three servers free · no card

Connect this server

This server runs on your own machine — install it with the package manager and the client starts it for you. Package name taken from the official registry entry.

run in your terminal
claude mcp add notifications-mcp -- npx -y @three-ws/notifications-mcp
~/Library/Application Support/Claude/claude_desktop_config.json
{
  "mcpServers": {
    "notifications-mcp": {
      "args": [
        "-y",
        "@three-ws/notifications-mcp"
      ],
      "command": "npx"
    }
  }
}
~/.codex/config.toml
[mcp_servers.notifications-mcp]
command = "npx"
args = ["-y", "@three-ws/notifications-mcp"]
.cursor/mcp.json
{
  "mcpServers": {
    "notifications-mcp": {
      "args": [
        "-y",
        "@three-ws/notifications-mcp"
      ],
      "command": "npx"
    }
  }
}
.vscode/mcp.json
{
  "mcpServers": {
    "notifications-mcp": {
      "args": [
        "-y",
        "@three-ws/notifications-mcp"
      ],
      "command": "npx"
    }
  }
}

This one needs environment variables set before it will start: THREE_WS_API_KEY (A three.ws API key (sk_live_… / sk_test_…) or OAuth access token for the account whose notifications you want to read and manage, carried as Authorization: Bearer. Required — every endpoint is account-scoped. Aliases: THREE_WS_TOKEN, THREE_WS_BEARER. Treat like a password.), THREE_WS_BASE (Base URL of the three.ws API. Override only when self-hosting or targeting a preview deployment.), THREE_WS_TIMEOUT_MS (Per-request timeout in milliseconds for the live inbox reads/writes.). The author declared them in the registry entry; get the values from the project itself.

Alternatives to three.ws Notifications

same job, measured the same way
Agent Push Kit
by justinbstrong

Send, search, and manage notifications, accounts, and push preferences

30 installs/wk answering
ntfy
by ni-c

Publish ntfy notifications, read the message cache, and manage users and topic access

46 installs/wk local only
Ntfy MCP Server
by cyanheads

Send, manage, and replay ntfy push notifications via MCP.

1 085 installs/wk local only
Ray notifications
by gege-mn

Send email, push, Slack, Discord, Telegram and webhook notifications and manage templates with Ray.

141 installs/wk 21 tools answering
Gotify MCP
by tootie

MCP server for self-hosted Gotify push notifications and message management.

59 installs/wk local only
Gotify RMCP
by dinglebear

Rust MCP server and CLI for Gotify push notifications and message management.

local only
Gotify MCP
by kcofoni

MCP server for Gotify push notifications - send messages and manage apps/clients.

local only
Courier
by trycourier

Send notifications, manage templates, and configure integrations with Courier.

145 tools answering

three.ws Notifications — questions

Answers built from our own checks of this server.

Why is there no uptime for three.ws Notifications?
three.ws Notifications runs on your own machine over stdio — there is no network address to reach, so uptime cannot be measured for it by anyone. What can be measured is adoption: the npm package @three-ws/notifications-mcp was installed 196 times last week.
How do I connect three.ws Notifications?
Copy the ready config from this page — we generate it for Claude Code, Claude Desktop, Codex, Cursor and VS Code, each with the file path that client actually reads. It runs locally, so the command pulls @three-ws/notifications-mcp straight from npm; nothing to host, nothing to sign up for.
How many people use three.ws Notifications?
The npm package @three-ws/notifications-mcp was installed 196 times in the last week. Week over week that is +579%. We show installs rather than GitHub stars on purpose: a star is a bookmark, an install is someone actually running it.
Is three.ws Notifications open source?
Yes — it is published under the Apache-2.0 licence, written in JavaScript and 194 stars on GitHub. The source link is on this page, so you can read exactly what it does with your data before you connect it.