Your library, available to your assistant.
Sanctuary ships a Model Context Protocol server, so an assistant like Claude Code can answer questions from your link library — who sent what, when, and about which project — without being handed your Messages database.
The privacy contract
Every tool returns titles, URLs, domains, categories, summaries, event dates, sender names, and counts — and never message text, conversation content, phone numbers, or handles. The output shape is defined in one place in the code and pinned by tests: stricter than the app's own AI features, because an assistant's context window is somebody else's computer. The server is read-only and works even while the app is closed.
The five link tools
| search_links | “What was that sample clearing site Maya sent me?” — keyword plus semantic search over the whole library |
| links_from_person | Everything a specific person has sent you |
| links_with_person | Links that came up in conversations with someone, whoever sent them |
| links_about | Links on a topic or category — restaurants, apartments, music |
| recent_links | What arrived in the last week, sent or received |
With the app installed the server adds more: counts, saved places, how far back the library goes, and — only while the switch in Profile → Connected chat apps is on — what Sanctuary learned from messages, such as a person's card and your open loops. It also ships three prompts that Claude Desktop shows as slash commands (/catch_me_up, /before_meeting, /this_week) and attachable resources: your recent links, the library's coverage, and behind the same switch, a person's card and your saved digests. Every tool is marked read-only, so Claude doesn't ask permission call by call.
Setup
One command — it finds your library and registers the server with your Claude clients:
npx -y @linksanctuary/mcp init
Or register it manually with the Claude Code CLI:
claude mcp add sanctuary -s user -- npx -y @linksanctuary/mcp
Needs Node 22.5+ and the Sanctuary Mac app (it reads the library the app builds — no Full Disk Access for your terminal or assistant, ever). Then just ask: “what was that link Sahil sent me last month?”
New to Sanctuary? Start with the setup guide— the MCP server reads the library the Mac app builds.