Yandex Calendar MCP server over CalDAV
yandex-calendar-mcp
A Yandex Calendar MCP server over CalDAV: reading the schedule, creating and editing events, invitations with real email delivery
High risk
We rate an entry high when the tool writes to external systems, handles money, production databases or secrets, or runs arbitrary commands. The CLI installs it only with your consent.
Why this level
- Adding or removing an attendee sends a real invitation or cancellation email that cannot be recalled
- Deleting events is irreversible on Yandex's side, though a local trash copy remains
Install
Manual install
pip install -r requirements.txtInstalls dependencies, including tzdata.
This is third-party code. Review the repository files before installing.
What it does
The server gives an agent read and write access to Yandex Calendar over the CalDAV protocol. It reads events for a period up to 92 days across all calendars or one, expands recurring events into concrete dates, marks attendees with their reply status, and names the time zone explicitly in every response. For writes it creates one-off and recurring events, moves and renames them, edits a single day of a series via RECURRENCE-ID or the whole series, invites and removes attendees, and replies to invitations from others. Every write is verified by reading it back from the server, and if Yandex silently failed to apply a change, the server honestly reports failure instead of a false success. Before every delete and update, a full copy of the event is saved to YANDEX_TRASH_DIR as an ics file, and deletion additionally checks the event's title against the passed id to avoid erasing the wrong one. Adding or removing an attendee sends a real invitation or cancellation email through Yandex, which cannot be recalled.
Who it is for. For people who keep their schedule in Yandex Calendar and want to manage events and invitations from an agent chat.
Good fit when
- You want to read and plan Yandex Calendar events from an agent
- You care about every write being verified by an actual read, not trusting the server's response
- You need correct handling of recurring events and time zones
Not a fit when
- You do not want the agent able to send real invitation emails to attendees on your behalf
- You need to edit someone else's event as if you were the organizer: the server only allows replying to an invitation, not editing someone else's event
Example request
Move the team meeting to Friday at 3pm and add the new hire to the attendeesLimitations
You need a Yandex app password for CalDAV; a regular account password does not work. It needs Python 3.10 and the tzdata package, since slim Linux images often ship without a time zone database. Invitations and cancellations are sent as real emails and cannot be recalled. Deleting or editing someone else's event as if you were the organizer is impossible: Yandex silently rejects such edits, and the server detects this and refuses upfront.
How to disable. Remove the yandex-calendar entry from your MCP client configuration.
MCP
- Transport
- stdio
- Authentication
- API key
| Environment variables | |
|---|---|
| YANDEX_USERNAME required | An address like name@yandex.ru |
| YANDEX_PASSWORD required, secret | A Yandex app password, not the account password |
| YANDEX_TRASH_DIR | The folder for ics copies of changed and deleted events |
Security check
- Adding or removing an attendee sends a real invitation or cancellation email that cannot be recalled
- Deleting events is irreversible on Yandex's side, though a local trash copy remains
README in short
The README details read and write capabilities, a table of six tools, three layers of delete protection, a title check, a trash with ics copies, and a mandatory choice between one day of a series and the whole series, separately explains why you cannot edit someone else's event as its organizer, and honestly warns that invitations are sent as real, unrecallable emails.
FAQ
Can a sent invitation be recalled?
No, Yandex sends a real email when an attendee is added or removed, and that cannot be undone.
What protects against deleting the wrong event?
The delete_event tool checks the event's id against the passed title and refuses on a mismatch, and saves a copy to YANDEX_TRASH_DIR before deleting.
Related
A self-hosted knowledge base with block-level references and a built-in MCP server for connecting AI agents to your notes
A CLI for every Google Workspace API with JSON output and agent skills: Drive, Gmail, Calendar, Sheets and more
Local search over Markdown notes, docs and meeting transcripts: keywords, semantic search and reranking, with an MCP server
A task manager for AI-driven development: breaks a PRD into dependent tasks and guides the agent through them via MCP or CLI