Readwise MCP server icon

Readwise

by Readwise

HIPAA CompliantSOC2 ReadyISO 27001 Ready
Productivity22 tools

Search every highlight you have saved and triage your Reader inbox. 22 tools, OAuth with separate read and write scopes, paid after a 30-day trial.

Verified connector

Listed by Anthropic as a partner connector in its Connectors Directory.

Connection checked by Agentman on .

Anthropic states this reflects the level of review a connector received, not a security audit.

Connect Readwise via MCP

https://mcp2.readwise.io/mcp

Works in any MCP-compatible client. In Agentman Studio it is one click — no config file to edit.

Use in Agentman

Connect Readwise once and your agents call these tools on their own — on a schedule, in a workflow, with nobody at the keyboard.

Open in Agentman Studio

Readwise Tools & Capabilities (22)

readwise_search_highlights
readwise_create_highlights
readwise_list_highlights
readwise_update_highlight
readwise_delete_highlight
readwise_get_daily_review
reader_search_documents
reader_create_document
reader_list_documents
reader_get_document_details
reader_list_tags
reader_add_tags_to_document
reader_remove_tags_from_document
reader_move_documents
reader_bulk_edit_document_metadata
reader_get_document_highlights
reader_add_tags_to_highlight
reader_remove_tags_from_highlight
reader_set_highlight_notes
reader_create_highlight
reader_export_documents
reader_get_export_documents_status

Tool names from Anthropic's directory listing. This server requires sign-in, so we could not read tool descriptions or parameter schemas.

Limits

  • It is paid software, and the two products are gated differently. Readwise states there is no free plan after the 30-day trial. More precisely: Readwise's pricing page lists Readwise Lite at $5.59 a month billed annually and marks the Reader app as not included at that tier, while the full Readwise plan at $9.99 a month billed annually explicitly includes Reader. So one subscription covers both products, but only the full one — a Lite subscriber connecting this server gets the six readwise_* tools working against a library the sixteen reader_* tools have nothing to read — and all five tag tools are Reader tools, so they go with it.
  • Deletion of a highlight is soft, not permanent — which cuts both ways. It is the reason an agent cannot destroy your notes. It is also the reason you cannot use this connector to genuinely erase anything: Readwise directs you to the original source for that.
  • There is no undo tool. Readwise's undo is a keyboard shortcut in the web app and shake-to-undo on iOS. An agent cannot reverse its own discard; you do it afterwards, by hand.
  • Reader's Trash is device-specific. Readwise states a deleted document must be restored from the device that deleted it. No connector tool deletes a document today, so this is a boundary to know rather than a live risk.
  • We could not read tool schemas or safety annotations. The server is gated and our anonymous handshake returned HTTP 401. Every behavioural claim above comes from Readwise's documentation or its skills repository, never from a schema we read. We make no claim about readOnlyHint or destructiveHint on any tool.
  • entry.permissions is absent from Anthropic's snapshot for this server. The single cheapest read/write cross-check is unavailable, and we state that rather than substituting a quieter inference.
  • The deprecated endpoint is still live and still documented. https://mcp.readwise.io/sse answers anonymously, exposes two tools, reaches Readwise highlights only, and publishes a descriptor with no scopes. Readwise's own legacy guide still prints that URL. Check which endpoint your client holds.
  • Batch operations have documented ceilings. Readwise's own tool table caps reader_bulk_edit_document_metadata at 50 documents at a time, and its skills repository puts the same 50-per-call cap on reader_move_documents and states the two tools share a rate limit of 20 calls per minute, advising you to batch IDs into fewer calls. A conversational "archive everything older than a month" can reach both ceilings.
  • The platform API is rate-limited at 240 requests per minute per access token. Readwise's API documentation adds that highlight and book listing endpoints are restricted to 20 per minute, and that a 429 carries a Retry-After header with the seconds to wait. Readwise does not state how MCP tool calls map onto those counters, so treat the figures as platform-wide rather than connector-specific.
  • Search is an index, and an index can miss. Readwise's own FAQ concedes that search and recency filtering can omit documents you know you saved, and advises naming the topic or roughly when you saved it, or asking for a list by topic first.
  • No prompts or resources on the current server. Anthropic's snapshot records no prompt names for this connector, and we could not probe the gated server's capabilities. On the deprecated endpoint both capabilities are declared and both list empty.
  • It has no end-to-end encryption. Readwise states this plainly and describes both products as consumer software optimising for user experience over enterprise compliance. Weigh that against whatever you have saved.

Frequently asked questions

Both, through one connection. Readwise states the integration indexes your Readwise highlights and your Reader documents and makes all of them available to connected AI apps. That is why the tool names split into two prefixes: six readwise ones covering saved highlights, and sixteen reader ones covering the read-later library.

It replaces it. Readwise states the previous Readwise-only server is being deprecated in favour of this one, which covers both products. Readwise tells anyone who configured the old server to update their AI app to the new URL. We found the old host still answering on 2026-08-18, so the switch is on you to make.

Yes for tags and moves. Readwise states every action the MCP takes is reversible the same way you would undo it in Reader, by removing the tag, moving the document back or restoring it from archive, and that you can ask the assistant to undo what it just did. Deletion is a separate question.

Continuously, in the background. Readwise states the index updates automatically as you add or change content, and that after the initial full index later syncs only process new or changed material so they finish quickly. A document saved moments ago may still be mid-index when an assistant searches for it.

Yes, with no stated ceiling. Readwise states you can use the same MCP server URL with as many compatible apps as you like. Each app runs its own OAuth authorisation, so every connection is a separate grant that you approve and can revoke on its own without disturbing the others.

No. Readwise states there is no free plan after the free trial, which runs 30 days. The connector fronts a paid subscription, so budget for it before wiring an agent to it. Readwise does document discounts for students, teachers, non-profits, military, first responders and people in countries with depressed currencies.

Because Readwise stores a soft discard rather than a hard delete. Readwise explains it keeps the record so a re-sync from Kindle or another source does not re-import the highlight as new, and says outright that a hard delete would frustrate users wanting to recover an accidental deletion. Readwise directs anyone needing true erasure to delete at the original source.

Yes, from Trash, with one catch that matters here. Readwise states deleted documents stay in Trash until you recover them or empty it, and that restoring returns the document to your library along with its highlights and notes. Readwise also states the Trash is device-specific, so a document must be restored from the same device that deleted it.

Sources

Server Info

Category
Productivity
Developer
Readwise
Tools
22
Domain
mcp2.readwise.io

Using Claude Desktop or another MCP client? Setup docs — the connection URL above works anywhere.

Ready to connect Readwise?

Connect Readwise once and your agents call these tools on their own — on a schedule, in a workflow, with nobody at the keyboard.