npm · skylight-mcp
$npx -y skylight-mcp@1.4.2 SKYLIGHT_REFRESH_TOKEN · secret — An OAuth refresh token you already hold. Supply this and no password is needed — the login is skipped entirely.
SKYLIGHT_EMAIL — Skylight account email. Pair with SKYLIGHT_PASSWORD for direct login. Needed only if you are not supplying SKYLIGHT_REFRESH_TOKEN.
SKYLIGHT_PASSWORD · secret — Skylight account password — required iff SKYLIGHT_EMAIL is set. Needed only if you are not supplying SKYLIGHT_REFRESH_TOKEN.
SKYLIGHT_FRAME_ID — Optional: pick a specific Skylight frame when the account has more than one.
SKYLIGHT_NAME — Friendly account name used in startup logs.
SKYLIGHT_TOKEN_CACHE — Set to false to disable the on-disk token cache and re-authenticate on every process start. Defaults to enabled.
SKYLIGHT_TOKEN_FILE — Absolute path for the token cache file. Defaults to $MCP_DATA_DIR/.skylight-mcp/tokens.json.
SKYLIGHT_BASE_URL — Override the API base (default https://app.ourskylight.com/api). The auth origin is derived from it, so pointing this elsewhere moves the login flow too — and the new host must be added to the registration’s egress allowlist, or every call is blocked.
SKYLIGHT_APPLE_APP_PASSWORD · secret — Optional: an app-specific password from appleid.apple.com, used only by skylight_link_apple_calendar. Env-only by design — the tool takes no password argument, so the credential never passes through the model or the transcript.
SKYLIGHT_APPLE_ID — Optional: the Apple ID email skylight_link_apple_calendar links; the tool's email argument overrides it.
SKYLIGHT_UPLOAD_DIR — Optional: directories that the photo-upload, event-import-from-photo and avatar tools may read files from (several separated by ':', or ';' on Windows; '~' allowed). Any other path is refused. Unset: ~/Pictures and ~/Downloads, or only $MCP_DATA_DIR/uploads in a hosted deployment.