The full upstream README, mirrored here for reference. Install config, tool schemas, adoption signals, and an original overview live on the Inbox To Action listing page.
Published on PyPI and listed on the
Official MCP Registry (io.github.tarunlnmiit/inbox-to-action),
Glama (deployable release, Quality A),
and Smithery (MCPB bundle).
Registry manifests (server.json, glama.json) ship in the repo.
One command. Your inbox triaged, summarized, drafted, and turned into tasks — in a single agentic pass.
Try it with zero setup: inbox-to-action run --mock (bundled sample inbox).
📖 Full documentation → docs/ — install · providers · Gmail OAuth · multi-account · integrations · MCP & Skill · config · troubleshooting · testing checklist. Quick version: SETUP.md.
Most people process their inbox with four separate tools: an email client to read, a task manager to capture to-dos, a calendar to block time, and (increasingly) an AI summarizer to make sense of long threads. Every message gets handled four times.
inbox-to-action collapses all four into one agentic pass. Run one command and get
a unified triage report, drafted replies saved to Gmail, and extracted tasks — without
ever leaving the terminal, and without ever sending an email automatically.
This tool cannot send email. It requests only the Gmail readonly + compose
scopes; there is no send scope and no send API call anywhere in the codebase
(enforced by a test). Replies are saved as Gmail drafts for you to review and send.
Email bodies flow into the LLM prompt, so a hostile email could try to steer its own classification or a drafted reply (prompt injection). Because every draft is saved for human review and nothing is ever sent automatically, the worst case is a draft you choose not to send. See SECURITY.md.
inbox-to-action reads your email. Where your email content goes for classification
depends on the LLM provider you pick — and the default (openrouter) is a cloud
provider, so an out-of-the-box run sends your subjects + bodies to a third party.
PROVIDER= | Email content goes to | Key |
|---|---|---|
ollama | Nowhere — fully local 🔒 | none |
claude / host | Your existing Claude Code / Anthropic session (keyless) | none |
openrouter (default) · openai · nim · anthropic | Third-party cloud ☁️ | API key |
Want privacy? Use ollama (local) or claude (keyless) so nothing is transmitted
to a third party. --telegram / --todoist also push subjects/tasks off-box (opt-in).
Full breakdown → PRIVACY.md.
Note:
triage-report.mdandtasks.mdare written to your working directory and contain private email content. If you run inside a git repo, add them to.gitignore.
action_needed · fyi · newsletter · noise.tasks.md (optional Todoist via --todoist).action_needed mail → saved as Gmail drafts.Final output: a single triage-report.md with a section per category, drafted-reply
previews, a tasks summary, and a calendar list.
The model's own classification of each email drives which tools fire next — the pipeline is not hardcoded. The same tool functions back the CLI agent and the MCP server.
This installs an inbox-to-action console command (and the python -m inbox_to_action.mcp_server entry point used by Claude Code / Glama).
Pick whichever keyless/free path you like — all run the full pipeline at no cost:
Option A — claude CLI (keyless, fastest; uses your Claude Code login):
Option B — Ollama (truly keyless, fully local):
Option C — OpenRouter free model (free signup key):
Option D — inside Claude Code (keyless, Claude Code is the LLM): see below.
--mock uses the bundled sample inbox so you can see a full report with zero Gmail
setup. Drop --mock once you've authorized Gmail. Free OpenRouter models are often
rate-limited; the client auto-rotates a fallback list and retries with backoff.
--no-drafts — classify, summarize, extract tasks, write the report, but create
no Gmail drafts. Recommended for a first run.--max N — cap emails per account (default 25) to bound cost/volume.--telegram)Push a concise summary to your phone after each run — counts, action-needed subjects (with draft-ready status), extracted tasks, and a link to your Gmail Drafts.
Off by default (opt-in flag). A send failure never breaks the run. Privacy: this sends email subjects + extracted tasks to Telegram's servers (into your own chat). It's notification only — it never sends email.
Declare accounts in config.json — one merged report, each email tagged with its
account. Personal Gmail and Workspace both use the Gmail path (Workspace may need
your admin to allow the OAuth app).
Multiple personal Gmail accounts can reuse one client_secret.json — each gets its
own cached token (~/.config/inbox-to-action/tokens/<id>.json). With no accounts
block, the tool uses a single default Gmail account (backwards compatible).
When run inside Claude Code, Claude Code is the LLM — no provider key needed. Two integration paths ship in this repo:
Exposes IO-only tools (fetch_emails, save_gmail_draft, append_tasks, write_report).
Claude Code does the classify/summarize/extract/draft reasoning itself and calls these.
This is the same stdio server that MCP registries (e.g. Glama) build from
the bundled Dockerfile (CMD python -m inbox_to_action.mcp_server).
Copy skills/inbox-to-action/ into your Claude Code skills directory, then type
/inbox-to-action. The skill instructs Claude Code to fetch, reason, draft, and write
the report — keyless.
ant auth login)The Anthropic provider uses the official SDK with a zero-arg client, so it picks up your
ant auth login OAuth profile — no ANTHROPIC_API_KEY required:
All keys live in .env (.env.example is committed). Switch providers with PROVIDER:
openrouter (default) · ollama · nim · openai · anthropic · claude · host.
The default buckets are generic — newsletters and job alerts are treated as no-action.
Override that with config.json (copy config.example.json). Two layers:
rules — deterministic field → category overrides applied before the LLM
(fast, free, exact). First match wins. field ∈ sender | subject | body | any.triage_instructions — freeform guidance injected into the classifier prompt for
nuance the model interprets.Quick override without a file: TRIAGE_INSTRUCTIONS="treat job alerts as action_needed".
This project demonstrates the contract skills:
agent.TOOL_SCHEMAS) shared by the CLI agent and MCP server.llm_client swaps OpenRouter / Ollama / NIM / OpenAI / Anthropic.MIT — see LICENSE.