Read, search, send, organize, draft and schedule email across your inboxes from any MCP client.
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent — or use 1-click editor setup below.
💡 Paste into ~/Library/Application Support/Claude/claude_desktop_config.json (macOS) or %APPDATA%\Claude\claude_desktop_config.json (Windows)
Give your AI agent an inbox. A hosted Model Context Protocol server that lets Claude, Cursor, or any MCP‑compatible client read, search, send, organize, and schedule email through your existing mailboxes — without ever storing your mail.
Connect a mailbox once, paste one URL into your agent, and it can work your inbox live. Email is fetched on demand and never retained; credentials are encrypted at rest and decrypted only at call time inside an isolated edge function.
🔗 mcpemails.com · 📚 Docs · 💳 Pricing
mcpe_…).inbox_list, email_read (action: "search"), email_compose (action: "send"), and schedule (action: "create"). Each request fetches live from your provider — nothing is mirrored or cached server‑side.Permissions are scoped per key, so you can hand an agent read:email only, or grant it send and folder management without ever exposing delete.
Claude Desktop / Cursor (OAuth): add a remote MCP server pointing at https://mcpemails.com/api/mcp and approve the consent screen. Pick the scopes the agent should have.
API key (any MCP client): create a key in the dashboard, choose its scopes and (optionally) restrict it to specific inboxes, then send it as a bearer token:
The protocol is JSON‑RPC 2.0 over HTTP (MCP 2025-06-18, Streamable transport). Start every session with inbox_list — it returns the inboxes the key can reach, their per‑provider capabilities, and a versioned compatibility profile. The profile marks normalized operations as exact, different, or unavailable, so agents can preserve provider differences rather than silently weakening a request.
SEARCH, and JMAP are normalized behind one email_read (action: "search") interface.10 tools. Most are resource-oriented and take an action argument that selects the specific operation (and, for actions that need different privileges, the required scope):
| Tool | Actions | Scope(s) |
|---|---|---|
inbox_list | (single action) | read:email |
email_read | list, read, read_batch, search, attachment, extract, original | read:email (search also accepts search:email) |
email_organize | move, move_batch, copy, copy_batch, flag, archive, search_and_move | manage:folders (move/copy/search_and_move), send:email (flag/archive) |
email_delete | delete, delete_batch, search_and_delete | delete:email |
email_compose | send, reply, forward | send:email |
folder | list, create, rename, delete | read:email (list), manage:folders (create/rename/delete) |
draft | list, create, reply, update, send, delete | manage:drafts (list/create/reply/update/delete), read:email (reply also), send:email (send) |
schedule | create, list, cancel | schedule:email |
signature | get, set | read:email (get), send:email (set) |
contact_search | (single action) | manage:contacts |
Notes:
inbox_id (UUID) or an inbox email address; single‑inbox keys auto‑resolve the target.email_read's read_batch) to 500 (move/delete/flag) messages per call.email_read with action: "search", then pass the returned message_id or message_ids to email_organize or email_delete. Search fields are accepted only by search_and_move and search_and_delete mutation actions.contact_search scans recent mail live — there is no stored address book.email_read's original action returns one complete provider-stored MIME message as a portable .eml file (up to 25 MB). It is read-only and never marks the message as read.draft's send action requires send:email, not manage:drafts — so a key that can only manage drafts can't use them to bypass the send‑mail consent.draft's reply action creates an unsent, provider-native reply in the source conversation. It needs both manage:drafts and read:email, and defaults to replying only to the sender.tools/list only returns the tools your key (or OAuth token) is actually scoped for.| Scope | Grants |
|---|---|
read:email | List inboxes & folders; list, read, and search messages |
search:email | Narrower alternative that grants only email_read's search action |
send:email | Send, reply, forward, flag, archive; also required to send a draft |
manage:folders | Create/rename/delete folders; move/copy messages |
delete:email | Trash or permanently expunge messages |
manage:drafts | Create, edit, and delete drafts (sending one also requires send:email) |
manage:contacts | Live contact lookup from recent mail |
schedule:email | Queue messages for future delivery |
| Provider | Connect via | Read/Search | Send | Folders | Permanent delete | Drafts |
|---|---|---|---|---|---|---|
| Gmail / Google Workspace | OAuth 2.0 | ✅ | ✅ | Labels | Trash only | ✅ |
| Fastmail | App password (IMAP/SMTP) | ✅ | ✅ | ✅ | ✅ | ✅ |
| iCloud, Yahoo, Zoho, Yandex | App password (IMAP/SMTP) | ✅ | ✅ | ✅ | ✅ | ✅ |
| Any IMAP/SMTP mailbox | App password | ✅ | ✅ | ✅ | ✅ | ✅ |
| Outlook / Microsoft 365 | OAuth 2.0 | 🚧 built, gated pending verification |
Outlook OAuth is implemented end‑to‑end but currently gated behind Microsoft publisher verification; it is hidden from the connect UI until it ships.
Every plan includes unlimited inboxes and API keys. Successful billable MCP calls use actions: Free includes 2,500 actions per billing period, Agent 50,000, and Scale 300,000. Paid tiers also add higher burst limits, analytics retention, team features, and support.
| Free | Agent | Scale | |
|---|---|---|---|
| Price | $0 | $12/mo · $120/yr | $49/mo · $490/yr |
| Inboxes / tool calls / API keys | Unlimited | Unlimited | Unlimited |
| Members | 1 (owner only) | Unlimited | Unlimited |
| Fair‑use rate limit | 60 req/min | 300 req/min | 1,000 req/min |
| Analytics retention | 7 days | 90 days | 1 year |
| Team roles & workspaces | — | — | ✅ |
| SSO (SAML/OIDC) + audit log | — | — | ✅ |
| Support | Community | Priority |
Per‑API‑key limits also apply (100 req/min · 1,000/hr · 10,000/day). Inviting members requires a paid plan. The "Scale" tier carries the internal id pro. See apps/web/src/lib/stripe/plans.ts.
/api/mcp is a thin Next.js route handler that proxies to the Supabase edge function mcp-server — the real MCP implementation, where credentials are decrypted and provider calls are made.Stack: Next.js 16 (App Router) · React 19 · next‑intl 4 · Supabase (Auth, Postgres, Edge Functions) · Stripe · Resend · TypeScript. Email parsing/sanitization via mailparser, jsdom, and isomorphic-dompurify.
Prerequisites: Node.js 20+, npm, and the Supabase CLI (for migrations and edge functions).
next.config.jsvalidates required env vars at build/start and rejects weakENCRYPTION_KEYvalues, so a misconfigured environment fails fast instead of at runtime.
Copy .env.example and fill in real values. Required in every environment:
| Variable | Purpose |
|---|---|
NEXT_PUBLIC_SUPABASE_URL / NEXT_PUBLIC_SUPABASE_ANON_KEY | Supabase client (public) |
SUPABASE_SERVICE_ROLE_KEY | Server‑side admin key (bypasses RLS) — secret |
NEXT_PUBLIC_APP_URL | Canonical base URL; drives OAuth redirect URIs |
GOOGLE_SITE_VERIFICATION (optional) | Google Search Console HTML-tag verification token; set only in production |
ENCRYPTION_KEY | 64‑hex AES‑256‑GCM key for credentials at rest — secret |
CSRF_SECRET | 64‑hex HMAC key for CSRF tokens (distinct from above) — secret |
Feature‑dependent:
| Variable(s) | Needed for |
|---|---|
GMAIL_CLIENT_ID / GMAIL_CLIENT_SECRET | Gmail OAuth (gmail.readonly, gmail.send, gmail.modify) |
OUTLOOK_CLIENT_ID / OUTLOOK_CLIENT_SECRET / OUTLOOK_TENANT_ID | Outlook OAuth (Mail.Read, Mail.Send, Mail.ReadWrite, offline_access) |
NEXT_PUBLIC_OAUTH_VERIFICATION_PENDING | Shows the unverified‑app warning until Google/Microsoft verification completes |
STRIPE_SECRET_KEY / STRIPE_WEBHOOK_SECRET / NEXT_PUBLIC_STRIPE_PUBLISHABLE_KEY | Billing |
STRIPE_PRICE_SOLO_MONTHLY / _YEARLY, STRIPE_PRICE_PRO_MONTHLY / _YEARLY | Plan price IDs (pro = Scale) |
Fastmail and other IMAP providers connect via app password and need no OAuth credentials.
Schema and Row‑Level Security policies live in supabase/migrations/. Core tables: workspaces, workspace_members, inboxes (encrypted credentials, soft‑deleted), api_keys (hashed, scoped, inbox‑restricted), oauth_clients, scheduled_sends, workspace_invites, and a month‑partitioned activity_log.
The Supabase CLI is the source of truth for DB changes in this project.
Web app → Vercel (project mcp-emails-web):
Security headers and function timeouts are defined in vercel.json. The marketing routes are served with a CDN‑cacheable Cache-Control (set in proxy.ts) so crawlers and repeat visitors hit the edge cache; the dashboard, auth, and API routes stay no-store.
MCP server → Supabase edge function:
Don't want to trust the hosted service with your mail? Run the same MCP server on your own
machine. self-host/ ships a containerized stack (Postgres + PostgREST + the Deno
server, no Supabase/Stripe/dashboard), so your credentials are encrypted with a key only you hold
and decrypted only inside your own container.
It is IMAP/SMTP-first (Fastmail, iCloud, Yahoo, Zoho, Yandex, generic) via app password; Gmail/Outlook
OAuth and the web dashboard remain hosted-only. The container runs supabase/functions/mcp-server/
unmodified; see self-host/README.md for the full guide.
Built with next‑intl (localePrefix: 'as-needed', localeDetection: false for stable canonical URLs). English is served at /; other locales carry a prefix (/nb, /es, /fr, /zh). Translations live under apps/web/messages/.
Supported locales: English, Norwegian Bokmål, Spanish, French, Chinese (Simplified).
X-Frame-Options: DENY, and related headers on every response.MCP Emails is open source under the GNU Affero General Public License v3.0 (AGPL‑3.0). The hosted service at mcpemails.com runs the same server you can self-host, so you can read the code, verify it, and run it yourself. See /security for the trust model.
Send and receive email from any agent. © MCPEmails, AGPL‑3.0.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/mcp-emails-2)<a href="https://allmcps.com/mcp/mcp-emails-2"><img src="https://allmcps.com/api/badge/mcp-emails-2?style=directory" alt="MCP Emails on AllMCPs" /></a>