The full upstream README, mirrored here for reference. Install config, tool schemas, adoption signals, and an original overview live on the Proton Safe MCP listing page.
A client-agnostic FastMCP server for Proton Mail through the official Proton Mail Bridge. It can read and search mail and create drafts with attachments. It deliberately cannot send email — you review every draft in Proton Mail and press Send yourself.
The server runs locally over STDIO for any MCP-compatible client (Claude Desktop, Claude Code, or anything else that speaks MCP). Received PDF, TXT, and CSV attachments can be inspected through bounded text extraction without exposing their raw bytes. Outgoing attachments are uploaded as bounded base64 chunks, so the server never receives or reads a client filesystem path.
Read the full documentation for setup, configuration, tool inputs, security boundaries, and troubleshooting.
Email is attacker-controlled input. Any sender can put adversarial instructions in a message body, and an AI agent that reads mail and holds write-capable tools is one prompt injection away from doing something you did not ask for. This project limits the blast radius by construction:
send_message tool in the codebase — a test asserts it.127.0.0.1.These controls reduce risk but do not make email trusted. Never expose unrelated write-capable tools in the same unattended agent workflow.

127.0.0.1 (PROTON_BRIDGE_HOST is intentionally unsupported).BODY.PEEK; attachment inspection returns bounded extracted text,
metadata, and a SHA-256 digest, never raw bytes or files.0700 directories, 0600 files, O_NOFOLLOW).uv.gnome-keyring or compatible).Install the reviewed release from PyPI with uv:
For development from source instead:
Set the Proton address and Bridge IMAP port in the MCP process environment. No credential is ever set here:
To draft as another Proton address of the same account, add the optional sender allowlist in that same environment, as comma-separated bare addresses:
Store the Bridge-generated IMAP password (shown in the Bridge UI), not your Proton account password:
The value shown by Bridge is installation-specific and works only against the local Bridge.
Configure a local STDIO server with these logical fields. Use command -v proton-safe-mcp
to obtain the absolute command path when your client does not inherit your shell PATH:
PROTON_BRIDGE_ALIASES goes in the same env block when a draft may use more than one From
address. See Sender addresses.
Do not put PROTON_BRIDGE_PASSWORD in the client configuration. The server reads it from the OS keyring established by setup.
Copy-paste instructions are available for Claude Code, Cursor, and VS Code.
AI coding agents can follow the safety-constrained llms-install.md guide.
Verify the complete local setup without printing credentials, addresses, or mailbox data:
The repository includes a private, local-first Proton Safe plugin for ChatGPT and Codex. It packages safety-focused mail review and draft workflows with the same restricted MCP server:
proton-safe-mcp and Proton Mail Bridge together, with IMAP
fixed to 127.0.0.1.See the OpenAI plugin guide for local ChatGPT desktop/Codex installation, direct MCP registration, and the optional remote tunnel.
Plugin installed but no Proton tools? The bundled MCP configuration forwards
PROTON_BRIDGE_USERandPROTON_IMAP_PORTfrom the environment that started Codex; it does not define their values. On Ubuntu, a correct~/.config/environment.d/*.conffile can still require a user-manager reload, while GNOME and already-running terminals can keep their earlier environment. If a menu relaunch still has no tools, start ChatGPT once from a terminal that has loaded the file. That terminal launch is a diagnostic, not a requirement for every start; the troubleshooting guide also provides a persistent per-user menu launcher. Follow the privacy-safe Ubuntu recovery procedure or the FAQ before reinstalling anything.
Help test the onboarding. Linux and Proton Mail Bridge users can run the 10-minute external test and submit privacy-safe installation feedback.
| Category | Tool | Notes |
|---|---|---|
| Read-only mail | mailbox_status | Bridge connectivity + INBOX counts |
list_folders | ||
list_sender_addresses | The fixed From allowlist a draft may use | |
list_messages | Never marks messages as read | |
search_messages | Injection-safe IMAP TEXT search | |
read_message | Bounded plain text; no attachment bytes | |
extract_attachment_text | Bounded PDF/TXT/CSV text; no raw bytes or files | |
get_reply_context | Candidate reply recipients, Re: subject, and a bounded quote — all suggestions | |
| Attachment staging | begin_attachment_upload | Declares filename, type, size, SHA-256 |
upload_attachment_chunk | Ordered base64 chunks | |
finish_attachment_upload | Verifies hash, returns single-use token | |
discard_attachment | ||
| Drafts | create_confirmed_draft | Requires exact conversational confirmation; optionally threads onto a reply target |
There is deliberately no send_message tool.
The MCP client only needs the ability to obtain the bytes of a file and call tools. There is no dependency on a particular client, service, or local directory.
begin_attachment_upload(filename, content_type, size_bytes, sha256_hex).max_chunk_bytes.upload_attachment_chunk(upload_id, chunk_index, data_base64) for indexes 0, 1, 2….finish_attachment_upload(upload_id) and retain the returned attachment_token.create_confirmed_draft(..., user_confirmed=true, attachment_tokens=[token]).Step 8 is the human gate, and it is the only one that matters: the server has no SMTP implementation, so a draft it creates cannot leave your account until you press Send in Proton Mail. Uploaded attachments expire after 30 minutes if no draft consumes them.
| Variable | Default | Purpose |
|---|---|---|
PROTON_BRIDGE_USER | required | Proton address configured in Bridge |
PROTON_BRIDGE_ALIASES | empty | Comma-separated additional From addresses a draft may use |
PROTON_IMAP_PORT | 1143 | Local Bridge IMAP port |
PROTON_MCP_STATE_DIR | ~/.local/state/proton-safe-mcp | Private attachment staging state |
PROTON_MCP_MAX_ATTACHMENT_BYTES | 20971520 | Maximum per file and per draft, capped at 25 MiB |
PROTON_MCP_MAX_RECEIVED_ATTACHMENT_BYTES | 10485760 | Received-file extraction maximum, capped at 25 MiB |
PROTON_MCP_MAX_CHUNK_BYTES | 393216 | Decoded chunk maximum, capped at 1 MiB |
PROTON_MCP_UPLOAD_TTL_SECONDS | 1800 | Attachment staging lifetime |
PROTON_MCP_MAX_BODY_CHARS | 100000 | Maximum outgoing draft body length |
PROTON_BRIDGE_HOST is intentionally unsupported.
For isolated containers without a Secret Service keyring, PROTON_BRIDGE_PASSWORD may contain
the Bridge-generated IMAP password. Avoid this fallback in desktop MCP client configuration:
environment values may be visible to the client process or its diagnostics.
Proton Bridge is not needed for development: the test suite fakes the IMAP layer. Tests cover path rejection, MIME restrictions, received-attachment size and format rejection, bounded PDF/text extraction, ordered chunks, size/hash verification, token consumption, header injection, draft confirmation, recipient and attachment bounds, and HTML-to-text sanitization.
See CONTRIBUTING.md for the design rules that reviews enforce.
Read this before relying on the server in an autonomous workflow:
user_confirmed: true is a client assertion, so the confirmation step depends on the client honoring the rule. It reduces accidents; it is not a boundary against a client under an attacker's influence.127.0.0.1.To report a vulnerability, use GitHub private vulnerability reporting — never a public issue. See SECURITY.md.
MIT © 2026 Francois Bossiere.
This project is not affiliated with or endorsed by Proton AG. "Proton Mail" and "Proton Mail Bridge" are trademarks of Proton AG.