Gmail + Calendar MCP Server
A multi-account MCP server providing 72 tools for Gmail and Google Calendar, with password protection, environment variable-based credentials, and support for multiple accounts.
README
Gmail + Calendar MCP Server
A multi-account Model Context Protocol server for Gmail and
Google Calendar (72 tools). Runs over stdio, installs via uvx, and takes all credentials
from environment variables — the host running the server never needs a credentials.json or
token.json file.
- One shared Google OAuth "Desktop" client authorizes every account.
- Each account contributes only its refresh token (one token covers both Gmail and Calendar).
- Every tool takes an
accountargument to pick the account and an optionalpassword(see below).
How credentials work (2 env vars + 1 optional)
| Variable | Required | Format | Example |
|---|---|---|---|
GMAIL_CLIENT |
yes | client_id|client_secret |
123-abc.apps.googleusercontent.com|GOCSPX-xxxx |
GMAIL_ACCOUNTS |
yes | selector=refresh_token pairs, separated by ; or newlines |
alice@gmail.com=1//0gFoo;work=1//0gBar |
PASSWORDS |
no | selector=password pairs, separated by ; or newlines |
alice@gmail.com=hunter2;work=s3cret |
The selector defaults to the account's email but you can rename it to a short alias
(work, personal). You never hand-write the credential values — the gmail-mcp-auth command prints them.
Password protection (optional)
Set PASSWORDS to require a per-account password on every tool call. When it's set, the
gate is on: each call must pass password matching that account's entry, or the tool returns
Invalid password for account '…' and does nothing (no Gmail request is made). Passwords are
compared in constant time. Notes:
- Keys must match your
GMAIL_ACCOUNTSselectors (case-insensitively). APASSWORDSkey that matches no account makes the server refuse to start. An account with noPASSWORDSentry is locked (no password can unlock it) while the gate is on — the server logs which accounts are locked at startup. - Passwords cannot contain
=,;, or newlines (those are the separators), and leading/trailing whitespace is trimmed. Pick passwords without those characters. - Fail-closed: if
PASSWORDSis set but has no validselector=passwordentries (e.g. only separators), the server errors out instead of silently running unprotected. Only an absent (or blank)PASSWORDSturns the gate off, in which case thepasswordargument is ignored. - Comparison is case-sensitive and constant-time. This is an authorization gate for the calling agent, not transport encryption — the value lives in the same environment as the tokens.
One-time setup
1. Create a Google OAuth client (once)
- In Google Cloud Console create/select a project.
- Enable the Gmail API.
- Configure the OAuth consent screen (External is fine; add yourself as a Test user, or publish).
- Create OAuth client ID → Desktop app. Note the client id and client secret.
2. Authorize each account (on a machine with a browser)
# From PyPI (after publishing — see "Publishing" below):
uvx --from gmail-calendar-mcp gmail-calendar-mcp-auth --client-id <ID> --client-secret <SECRET>
# Or straight from GitHub, no publish needed:
uvx --from git+https://github.com/eitan3/Gmail_MCP.git gmail-mcp-auth --client-id <ID> --client-secret <SECRET>
⚠️ The bare name
gmail-mcpbelongs to an unrelated PyPI package — don't use it. This project is published asgmail-calendar-mcp.
A browser opens for Google consent. On success the command prints:
GMAIL_CLIENT="<id>|<secret>"
GMAIL_ACCOUNTS="alice@gmail.com=1//0g..."
Add more accounts (re-uses the client from GMAIL_CLIENT in your env if set):
gmail-mcp-auth --merge --alias work # prints the full merged GMAIL_ACCOUNTS
If several Google accounts are signed into your browser, pass --login-hint you@example.com to
target the right one (also handy for re-consenting a specific account after a scope upgrade):
gmail-mcp-auth --merge --login-hint personal@gmail.com
Headless host? Use --no-browser and open the printed URL yourself (forward the redirect
port over SSH if consent happens on another machine).
3. Configure your MCP client
{
"mcpServers": {
"gmail": {
"command": "uvx",
"args": ["gmail-calendar-mcp"],
"env": {
"GMAIL_CLIENT": "…id…|…secret…",
"GMAIL_ACCOUNTS": "alice@gmail.com=1//0g…;work=1//0g…",
"PASSWORDS": "alice@gmail.com=hunter2;work=s3cret"
}
}
}
}
uvx gmail-calendar-mcp works once the package is published to PyPI. Before that (or to skip
PyPI entirely), use "args": ["--from", "git+https://github.com/eitan3/Gmail_MCP.git", "gmail-mcp"].
Publishing to PyPI
The bare-name uvx gmail-calendar-mcp requires the package on PyPI. To publish a release:
uv build # builds dist/*.whl and *.tar.gz
uv publish --token pypi-XXXX # upload (get the token from pypi.org -> Account -> API tokens)
- Create a free account at https://pypi.org, then Account settings → API tokens → Add token
(scope "Entire account" for the first upload). The token starts with
pypi-. - Each upload needs a new
versioninpyproject.toml(PyPI rejects re-uploading the same version). - Prefer a quick dry run on TestPyPI first:
uv publish --publish-url https://test.pypi.org/legacy/ --token <testpypi-token>.
Tools
Send send_email · reply_to_message · forward_message
Drafts create_draft · list_drafts · send_draft · update_draft · delete_draft
Read get_profile · get_message · search_messages · search_threads · get_thread
Attachments get_message_attachments · download_attachment
Trash trash_message · untrash_message · trash_thread · untrash_thread
Labels list_labels · create_label · update_label · delete_label ·
label_message · unlabel_message · label_thread · unlabel_thread
Filters list_filters · create_filter · delete_filter
Signature get_signature · update_signature
Vacation get_vacation_responder · set_vacation_responder
State (extra) mark_read · mark_unread · star · unstar · archive ·
move_to_inbox · mark_important · mark_not_important
Batch (extra) batch_modify_messages · batch_trash · batch_untrash
Every tool accepts account (alias or email). With a single configured account it's optional;
with several, omitting it returns an error listing the available selectors. Every tool also accepts
password, which is required only when PASSWORDS is configured (see Password protection above).
Example tool call (tools/call arguments) with the password gate enabled:
{
"name": "search_messages",
"arguments": { "account": "work", "password": "s3cret", "query": "is:unread", "max_results": 10 }
}
Label arguments accept human names (e.g. Clients/Acme) or raw label ids. Search tools use
Gmail query syntax (e.g. is:unread from:alice newer_than:7d).
Google Calendar
Calendar shares the same accounts and password gate — every calendar tool takes the same account
and password arguments and is routed through the identical authentication path.
Events list_events · get_event · create_event · update_event · delete_event ·
quick_add_event · move_event · list_event_instances · respond_to_event · import_event
Calendars list_calendars · get_calendar · create_calendar · update_calendar ·
delete_calendar · clear_calendar · subscribe_calendar · unsubscribe_calendar ·
update_calendar_subscription
Sharing list_acl · share_calendar · update_acl · unshare_calendar
Misc get_freebusy · list_settings · get_setting · get_colors
Conventions:
- Time: pass
start/endas RFC3339 (2026-06-15T10:00:00) withtime_zone(IANA, e.g.Asia/Jerusalem), or setall_day=truewith aYYYY-MM-DDdate. Calendar ops default to theprimarycalendar whencalendar_idis omitted. - Recurring:
recurrenceis a list of RRULE strings, e.g.["RRULE:FREQ=WEEKLY;BYDAY=MO;COUNT=8"]. - Invites:
attendeesis an email list;add_meet=trueattaches a Google Meet link;send_updates∈all/externalOnly/nonecontrols attendee notifications. extra_fields(a dict) merges into the event body so any Calendar field is reachable.
⚠️ Re-auth required for Calendar. Tokens minted before Calendar was added only have Gmail scopes — Calendar calls return a 403 with a re-auth hint until you re-run
gmail-mcp-auth(re-consent) for each account and replace its token inGMAIL_ACCOUNTS. Gmail keeps working throughout.
Scopes
Gmail: gmail.modify, gmail.compose, gmail.settings.basic (no permanent delete — only Trash).
Calendar: calendar, calendar.settings.readonly.
Local development
uv sync --extra dev
uv run gmail-mcp-auth --client-id <ID> --client-secret <SECRET> # mint a token
$env:GMAIL_CLIENT="…"; $env:GMAIL_ACCOUNTS="…" # PowerShell
uv run gmail-mcp # run the server (stdio)
npx @modelcontextprotocol/inspector uv run gmail-mcp # interactive tool testing
uv run pytest # unit tests
推荐服务器
Baidu Map
百度地图核心API现已全面兼容MCP协议,是国内首家兼容MCP协议的地图服务商。
Playwright MCP Server
一个模型上下文协议服务器,它使大型语言模型能够通过结构化的可访问性快照与网页进行交互,而无需视觉模型或屏幕截图。
Magic Component Platform (MCP)
一个由人工智能驱动的工具,可以从自然语言描述生成现代化的用户界面组件,并与流行的集成开发环境(IDE)集成,从而简化用户界面开发流程。
Audiense Insights MCP Server
通过模型上下文协议启用与 Audiense Insights 账户的交互,从而促进营销洞察和受众数据的提取和分析,包括人口统计信息、行为和影响者互动。
VeyraX
一个单一的 MCP 工具,连接你所有喜爱的工具:Gmail、日历以及其他 40 多个工具。
graphlit-mcp-server
模型上下文协议 (MCP) 服务器实现了 MCP 客户端与 Graphlit 服务之间的集成。 除了网络爬取之外,还可以将任何内容(从 Slack 到 Gmail 再到播客订阅源)导入到 Graphlit 项目中,然后从 MCP 客户端检索相关内容。
Kagi MCP Server
一个 MCP 服务器,集成了 Kagi 搜索功能和 Claude AI,使 Claude 能够在回答需要最新信息的问题时执行实时网络搜索。
e2b-mcp-server
使用 MCP 通过 e2b 运行代码。
Neon MCP Server
用于与 Neon 管理 API 和数据库交互的 MCP 服务器
Exa MCP Server
模型上下文协议(MCP)服务器允许像 Claude 这样的 AI 助手使用 Exa AI 搜索 API 进行网络搜索。这种设置允许 AI 模型以安全和受控的方式获取实时的网络信息。