gmail-mcp-server

gmail-mcp-server

A secure Gmail MCP server that lets Claude search, read, and triage mail, draft replies, and send drafts—with encrypted credential storage, scoped OAuth permissions, and explicit human checkpoints before any irreversible action.

Category
访问服务器

README

Gmail MCP Server

A working example of connecting Claude to a real business tool — Gmail — the way it should be done: with proper login security, the AI only able to do what it's explicitly allowed to do, and no way for it to take an irreversible action (like sending an email) without a clear checkpoint.

The problem this solves

AI assistants like Claude are increasingly expected to do things, not just talk — search an inbox, draft a reply, flag something urgent — instead of a person copy-pasting between a chat window and their actual tools. That capability is genuinely useful, but connecting an AI assistant directly to something as sensitive as an email account raises an obvious question: what happens if it gets it wrong, or is tricked into doing something it shouldn't?

Most quick "connect my AI to my inbox" setups skip past that question — they hand over broad access and hope for the best. That's the gap this project is built to close. It's a demonstration, using a real Google account and the real Gmail API (not a mock or toy example), of what a properly scoped AI-to-business-tool integration looks like: the AI gets exactly the access it needs for the job, nothing more, and the riskiest action (sending real email) requires an explicit extra step rather than happening automatically.

How it stays safe, in plain terms

  • A specific, limited key — not the master key. Logging in grants three narrow permissions (read mail, draft/send mail, apply labels). There is no permission to delete anything, change account settings, or touch anything outside Gmail.
  • The key is locked in a safe. Once you log in, the credentials that let Claude access your inbox are encrypted on your own computer. They're never sent anywhere else, and the encryption key lives only in a local file that's never shared or uploaded.
  • Drafting and sending are two separate, deliberate steps. Claude can prepare a reply as a draft at any time — that's harmless and reversible, the same as you starting an email and not hitting send. Actually sending it is a separate action, clearly flagged to whatever app is running Claude as a sensitive one-way step, so it isn't something that happens as a side effect of Claude just being "helpful."
  • Labels can't be used to hide or destroy mail. Claude can tag messages with custom labels you create (e.g. "Needs Reply"), but it's structurally blocked from touching Gmail's built-in Trash/Spam/Archive controls through that same feature — a subtle way "just add a label" could otherwise be misused.

The full technical breakdown — exact permissions requested, what's reversible vs. not, and what the honest residual risk is — is in SECURITY.md.

Why build this instead of using Google's own Gmail MCP integration

Google has since released its own first-party remote MCP server for Gmail. For someone who just wants Gmail-in-Claude working today, that's the faster path. This project exists for a different reason: to show, on a tool everyone recognizes, the underlying skill of building this kind of integration from scratch — the login flow, the credential storage, the tool design, the safety boundaries — for the many business tools (CRMs, ad platforms, shipping, payments, internal systems) that don't have a ready-made AI integration and need someone to build one deliberately.

See it in action

  1. One-time login: run the authorize command, sign in with Google in the browser that opens, and approve access.
  2. Ask Claude: "Search my inbox for anything from [sender] this week" — it searches, nothing else.
  3. Ask: "Check my inbox and tell me if anything looks urgent" — it pulls a fast summary of recent mail and reasons over it.
  4. Ask: "Draft a reply to that saying I'll follow up tomorrow" — a real draft appears in Gmail. Nothing has been sent.
  5. Only if you then say so, ask Claude to send it — that's the one deliberate, irreversible step in the whole flow.

Under the hood

Tools

Tool Scope Description
gmail_search read Search messages with Gmail search syntax
gmail_read_message read Fetch one message's full body
gmail_list_recent read Fast metadata/snippet fetch for periodic triage
gmail_create_draft write Create a draft (never sends)
gmail_send_draft write Send a previously created draft
gmail_apply_label write Attach a custom (non-system) label

Setup

  1. Install dependencies (requires Python 3.10+; this repo uses uv):

    uv sync
    
  2. Set up Google OAuth and authorize an account — follow workflows/setup_google_oauth.md. Short version:

    cp .env.example .env
    python -c "from cryptography.fernet import Fernet; print(Fernet.generate_key().decode())"
    # paste the output into .env as TOKEN_ENCRYPTION_KEY
    # download credentials.json from Google Cloud Console into the project root
    python -m tools.gmail_mcp.authorize personal
    
  3. Point Claude Desktop/Code at the server. Add to your MCP client config (e.g. claude_desktop_config.json):

    {
      "mcpServers": {
        "gmail": {
          "command": "/absolute/path/to/mcp-business-tools/.venv/bin/python",
          "args": ["-m", "tools.gmail_mcp.server"],
          "cwd": "/absolute/path/to/mcp-business-tools"
        }
      }
    }
    
  4. Restart Claude Desktop/Code so it picks up the new server.

Adding more accounts

See workflows/add_gmail_account.md.

Project layout

workflows/            SOPs: OAuth setup, adding accounts, inbox-summary pattern
tools/gmail_mcp/       the MCP server package
  config.py            env-driven settings, scopes
  auth.py              OAuth flow + encrypted token storage
  gmail_client.py       Gmail API wrapper functions
  server.py             MCP tool definitions
  authorize.py           one-time per-account OAuth CLI
tokens/                encrypted per-account tokens (gitignored)

推荐服务器

Baidu Map

Baidu Map

百度地图核心API现已全面兼容MCP协议,是国内首家兼容MCP协议的地图服务商。

官方
精选
JavaScript
Playwright MCP Server

Playwright MCP Server

一个模型上下文协议服务器,它使大型语言模型能够通过结构化的可访问性快照与网页进行交互,而无需视觉模型或屏幕截图。

官方
精选
TypeScript
Magic Component Platform (MCP)

Magic Component Platform (MCP)

一个由人工智能驱动的工具,可以从自然语言描述生成现代化的用户界面组件,并与流行的集成开发环境(IDE)集成,从而简化用户界面开发流程。

官方
精选
本地
TypeScript
Audiense Insights MCP Server

Audiense Insights MCP Server

通过模型上下文协议启用与 Audiense Insights 账户的交互,从而促进营销洞察和受众数据的提取和分析,包括人口统计信息、行为和影响者互动。

官方
精选
本地
TypeScript
VeyraX

VeyraX

一个单一的 MCP 工具,连接你所有喜爱的工具:Gmail、日历以及其他 40 多个工具。

官方
精选
本地
graphlit-mcp-server

graphlit-mcp-server

模型上下文协议 (MCP) 服务器实现了 MCP 客户端与 Graphlit 服务之间的集成。 除了网络爬取之外,还可以将任何内容(从 Slack 到 Gmail 再到播客订阅源)导入到 Graphlit 项目中,然后从 MCP 客户端检索相关内容。

官方
精选
TypeScript
Kagi MCP Server

Kagi MCP Server

一个 MCP 服务器,集成了 Kagi 搜索功能和 Claude AI,使 Claude 能够在回答需要最新信息的问题时执行实时网络搜索。

官方
精选
Python
e2b-mcp-server

e2b-mcp-server

使用 MCP 通过 e2b 运行代码。

官方
精选
Neon MCP Server

Neon MCP Server

用于与 Neon 管理 API 和数据库交互的 MCP 服务器

官方
精选
Exa MCP Server

Exa MCP Server

模型上下文协议(MCP)服务器允许像 Claude 这样的 AI 助手使用 Exa AI 搜索 API 进行网络搜索。这种设置允许 AI 模型以安全和受控的方式获取实时的网络信息。

官方
精选