Mail for Zoho

Mail for Zoho

Enables ChatGPT and Codex to interact with Zoho Mail through Zoho's official MCP service, with safe workflows and capability boundaries.

Category
访问服务器

README

Mail for Zoho

An unofficial open-source OpenAI plugin and safety package for Zoho's official Mail MCP service.

ChatGPT or Codex -> Zoho official MCP service -> Zoho Mail APIs

OnlineChefGroep is not in the mailbox data path. This project does not operate a proxy, receive Zoho OAuth tokens, store mailbox content or embed generated Zoho MCP URLs.

Mail for Zoho is not affiliated with or endorsed by Zoho Corporation or OpenAI.

What this solves

Zoho already provides the remote MCP server and its OAuth authorization flow. This repository provides a reusable ChatGPT/Codex package with safe workflow instructions, a reviewed capability boundary, validation and a managed-app submission packet.

A managed ChatGPT app or template is still a platform object. The repository intentionally contains no .app.json, app ID or template ID until OpenAI creates and assigns the real record.

Package contents

  • .codex-plugin/plugin.json — discovery and interface metadata;
  • .mcp.json — local/Codex launcher using the hardened Node wrapper;
  • scripts/runtime-security.mjs — protected config parsing, endpoint validation, child-environment isolation and redaction;
  • skills/zoho-mail/SKILL.md — inbox routing, live mailbox discovery and safety workflow;
  • chatgpt/tool-policy.json — reviewed allow/deny contract and explicit enforcement boundary;
  • openai/submission.json — machine-readable review payload;
  • openai/APP_TEMPLATE.md — managed-template requirements;
  • openai/SUBMISSION.md — directory submission checklist and listing copy;
  • openai/evals.json — routing, privacy, injection and destructive-action evals.

Capability baseline

Release 1 supports mailbox and folder discovery, bounded message listing and search, message/thread reading, attachment metadata, mark read/unread, flag/unflag and drafting reply text in ChatGPT without sending.

Sending, replying, forwarding, deleting, trashing, purging, mailbox administration, delegation and security-setting changes are forbidden by the approved baseline.

The repository does not proxy or filter MCP tools at runtime. Enforce the baseline by selecting only approved tools on the Zoho MCP server, reviewing ChatGPT action controls, and running npm run verify:remote before publication and after every upstream tool change.

Managed ChatGPT setup

The intended installation flow is:

  1. An administrator creates or selects a Zoho MCP server and enables only the approved Mail tools.
  2. Zoho generates a unique secure MCP URL.
  3. The administrator installs Mail for Zoho and configures that URL as a masked secret.
  4. The administrator scans and reviews the tool surface and action controls before publishing the workspace app.
  5. Authorized users connect through Zoho's OAuth flow.

See openai/APP_TEMPLATE.md. Publishing the managed app and assigning its real ID require OpenAI's platform or publisher flow and cannot be simulated in Git.

Direct custom connection

For development or a personal custom app:

  1. Create or select a Zoho MCP server.
  2. Add only the required Zoho Mail tools.
  3. Copy the unique URL from Zoho MCP Console.
  4. Store it outside Git as ZOHO_MCP_URL or in the protected config file documented in .env.example.
  5. Create a custom remote MCP app in a supported ChatGPT surface and choose OAuth.

Detailed checks are in chatgpt/INSTALL.md.

Local bridge security

The optional local/Codex bridge is pinned to mcp-remote@0.1.37. The protected config file is parsed as data and never sourced as shell. It must be a non-symlink regular file with mode 0600 or stricter and may contain only ZOHO_MCP_URL (a legacy MCP_REMOTE_VERSION line is ignored). Default single-account mode resolves ZOHO_MCP_URL, then ZOHO_MCP_ENV, then ~/.config/mail-for-zoho/env. Profile mode uses ~/.config/mail-for-zoho/profiles/<slug>/env and an isolated MCP_REMOTE_CONFIG_DIR. The launcher spawns process.execPath with npx-cli.js (never npx.cmd) and redacts endpoints from stderr.

The launcher passes a minimal environment to npx, excludes unrelated credentials and code-injection variables, disables npm lifecycle scripts and fixes the npm registry. The endpoint remains visible in the bridge process arguments, so do not use the local bridge on an untrusted shared host.

Multiple mailboxes and identities

There are two different multi-account cases:

  1. One authorized Zoho identity can return several mailbox accounts. The assistant always calls ZohoMail_getMailAccounts, maps mailbox addresses to live accountId values and selects automatically only for one returned account or one exact mailbox-address match. Otherwise it lists the available mailbox identities instead of guessing. Results and low-risk mutations stay scoped to one account and retain mailbox provenance.
  2. Two independent Zoho identities require two independent MCP server connections. Each connection uses its own Zoho-generated MCP URL and OAuth cache. Grants, tokens, account IDs and message results are never combined.

For clients such as Cursor that support multiple MCP server entries, copy examples/cursor.multi-account.mcp.json. Create one protected file per profile:

~/.config/mail-for-zoho/profiles/work/env
~/.config/mail-for-zoho/profiles/personal/env

Each file must be a non-symlink regular file with mode 0600 and contain only one unquoted ZOHO_MCP_URL=... line. Start a profile with node scripts/run-local.mjs --profile work. Profile names accept only lowercase letters, digits and single hyphens.

The current managed ChatGPT template has one zoho_mcp_url field. Independent multi-login support is therefore guaranteed only in clients that support multiple MCP server connections.

Verification

npm test

export ZOHO_MCP_URL='RETRIEVE_FROM_A_SECRET_STORE'
npm run verify:remote

npm test validates plugin metadata, submission artifacts, public-source hygiene, pinned Actions, policy truthfulness, runtime isolation, config-file safety and the absence of embedded credentials or fabricated OpenAI IDs. verify:remote performs a sanitized MCP handshake and validates the live tool surface without printing the endpoint.

Publishing

This source tree is intended to be imported into a fresh public repository without the private repository's Git history. Do not make the private operational repository public as-is.

Before submission:

  • verify privacy, terms and support URLs work without authentication;
  • configure required reviewers on the zoho-remote-smoke GitHub environment before storing its secret;
  • run the static and live verification suites on the exact release commit;
  • create the real OpenAI app/template record;
  • add .app.json only after OpenAI supplies a real app ID.

See openai/SUBMISSION.md, PRIVACY.md, TERMS.md, SECURITY.md, SUPPORT.md and NOTICE.

推荐服务器

Baidu Map

Baidu Map

百度地图核心API现已全面兼容MCP协议,是国内首家兼容MCP协议的地图服务商。

官方
精选
JavaScript
Playwright MCP Server

Playwright MCP Server

一个模型上下文协议服务器,它使大型语言模型能够通过结构化的可访问性快照与网页进行交互,而无需视觉模型或屏幕截图。

官方
精选
TypeScript
Magic Component Platform (MCP)

Magic Component Platform (MCP)

一个由人工智能驱动的工具,可以从自然语言描述生成现代化的用户界面组件,并与流行的集成开发环境(IDE)集成,从而简化用户界面开发流程。

官方
精选
本地
TypeScript
Audiense Insights MCP Server

Audiense Insights MCP Server

通过模型上下文协议启用与 Audiense Insights 账户的交互,从而促进营销洞察和受众数据的提取和分析,包括人口统计信息、行为和影响者互动。

官方
精选
本地
TypeScript
VeyraX

VeyraX

一个单一的 MCP 工具,连接你所有喜爱的工具:Gmail、日历以及其他 40 多个工具。

官方
精选
本地
graphlit-mcp-server

graphlit-mcp-server

模型上下文协议 (MCP) 服务器实现了 MCP 客户端与 Graphlit 服务之间的集成。 除了网络爬取之外,还可以将任何内容(从 Slack 到 Gmail 再到播客订阅源)导入到 Graphlit 项目中,然后从 MCP 客户端检索相关内容。

官方
精选
TypeScript
Kagi MCP Server

Kagi MCP Server

一个 MCP 服务器,集成了 Kagi 搜索功能和 Claude AI,使 Claude 能够在回答需要最新信息的问题时执行实时网络搜索。

官方
精选
Python
e2b-mcp-server

e2b-mcp-server

使用 MCP 通过 e2b 运行代码。

官方
精选
Neon MCP Server

Neon MCP Server

用于与 Neon 管理 API 和数据库交互的 MCP 服务器

官方
精选
Exa MCP Server

Exa MCP Server

模型上下文协议(MCP)服务器允许像 Claude 这样的 AI 助手使用 Exa AI 搜索 API 进行网络搜索。这种设置允许 AI 模型以安全和受控的方式获取实时的网络信息。

官方
精选