Yahoo Mail ChatGPT MCP
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@Yahoo Mail ChatGPT MCPsummarize my unread emails from the last 24 hours"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
Yahoo Mail ChatGPT MCP
A security-first Yahoo Mail MCP server designed for use with ChatGPT, Claude and other MCP hosts. Reading is the default; a small set of reversible mailbox actions (mark read, flag, move, archive, move to Trash) is available and annotated so hosts can ask for confirmation.
Status: v0.1 foundation. Do not add real Yahoo credentials until CI is green and the deployment has been reviewed.
Architecture
ChatGPT / MCP host
|
| HTTPS + bearer authentication
v
Remote MCP endpoint: /mcp
|
| tool calls (read + annotated mailbox actions)
v
Yahoo Mail reader
|
| IMAPS / TLS 1.2+ / port 993
v
imap.mail.yahoo.comThe server uses the current Model Context Protocol TypeScript SDK v2 and Streamable HTTP. The MCP endpoint is /mcp.
Related MCP server: mail-mcp
Security goals
This project treats mailbox data as high-risk. Yahoo mail may contain OTPs, password-reset links, banking alerts, account identifiers and other authentication material.
The design therefore follows four rules:
Read first, no sending. There is no send tool and nothing permanently deletes mail. Mailbox actions (mark read/unread, flag/unflag, move, archive, move to Trash) are marked with MCP tool annotations (
readOnlyHint,destructiveHint) so the host can require user confirmation.Fail closed. The server refuses to start if Yahoo credentials or MCP authentication are missing or invalid.
Minimize output. Tools return bounded summaries; full raw RFC822 messages are never exposed through MCP.
Sanitize before output. OTPs, verification codes, sensitive login/reset URLs and long card/account-like numbers are redacted before data is returned to the MCP host.
Email body text is treated as untrusted data, never instructions. Every mail-returning tool includes a security notice reminding the caller of this boundary.
Threat model
The main threats considered are:
compromise of the remote MCP endpoint;
accidental public deployment without authentication;
credential leakage through Git, logs, health checks or error responses;
prompt injection embedded in email content;
OTP / reset-link exposure to the model;
excessive email-body disclosure;
DNS rebinding / hostile Origin or Host headers;
brute-force access to the MCP endpoint;
weak or invalid TLS to Yahoo;
unsafe mailbox modifications.
Current mitigations include bearer authentication, constant-time token comparison, Host/Origin validation provided by the MCP Express integration, rate limiting, request-size checks, security headers, bounded tool inputs, TLS verification, read-only IMAP mailbox opens, deterministic sanitization and secret-free error responses.
What the MCP host can access
Read-only tools (readOnlyHint: true)
get_voice_brief
Returns a short plain-text brief across every configured account, one line per email (sender, subject, unread/category). No JSON and no previews, so it is suited to voice conversations in ChatGPT or Claude.
Inputs: hours (1–168, default 24), limit per account (1–10, default 5), unreadOnly (default true).
get_morning_brief_emails
Returns a small set of recent, sanitized emails prioritized for a morning brief.
Inputs:
hours: 1–168, default 24limit: bounded byMAX_EMAILS_PER_REQUESTunreadOnly: optional
Output includes safe metadata such as UID, folder, sender, subject, timestamp, unread state, attachment presence, sanitized preview, category and importance score.
get_all_accounts_morning_brief
Returns one bounded, sanitized result containing every configured Yahoo account. Each account is labeled with its email address and reports ok or failed independently. Scheduled morning and evening briefs should use this tool instead of making separate per-account calls, so a connector can discover one stable all-account action and preserve partial results when an account is unavailable.
Inputs:
hours: 1–168, default 24limit: bounded byMAX_EMAILS_PER_REQUEST, applied per accountunreadOnly: optional
list_emails, search_emails, read_email, read_email_attachments, list_folders
List, search and read sanitized, size-limited mail and attachment text, and list folder names.
Mailbox actions (readOnlyHint: false)
Tool | Annotation | Effect |
| non-destructive | toggles the seen flag |
| non-destructive | toggles the star |
| non-destructive | moves mail between folders |
| destructive | moves mail to Trash (recoverable in Yahoo) |
What the MCP host cannot access
There are deliberately no MCP tools for:
sending mail;
permanently deleting (expunging) mail;
changing Yahoo account settings;
retrieving the Yahoo app password;
retrieving environment variables;
retrieving raw unsanitized RFC822 messages.
Sensitive-content redaction
The sanitizer attempts to redact:
4–8 digit OTP / verification / login / security codes when authentication context is present;
codes separated with spaces, dashes or punctuation;
password-reset and account-recovery URLs;
login / magic-link / authentication URLs and token-bearing URLs;
long card/account-like digit sequences;
bearer/JWT-like token strings;
active HTML tags, scripts and styles.
Example:
Your verification code is 492811becomes:
Your verification code is [REDACTED]Redaction reduces risk but is not a mathematical guarantee. The stronger protection is data minimization: use get_morning_brief_emails for normal workflows and reserve read_email for explicit requests.
Yahoo authentication
Use a Yahoo app-specific password, not your normal Yahoo account password.
Never paste the password into ChatGPT and never commit it to GitHub.
Copy the environment template:
cp .env.example .envThen provide values locally or, preferably, through your hosting provider's secret manager:
YAHOO_EMAIL=you@example.com
YAHOO_APP_PASSWORD=your-yahoo-app-specific-password
MCP_API_TOKEN=a-long-random-token-at-least-32-charactersGenerate MCP_API_TOKEN using a cryptographically secure password/token generator. Do not reuse another password.
Local development
Requirements: Node.js 20+.
npm install
cp .env.example .env
npm run devThe default bind is 127.0.0.1:3000.
Health check:
curl http://127.0.0.1:3000/healthExpected response:
{"status":"ok"}The health endpoint intentionally contains no email address, Yahoo state, token details, IMAP diagnostics or environment information.
Testing
npm run lint
npm run typecheck
npm test
npm run buildTests do not require real Yahoo credentials. CI performs these checks for pushes and pull requests.
Docker
Build:
docker build -t yahoo-mail-chatgpt-mcp .Run with secrets supplied at runtime:
docker run --rm \
-p 127.0.0.1:3000:3000 \
--env-file .env \
yahoo-mail-chatgpt-mcpFor a public container deployment set:
HOST=0.0.0.0
ALLOWED_HOSTS=mcp.example.comTerminate TLS at a trusted reverse proxy or managed hosting platform and expose HTTPS only.
Managed deployment
The service can run on Render, Railway, Fly.io or a conventional VPS/container host. It does not depend on any specific existing server.
Production checklist:
deploy from a reviewed commit;
configure
YAHOO_EMAIL,YAHOO_APP_PASSWORDandMCP_API_TOKENusing the platform's secret storage;set
HOST=0.0.0.0only when required by the platform;set
ALLOWED_HOSTSto the exact public MCP hostname;keep HTTPS enabled at all times;
do not enable request/body logging at the proxy;
rotate the MCP token and Yahoo app password after any suspected compromise;
keep the tool surface free of send and permanent-delete actions.
Connecting to ChatGPT
ChatGPT custom apps connect to remote MCP servers. In ChatGPT developer mode, create a custom app and provide the deployed HTTPS MCP endpoint, for example:
https://mcp.example.com/mcpThe exact authentication options offered by ChatGPT can evolve. This repository currently implements a static bearer-token gate suitable for private deployments and MCP clients that can send an Authorization: Bearer ... header.
If your ChatGPT custom-app setup requires OAuth rather than a static bearer credential, do not disable authentication. Add or place a standards-compliant OAuth/OIDC layer in front of /mcp instead. OpenAI recommends refresh-token support when OAuth is used so connectivity can be maintained after access-token expiry.
The server must never be changed to accept unauthenticated /mcp traffic merely to make a client connect.
Connecting to Claude
Claude (claude.ai web, desktop and mobile apps) connects to remote MCP servers as custom connectors.
Deploy with
PUBLIC_URLset to the exact public HTTPS origin (for examplehttps://mcp.example.com).OAUTH_REDIRECT_ORIGINSalready includeshttps://claude.aiandhttps://claude.comby default; if you have overridden it, add them back.In Claude, open Settings → Connectors → Add custom connector and enter
https://mcp.example.com/mcp.Claude discovers OAuth automatically:
/.well-known/oauth-protected-resource/mcp(RFC 9728), also advertised in theWWW-Authenticateheader of a 401;/.well-known/oauth-authorization-server(RFC 8414);/registerfor dynamic client registration (RFC 7591).
When the browser opens the authorize page, paste your
MCP_API_TOKEN. Claude receives a short-lived access token plus a refresh token, so it stays connected without re-entering the token.
Leave Advanced settings (OAuth Client ID / Secret) empty; registration is automatic.
Voice: whether custom connectors are available in voice conversations depends on the Claude app and plan. For spoken summaries ask for the voice brief (get_voice_brief), which returns short plain text instead of JSON.
OAuth tokens
Access tokens last
ACCESS_TOKEN_TTL_SECONDS(default 90 days).Refresh tokens last
REFRESH_TOKEN_TTL_SECONDS(default 365 days) and are rotated on every refresh. They are signed with a separate key and cannot be used as bearer credentials.Bump
TOKEN_EPOCHto revoke every issued access and refresh token at once (all connected hosts must re-authorize).
Existing ChatGPT connections are unaffected: the authorization-code flow, token format and master-token bearer access are unchanged. ChatGPT now also receives a refresh token, which it can use when its access token expires.
Credential rotation
Rotate the MCP bearer token
Generate a new random token.
Update the hosting secret.
Restart/redeploy the service.
Update the authorized MCP client/app.
Invalidate the old token by ensuring it is no longer present anywhere in deployment configuration.
Rotate Yahoo access
Revoke the Yahoo app-specific password in Yahoo account security.
Create a new app-specific password.
Replace the hosting secret.
Restart/redeploy.
Your normal Yahoo password should not need to change solely because an app-specific password was revoked.
Incident response
If the server, deployment account or Yahoo app password may have been compromised:
Disable or scale down the MCP service immediately.
Revoke the Yahoo app-specific password.
Rotate
MCP_API_TOKEN.Review hosting access/audit logs without copying message bodies into tickets or chat.
Review Git history for accidentally committed secrets.
Re-deploy from a known-good reviewed commit.
Reconnect the MCP client only after authentication and sanitization have been revalidated.
Logging policy
Application logs intentionally contain operational events only. Do not add logging of:
email bodies or previews;
subjects or sender addresses;
Yahoo credentials;
bearer tokens;
Authorization headers;
MCP request bodies;
parsed environment variables.
Project layout
src/
config.ts fail-closed environment validation
index.ts HTTPS-facing MCP application entry point
mcp.ts MCP tool definitions and annotations
yahoo.ts Yahoo IMAP reader
security/
auth.ts bearer authentication
redact.ts deterministic secret/content sanitization
tests/
redact.test.ts
config-auth.test.ts
.github/workflows/ci.yml
Dockerfile
.env.exampleSecurity note
This repository is public, so assume every committed byte is permanently visible. Never commit .env, credentials, tokens, real email samples, OTPs or Yahoo app passwords.
See SECURITY.md for the security policy.
This server cannot be deployed
Maintenance
Related MCP Connectors
Your mailbox for MCP clients: search, read, draft, send, rules and notes. Sending is off by default.
Your own IMAP mailbox in any MCP client: search, read, flag, move; send and delete need confirm.
1Hosted email MCP for your own Gmail, Outlook.com, Microsoft 365, iCloud or IMAP inbox: read, search, draft, reply in thread, forward and file mail. It moves or flags up to 500 messages in one call, and a send leaves exactly one copy in Sent. A calendar is a separate connection, and connecting one adds diary and scheduling tools.
Email infrastructure for AI agents — send, receive, search, and reply to email over MCP.
Related MCP Servers
- AlicenseNot gradedqualityDmaintenanceEnables reading, searching, composing, and managing Yahoo Mail emails via IMAP with OAuth support for both local and remote MCP clients.24 npmISC
- AlicenseNot gradedqualityBmaintenanceEnables read-only Gmail access via MCP, allowing users to list and retrieve email messages with query and pagination support.4MIT
- AlicenseNot gradedqualityCmaintenanceEnables authenticated, read-only access to mailbox folders, tags, message metadata, and message text via MCP, while preventing send, draft, delete, move, tag-change, contact/calendar changes, and attachment downloads.MIT
- AlicenseAqualityBmaintenanceEnables MCP clients to read, search, and manage a Yahoo Mail mailbox over IMAP and send or forward messages over SMTP, with multiple accounts selectable per call and writes defaulting to drafts, trash, or dry-runs until explicitly confirmed.13MIT