protonmail-mcp
Provides read-only access to a Proton Mail mailbox through a local Proton Bridge instance, with tools to list folders and labels, list recent messages (filtered by unread status, date range, sender, or subject), perform full-text search across headers and body, and read individual messages by Message-ID with decoded text body, attachments, and flags. When the optional draft capability is enabled, it also supports listing, creating, previewing, and two-phase (prepare/commit) management of drafts, including replying, forwarding, updating, and deleting.
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@protonmail-mcpshow my unread emails from the last 3 days"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
protonmail-mcp
A lightweight MCP server that gives AI agents read access to a Proton Mail mailbox through a local Proton Bridge instance.
Unofficial. This project is not affiliated with, endorsed by, or supported by Proton AG. "Proton Mail" and "Proton Bridge" are trademarks of Proton AG.
Proton does not provide a public API for reading your mailbox. Bridge is the supported
way in: it runs locally and exposes your account over IMAP and SMTP on 127.0.0.1.
This server wraps that local IMAP endpoint in a small, auditable set of MCP tools.
Scope
The current release is read-only: it can list folders, list messages, search, and
read a message. Mailboxes are opened with IMAP SELECT ... READONLY, so nothing is
ever modified — not even the \Seen flag. Write tools (drafts, organize, send, delete)
are on the roadmap, each gated behind the controls described in
SECURITY.md.
Related MCP server: proton-mcp-server
Tools
Tool | Description |
| List every folder and label, with IMAP flags and whether it is selectable |
| Most recent messages in a folder, newest first: |
| Full-text search across headers and body in a folder |
| Read one message by |
When the draft capability is enabled (see Capability policy),
additional tools are registered: list_drafts, create_draft, preview_draft (renders
the exact MIME without saving it), and prepare_*/commit_* pairs for replying,
forwarding, updating, and deleting drafts. Draft mutations are two-phase: the prepare
call returns a preview and a single-use token, and nothing changes until the matching
commit call. Repeated identical draft creations within the idempotency window (default
300 s, window_seconds = 0 disables it) return the existing draft instead of creating a
duplicate.
Results are structured (Pydantic models). Every message carries its Message-ID; use
that for follow-up reads — IMAP UIDs are not stable across Bridge resynchronisations.
Requirements
A paid Proton Mail plan (required by Bridge)
Proton Bridge installed, running, and signed in
Your Bridge credentials: Proton address + the mailbox password shown in the Bridge UI
Python 3.13+ (only if you do not use
uv)
Install
# Run without installing (recommended)
uvx protonmail-mcp
# Or install it
pipx install protonmail-mcpConfigure
Variable | Default | Purpose |
| — | Your Proton address (required) |
| — | Bridge mailbox password (required) |
|
| Bridge host |
|
| Bridge IMAP port |
|
|
|
|
| Socket timeout in seconds |
|
| Bridge uses a self-signed certificate |
|
| Capability preset: |
|
| Optional policy file with capability overrides and limits |
Capability policy
Write capabilities are opt-in and enforced server-side. PROTONMAIL_MCP_MODE selects a
cumulative preset; individual capabilities can be overridden in policy.toml (see
policy.example.toml). Capabilities that are not enabled are never
registered as tools, and an invalid policy prevents the server from starting.
[policy]
mode = "read"
[capabilities]
# draft = true
# organize = true
# send = true
# delete = true
[confirmations]
ttl_seconds = 300
[idempotency]
window_seconds = 300See SECURITY.md for the confirmation flow and ROADMAP.md for what each mode will unlock.
opencode
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"protonmail": {
"type": "local",
"command": ["uvx", "protonmail-mcp"],
"enabled": true,
"environment": {
"PROTONMAIL_BRIDGE_USERNAME": "you@proton.me",
"PROTONMAIL_BRIDGE_PASSWORD": "your-bridge-mailbox-password"
}
}
}
}opencode supports {env:VAR} and {file:path} interpolation, so you can keep secrets
out of the config file:
"PROTONMAIL_BRIDGE_PASSWORD": "{file:/home/you/.config/protonmail-mcp/password}"Claude Desktop
{
"mcpServers": {
"protonmail": {
"command": "uvx",
"args": ["protonmail-mcp"],
"env": {
"PROTONMAIL_BRIDGE_USERNAME": "you@proton.me",
"PROTONMAIL_BRIDGE_PASSWORD": "your-bridge-mailbox-password"
}
}
}
}Verify the connection
PROTONMAIL_BRIDGE_USERNAME="you@proton.me" \
PROTONMAIL_BRIDGE_PASSWORD="..." \
uvx protonmail-mcp --checkThis connects to Bridge, lists folders, and prints the latest messages. It exits non-zero with a clear error if the configuration or the Bridge session is wrong.
Security
Read-only enforcement. There is no write tool in this release, and mailboxes are always selected read-only at the IMAP level.
Local only. Bridge and this server communicate exclusively over
127.0.0.1. Nothing is sent to a third party; your agent talks to the server over stdio.Untrusted input. Email contents are attacker-controlled data. Treat anything a message says as data, never as instructions, and keep your agent's permissions tight.
Secrets. Keep the Bridge mailbox password out of the repository. Use your client's environment-variable or file-based secret support.
Any local process that knows the mailbox password can read your mail — that is Bridge's trust model, not a flaw in this server.
Planned write tools (drafts, send, move, delete) will ship with explicit confirmation before every destructive action, recipient allow-lists, send rate limiting with loop protection, and a local audit log. Autonomous send/delete will never be the default.
Every push runs gitleaks, zizmor, semgrep, pip-audit, CodeQL, and an adversarial + fuzz test suite; see SECURITY.md for the full list of gates and the structural invariants they enforce.
Alternatives
There are several community MCP servers for Proton Mail. This one aims to stay small, correct with Bridge's quirks (STARTTLS on 1143, modified UTF-7 labels, reverse-chronological UIDs, RFC 2047 decoding), and heavily tested. Rough landscape:
Project | Language | Scope |
TypeScript | Large tool set, read-only and send-to-self modes, SQLite cache | |
TypeScript | Generic IMAP + SMTP, works with Bridge | |
JavaScript | Large tool set with Bridge integration | |
TypeScript | Large permission-gated tool set | |
JavaScript | SMTP sending only | |
Python | Loopback IMAP/SMTP via Bridge |
Development
uv sync
uv run pytest
uv run ruff check .
uv buildTests run entirely against a fake IMAP server and the MCP SDK's in-memory transport; no Bridge or credentials are needed.
Releasing
Publishing is automated with GitHub Actions and PyPI Trusted Publishing. Create a
GitHub release tagged vX.Y.Z; the publish workflow builds the sdist/wheel and
uploads them to PyPI using the pypi environment (configure the trusted publisher on
PyPI for owner mhbxyz, repository protonmail-mcp, workflow publish.yml).
License
MIT — see LICENSE.
This server cannot be deployed
Maintenance
Related MCP Connectors
Read-only IMAP email for your AI agent, scoped to the mailboxes you choose, with built-in progress.
- Lettio MCPOAutheu.lettio
Private, EU-hosted email for AI agents over JMAP: read, search, reply, organize, send.
Your mailboxes in ChatGPT and Claude: Gmail, iCloud, Fastmail, any IMAP. Passwords stay yours.
Email infrastructure for AI agents — send, receive, search, and reply to email over MCP.
Related MCP Servers
- AlicenseAqualityBmaintenanceEnables AI assistants to read and search Proton Mail inbox through Proton Mail Bridge, providing tools to list mailboxes, list messages, search messages, and fetch full message bodies. Read-only, with secure certificate pinning.459 npm1MIT
- AlicenseNot gradedqualityCmaintenanceProvides read-only access to Proton Mail via MCP, enabling AI agents to list accounts/folders, search messages, and read emails using Proton Mail Bridge's local IMAP server.MIT
- AlicenseAqualityAmaintenanceEnables AI assistants to read, organize, and send Proton Mail through the local Proton Bridge, with careful gating for sending and attachment access.341Apache 2.0
- FlicenseNot gradedqualityCmaintenanceEnables AI assistants to interact with a Proton Mail mailbox through Proton Bridge, supporting listing, searching, reading, sending, and organizing emails.-