Yahoo Mail MCP Server
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| PORT | No | Port for HTTP mode (auto-set by Render) | 3000 |
| ENV_FILE | No | Env file to load, relative to `server.js` (e.g. `.env.test` for a test account) | .env |
| NODE_ENV | No | Environment: `development` or `production` | development |
| TRUST_PROXY | No | Express "trust proxy" setting. Set to `1` on Render so sign-in lockouts apply per client address. Don't set it when the server is reached directly, or clients could fake their address | |
| YAHOO_EMAIL | No | Your Yahoo Mail email address | |
| IMAP_IDLE_MS | No | Log out of the shared IMAP connection after this many milliseconds without use | 300000 |
| AUTH_USERNAME | No | Username for the sign-in page | |
| DRAFTS_FOLDER | No | Drafts folder name. Normally detected from the server's `\Drafts` folder flag (Yahoo: `Draft`) | auto-detected |
| TRANSPORT_MODE | No | `stdio`, or `http` for remote access (Streamable HTTP at `/mcp` + legacy SSE at `/mcp/sse`; `sse` is an alias) | stdio |
| OAUTH_CLIENT_ID | No | OAuth 2.0 client ID for MCP server authentication (generate with `openssl rand -hex 16`) | |
| AUTH_TOTP_SECRET | No | Base32 authenticator secret from `npm run setup-login`; when set, sign-in also asks for a 6-digit code | |
| AUTH_PASSWORD_HASH | No | scrypt hash of the sign-in password, from `npm run setup-login` (plain passwords are rejected) | |
| YAHOO_APP_PASSWORD | No | 16-character app-specific password from Yahoo | |
| OAUTH_CLIENT_SECRET | No | OAuth 2.0 client secret for MCP server authentication (generate with `openssl rand -hex 32`) | |
| OAUTH_REDIRECT_HOSTS | No | Hostnames allowed as OAuth redirect targets (https only; subdomains allowed; localhost is always allowed). Add other clients, e.g. `chatgpt.com` | claude.ai,claude.com |
| ALLOW_UNAUTHENTICATED | No | Set to `true` to run HTTP mode without OAuth or a sign-in. **Local testing only**: anyone who can reach the server can read and change the mailbox | |
| OAUTH_ACCESS_TOKEN_TTL | No | Access token lifetime in seconds | 3600 |
| OAUTH_REFRESH_TOKEN_TTL | No | Refresh token lifetime in seconds (30 days). Each refresh token can be used once and is replaced | 2592000 |
| ALLOW_CLIENT_CREDENTIALS | No | Set to `true` to allow the `client_credentials` grant, which skips the sign-in page. Only for trusted machine-to-machine use |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| list_emailsA | List recent emails from a Yahoo Mail folder. Returns UIDs (permanent identifiers) and enriched metadata including size, flags, and attachment status. |
| read_emailA | Read email content using UIDs (permanent identifiers). UIDs don't change when emails are deleted. Get UIDs from list_emails or search_emails. |
| search_emailsA | Search emails using UIDs with advanced filters. Returns UIDs which are permanent identifiers that don't change when emails are deleted. Get UIDs from results for subsequent operations. |
| delete_emailsA | Move emails to Trash folder using UIDs (soft delete, recoverable). UIDs are permanent identifiers. |
| archive_emailsC | Move emails to Archive folder using UIDs for long-term storage. UIDs are permanent identifiers. |
| mark_as_readB | Mark emails as read using UIDs. UIDs are permanent identifiers. |
| mark_as_unreadC | Mark emails as unread using UIDs. UIDs are permanent identifiers. |
| flag_emailsB | Flag emails as important/starred using UIDs. UIDs are permanent identifiers. |
| unflag_emailsB | Remove flag/star from emails using UIDs. UIDs are permanent identifiers. |
| move_emailsA | Move emails to a specified folder using UIDs. UIDs are permanent identifiers. Use list_folders to see available folders. |
| download_attachmentsA | Download attachments from an email (by UID) and save them to disk. Returns the saved file paths. Use read_email to see attachment names first. |
| create_draftA | Create a new email draft and save it to the Yahoo Mail Drafts folder. The email is NOT sent; the user reviews and sends it from Yahoo Mail. Returns the full draft and its UID. To revise the draft later, call update_draft with that UID. |
| create_reply_draftA | Create a reply to an existing email (by UID) and save it as a draft. Fills in the recipients, "Re:" subject, and threading headers so the reply stays in the same conversation. The email is NOT sent. Returns the full draft and its UID; use update_draft with that UID to revise it. |
| update_draftA | Revise an existing draft in the Drafts folder. Only the fields you pass are changed; everything else (recipients, subject, reply threading, attachments) is kept. IMPORTANT: the draft gets a NEW UID on every update. Always use the UID returned by the most recent create/update call. The old version is removed. The email is NOT sent. |
| list_foldersA | List all available IMAP folders/mailboxes in your Yahoo Mail account |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
TDQS
Scored across 15 tools
Tools target distinct actions on UIDs or drafts; delete/archive/move overlap slightly because delete and archive are specialized moves, but descriptions clarify intent. No two tools are indistinguishable.
Most tools follow verb_noun (list_emails, create_draft), but mark_as_read/mark_as_unread use a different pattern and read_email is singular while list/search use plural. Still readable and predictable overall.
15 tools is well-scoped for an email management server, covering message retrieval, flags, folders, attachments, and drafts without excessive surface.
Core read/manage/draft workflows are covered, but there is no send operation—agents can only create drafts—and no folder creation/deletion. This is a notable gap for an email client, though the draft-only design may be intentional.