Skip to main content
Glama
91,523 servers. Updated
20 Best Email MCP Servers: compared and ranked, September 2026Ranked from 2,467 matching servers on stars, growth, downloads and maintenance. Updated .

Matching MCP tools:

Matching MCP Connectors:

"Instructions for accessing Gmail messages programmatically using a cursor" matching MCP servers:

GET /v1/servers – MCP directory API reference
  • A
    license
    A
    quality
    B
    maintenance
    Local-first Gmail MCP server using PKCE + loopback OAuth flow that stores refresh tokens in the OS keychain, enabling secure read/write Gmail access via MCP tools without tokens leaving the device.
    20
    MIT
  • A
    license
    Not graded
    quality
    D
    maintenance
    A privacy-focused MCP server that grants Claude read-only access to Gmail using strict, user-defined filters to control which emails are exposed. It enables searching and fetching email metadata while ensuring data security through OAuth and localized filter enforcement.
    MIT
  • F
    license
    Not graded
    quality
    B
    maintenance
    This MCP server provides secure access to databases for AI agents, enforcing authentication, authorization, human approval, logging, and notifications to prevent dangerous actions.
    -
  • A
    license
    A
    quality
    B
    maintenance
    MCP server that gives an AI assistant simultaneous access to multiple Gmail accounts with per-account read-only, draft, or send tiers, two-phase write confirmation, and safeguards for handling untrusted email content.
    10
    8 npm
    MIT
  • F
    license
    A
    quality
    A
    maintenance
    An MCP server that sends plain-text Gmail messages only to a predefined allowlist, using generated recipient IDs instead of email addresses to enforce security.
    2
    1
    -
  • A
    license
    A
    quality
    F
    maintenance
    Provides AI assistants with specialized tools to interact with NIST's Open Security Controls Assessment Language (OSCAL) framework. It enables agents to retrieve schemas, explore models, and generate valid OSCAL documentation for security compliance automation.
    40
    53
    Apache 2.0
  • F
    license
    D
    quality
    Not graded
    maintenance
    A proof-of-concept attack that exploits Model Context Protocol (MCP) tool registration to achieve persistent agent poisoning in AI assistants like Cursor, embedding malicious instructions that persist across chat contexts without requiring tool execution.
    2
    -
  • A
    license
    Not graded
    quality
    A
    maintenance
    A client-side MCP proxy that injects OAuth 2.0 bearer tokens or API keys into MCP requests, enabling MCP clients to connect to OAuth/API-key-protected MCP servers like Amazon Bedrock AgentCore Gateway. It automatically fetches and refreshes credentials using AgentCore Identity or static values.
    MIT No Attribution
  • A
    license
    Not graded
    quality
    A
    maintenance
    Turn Claude into an ISO 27001 compliance assistant - controls, risk register, policies, evidence tracking, SoA generation, and full audit workflows in one local encrypted MCP server.
    75 npm
    31
    MIT
  • F
    license
    Not graded
    quality
    B
    maintenance
    Enables sending emails via Gmail using SMTP and app passwords without OAuth. It provides a custom authorization flow and encrypted credential storage for multi-user access.
    -
  • A
    license
    Not graded
    quality
    A
    maintenance
    Manage a fleet of OPNsense firewalls from an AI agent, inside guardrails it can't drive around. MCP server for central management of OPNsense firewall fleets. 129 tools across devices, config sync, tasks, schedules, templates, backups and remote consoles - destructive actions confirmation-gated, MCP-issued tokens lifetime-bounded, backup and storage secrets excluded from the toolset entirely.
    Apache 2.0
  • A
    license
    Not graded
    quality
    D
    maintenance
    Provides agent certification and trust verification tools for AI agents, enabling certification checks, trust score calculations, audit ticket issuance, and emergency kill switch activation through the A-SOC trust network.
    1 npm
    1
    -
  • A
    license
    Not graded
    quality
    B
    maintenance
    Enables secure one-time encrypted file and note sharing by encrypting data locally before upload and providing tools for sending, listing, checking, and revoking links.
    MIT
  • A
    license
    Not graded
    quality
    D
    maintenance
    A safety layer and monitoring copilot for AI agents using Splunk MCP, recording tool calls, enforcing policies, and blocking risky actions.
    MIT
  • F
    license
    Not graded
    quality
    C
    maintenance
    A remote MCP server that links World ID 4.0 sessions to AI assistants, enabling verified human authentication and tools for claiming Founding Human places, accessing human grants, and interacting with a verified human wall.
    -
  • F
    license
    Not graded
    quality
    C
    maintenance
    A secure MCP proxy server with JWT authentication, SQL guardrails, rate limiting, and Kafka audit logging, enabling enterprise-grade access control for MCP clients like Cursor and Claude Desktop.
    -
  • A
    license
    A
    quality
    C
    maintenance
    A reference MCP server that enforces identity-aware tool access using role-based permissions (Reader, Analyst, Auditor) and supports multiple identity routes like Entra RBAC, Copilot Studio, and Okta XAA. It provides read-only access to test evidence with explicit denial paths for unauthorized tools.
    7
    MIT