Connect your mail to Claude or ChatGPT. Step by step.

From your first app password to your first question, “what came in from accounting this week”. Shared server: 10 minutes. Your own server for a company: another 15. In a hurry? A short version with a Czech/English switch is at https://mailai.netbear.nu/start, and you can let your ChatGPT or Claude walk you through it: send it the link https://mailai.netbear.nu/llms.txt.

What this is

mailmcp is a small server that gives Claude or ChatGPT access to your mailboxes: Gmail, iCloud, Fastmail, Yahoo, Zoho or any IMAP account, several at once if you like. Claude can then search, read, summarise and prepare replies as drafts. Sending, moving and deleting are switched off until you turn them on yourself.

The crucial difference from off-the-shelf connectors: your mail passwords never travel through OpenAI or Anthropic in readable form and the server never stores them. Your whole configuration travels inside a single encrypted token. The key to it is split in two halves: one is in the token, the other (the master key) lives only on the server. Anyone holding just the token (logs at OpenAI, for example) can read nothing. Anyone holding just the master key has no configuration. Only the server can decrypt, and only at the moment it is handling a request for you.

WhoWhat they see
Youeverything
Your mail provider (Google, Microsoft…)what it always saw
OpenAI / Anthropic (ChatGPT, Claude)the results the assistant asked for, and your token as unreadable ciphertext
Operator of the shared server (the person or company running it)the master key; your data only in memory during your request, nothing at rest
Hosting (Vercel)the same as the operator
The author of mailmcpnothing

Companies and teams where everyone has their own token on one server will find an overview at https://mailai.netbear.nu/teams. A detailed security breakdown (who sees what, the four rules, a permissions table) is at https://mailai.netbear.nu/security.

Which path to take

Shared serverThe recommended start. You use this server (https://mailai.netbear.nu), generate a token and paste it into ChatGPT, claude.ai, Claude Code or another client. No installation, no hosting.
Your own serverYou want the master key under your own control too (a company, a team). You deploy mailmcp to your own Vercel account with a single secret; everyone else then uses your server exactly like the shared one.
My computer onlyClaude Desktop or Claude Code locally. Nothing runs outside your computer, but it will not work from your phone or from ChatGPT.

Steps 1 to 3 describe the shared server. Your own server and the local variants come later.

Step 1 · Passwords for your accounts

mailmcp signs in to mailboxes over IMAP/SMTP, exactly like the mail app on your phone. Most providers require an app password for that: a special password you generate and can revoke at any time without changing your main password. Prepare one now for every mailbox. Outlook.com and Microsoft 365 are the exception: there you type no password at all, you sign in at Microsoft in step 2.

Gmail

  1. Turn on two-step verification: myaccount.google.com → Security → 2-Step Verification. Without it Google will not offer app passwords: the page myaccount.google.com/apppasswords says “The setting you are looking for is not available for your account”. Nothing is wrong with the account, 2-Step Verification is simply off; turn it on and reload the page.
  2. Open myaccount.google.com/apppasswords, enter mailmcp as the name and click Create.
  3. Google shows 16 characters in four groups. Copy them (the spaces do not matter). You will see this password only once.
Google Workspace accounts: app passwords have to be allowed by your domain administrator. If the option is missing, ask IT, or use a different account.

Outlook / Microsoft 365

Microsoft needs no password from you. App passwords are blocked on most accounts, so you sign in to Outlook.com and to company Microsoft 365 at Microsoft itself. You never type a password into mailmcp; you only confirm to Microsoft what mailmcp may do with your mail. The sign-in happens in step 2 on the setup page, once per mailbox, and is protected by the same invite code as creating the token. The variant where you type a code additionally requires an invite code always, even on a server that otherwise lets anyone create a token.

  1. In the setup form pick the provider Outlook / Microsoft 365 for that mailbox and click Sign in with Microsoft.
  2. One of two things happens, depending on the server. On mailmcp.ai (and on your own server whose address is registered with Microsoft) a window opens with the Microsoft account picker: choose the account, sign in, and the window closes by itself. On your own server whose app registration does not list the server's address you get two buttons instead of one, because Microsoft handles sign-in with a code in a different place for each kind of account: Personal account (Outlook.com, Hotmail) or Work or school account (Microsoft 365). Pick the one you sign in with. The setup page then shows a short code and the address to enter it at: microsoft.com/link for a personal account, login.microsoft.com/device for a work account (both are Microsoft’s own pages). Type the code and sign in; the setup page waits in the meantime and carries on by itself once you are signed in. New Microsoft 365 tenants have security defaults switched on, which block sign-in with a code; then the server operator has to set up sign-in through a window, see below.
  3. Microsoft shows what mailmcp is asking for. The list follows the boxes you ticked for that mailbox: a read-only mailbox asks for “Read your mail”, “Sign you in and read your profile” and “Maintain access to data you have given it access to”. Turn on drafts, sending, labels or Trash and it also asks for “Read and write access to your mail” and “Send mail as you”. Your tick boxes in mailmcp still decide: the Microsoft consent is the ceiling, and inside it mailmcp allows only what you switched on. Widening the permissions later needs a new sign-in. The other way round, removing capabilities does not shrink the permission you already granted at Microsoft: sign in again with fewer capabilities ticked, or revoke the app at Microsoft.
  4. After the sign-in the address is filled in from what Microsoft returned for that account, and locked. Shared mailboxes and send-as aliases are not supported yet.
Up to three Microsoft mailboxes fit in one token, as long as the token stays under its size limit: the sign-in is long and it travels inside the token, and a work account’s is longer still, so usually two of those fit. The setup page says so before it hands you a token that would not work. Add another Microsoft account the same way: the Microsoft window gets the address you typed, and if it offers an account you are already signed in to, choose “Use another account”. With sign-in by code open Microsoft’s address in a private window.

A sign-in lasts about 90 days. The date is shown next to the mailbox on the setup page and the assistant can tell you as well (“list my accounts”, the reauth_by field). A client that refreshes its connection on the server’s own sign-in page (claude.ai including the mobile app, Claude Code connected that way) carries the renewed Microsoft sign-in; other clients holding the same token keep the original one and reach that date on their own schedule. If you paste the token as a header, or use a ChatGPT connector, you sign in again after ninety days.

How to sign in again: on the setup page load the token with your edit password, click Sign in again on that mailbox and generate the token once more. In ChatGPT and claude.ai remove the connector and add it again; in Claude Desktop paste the new configuration. Without an edit password the token cannot be loaded back and has to be built from scratch.

Changing your mailbox password does not end the sign-in, because mailmcp holds no password of yours. You take access away at Microsoft: personal accounts at account.live.com/consent/Manage, work accounts at myapps.microsoft.com under the mailmcp app. Revoking there disconnects every mailmcp token that used that account.

Work accounts. Until Microsoft has verified the publisher you will see an unverified-publisher notice on the consent screen; the app is called mailmcp and the publisher is Swinging Dogs s.r.o. If your organisation leaves consent to administrators, the sign-in ends with “Need admin approval”. Send your administrator this link: https://login.microsoftonline.com/organizations/adminconsent?client_id=ac867c04-6aec-4664-b4c7-dbf020f4907a. It approves the app for the organisation; the permissions each mailbox asks for stay exactly as above.

What is different with Outlook: messages are addressed by a long text id instead of a number, which the assistant handles on its own; after a message is moved it uses the new id the server returns. Labels are Outlook categories, and a move to Trash lands in Deleted Items. If the mailbox uses an online archive, a message id changes when the message moves into the archive; just have the assistant find it again.

Microsoft sign-in on your own server

For operators of their own server. Microsoft sign-in on your server needs an app registration of your own: the mailmcp registration is used on mailmcp.ai only, so that nobody can run a sign-in with a code under our name. Sign-in through a window, which works for personal and work accounts alike, needs a registration that lists your server’s address:

  1. In Microsoft Entra open App registrations → New registration. Supported account types: Accounts in any organizational directory and personal Microsoft accounts.
  2. Under Authentication add the platform Mobile and desktop applications (not Web) with the redirect URI https://<your host>/api/ms/callback. mailmcp is a public client without a secret; under the Web platform Microsoft would require one and the sign-in would end with AADSTS7000218.
  3. In the same place set Allow public client flows to Yes.
  4. Under API permissions add the delegated Microsoft Graph permissions Mail.Read, Mail.ReadWrite, Mail.Send, User.Read and offline_access.
  5. On the server set MAILMCP_MS_CLIENT_ID=<Application (client) ID> and MAILMCP_MS_REDIRECT=1 and redeploy. The setup page then offers sign-in through a window for Outlook.

Organisations that allow consent only to apps from verified publishers need publisher verification on your registration (Publisher verification in Microsoft Entra, which requires Microsoft AI Cloud Partner Program membership), or an administrator’s consent for the whole organisation.

iCloud

  1. account.apple.com → Sign-In and Security → App-Specific Passwords → Generate.
  2. In the setup form enter the full address (for example name@icloud.com); mailmcp works out the difference between the IMAP and SMTP logins on its own.

Fastmail, Yahoo, Zoho

All three require an app password from the account security settings (Fastmail: Settings → Privacy & Security → Integrations). Fastmail does not offer IMAP access on the Basic plan.

Your own domain, company server

Have ready the IMAP server address and port (usually 993), the SMTP server address and port (465 or 587), the login name and the password. You will find them in your hosting provider's instructions under “mail client settings”.

Step 2 · Creating your token

Open https://mailai.netbear.nu/setup. The page runs in your browser: the passwords you type into it are encrypted before anything leaves your computer. Only a 32-byte encryption key goes to the server, which seals it with its master key and hands it back. Nothing is stored.

  1. Accounts. For every mailbox pick the provider, enter a short Account id (for example personal, work; the assistant will use it in its answers), the e-mail address and the password from step 1. For your own server fill in the IMAP/SMTP details as well. With the provider Outlook / Microsoft 365 a Sign in with Microsoft button appears instead of the password field: the steps are in the Outlook section, the address fills itself in, and up to three such mailboxes belong in one token, as long as the token stays under its size limit (a work account’s sign-in token is larger, so usually two fit).
  2. Permissions. Tick what the assistant may do with that mailbox. A good starting point: Read & search and Create drafts. Turn sending on only together with an allowlist (for example @yourcompany.com), otherwise the assistant cannot send anything at all.
  3. Edit password. Choose a password you will use later to load the token back, when you want to add a mailbox or change permissions. Assistants never see it, so a token on its own can never hand over your mail passwords. Without it the token can later only be created again from scratch.
  4. Click Generate my token. Copy Your mailmcp token (the long text starting with mmt1.). Save it in your password manager: whoever holds it can read your mail through this server.
The section “Options for your own single-owner deployment” and the values MAILMCP_CONFIG / MAILMCP_KEY are not needed on a shared server. They are for your own deployment and for Claude Desktop.

Step 3 · Connecting clients

The server address is https://mailai.netbear.nu/mcp. The token is used in two ways: as a bearer token where the client can send headers, or pasted into the login page where the client uses OAuth.

ChatGPT

  1. Settings → Connectors (or Apps & Connectors) → in the advanced settings turn on Developer mode. Custom connectors are available on the Plus, Pro, Business, Enterprise and Edu plans.
  2. Create → name “mailmcp”, URL https://mailai.netbear.nu/mcp.
  3. Authentication: either OAuth (ChatGPT opens the server's login page, where you paste your token), or, if the form offers a bearer token, paste the token straight in. Do not add any other headers or variables.
  4. Enable the connector in the chat and try: “List my mail accounts.”
Two ways to add it. ChatGPT can add a connector on the chatgpt.com website or inside the app, and the two behave slightly differently. Add it on the website: it is then available everywhere, in the apps and in the browser, and ChatGPT looks for tools there first. If the assistant claims a tool is missing (sending, say) although your token permits it, tell it to look at the connected mailmcp tools. ChatGPT stores the tool list when the connector is added; after changing the rights in your token, click Refresh in the connector settings or add it again. Leave authentication on Automatic; if that reports an error, pick Dynamic Client Registration (DCR).

claude.ai (web, mobile, Claude Desktop)

  1. Settings → Connectors → Add custom connector, URL https://mailai.netbear.nu/mcp, save, Connect.
  2. The server's login page opens. Paste your token and confirm. The connector is then active in the mobile app as well. Requires the Pro plan or higher.

Claude Code

claude mcp add --transport http mailmcp https://mailai.netbear.nu/mcp \
  --header "Authorization: Bearer mmt1.…your whole token…"

Cursor, VS Code, Gemini CLI and others

Same address, the token either as a bearer header or through OAuth sign-in. The exact snippets are in the details for individual clients.

Your own shared server

If you want to run the server for yourself or for a team, you need three values: the master key MAILMCP_KEY, the invite code MAILMCP_INVITE_CODE and the license key MAILMCP_LICENSE (Personal €19 once for one person and up to 5 mailboxes; Unlimited €149 for shared token mode within one organization; pricing at https://mailai.netbear.nu/pricing). The server stores nothing, so it needs no database; for personal use the free Hobby plan on Vercel is enough, for a company use Vercel Pro or Docker.

  1. Accounts at github.com and vercel.com.
  2. Click the Deploy button on https://mailai.netbear.nu/deploy: Vercel copies the distribution repository kojott/mailmcp-dist into your GitHub account and asks for all three variables right away. (Manually: fork the repository and in Vercel choose Add New → Project → Import.)
  3. Under Environment Variables add MAILMCP_LICENSE (the key from the e-mail you got after buying), MAILMCP_INVITE_CODE (the invite code, at least 8 characters; without it the server issues no tokens) and MAILMCP_KEY: 32 random bytes in base64url. Generate them in a terminal with node -e "console.log(require('crypto').randomBytes(32).toString('base64url'))", or on the setup page in the section for your own deployment (the MAILMCP_KEY field). Save the key in your password manager: losing it invalidates every user token.
  4. Deploy. At https://your-project.vercel.app you will see the home page in shared mode; users create their tokens at /setup.
Never change the master key without telling your users: every change invalidates all issued tokens and everyone has to generate a new one.

Licensing: one license = one running installation; you can move it to another server at any time. The terms, including the refund within 14 days of each new purchase, are in the LICENSE file in the repository.

Mail servers on a private network: a user token names its own IMAP and SMTP servers. So that a public server cannot be used to probe the operator's network, hosts from tokens are resolved before connecting and private, loopback, link-local and CGNAT addresses (and localhost, .local, .internal) are refused; the connection is then pinned to the vetted address while TLS still verifies the original hostname. Public providers (Gmail, iCloud, Fastmail, your own mail.company.com) are unaffected. A company whose mail server lives on a private address deploys mailmcp inside its network and sets MAILMCP_ALLOW_PRIVATE_MAIL_HOSTS=1. The owner configuration (MAILMCP_CONFIG) is never subject to this check.

The invite code is required: MAILMCP_INVITE_CODE (at least 8 characters) belongs next to MAILMCP_KEY and MAILMCP_LICENSE as the third required value. Only someone who knows the code can then create a token on the setup page (an “Invite code” step appears). Without it the server issues no tokens at all and the setup page shows a notice for the operator; otherwise anyone who knows the address could create a token on your server and use up your limits. Forgot the code? Read it in your environment variables on Vercel or in Docker, or set a new one and redeploy; tokens already issued keep working. A deliberately public server (like mailmcp.ai) sets MAILMCP_OPEN_SIGNUP=1 instead of a code.

Microsoft sign-in on your own server: it needs a Microsoft Entra app registration of your own. Create it as described in the Outlook section, put its id into MAILMCP_MS_CLIENT_ID and add MAILMCP_MS_REDIRECT=1; your users then sign in through a window and see your application’s name on the consent screen. Without your own registration the setup page offers no Microsoft sign-in. MAILMCP_MS_DISABLED=1 hides the Microsoft sign-in entirely, and MAILMCP_DISABLE_GRAPH=1 additionally refuses to serve Microsoft mailboxes even in tokens already issued. The desktop build for Claude Desktop asks GitHub once on every start whether a newer version exists; MAILMCP_NO_UPDATE_CHECK=1 turns that off.

Your own reverse proxy (Docker, VPS): set MAILMCP_PUBLIC_URL to the public address of the server. Without it the server does not trust X-Forwarded-* headers (on Vercel it trusts them automatically).

Optionally you can also add MAILMCP_CONFIG with the operator's own mailboxes to your server; it then works as a single-user server (connector password, your own bearer token) and a shared one at the same time.

My computer only · A · Claude Desktop

For the local variants you need the values MAILMCP_CONFIG and MAILMCP_KEY from the “Values for your own deployment” section of the setup page, not a token.

  1. Download mailmcp.mcpb from the latest release on GitHub.
  2. Double-click it (or in Claude Desktop: Settings → Extensions → Install Extension). You need Node.js 20 or newer installed; Claude Desktop will tell you if it is missing.
  3. Paste MAILMCP_CONFIG and MAILMCP_KEY into the form. They are stored in your computer's system keychain.
  4. Open a new chat and write: “List my mail accounts.” Claude should call the list_accounts tool.
In this variant nothing runs outside your computer. When the computer sleeps, the connector does not work; for mobile use path B.

B · Your own single-user server on Vercel

An alternative to the shared server for anyone who wants everything in their own account but does not want to install anything. The procedure is the same as for your own shared server, except that instead of a master key you set two variables holding your configuration.

  1. Create an account at github.com and at vercel.com (sign in with GitHub, it saves a few steps).
  2. Make your own copy of the distribution repository on GitHub: on github.com/kojott/mailmcp-dist click Fork (or use the Deploy button at /deploy).
  3. In Vercel: Add New → Project → Import and pick your mailmcp fork. Vercel detects the app on its own; change nothing.
  4. Before clicking Deploy, expand Environment Variables and add MAILMCP_CONFIG and MAILMCP_KEY from step 2. (If you forget, you can add them later under Settings → Environment Variables and then pick Redeploy on the Deployments tab.)
  5. Click Deploy. In a minute you get an address like https://mailmcp-xyz.vercel.app. Open it: you should see the home page with your mailboxes. The /health address returns {"ok":true}.
  6. In claude.ai: Settings → Connectors → Add custom connector. As the URL enter your address with /mcp at the end, for example https://mailmcp-xyz.vercel.app/mcp. Save and click Connect.
  7. Your server's login page opens. Enter the connector password from the setup (not your e-mail password). Once confirmed, the connector is active in the mobile app and in Claude Desktop too.
Custom connectors are available on the Claude Pro, Max, Team and Enterprise plans. On Team/Enterprise they are added by the organisation owner.

C · Claude Code locally

Against the shared server the command from step 3 is all you need. Locally, with no hosting (requires Node.js 22+):

claude mcp add mailmcp -e MAILMCP_CONFIG="mmc1..." -e MAILMCP_KEY="..." -- npx -y mailmcp

To verify: claude mcp list shows mailmcp as connected.

Details for ChatGPT, Cursor, VS Code, Gemini CLI and others

Every tool connects to an address ending in /mcp. Two ways to sign in: OAuth (the client opens the server's login page, where you paste your token) or a bearer token in a header, where you paste the same token. The examples below use the address of your own server; on the shared server substitute https://mailai.netbear.nu/mcp.

ChatGPT

  1. In ChatGPT open Settings → Connectors (in some versions Settings → Apps & Connectors) and turn on Developer mode in the advanced settings. Custom connectors are available on the Plus, Pro, Business, Enterprise and Edu plans.
  2. Click Create (or +), enter the name “mailmcp” and as the URL your address with /mcp, for example https://mailmcp-xyz.vercel.app/mcp. Leave the authentication set to OAuth.
  3. ChatGPT redirects you to the server's login page. Paste your token (on your own single-user server, the connector password).
  4. Enable the connector in the tools menu of the chat. ChatGPT uses the search and fetch tools, which mailmcp provides for it: “search” searches all mailboxes with one query (Gmail syntax works for Gmail accounts, and you can pick a single mailbox with the prefix account:work), “fetch” reads one specific message. In Developer mode ChatGPT also has all the other tools available, drafts included.
ChatGPT requires PKCE, dynamic client registration or a Client ID Metadata Document, and the issuer confirmation on the redirect. mailmcp does all of that; there is nothing else to configure.
Two ways to add it. ChatGPT can add a connector on the chatgpt.com website or inside the app, and the two behave slightly differently. Add it on the website: it is then available everywhere, in the apps and in the browser, and ChatGPT looks for tools there first. If the assistant claims a tool is missing (sending, say) although your token permits it, tell it to look at the connected mailmcp tools. ChatGPT stores the tool list when the connector is added; after changing the rights in your token, click Refresh in the connector settings or add it again. Leave authentication on Automatic; if that reports an error, pick Dynamic Client Registration (DCR).

Cursor

The file ~/.cursor/mcp.json (globally) or .cursor/mcp.json in a project:

{
  "mcpServers": {
    "mailmcp": {
      "url": "https://mailmcp-xyz.vercel.app/mcp",
      "headers": { "Authorization": "Bearer mmt1.…your whole token…" }
    }
  }
}

Without the headers entry Cursor starts an OAuth sign-in in the browser; both variants work.

VS Code (GitHub Copilot)

The MCP: Add Server command → HTTP → address https://mailmcp-xyz.vercel.app/mcp. On the first connection VS Code opens the browser to sign in (OAuth). Written by hand into mcp.json:

{
  "servers": {
    "mailmcp": {
      "type": "http",
      "url": "https://mailmcp-xyz.vercel.app/mcp"
    }
  }
}

Gemini CLI

gemini mcp add --transport http --header "Authorization: Bearer mmt1.…your whole token…" \
  mailmcp https://mailmcp-xyz.vercel.app/mcp

Or in ~/.gemini/settings.json as "mailmcp": { "httpUrl": "https://…/mcp", "headers": { "Authorization": "Bearer …" } }.

Windsurf, Zed, Continue, JetBrains and others

Anywhere you can enter a “remote MCP server” with a Streamable HTTP address and an Authorization: Bearer … header, the same snippet as for Cursor works. Clients that speak OAuth sign in with the connector password.

How to work with it

Talk to Claude normally; it picks the tools itself. Questions that work well:

  • “List my mail accounts and what you are allowed to do with them.”
  • “What came in over the last three days across all accounts? Group it by account and tell me what needs a reply.”
  • “Find invoices with an attachment from this month in my work account.” (Gmail also understands queries like from:accounting has:attachment newer_than:30d.)
  • “Read me the last message from Chris Miller and prepare a polite reply as a draft.” You will find the draft in the Drafts folder of your mail app and send it yourself.
  • “Mark all newsletters from this week as read.” (works only with the Flag / label / move permission enabled)
ToolWhat it doesWhen it is available
list_accountslist of mailboxes and permissionsalways
search, fetchsimplified search and read for ChatGPT and similar clientsRead & search
search_messagessearch in one mailbox or all of themRead & search
get_message, get_threadreads a message and a whole threadRead & search
get_attachmentattachment as text, or a download link valid for an hourRead & search (downloadable attachments are the default)
reply_drafta reply as a draft in the same thread: headers, “Re:”, recipients and the quoted original are set by the serverCreate drafts
reply_sendsends the reply straight away, allowlisted recipients onlySend + allowlist
get_signature, set_signaturethe signature kept in the folder “mailmcp-signature” of your mailbox (HTML and images): show or storeRead & search / Create drafts
create_draftsaves a draft, sends nothingCreate drafts
send_messagesends only to recipients on the allowlist, attachments includedSend + allowlist
send_draftsends a saved draft exactly as it is, attachments includedSend + allowlist
forward_messageforwards a message with all its attachments (or saves it as a draft)Send + allowlist / Create drafts
upload_attachment, request_upload, list_uploadshanding a file to the assistant: text or base64 directly, larger files through a one-hour upload linkCreate drafts or Send
modify_messageread, starred, labels, move, archiveFlag / label / move
trash_messagemoves to trash, never a permanent deleteMove to trash

Threaded replies and the signature

When you say “reply” or “write a draft”, the draft lands in the same thread: the server sets the threading headers, the “Re:” subject, the recipients (everyone on “reply to all”) and quotes the original under the reply, as your mail client does. “Write me a reply” or “suggest a reply” only shows a suggestion in the chat; “send” sends, provided sending is enabled and the recipient is allowed.

Signature. A plain-text signature goes straight into the token form. A signature with a photo or logo does not belong in the token: tick “Signature with a photo or logo: take it from my mailbox” in the form, then send yourself an e-mail with your signature from your usual mail client and move it into the folder mailmcp-signature (create it, or let the assistant create it with “set my signature”). The newest message in that folder is your signature; its images are embedded in every reply, nothing is stored with us. To change it, put a newer message into the folder. Ask the assistant “show my signature” any time.

Attachments

Attachments do not load up the assistant's context. For every message the assistant gets a list of attachments and, for each one, a download link valid for one hour. You click it and the file downloads straight from the server (which fetches it from your mailbox at that moment) without ever passing through OpenAI or Anthropic. Text attachments (TXT, CSV, JSON, XML) can also be read by the assistant directly; the contents of any other file go into the context only when you explicitly ask (“load the contents of that attachment for me”, up to 2 MB). The link works for anyone who has it, for an hour, so pass it on as carefully as a password.

PDF. For PDF attachments up to 5 MB the assistant gets the extracted text straight away (up to 20,000 characters), so it does not have to ask for the contents. The text comes out as it is stored in the file, so it can include passages that are invisible in the rendered PDF; treat it as somebody else’s text, not as an instruction. A scanned PDF with no text layer stays a download link.

Limits you set during setup: the length of a message body per read (8,000 characters by default), how many messages may be sent per hour, and whether attachments are listed only or downloadable too.

Sending attachments

The assistant can send an attachment as well, and the file never goes through the chat. Three ways:

  • An attachment already in your mail: “Forward that invoice to accounting.” The assistant uses forward_message, or attaches one specific attachment to a draft or an outgoing message; the server takes it straight from the mailbox.
  • A file the assistant wrote: a contract, a CSV, a quote. The assistant hands it over with upload_attachment and attaches it.
  • A file from your disk: the assistant asks for a one-hour upload link (request_upload). Claude Code, Cursor or Gemini CLI can send the file themselves (curl -T file link); in ChatGPT or claude.ai you open the link and drop the file in. In Claude Desktop the path to a file in an allowed folder is enough.
  • Saving attachments to disk (Claude Desktop, Claude Code): allow folders in Claude Desktop under Settings → Extensions → mailmcp → Attachment folders (a fresh install has Downloads filled in; after an update from an earlier version the field is empty, pick the folder and restart Claude Desktop); in Claude Code with MAILMCP_ATTACHMENT_DIRS. Then “save the attachments from the accountant’s last email” writes the files themselves, PDFs included.

Uploaded files wait in the mailmcp-uploads folder of your mailbox (the server keeps nothing) and are deleted once attached. The limit is 20 MB per message; on Vercel an upload through a link handles roughly 4 MB per file, so send larger files by forwarding them from your mail, or run mailmcp in Docker.

Changing your configuration

Shared server: at the bottom of the setup page expand “Edit an existing configuration”, paste your current token and your edit password and click Load. The form fills itself in (the passwords are decrypted only in your browser). Add a mailbox or change permissions, click Generate my token again and put the new token into your clients in place of the old one (for ChatGPT and claude.ai: disconnect and connect again). The old token stops working as soon as you delete the app password it contains at your provider.

Your own single-user server: Settings → Environment Variables → edit MAILMCP_CONFIG → Deployments → Redeploy. Claude Desktop: Settings → Extensions → mailmcp → Configure.

To revoke access at any time: delete the app password at your provider (Google, Microsoft, Apple…). The server then cannot get into the mailbox, no matter who holds the token. Microsoft mailboxes have no password: take access away at account.live.com/consent/Manage (personal accounts) or myapps.microsoft.com (work accounts).

Troubleshooting

Google does not offer app passwords: “The setting you are looking for is not available for your account”

Google shows app passwords only with 2-Step Verification turned on. Enable it at myaccount.google.com → Security → 2-Step Verification (a phone or SMS is enough), then open myaccount.google.com/apppasswords again. On Google Workspace accounts the domain administrator must also allow app passwords.

“List my accounts” works, but searching reports a sign-in error (Invalid credentials, AUTHENTICATIONFAILED)

A wrong or invalid app password. For Gmail check that two-step verification is on and that the password has 16 characters. Generate a new one, load the configuration in the setup page, fix the password and deploy again.

I forgot my edit password, or I never set one

The token cannot be loaded back. Create a new token from scratch on the setup page (entering the mailboxes again), this time with an edit password, and swap it in your assistants. You invalidate the old token by deleting the app password at your provider and creating a new one.

Outlook says you have to sign in again (or the sign-in failed)

A Microsoft sign-in lasts about 90 days and is also ended by revoking access at Microsoft; changing your mailbox password does nothing to it. On the setup page load the token with your edit password, click Sign in again on that mailbox and generate the token once more; in ChatGPT and claude.ai remove the connector and add it again, in Claude Desktop paste the new configuration. Without an edit password the token has to be built from scratch. If the sign-in ended with “Need admin approval”, your organisation requires an administrator to approve the app; the link is in the Outlook section. Claude Desktop users sign in on the setup page of mailmcp.ai, and sign in again there too.

An attachment link does not work (“Download link is invalid or has expired”)

Links are valid for one hour. Ask the assistant to load the message again; you will get a fresh link.

The server shows “This server needs a license key”

The MAILMCP_LICENSE variable is missing or invalid, or the configuration exceeds the license (Personal: at most 5 mailboxes in the configuration and in every token; Unlimited has no cap). Without MAILMCP_LICENSE the server runs for free: up to 2 mailboxes per token (tokens created before 0.7.0 keep 5). The page states the exact reason. After fixing the variable, hit Redeploy.

“Token was not issued by this server”

The token was created on a different server, or the operator changed the master key. Create a new token on the setup page of the server you are connecting to.

ChatGPT or Cursor complains that the header is too long

The token carries the whole configuration; with many accounts it can exceed the header limit of some clients (roughly 8 kB). Create a token holding only the mailboxes you need in that client, or use the OAuth sign-in, where the limit does not apply.

Claude says the account “does not allow send/draft/modify”

That permission is not enabled for that mailbox. Turn it on in the setup (Edit existing) and update the configuration. This is by design: the default state is read-only.

“Recipient not in send_allowlist”

Sending is allowed, but the recipient is not on the list. Add the address or the domain (@company.com) to the allowlist, or let Claude create a draft and send it yourself.

The Vercel page shows the error “No configuration” or “Could not decrypt”

The MAILMCP_CONFIG and MAILMCP_KEY variables are missing, come from different pairs, or you did not Redeploy after changing them. Check that the blob starts with mmc1. and that you copied the whole line with no extra spaces.

claude.ai connector: “Unknown client_id”, or the sign-in ends with an error

Open the connector URL without /mcp in a browser; the home page has to appear. Then remove the connector in claude.ai and add it again. The address has to be exactly the one from Vercel, including https:// and with /mcp at the end.

The connector is added, but Claude “sees” no tools

In the connector settings in claude.ai check that it is enabled for the current chat (the connector icon under the message box). Failing that, sign out and connect again with the connector password.

The connection is slow, or the first query times out

On Vercel every query signs in to the IMAP server again, so expect 1 to 3 seconds. Try the query again; when searching all accounts, narrow the period (“over the last week”, for example).

Gmail: Claude searches “All Mail”, not just the inbox

That is by design: everything including the archive is searched. Say “in the inbox only” or use the Gmail operator in:inbox.

I want to know exactly what the server sends where

The server talks only to your mail servers and to your client (ChatGPT, Claude). No telemetry, no phoning home; the license is verified locally only. The distribution repository is on GitHub; the source code is not provided; the data flow for review (by a DPO, for example) is described in the security audit.

Security in five sentences

The server has been through a security audit (cryptography, OAuth, the mail layer, the web, operations). The known limitations of the stateless design, which the audit confirmed: the protection against replaying an authorization code holds within a single instance (the code is valid for 3 minutes and is protected by PKCE), access tokens are valid for 30 days (because of ChatGPT, which does not refresh them itself) and cannot be revoked individually before they expire (refresh tokens last 90 days); the only immediate revocation is deleting the app password at your provider, sign-in attempt limits are counted per server instance, and attachment links are valid for an hour for anyone holding them.

  • E-mail is untrusted content: the server strips hidden text and marks message bodies as data, so that a forged e-mail cannot “instruct” Claude. Even so: check whatever Claude proposes to send.
  • Start with read-only and drafts. Turn sending on only with a narrow allowlist.
  • Keep your token in a password manager, like a password. Whoever holds it can read your mail through this server; without the server's master key, though, it is unreadable for anyone else (OpenAI and Anthropic included). A token on its own never hands over your mail passwords: loading it back into the form also requires the edit password, which assistants never see.
  • Use app passwords, not your main account password. They can be revoked at any time with one click.
  • Signing in to the connector is limited to 5 attempts per 15 minutes; access tokens are valid for 30 days and refresh automatically.

What it protects, what it reduces, and what it cannot solve

Protects: mailbox passwords (encrypted in your browser; the server holds one key and stores nothing), scope (permissions per mailbox, reading by default), sending (only to allowlisted addresses, so a planted instruction cannot mail your data to a stranger) and deletion (never permanent, only Trash).

Reduces, does not remove: instructions hidden in e-mails. Hidden text is stripped, bodies reach the model as quoted data, headers are sanitized. The model can still follow an instruction in plain text; the damage is bounded by the permissions above: a draft or a mail to an allowed address, not exfiltration and not deleted mail.

Does not protect: the content of mail the assistant reads is seen by the model and its vendor. Whatever it reads it can repeat in its reply or hand to another tool you have enabled in ChatGPT or Claude. That is the connector's edge, not a setting. So connect only mailboxes whose content the assistant may see, and leave sending off until you need it.

Napojte svou poštu na Claude nebo ChatGPT. Krok za krokem.

Od prvního hesla pro aplikace po první dotaz „co mi tento týden přišlo od účetní“. Sdílený server: 10 minut. Vlastní server pro firmu: dalších 15. Spěcháte? Zkrácená verze s přepínáním češtiny a angličtiny je na https://mailai.netbear.nu/start, a svého ChatGPT nebo Claude můžete nechat, ať vás provede: pošlete mu odkaz https://mailai.netbear.nu/llms.txt.

Co to je

mailmcp je malý server, který dává Claude nebo ChatGPT přístup k vašim e-mailovým schránkám: Gmail, Seznam.cz, Volný.cz, iCloud, Fastmail, Yahoo, Zoho nebo libovolný IMAP účet, klidně několik najednou. Claude pak umí poštu prohledávat, číst, shrnovat a připravovat odpovědi jako koncepty. Odesílání, přesouvání a mazání jsou vypnuté, dokud je sami nezapnete.

Zásadní rozdíl proti hotovým konektorům: hesla k poště nikdy neputují přes OpenAI ani Anthropic v čitelné podobě a server si je neukládá. Vaše nastavení cestuje v jednom zašifrovaném tokenu. Klíč k němu je rozdělený na dvě půlky: jedna je v tokenu, druhá (hlavní klíč) jen na serveru. Kdo má jen token (například logy u OpenAI), nepřečte nic. Kdo má jen hlavní klíč, nemá žádné nastavení. Rozšifrovat umí jen server v okamžiku, kdy pro vás vyřizuje požadavek.

KdoCo vidí
Vyvše
Váš poštovní provider (Google, Seznam…)to, co viděl vždy
OpenAI / Anthropic (ChatGPT, Claude)výsledky, které si asistent vyžádal, a váš token jako nečitelný šifrovaný text
Provozovatel sdíleného serveru (lektor, firma)hlavní klíč; vaše data jen v paměti během vašeho požadavku, nic v klidu
Hosting (Vercel)totéž co provozovatel
Autor mailmcpnic

Firmy a týmy, kde má každý svůj token na jednom serveru, najdou přehled na https://mailai.netbear.nu/teams. Podrobný bezpečnostní rozbor (kdo co vidí, čtyři pravidla, tabulka oprávnění) je na https://mailai.netbear.nu/security.

Kterou cestu zvolit

Sdílený serverDoporučeno pro kurz. Použijete tento server (https://mailai.netbear.nu), vygenerujete si token a vložíte ho do ChatGPT, claude.ai, Claude Code nebo jiného klienta. Bez instalace, bez hostingu.
Vlastní serverChcete mít i hlavní klíč pod svou kontrolou (firma, tým). Nasadíte mailmcp do vlastního Vercel účtu s jedním tajemstvím; ostatní pak používají váš server stejně jako sdílený.
Jen můj počítačClaude Desktop nebo Claude Code lokálně. Nic neběží mimo váš počítač, ale nefunguje z mobilu ani z ChatGPT.

Kroky 1 až 3 popisují sdílený server. Vlastní server a lokální varianty jsou dál.

Krok 1 · Hesla k účtům

mailmcp se do schránek přihlašuje protokolem IMAP/SMTP, tedy stejně jako poštovní program v telefonu. Většina poskytovatelů k tomu vyžaduje heslo pro aplikace: speciální heslo, které vygenerujete a kdykoli zrušíte, aniž byste měnili hlavní heslo. Pro každou schránku si ho připravte teď. Výjimka je Outlook.com a Microsoft 365: tam žádné heslo nezadáváte, přihlásíte se přímo u Microsoftu v kroku 2.

Gmail

  1. Zapněte dvoufázové ověření: myaccount.google.com → Zabezpečení → Dvoufázové ověření. Bez něj Google hesla pro aplikace nenabídne: stránka myaccount.google.com/apppasswords hlásí „Nastavení, které hledáte, není pro váš účet k dispozici“ (anglicky „The setting you are looking for is not available for your account“). Není to chyba účtu, jen chybí dvoufázové ověření; zapněte ho a stránku načtěte znovu.
  2. Otevřete myaccount.google.com/apppasswords, jako název zadejte mailmcp a klikněte na Vytvořit.
  3. Google ukáže 16 znaků ve čtyřech skupinách. Zkopírujte je (mezery nevadí). Toto heslo uvidíte jen jednou.
Pracovní účet Google Workspace: hesla pro aplikace musí povolit správce domény. Pokud volba chybí, požádejte IT, nebo použijte jiný účet.

Outlook / Microsoft 365

U Microsoftu žádné heslo nevytváříte. Hesla pro poštovní programy Microsoft u většiny účtů zakázal, a tak se k Outlook.com i k firemnímu Microsoftu 365 přihlásíte přímo u něj. Do mailmcp tedy nepíšete žádné heslo; Microsoftu jen potvrdíte, co smí mailmcp s poštou dělat. Přihlášení proběhne až v kroku 2 na setup stránce, u každé schránky zvlášť, a chrání ho stejný pozvánkový kód jako vytvoření tokenu. Varianta s opisováním kódu navíc pozvánkový kód vyžaduje vždy, i na serveru, který jinak tokeny vydává komukoli.

  1. V setupu zvolte u schránky poskytovatele Outlook / Microsoft 365 a klikněte na Přihlásit se přes Microsoft.
  2. Podle nastavení serveru se stane jedno ze dvou. Na mailmcp.ai (a na vlastním serveru, který má svou adresu zaregistrovanou u Microsoftu) se otevře okno s výběrem účtu Microsoft: vyberete účet, přihlásíte se a okno se zavře samo. Na vlastním serveru, jehož registrace aplikace adresu serveru zapsanou nemá, se místo jednoho tlačítka ukážou dvě, protože přihlášení kódem funguje u Microsoftu pro každý druh účtu jinde: Osobní účet (Outlook.com, Hotmail), nebo Pracovní nebo školní účet (Microsoft 365). Zvolte ten, kterým se budete přihlašovat. Setup stránka pak ukáže krátký kód a adresu, na které ho zadáte: u osobního účtu microsoft.com/link, u pracovního login.microsoft.com/device (obě stránky jsou Microsoftu). Kód opíšete a přihlásíte se; setup stránka mezitím čeká a po přihlášení pokračuje sama. Nové firemní tenanty Microsoft 365 mají zapnuté výchozí zabezpečení (security defaults), které přihlášení kódem blokuje; pak je potřeba, aby provozovatel serveru nastavil přihlášení v okně, viz níže.
  3. Microsoft ukáže, co po něm mailmcp žádá. Rozsah se řídí tím, co jste té schránce zaškrtli: schránka jen pro čtení si řekne o „Read your mail“, „Sign you in and read your profile“ a „Maintain access to data you have given it access to“. Jakmile zapnete koncepty, odesílání, štítky nebo koš, přibude „Read and write access to your mail“ a „Send mail as you“. Rozhoduje dál to, co jste zaškrtli v mailmcp: souhlas u Microsoftu je strop, mailmcp uvnitř něj dovolí jen to, co jste zapnuli. Když práva rozšíříte později, je potřeba se přihlásit znovu. A naopak: odebrání schopností nezmenší oprávnění, které jste u Microsoftu už udělili — pro to se přihlaste znovu s méně zaškrtnutými schopnostmi, nebo aplikaci odvolejte u Microsoftu.
  4. Po přihlášení se adresa vyplní sama podle toho, co o účtu vrátil Microsoft, a zamkne se. Sdílené schránky a odesílání pod aliasem zatím podporované nejsou.
Do jednoho tokenu se vejdou až tři schránky Microsoftu, pokud se token vejde do velikostního limitu: přihlášení je dlouhé a veze se celé v tokenu, u firemních účtů je ještě delší, takže obvykle se vejdou dvě. Setup stránka to řekne dřív, než by vám vydala token, který by nefungoval. Další účet Microsoftu přidáte stejně: okno Microsoftu dostane adresu, kterou jste napsali; když nabídne jiný, už přihlášený účet, zvolte „Použít jiný účet“. Při přihlášení kódem otevřete adresu Microsoftu v anonymním okně.

Přihlášení platí zhruba 90 dní. Datum uvidíte u schránky na setup stránce a řekne vám ho i asistent („vypiš mé účty“, údaj reauth_by). Klient, který se k serveru přihlašuje na jeho přihlašovací stránce (claude.ai včetně mobilní aplikace, Claude Code připojený tímto způsobem), si při každém obnovení spojení odnese protažené přihlášení u Microsoftu; ostatní klienti, které máte na stejném tokenu, drží dál to původní. Kdo vkládá token jako hlavičku nebo má konektor v ChatGPT, přihlásí se po devadesáti dnech znovu.

Jak se přihlásit znovu: na setup stránce načtěte token heslem pro úpravy, u schránky klikněte na Přihlásit se znovu a token vygenerujte znovu. V ChatGPT a claude.ai pak konektor odeberte a přidejte znovu, v Claude Desktop vložte novou konfiguraci. Bez hesla pro úpravy token načíst nejde a musíte ho poskládat od začátku.

Změna hesla ke schránce přihlášení nezruší, protože mailmcp žádné vaše heslo nemá. Přístup odeberete u Microsoftu: osobní účty na account.live.com/consent/Manage, pracovní na myapps.microsoft.com u aplikace mailmcp. Odvoláním se odpojí každý token mailmcp, který ten účet používal.

Firemní účty. Než Microsoft ověří vydavatele aplikace, uvidíte u souhlasu upozornění na neověřeného vydavatele; aplikace se jmenuje mailmcp a vydavatelem je Swinging Dogs s.r.o. Pokud vaše firma nechává souhlas jen na správci, skončí přihlášení hláškou „Vyžaduje se souhlas správce“ (Need admin approval). Pošlete správci tenhle odkaz: https://login.microsoftonline.com/organizations/adminconsent?client_id=ac867c04-6aec-4664-b4c7-dbf020f4907a. Povolí tím aplikaci pro celou firmu; oprávnění zůstávají ta, která si vyžádá každá schránka zvlášť.

Co je u Outlooku jinak: zprávy se neoznačují číslem, ale dlouhým textovým identifikátorem, se kterým asistent pracuje sám; po přesunu zprávy používá nové označení, které mu server vrátí. Štítky jsou kategorie Outlooku, přesun do koše končí ve složce Odstraněná pošta. Má-li schránka zapnutý online archiv, změní se identifikátor zprávy při přesunu do archivu; stačí ji nechat najít znovu.

Přihlášení k Microsoftu na vlastním serveru

Pro provozovatele vlastního serveru. Přihlášení k Microsoftu na vašem serveru potřebuje vaši vlastní registraci aplikace: registrace mailmcp slouží jen na mailmcp.ai, aby pod naším jménem nikdo nemohl provozovat přihlašování kódem. Přihlášení v okně, které funguje pro osobní i firemní účty, potřebuje registraci, ve které je zapsaná adresa vašeho serveru:

  1. V Microsoft Entra otevřete App registrations → New registration. Supported account types: Accounts in any organizational directory and personal Microsoft accounts.
  2. V Authentication přidejte platformu Mobile and desktop applications (ne Web) s redirect URI https://<adresa-vašeho-serveru>/api/ms/callback. mailmcp je veřejný klient bez tajného klíče; u platformy Web by Microsoft klíč vyžadoval a přihlášení by skončilo chybou AADSTS7000218.
  3. Tamtéž nastavte Allow public client flows na Yes.
  4. V API permissions přidejte delegovaná oprávnění Microsoft Graph Mail.Read, Mail.ReadWrite, Mail.Send, User.Read a offline_access.
  5. Na serveru nastavte MAILMCP_MS_CLIENT_ID=<Application (client) ID> a MAILMCP_MS_REDIRECT=1 a znovu nasaďte. Setup stránka pak u Outlooku nabídne přihlášení v okně.

Firmy, které dovolují souhlas jen aplikacím od ověřeného vydavatele, potřebují u registrace ověřeného vydavatele (Publisher verification v Microsoft Entra, vyžaduje členství v Microsoft AI Cloud Partner Program), nebo souhlas správce pro celou firmu.

Seznam.cz

  1. Přihlaste se na email.seznam.cz, vpravo nahoře Nastavení → Zabezpečení.
  2. Máte-li zapnuté dvoufázové ověření, vytvořte Heslo pro aplikace. Bez dvoufázového ověření použijte běžné heslo k účtu.

Volný.cz

Stačí běžné heslo k účtu. V nastavení webmailu Volný.cz zkontrolujte, že je povolený přístup přes IMAP.

iCloud

  1. account.apple.com → Přihlášení a zabezpečení → Hesla aplikací → Vytvořit.
  2. V setupu zadejte celou adresu (např. jana@icloud.com); rozdíl mezi IMAP a SMTP přihlášením mailmcp vyřeší sám.

Fastmail, Yahoo, Zoho

Všichni tři vyžadují heslo pro aplikace z nastavení zabezpečení účtu (Fastmail: Settings → Privacy & Security → Integrations). Fastmail na tarifu Basic přístup přes IMAP nenabízí.

Vlastní doména, firemní server

Připravte si adresu IMAP serveru a port (obvykle 993), adresu SMTP serveru a port (465 nebo 587), přihlašovací jméno a heslo. Najdete je v návodu vašeho hostingu pod heslem „nastavení poštovního klienta“.

Krok 2 · Vytvoření tokenu

Otevřete https://mailai.netbear.nu/setup. Stránka běží ve vašem prohlížeči: hesla, která do ní napíšete, se zašifrují dřív, než cokoli opustí váš počítač. Na server odchází jen 32bajtový šifrovací klíč, který server zapečetí svým hlavním klíčem a vrátí. Nic se neukládá.

  1. Účty. Pro každou schránku zvolte poskytovatele, zadejte krátké Account id (např. osobni, firma; asistent ho bude používat v odpovědích), e-mailovou adresu a heslo z kroku 1. U vlastního serveru vyplňte i IMAP/SMTP údaje. U poskytovatele Outlook / Microsoft 365 se místo hesla objeví tlačítko Přihlásit se přes Microsoft: postup je v kapitole o Outlooku, adresa se doplní sama a do jednoho tokenu patří až tři takové schránky, pokud se token vejde do velikostního limitu (firemní účty mají delší přihlašovací token, obvykle se vejdou dvě).
  2. Oprávnění. Zaškrtněte, co smí asistent s danou schránkou dělat. Doporučený začátek: Read & search a Create drafts. Odesílání zapínejte jen s allowlistem (např. @vasefirma.cz), jinak asistent odeslat nic nemůže.
  3. Heslo pro úpravy. Zvolte heslo, kterým později token načtete zpět, až budete chtít přidat schránku nebo změnit oprávnění. Asistenti ho nikdy nevidí, takže samotný token nikdy nevydá vaše poštovní hesla. Bez něj jde token později jen vytvořit znovu od začátku.
  4. Klikněte na Generate my token. Zkopírujte Your mailmcp token (dlouhý text začínající mmt1.). Uložte ho do správce hesel: kdo ho má, může přes tento server číst vaši poštu.
Bod „Options for your own single-owner deployment“ a hodnoty MAILMCP_CONFIG / MAILMCP_KEY na sdíleném serveru nepotřebujete. Slouží pro vlastní nasazení a Claude Desktop.

Krok 3 · Připojení klientů

Adresa serveru je https://mailai.netbear.nu/mcp. Token se používá dvěma způsoby: jako bearer token tam, kde klient umí hlavičky, nebo se vloží na přihlašovací stránce tam, kde klient používá OAuth.

ChatGPT

  1. Settings → Connectors (případně Apps & Connectors) → v pokročilém nastavení zapněte Developer mode. Vlastní konektory jsou v tarifech Plus, Pro, Business, Enterprise a Edu.
  2. Create → název „mailmcp“, URL https://mailai.netbear.nu/mcp.
  3. Ověření: buď OAuth (ChatGPT otevře přihlašovací stránku serveru, kam vložíte token), nebo pokud formulář nabízí bearer token, vložte token přímo tam. Nepřidávejte žádné další hlavičky ani proměnné.
  4. V chatu zapněte konektor a zkuste: „Vypiš mé poštovní účty.“
Dvě cesty přidání. ChatGPT umí konektor přidat na webu chatgpt.com i přímo v aplikaci a chová se u nich trochu jinak. Přidávejte ho na webu: pak je dostupný všude, v aplikacích i v prohlížeči, a ChatGPT v něm hledá nástroje jako první. Když asistent tvrdí, že nástroj chybí (třeba odeslání), přestože ho token povoluje, napište mu, ať se podívá na připojené nástroje mailmcp. Seznam nástrojů si ChatGPT ukládá při přidání konektoru; po změně práv v tokenu dejte v nastavení konektoru Obnovit, nebo ho přidejte znovu. Ověření nechte na Automatická; kdyby hlásilo chybu, zvolte Dynamická registrace klienta (DCR).

claude.ai (web, mobil, Claude Desktop)

  1. Settings → Connectors → Add custom connector, URL https://mailai.netbear.nu/mcp, uložit, Connect.
  2. Otevře se přihlašovací stránka serveru. Vložte svůj token a potvrďte. Konektor je pak aktivní i v mobilní aplikaci. Vyžaduje tarif Pro nebo vyšší.

Claude Code

claude mcp add --transport http mailmcp https://mailai.netbear.nu/mcp \
  --header "Authorization: Bearer mmt1.…celý token…"

Cursor, VS Code, Gemini CLI a další

Stejná adresa, token jako bearer hlavička nebo OAuth přihlášení. Přesné zápisy jsou v detailech pro jednotlivé klienty.

Vlastní sdílený server

Když chcete provozovat server pro sebe nebo pro tým, potřebujete tři hodnoty: hlavní klíč MAILMCP_KEY, pozvánkový kód MAILMCP_INVITE_CODE a licenční klíč MAILMCP_LICENSE (Personal €19 jednou pro jednoho a až 5 schránek; Unlimited €149 pro sdílený režim s tokeny v rámci jedné organizace; ceník na https://mailai.netbear.nu/pricing). Server si nic neukládá, takže nepotřebuje databázi; pro osobní použití stačí tarif Hobby na Vercelu zdarma, pro firemní Vercel Pro nebo Docker.

  1. Účty na github.com a vercel.com.
  2. Klikněte na tlačítko Deploy na stránce https://mailai.netbear.nu/deploy: Vercel si zkopíruje distribuční repozitář kojott/mailmcp-dist do vašeho GitHubu a rovnou se zeptá na všechny tři proměnné. (Ručně: Fork repozitáře a ve Vercelu Add New → Project → Import.)
  3. Do Environment Variables přidejte MAILMCP_LICENSE (klíč z e-mailu po nákupu), MAILMCP_INVITE_CODE (pozvánkový kód, aspoň 8 znaků; bez něj server tokeny nevydá) a MAILMCP_KEY: 32 náhodných bajtů v base64url. Vygenerujete je v terminálu příkazem node -e "console.log(require('crypto').randomBytes(32).toString('base64url'))" nebo na setup stránce v části pro vlastní nasazení (pole MAILMCP_KEY). Uložte klíč do správce hesel: jeho ztráta zneplatní všechny tokeny uživatelů.
  4. Deploy. Na adrese https://vas-projekt.vercel.app se ukáže úvodní stránka se sdíleným režimem, uživatelé si tokeny vytvoří na /setup.
Hlavní klíč nikdy neměňte bez domluvy s uživateli: každá změna zneplatní všechny vydané tokeny a všichni si musí vygenerovat nové.

Licence: jedna licence = jedna běžící instalace; přenést ji na jiný server můžete kdykoli. Podmínky včetně vrácení peněz do 14 dnů od každého nového nákupu jsou v souboru LICENSE v repozitáři.

Poštovní servery na vnitřní síti: token uživatele si sám určuje, na jaký IMAP a SMTP server se připojí. Aby veřejný server nešel zneužít jako sonda do sítě provozovatele, jsou adresy z tokenů před připojením přeloženy přes DNS a privátní, loopback, link-local a CGNAT adresy (i localhost, .local, .internal) se odmítnou; spojení se pak váže na ověřenou adresu a TLS dál ověřuje původní hostname. Veřejných poskytovatelů (Gmail, Seznam.cz, iCloud, Fastmail, vlastní mail.firma.cz) se to netýká. Firma s poštovním serverem na privátní adrese nasadí mailmcp uvnitř své sítě a nastaví MAILMCP_ALLOW_PRIVATE_MAIL_HOSTS=1. Konfigurace vlastníka (MAILMCP_CONFIG) kontrole nepodléhá.

Pozvánkový kód je povinný: proměnná MAILMCP_INVITE_CODE (aspoň 8 znaků) patří k MAILMCP_KEY a MAILMCP_LICENSE jako třetí povinná hodnota. Token si pak na setup stránce vytvoří jen ten, kdo kód zná (zobrazí se krok „Pozvánkový kód“). Bez ní server tokeny nevydá vůbec a na setup stránce se ukáže upozornění pro provozovatele; jinak by si token mohl vytvořit kdokoli, kdo zná adresu, a čerpat vaše limity. Kód jste zapomněli? Přečtete ho v proměnných prostředí na Vercelu nebo v Dockeru, nebo nastavte nový a znovu nasaďte; už vydané tokeny fungují dál. Veřejný server (jako mailmcp.ai) se místo kódu označí proměnnou MAILMCP_OPEN_SIGNUP=1.

Přihlášení k Microsoftu na vlastním serveru: potřebuje vaši vlastní registraci aplikace v Microsoft Entra. Založte ji podle návodu v kapitole Outlook, vložte její identifikátor do MAILMCP_MS_CLIENT_ID a přidejte MAILMCP_MS_REDIRECT=1; uživatelé se pak přihlašují v okně a u souhlasu vidí název vaší aplikace. Bez vlastní registrace setup stránka přihlášení k Microsoftu nenabídne. MAILMCP_MS_DISABLED=1 přihlášení přes Microsoft úplně skryje, MAILMCP_DISABLE_GRAPH=1 navíc odmítne obsluhovat schránky Microsoftu i v už vydaných tokenech. Desktopová verze pro Claude Desktop se při každém spuštění jednou zeptá GitHubu, jestli nevyšla novější verze; vypnete to proměnnou MAILMCP_NO_UPDATE_CHECK=1.

Vlastní reverzní proxy (Docker, VPS): nastavte MAILMCP_PUBLIC_URL na veřejnou adresu serveru. Bez ní server hlavičkám X-Forwarded-* nevěří (na Vercelu je věří automaticky).

Volitelně lze na vlastní server přidat i MAILMCP_CONFIG s vlastními schránkami provozovatele; pak funguje zároveň jako jednouživatelský (connector password, vlastní bearer token) i sdílený server.

Jen můj počítač · A · Claude Desktop

Pro lokální varianty potřebujete ze setup stránky hodnoty MAILMCP_CONFIG a MAILMCP_KEY z části „Values for your own deployment“, ne token.

  1. Stáhněte soubor mailmcp.mcpb z poslední verze na GitHubu.
  2. Poklepejte na něj (nebo v Claude Desktop: Settings → Extensions → Install Extension). Potřebujete nainstalovaný Node.js 20 nebo novější; Claude Desktop vás případně upozorní.
  3. Do formuláře vložte MAILMCP_CONFIG a MAILMCP_KEY. Uloží se do systémové klíčenky vašeho počítače.
  4. Otevřete nový chat a napište: „Vypiš mi mé poštovní účty.“ Claude by měl zavolat nástroj list_accounts.
V této variantě neběží nic mimo váš počítač. Když počítač spí, konektor nefunguje; pro mobil použijte cestu B.

B · Vlastní jednouživatelský server na Vercelu

Alternativa ke sdílenému serveru pro jednotlivce, který chce mít vše ve vlastním účtu, ale nechce nic instalovat. Postup je stejný jako u vlastního sdíleného serveru, jen místo hlavního klíče nastavíte dvě proměnné se svou konfigurací.

  1. Založte si účet na github.com a na vercel.com (přihlaste se přes GitHub, ušetříte kroky).
  2. Na GitHubu si vytvořte kopii distribučního repozitáře: na stránce github.com/kojott/mailmcp-dist klikněte na Fork (nebo použijte tlačítko Deploy na /deploy).
  3. Ve Vercelu: Add New → Project → Import a vyberte svůj fork mailmcp. Vercel rozpozná aplikaci sám; nic neměňte.
  4. Před kliknutím na Deploy rozbalte Environment Variables a přidejte MAILMCP_CONFIG a MAILMCP_KEY z kroku 2. (Když to zapomenete, doplníte je později v Settings → Environment Variables a v záložce Deployments zvolíte Redeploy.)
  5. Klikněte na Deploy. Za minutu dostanete adresu ve tvaru https://mailmcp-xyz.vercel.app. Otevřete ji: měla by se ukázat úvodní stránka s vašimi schránkami. Adresa /health vrací {"ok":true}.
  6. V claude.ai: Settings → Connectors → Add custom connector. Jako URL zadejte svou adresu s /mcp na konci, například https://mailmcp-xyz.vercel.app/mcp. Uložte a klikněte na Connect.
  7. Otevře se přihlašovací stránka vašeho serveru. Zadejte connector password ze setupu (ne heslo k e-mailu). Po potvrzení je konektor aktivní i v mobilní aplikaci a v Claude Desktop.
Custom connectors jsou dostupné v tarifech Claude Pro, Max, Team a Enterprise. V Team/Enterprise je přidává vlastník organizace.

C · Claude Code lokálně

Proti sdílenému serveru stačí příkaz z kroku 3. Lokálně bez hostingu (vyžaduje Node.js 22+):

claude mcp add mailmcp -e MAILMCP_CONFIG="mmc1..." -e MAILMCP_KEY="..." -- npx -y mailmcp

Ověření: claude mcp list ukáže mailmcp jako připojený.

Detaily pro ChatGPT, Cursor, VS Code, Gemini CLI a další

Všechny nástroje se připojují na adresu končící /mcp. Dva způsoby přihlášení: OAuth (klient otevře přihlašovací stránku serveru, kam vložíte token) nebo bearer token v hlavičce, kam vložíte tentýž token. Příklady níže používají adresu vlastního serveru; na sdíleném serveru dosaďte https://mailai.netbear.nu/mcp.

ChatGPT

  1. V ChatGPT otevřete Settings → Connectors (v některých verzích Settings → Apps & Connectors) a v pokročilém nastavení zapněte Developer mode. Vlastní konektory jsou dostupné v tarifech Plus, Pro, Business, Enterprise a Edu.
  2. Klikněte na Create (nebo +), zadejte název „mailmcp“ a jako URL svou adresu s /mcp, například https://mailmcp-xyz.vercel.app/mcp. Ověření nechte na OAuth.
  3. ChatGPT vás přesměruje na přihlašovací stránku serveru. Vložte svůj token (na vlastním jednouživatelském serveru connector password).
  4. V chatu zapněte konektor v nabídce nástrojů. ChatGPT používá nástroje search a fetch, které mailmcp pro něj má připravené: „search“ prohledá všechny schránky jedním dotazem (u Gmailu funguje i Gmail syntaxe, jednu schránku vyberete předponou account:firma), „fetch“ přečte konkrétní zprávu. V Developer mode má ChatGPT k dispozici i všechny ostatní nástroje včetně konceptů.
ChatGPT vyžaduje PKCE, dynamickou registraci klienta nebo Client ID Metadata Document a potvrzení vydavatele v přesměrování. mailmcp to vše splňuje, nic dalšího nenastavujete.
Dvě cesty přidání. ChatGPT umí konektor přidat na webu chatgpt.com i přímo v aplikaci a chová se u nich trochu jinak. Přidávejte ho na webu: pak je dostupný všude, v aplikacích i v prohlížeči, a ChatGPT v něm hledá nástroje jako první. Když asistent tvrdí, že nástroj chybí (třeba odeslání), přestože ho token povoluje, napište mu, ať se podívá na připojené nástroje mailmcp. Seznam nástrojů si ChatGPT ukládá při přidání konektoru; po změně práv v tokenu dejte v nastavení konektoru Obnovit, nebo ho přidejte znovu. Ověření nechte na Automatická; kdyby hlásilo chybu, zvolte Dynamická registrace klienta (DCR).

Cursor

Soubor ~/.cursor/mcp.json (globálně) nebo .cursor/mcp.json v projektu:

{
  "mcpServers": {
    "mailmcp": {
      "url": "https://mailmcp-xyz.vercel.app/mcp",
      "headers": { "Authorization": "Bearer mmt1.…celý token…" }
    }
  }
}

Bez hlavičky headers Cursor spustí OAuth přihlášení v prohlížeči; obě varianty fungují.

VS Code (GitHub Copilot)

Příkaz MCP: Add Server → HTTP → adresa https://mailmcp-xyz.vercel.app/mcp. VS Code při prvním připojení otevře prohlížeč s přihlášením (OAuth). Ruční zápis do mcp.json:

{
  "servers": {
    "mailmcp": {
      "type": "http",
      "url": "https://mailmcp-xyz.vercel.app/mcp"
    }
  }
}

Gemini CLI

gemini mcp add --transport http --header "Authorization: Bearer mmt1.…celý token…"   mailmcp https://mailmcp-xyz.vercel.app/mcp

Nebo v ~/.gemini/settings.json jako "mailmcp": { "httpUrl": "https://…/mcp", "headers": { "Authorization": "Bearer …" } }.

Windsurf, Zed, Continue, JetBrains a další

Kdekoli lze zadat „remote MCP server“ se Streamable HTTP adresou a hlavičkou Authorization: Bearer …, funguje stejný zápis jako u Cursoru. Klienti, kteří umí OAuth, se přihlásí connector passwordem.

Jak s tím pracovat

Mluvte s Claude normálně; nástroje si vybírá sám. Osvědčené dotazy:

  • „Vypiš mi mé poštovní účty a co s nimi smíš dělat.“
  • „Co mi přišlo za poslední tři dny přes všechny účty? Rozděl to podle účtů a řekni, co vyžaduje odpověď.“
  • „Najdi v pracovním účtu faktury z tohoto měsíce s přílohou.“ (Gmail rozumí i dotazům jako from:ucetni has:attachment newer_than:30d.)
  • „Přečti mi poslední zprávu od Nováka a připrav zdvořilou odpověď jako koncept.“ Koncept najdete ve složce Koncepty svého poštovního programu a odešlete ho sami.
  • „Označ všechny newslettery z tohoto týdne jako přečtené.“ (funguje jen se zapnutým oprávněním Flag / label / move)
NástrojCo děláKdy je k dispozici
list_accountsseznam schránek a oprávněnívždy
search, fetchzjednodušené hledání a čtení pro ChatGPT a spol.Read & search
search_messageshledání v jedné nebo všech schránkáchRead & search
get_message, get_threadpřečtení zprávy a celého vláknaRead & search
get_attachmentpříloha jako text, nebo odkaz ke stažení platný hodinuRead & search (přílohy ke stažení jsou výchozí)
reply_draftodpověď jako koncept ve stejném vlákně: hlavičky, „Re:“, adresáti a citace původní zprávy doplní serverCreate drafts
reply_sendodpověď rovnou odešle, jen adresátům z allowlistuSend + allowlist
get_signature, set_signaturepodpis uložený ve složce „mailmcp-signature“ ve vaší schránce (HTML i obrázky), zobrazí nebo uložíRead & search / Create drafts
create_draftuloží koncept, nic neodesíláCreate drafts
send_messageodešle jen adresátům z allowlistu, i s přílohamiSend + allowlist
send_draftodešle uložený koncept tak, jak je, včetně přílohSend + allowlist
forward_messagepřepošle zprávu včetně všech příloh (nebo uloží jako koncept)Send + allowlist / Create drafts
upload_attachment, request_upload, list_uploadspředání souboru asistentovi: text nebo base64 rovnou, větší soubory přes hodinový odkaz k nahráníCreate drafts nebo Send
modify_messagepřečteno, hvězdička, štítky, přesun, archivFlag / label / move
trash_messagepřesun do koše, nikdy trvalé smazáníMove to trash

Odpovědi ve vlákně a podpis

Když řeknete „odpověz“ nebo „napiš koncept“, vznikne koncept ve stejném vlákně: server sám doplní hlavičky vlákna, předmět „Re:“, adresáty (na „odpověz všem“ všechny) a pod odpověď ocituje původní zprávu, jak to dělá váš poštovní program. „Napiš mi odpověď“ nebo „navrhni odpověď“ znamená jen návrh v chatu, nic nevznikne; „pošli“ odešle, pokud jste odesílání zapnuli a adresát je povolený.

Podpis. Textový podpis zadáte přímo ve formuláři tokenu. Podpis s fotkou nebo logem se do tokenu nevejde a ani tam nepatří: ve formuláři zaškrtněte „Podpis s fotkou nebo logem: brát ze schránky“, pak si ze svého poštovního programu pošlete e-mail s podpisem a přesuňte ho do složky mailmcp-signature (založte ji, nebo ji vytvoří asistent příkazem „nastav podpis“). Nejnovější zpráva v této složce je váš podpis; obrázky se vloží přímo do odpovědi, nic se neukládá u nás. Podpis změníte tak, že do složky pošlete novou zprávu. Asistentovi můžete říct „ukaž mi podpis“.

Přílohy

Přílohy nezatěžují kontext asistenta. U každé zprávy dostane asistent seznam příloh a ke každé odkaz ke stažení platný jednu hodinu. Kliknete a soubor se stáhne přímo ze serveru (ten ho v tu chvíli vyzvedne z vaší schránky), aniž by prošel přes OpenAI nebo Anthropic. Textové přílohy (TXT, CSV, JSON, XML) umí asistent přečíst i přímo; obsah jiného souboru vloží do kontextu jen když o to výslovně požádáte („načti mi obsah té přílohy“, do 2 MB). Odkaz funguje pro kohokoli, kdo ho má, hodinu; přeposílejte ho proto jako heslo.

PDF. U příloh v PDF do 5 MB dostane asistent rovnou vytažený text (do 20 000 znaků), takže se nemusí ptát na obsah. Text je vytažený tak, jak je v souboru uložený, takže může obsahovat i pasáže, které ve vykresleném PDF nejsou vidět; berte ho jako cizí text, ne jako pokyn. Naskenované PDF bez textové vrstvy zůstává odkazem ke stažení.

Limity, které v setupu nastavíte: délka těla zprávy na jedno čtení (výchozí 8 000 znaků), počet odeslání za hodinu, přílohy jen jako seznam nebo i ke stažení.

Odesílání příloh

Asistent umí přílohu i poslat, a soubor přitom nikdy neprochází chatem. Tři cesty:

  • Příloha, která už v poště je: „Přepošli tu fakturu účetní.“ Asistent použije forward_message nebo přiloží konkrétní přílohu ke konceptu či odeslané zprávě; server si ji vezme přímo ze schránky.
  • Soubor, který asistent napsal: smlouva, CSV, nabídka. Asistent ho předá nástrojem upload_attachment a přiloží.
  • Soubor z vašeho disku: asistent si vyžádá hodinový odkaz k nahrání (request_upload). Claude Code, Cursor nebo Gemini CLI na něj soubor pošlou samy (curl -T soubor odkaz); v ChatGPT nebo claude.ai odkaz otevřete a soubor přetáhnete. V Claude Desktop stačí cesta k souboru v povolené složce.
  • Uložení příloh na disk (Claude Desktop, Claude Code): povolené složky nastavíte v Claude Desktop v Nastavení → Rozšíření → mailmcp → Attachment folders (nová instalace má předvyplněné Stažené soubory; po aktualizaci ze starší verze je pole prázdné, složku vyberte a Claude Desktop restartujte); v Claude Code proměnnou MAILMCP_ATTACHMENT_DIRS. Pak stačí říct „ulož přílohy z posledního mailu od účetní“ a soubory se uloží přímo, včetně PDF.

Nahrané soubory čekají ve složce mailmcp-uploads vaší schránky (server nic nedrží) a po přiložení se smažou. Limit je 20 MB na zprávu; na Vercelu projde nahráním přes odkaz zhruba 4 MB na soubor, větší soubory pošlete přeposláním z pošty nebo z Dockeru.

Změna konfigurace

Sdílený server: na setup stránce dole rozbalte „Edit an existing configuration“, vložte svůj současný token a heslo pro úpravy a klikněte Load. Formulář se předvyplní (hesla se rozšifrují jen ve vašem prohlížeči). Přidejte schránku nebo změňte oprávnění, znovu klikněte Generate my token a nový token vložte do klientů místo starého (u ChatGPT a claude.ai: odpojit a znovu připojit). Starý token přestane fungovat, jakmile u poskytovatele smažete heslo pro aplikace, které obsahuje.

Vlastní jednouživatelský server: Settings → Environment Variables → upravte MAILMCP_CONFIG → Deployments → Redeploy. Claude Desktop: Settings → Extensions → mailmcp → Configure.

Zrušení přístupu kdykoli: smažte heslo pro aplikace u poskytovatele (Google, Seznam…). Server se pak do schránky nedostane, ať má token kdokoli. U schránek Microsoftu žádné heslo není: přístup odeberete na account.live.com/consent/Manage (osobní účty) nebo na myapps.microsoft.com (pracovní).

Řešení potíží

Google mi heslo pro aplikace nenabízí: „Nastavení, které hledáte, není pro váš účet k dispozici“

Hesla pro aplikace Google zobrazí jen s zapnutým dvoufázovým ověřením. Zapněte ho na myaccount.google.com → Zabezpečení → Dvoufázové ověření (stačí telefon nebo SMS), pak znovu otevřete myaccount.google.com/apppasswords. U účtů Google Workspace musí hesla pro aplikace navíc povolit správce domény.

„Vypiš mi účty“ funguje, ale hledání hlásí chybu přihlášení (Invalid credentials, AUTHENTICATIONFAILED)

Špatné nebo neplatné heslo pro aplikace. U Gmailu ověřte, že je zapnuté dvoufázové ověření a heslo má 16 znaků. Vygenerujte nové, v setupu načtěte konfiguraci, opravte heslo a nasaďte znovu.

Zapomněl jsem heslo pro úpravy, nebo jsem ho nezadal

Token pak nejde načíst zpět. Vytvořte na setup stránce nový token od začátku (schránky zadáte znovu), tentokrát s heslem pro úpravy, a v asistentech ho vyměňte. Starý token zneplatníte tak, že u poskytovatele smažete heslo pro aplikace a vytvoříte nové.

Outlook hlásí, že je potřeba se přihlásit znovu (nebo se přihlášení nepovedlo)

Přihlášení k Microsoftu platí zhruba 90 dní a zruší ho i odvolání přístupu u Microsoftu; změna hesla ke schránce s ním nic neudělá. Na setup stránce načtěte token heslem pro úpravy, u schránky klikněte na Přihlásit se znovu a token vygenerujte znovu; v ChatGPT a claude.ai konektor odeberte a přidejte znovu, v Claude Desktop vložte novou konfiguraci. Bez hesla pro úpravy je potřeba poskládat token od začátku. Skončilo-li přihlášení hláškou „Vyžaduje se souhlas správce“, potřebujete souhlas správce firmy; odkaz je v kapitole o Outlooku. Uživatelé Claude Desktop se přihlašují na setup stránce serveru mailmcp.ai, znovupřihlášení tamtéž.

Odkaz na přílohu nefunguje („Download link is invalid or has expired“)

Odkazy platí hodinu. Požádejte asistenta, aby zprávu načetl znovu; dostanete nový odkaz.

Server ukazuje „Tento server potřebuje licenční klíč“

Chybí nebo je neplatná proměnná MAILMCP_LICENSE, nebo konfigurace překračuje licenci (Personal: nejvýš 5 schránek v konfiguraci i v každém tokenu; bez limitu je Unlimited). Bez proměnné MAILMCP_LICENSE běží server zdarma: do 2 schránek na token (tokeny z doby před 0.7.0 mají 5) a zprávy sestavené asistentem končí podpisem „Sent with mailmcp.ai“. Stránka říká přesný důvod. Po opravě proměnné dejte Redeploy.

„Token was not issued by this server“

Token byl vytvořen na jiném serveru, nebo provozovatel změnil hlavní klíč. Vytvořte nový token na setup stránce toho serveru, ke kterému se připojujete.

ChatGPT nebo Cursor hlásí, že hlavička je příliš dlouhá

Token nese celou konfiguraci; s mnoha účty může přesáhnout limit hlavičky některých klientů (zhruba 8 kB). Vytvořte token jen pro schránky, které v daném klientovi potřebujete, nebo použijte OAuth přihlášení, kde limit neplatí.

Claude říká, že účet „does not allow send/draft/modify“

Pro tu schránku není oprávnění zapnuté. Zapněte ho v setupu (Edit existing) a aktualizujte konfiguraci. Toto je záměr: výchozí stav je jen čtení.

„Recipient not in send_allowlist“

Odesílání je povolené, ale adresát není na seznamu. Přidejte adresu nebo doménu (@firma.cz) do allowlistu, nebo nechte Claude vytvořit koncept a odešlete ho sami.

Vercel stránka ukazuje chybu „No configuration“ nebo „Could not decrypt“

Proměnné MAILMCP_CONFIG a MAILMCP_KEY chybí, jsou z jiné dvojice, nebo jste po jejich změně nespustili Redeploy. Zkontrolujte, že blob začíná mmc1. a že jste zkopírovali celý řádek bez mezer navíc.

claude.ai konektor: „Unknown client_id“ nebo přihlášení skončí chybou

Otevřete URL konektoru bez /mcp v prohlížeči; musí se ukázat úvodní stránka. Pak konektor v claude.ai odeberte a přidejte znovu. Adresa musí být přesně ta z Vercelu, včetně https:// a s /mcp na konci.

Konektor je přidaný, ale Claude „nevidí“ žádné nástroje

V nastavení konektoru v claude.ai zkontrolujte, že je zapnutý pro aktuální chat (ikona konektorů pod polem pro zprávu). Případně se odhlaste a znovu připojte connector passwordem.

Připojení je pomalé nebo první dotaz vyprší

Na Vercelu se každý dotaz přihlašuje k IMAP serveru znovu, počítejte s 1 až 3 sekundami. Zkuste dotaz zopakovat; při hledání ve všech účtech omezte období (např. „za poslední týden“).

Gmail: Claude hledá v „All Mail“, ne jen v doručené poště

To je záměr: prohledává se vše včetně archivu. Řekněte „jen v doručené poště“ nebo použijte Gmail výraz in:inbox.

Chci vědět, co přesně server odesílá kam

Server komunikuje jen s vašimi poštovními servery a s klientem (ChatGPT, Claude). Žádná telemetrie, žádné volání domů; licence se ověřuje jen lokálně. Na GitHubu je distribuční repozitář; zdrojový kód neposkytujeme; tok dat pro prověření (např. pro DPO) popisuje bezpečnostní audit.

Bezpečnost v pěti větách

Server prošel bezpečnostním auditem (kryptografie, OAuth, poštovní vrstva, web, provoz). Známá omezení bezstavového návrhu, která audit potvrdil: ochrana proti opakovanému použití autorizačního kódu platí v rámci jedné instance (kód platí 3 minuty a je chráněn PKCE), přístupové tokeny platí 30 dní (kvůli ChatGPT, který je sám neobnovuje) a nejde je jednotlivě odvolat před vypršením (obnovovací 90 dní); jediné okamžité odvolání je smazání hesla pro aplikace u poskytovatele, limity pokusů o přihlášení se počítají per instance serveru, odkazy na přílohy platí hodinu pro kohokoli, kdo je má.

  • E-mail je nedůvěryhodný obsah: server odstraňuje skrytý text a označuje těla zpráv jako data, aby podvržený e-mail nemohl Claude „instruovat“. Přesto platí: co Claude navrhne odeslat, zkontrolujte.
  • Začněte s právy jen na čtení a koncepty. Odesílání zapněte až s úzkým allowlistem.
  • Token držte ve správci hesel jako heslo. Kdo ho má, může přes tento server číst vaši poštu; bez hlavního klíče serveru je ale pro kohokoli jiného (včetně OpenAI a Anthropic) nečitelný. Samotný token nikdy nevydá vaše poštovní hesla: k načtení zpět do formuláře je potřeba i heslo pro úpravy, které asistenti nevidí.
  • Používejte hesla pro aplikace, ne hlavní heslo k účtu. Jdou kdykoli zrušit jedním kliknutím.
  • Přihlášení do konektoru je omezené na 5 pokusů za 15 minut; přístupové tokeny platí 30 dní a obnovují se automaticky.

Co to chrání, co snižuje a co nevyřeší

Chrání: hesla ke schránkám (šifrují se ve vašem prohlížeči, server drží jen klíč a nic si neukládá), rozsah (práva po schránkách, čtení jako výchozí), odesílání (jen na allowlist adres, takže podvržený mail nemůže poslat vaši poštu na cizí adresu) a mazání (trvalé neexistuje, jen koš).

Snižuje, nevylučuje: instrukce ukryté v mailech. Skrytý text se odstraní, tělo jde modelu jako citovaná data, hlavičky se čistí. Model přesto může poslechnout instrukci v běžném odstavci; škodu ohraničují práva výše: koncept nebo mail na povolenou adresu, ne exfiltrace a ne smazaná pošta.

Nechrání: obsah přečtených mailů vidí model a jeho provozovatel. Co asistent přečte, může zopakovat v odpovědi nebo předat jinému nástroji, který máte v ChatGPT nebo Claude povolený. To je hranice konektoru, ne jeho nastavení. Proto připojte jen schránky, jejichž obsah smí asistent vidět, a nechte odesílání vypnuté, dokud ho nepotřebujete.