Open Source — MIT License

Apple Mail for
Claude Code & Codex

List accounts and mailboxes, search by subject or sender, read messages, and prepare drafts for your review — using the Mail accounts already on your Mac. No email passwords, no OAuth, no hosted service.

5Tools
0Extra Credentials
0Send Tools
click to copy $ git clone https://github.com/jenyago/apple-mail-mcp.git
Tools
Five tools, nothing hidden
Every tool an MCP client can call. No arbitrary scripting tool, no send, no delete, no move.
list_accounts
Permitted account IDs, names, and email addresses.
list_mailboxes
Nested mailbox paths for an account.
search_messages
Paginated, case-insensitive subject/sender search in one mailbox.
search_inboxes
The same search across every permitted account's inbox in one call — review what's unread everywhere at once.
read_message
Message metadata and bounded plain-text content.
create_draftOpt-in
Saves a visible draft in Mail for you to review. Never sends it. Off unless you enable it.
Security Model
Email is attacker-controlled input
A message body can carry instructions aimed at the model reading it. This server can't stop that — it bounds what it can do, and what surrounds it.
🔒
Account allowlist
Set APPLE_MAIL_ACCOUNTS and every other account is invisible and unreachable, enforced in one place, fail-closed.
👁
Read-only by default
The only write path — create_draft — doesn't exist as a tool until you explicitly enable it.
📋
Audit log
One line per call: time, operation, account, mailbox, outcome. Never a subject, sender, body, or draft content.
🧍
Isolated session recipe
The README's recommended Claude Code launch strips the shell and every other tool, so an injected instruction in an email has nothing to use.
Get Started
Clone, sync, register
Requires macOS, Apple Mail with at least one account configured, and uv.
terminal
# Clone and install dependencies
$ git clone https://github.com/jenyago/apple-mail-mcp.git
$ cd apple-mail-mcp && uv sync --locked

# Register with Claude Code as an isolated session (recommended)
$ cat > ~/.claude/mcp-apple-mail.json <<EOF
{"mcpServers":{"apple-mail":{"type":"stdio",
 "command":"$PWD/.venv/bin/python","args":["$PWD/server.py"]}}}
EOF
$ claude --tools "" --restricted --strict-mcp-config \
  --mcp-config ~/.claude/mcp-apple-mail.json
1
Try it"List my Mail accounts" — then mailboxes, search, read
2
Scope itAdd APPLE_MAIL_ACCOUNTS to the config once you know which addresses you want reachable
3
Codex & Claude DesktopAlso supported — setup for each is in the README
Your inbox, your Mac,
your assistant.

No credentials to configure, no data leaving your machine except what the tool call returns. Read the full spec and security model on GitHub.

View on GitHub

MIT License — Free and open source