Sign inSign up

mkrasselt1/imap-mcp-server

By mkrasselt1

•Updated 6 months ago

Multi-agent multi-user IMAP bridge with OAuth 2.1 for MCP (Claude.ai, etc.)

Image
0

1.2K

mkrasselt1/imap-mcp-server repository overview

⁠IMAP MCP Server

Docker Hub

A multi-agent, multi-user HTTP IMAP bridge that acts as a remote MCP⁠ server with built-in OAuth 2.1 authorization. Designed to let AI agents (like Claude.ai) securely access email on behalf of users, with granular per-agent permission control.

⁠Features

  • MCP over Streamable HTTP — standard protocol that Claude.ai and other MCP clients speak natively
  • OAuth 2.1 Authorization Server — RFC 8414 discovery, RFC 7591 Dynamic Client Registration, PKCE-enforced flows
  • Multi-user / multi-agent — each user manages their own IMAP accounts; each agent connection gets its own scoped token
  • Granular permissions — users choose exactly which capabilities to grant each agent:
    ScopeGrants
    mail:foldersList mailbox folders
    mail:readRead email messages
    mail:searchSearch emails
    mail:modifyMove, flag, delete messages
    mail:sendSend emails via SMTP
  • Encrypted credential storage — IMAP/SMTP passwords encrypted with AES-256-GCM at rest
  • Connection pooling — IMAP connections are reused across tool calls with auto-disconnect on idle
  • Web dashboard — manage email accounts and revoke agent tokens

⁠Quick Start with Docker

docker run -d \
  --name imap-bridge \
  -p 3000:3000 \
  -v imap-bridge-data:/app/data \
  -e BASE_URL=https://your-domain.com \
  -e ENCRYPTION_KEY=$(openssl rand -hex 32) \
  -e SESSION_SECRET=$(openssl rand -hex 32) \
  mkrasselt1/imap-mcp-server

Or with Docker Compose:

git clone https://github.com/mkrasselt1/imap-mcp-server.git
cd imap-mcp-server
cp .env.example .env
# Edit .env with your values
docker compose up -d

⁠Environment Variables

VariableRequiredDescription
BASE_URLYesPublic URL of the server (e.g. https://mail.example.com). Must be HTTPS for Claude.ai.
PORTNoListen port (default: 3000)
ENCRYPTION_KEYYes64-char hex string for AES-256-GCM encryption. Generate with openssl rand -hex 32
SESSION_SECRETYesRandom string for session cookies. Generate with openssl rand -hex 32

⁠Setup

⁠1. Deploy the server

Deploy behind a reverse proxy (nginx, Caddy, Traefik) with TLS. Claude.ai requires HTTPS.

⁠2. Create an account and add email credentials
  1. Visit https://your-domain.com/signup and create an account
  2. Go to the Dashboard and click Add Email Account
  3. Enter your IMAP server details and credentials (use an App Password for Gmail/Outlook)
  4. Optionally add SMTP settings for sending
⁠3. Connect from Claude.ai
  1. Go to Claude.ai Settings > Integrations⁠
  2. Click Add Custom Connector (or Add MCP Server)
  3. Enter your server URL: https://your-domain.com/mcp
  4. Claude.ai will automatically:
    • Discover OAuth endpoints via /.well-known/oauth-authorization-server
    • Register itself as an OAuth client (Dynamic Client Registration)
    • Redirect you to the consent screen
  5. On the consent screen, select which email account and permissions to grant
  6. After authorizing, Claude.ai can use the email tools

⁠OAuth 2.1 Flow

Claude.ai                          IMAP Bridge                    User
   │                                    │                           │
   │  GET /.well-known/oauth-           │                           │
   │  authorization-server              │                           │
   │───────────────────────────────────>│                           │
   │  { endpoints, scopes }            │                           │
   │<───────────────────────────────────│                           │
   │                                    │                           │
   │  POST /oauth/register             │                           │
   │  { redirect_uris }                │                           │
   │───────────────────────────────────>│                           │
   │  { client_id }                    │                           │
   │<───────────────────────────────────│                           │
   │                                    │                           │
   │  Redirect to /oauth/authorize      │                           │
   │  + PKCE code_challenge             │                           │
   │───────────────────────────────────>│  Login form               │
   │                                    │──────────────────────────>│
   │                                    │  Username + password      │
   │                                    │<──────────────────────────│
   │                                    │  Consent screen           │
   │                                    │  (select account + perms) │
   │                                    │──────────────────────────>│
   │                                    │  Approve                  │
   │                                    │<──────────────────────────│
   │  Callback with auth code          │                           │
   │<───────────────────────────────────│                           │
   │                                    │                           │
   │  POST /oauth/token                │                           │
   │  + code_verifier (PKCE)           │                           │
   │───────────────────────────────────>│                           │
   │  { access_token, refresh_token }  │                           │
   │<───────────────────────────────────│                           │
   │                                    │                           │
   │  POST /mcp (tool calls)           │                           │
   │  Authorization: Bearer <token>    │                           │
   │───────────────────────────────────>│  IMAP                    │
   │  { tool results }                 │                           │
   │<───────────────────────────────────│                           │

⁠MCP Tools

ToolScope RequiredDescription
list_foldersmail:foldersList all mailbox folders
list_messagesmail:readList messages with pagination
read_messagemail:readRead full message by UID
search_messagesmail:searchSearch by sender, date, subject, body
move_messagemail:modifyMove message between folders
flag_messagemail:modifySet read/unread, star, delete flags
send_mailmail:sendSend email via SMTP

⁠Development

npm install
npm run dev     # starts with tsx watch
npm run build   # compile TypeScript
npm start       # run compiled output

⁠Security Notes

  • HTTPS required for production — Claude.ai will not connect over plain HTTP
  • App Passwords — use app-specific passwords for Gmail, Outlook, etc. rather than your main password
  • Encryption key — keep your ENCRYPTION_KEY safe; losing it means stored IMAP passwords become unrecoverable
  • Token revocation — users can revoke agent tokens from the dashboard at any time
  • PKCE enforced — all OAuth flows require Proof Key for Code Exchange (S256)

⁠License

MIT

Tag summary

Content type

Image

Digest

sha256:fd3b79987…

Size

86.2 MB

Last updated

6 months ago

docker pull mkrasselt1/imap-mcp-server