Apple Mail MCP
MCP server for Apple Mail on macOS.
Provides access to mailboxes, message search, reading, and composition. Keep Mail as the system of record while enabling agents to search, read, draft, and send email.
When to use
- Mail-only workflows
- Tighter permissions than the all-in-one server
- Draft and send workflows through the native Mail app
What It Does
- List mailboxes
- Search and read messages
- Create drafts and send messages
- Reply, forward, mark read/unread, move, and delete
- Tool discovery helpers
search_toolsandget_tool_infofor context-constrained clients - Thread helpers:
mail_get_thread,mail_reply_latest_in_thread,mail_archive_thread - Mailbox resources and reply-oriented prompts
- Health and permission checks:
mail_health,mail_permission_guide,mail_recheck_permissions
Tools
mail_health, mail_permission_guide, mail_recheck_permissions, mail_list_mailboxes, mail_search_messages, mail_get_message, mail_get_thread, mail_compose_draft, mail_send_message, mail_reply_message, mail_forward_message, mail_mark_message, mail_move_message, mail_delete_message, mail_reply_latest_in_thread, mail_archive_thread, mail_list_prompts, mail_get_prompt, plus the discovery helpers search_tools and get_tool_info.
Install On This Mac
From a clone
git clone https://github.com/JonathanRReed/Apple-MCPs.git
cd Apple-MCPs
uv sync --all-packages
This builds one workspace environment with every server's entry point in .venv/bin (for example .venv/bin/apple-mail-mcp). You can also point an MCP client at AppleMail-MCP/start.sh, which prefers uv run and falls back to a plain venv bootstrap (Python 3.11+ required).
Install In AI Agents
Generic MCP client config
{
"mcpServers": {
"apple-mail": {
"command": "uvx",
"args": ["apple-mcp-mail"],
"env": {
"APPLE_MAIL_MCP_SAFETY_PROFILE": "safe_manage",
"APPLE_MAIL_MCP_VISIBLE_DRAFTS": "true"
}
}
}
}
Running from a clone instead? Use /path/to/Apple-MCPs/AppleMail-MCP/start.sh as the command with empty args.
Claude Code example
claude mcp add --transport stdio --scope project apple-mail -- uvx apple-mcp-mail
Safety Modes
safe_readonly, read and search onlysafe_manage, read plus draft creationfull_access, full Mail tool surface in this repo
Transport
stdio is the default and recommended transport. Set APPLE_MAIL_MCP_TRANSPORT=streamable-http (with optional APPLE_MAIL_MCP_HOST and APPLE_MAIL_MCP_PORT) to serve Streamable HTTP instead.
macOS Permissions
- Automation access to Mail is required
Launch Checklist
- Add
uvx apple-mcp-mail(or a clone'sAppleMail-MCP/start.sh) to your MCP client - Reload or reconnect the client so the Mail tool surface is loaded into context
- Call
mail_healthfirst to confirm the server is reachable - If Mail automation is blocked, call
mail_permission_guide - After changing macOS permissions, call
mail_recheck_permissions
Prompting Notes
- Run Contacts before any send or reply when the user identifies a person rather than an email address.
tools/listreturns the full Mail tool surface. Context-constrained clients can callsearch_toolsfirst, thenget_tool_infofor the exact Mail tool they plan to call.mail_search_messagesrequires a query string. Use a sender, a subject fragment, or*as a wildcard.- There is no list-all recent-mail endpoint.
- Use
mail_get_threadwhen the user means a conversation, not a single message. - Use
mail_reply_latest_in_threadwhen the agent should reply to the newest message in the conversation. - Use
mail_archive_threadwhen the user wants thread-level cleanup and Archive is the intended mailbox. - If the user could mean text or email, ask once before choosing Messages or Mail.
- When Mail must send from a specific identity, pass the exact sender email in
from_account.
Related
Attachment access
File attachments are disabled until you set APPLE_MAIL_MCP_ALLOWED_ATTACHMENT_ROOT
to a directory you choose, such as ~/Documents/Mail Attachments. This applies to
both drafts and sends, including calls through Apple Tools. The server resolves
symlinks and accepts only regular files inside that directory. Files outside it,
directories, and paths containing the attachment transport separator are rejected.
Mail operations without attachments continue to work with the existing safety profile.
Release files for apple-mcp-mail 1.0.4
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| apple_mcp_mail-1.0.4.tar.gz | 26.2 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| apple_mcp_mail-1.0.4-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 57.0 kB
Release files / apple_mcp_mail-1.0.4.tar.gz
| Download URL | apple_mcp_mail-1.0.4.tar.gz |
|---|---|
| Size | 26.2 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
2ce43049c23755769d63e3bc8c1d20105332aa08a3cf00b2df959bbbf3a7a17e
|
|
BLAKE2b-256 checksum How to use checksums |
191be2457ccfc99f15ce25840502cb67d3c1b6964fb327d9905a31b0bd80daa7
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 4, 2026.
Transparency logRelease files / apple_mcp_mail-1.0.4-py3-none-any.whl
| Download URL | apple_mcp_mail-1.0.4-py3-none-any.whl |
|---|---|
| Size | 30.8 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
bab57da9b0bc58bf226b568d177d7139b5dda58358fa45ec1ae3b1014a79c261
|
|
BLAKE2b-256 checksum How to use checksums |
3bcda507002137daaf6528cff0081fccd0a2a52cb55ffa2f101d0a27bb80c29a
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 4, 2026.
Transparency log