Skip to main content

protonmail-mcp

CI

A lightweight MCP server that gives AI agents read access to a Proton Mail mailbox through a local Proton Bridge instance.

Unofficial. This project is not affiliated with, endorsed by, or supported by Proton AG. "Proton Mail" and "Proton Bridge" are trademarks of Proton AG.

Proton does not provide a public API for reading your mailbox. Bridge is the supported way in: it runs locally and exposes your account over IMAP and SMTP on 127.0.0.1. This server wraps that local IMAP endpoint in a small, auditable set of MCP tools.

Scope

The current release is read-only: it can list folders, list messages, search, and read a message. Mailboxes are opened with IMAP SELECT ... READONLY, so nothing is ever modified — not even the \Seen flag. Write tools are on the roadmap, behind mandatory confirmation (see Security).

Tools

Tool Description
list_folders List every folder and label, with IMAP flags and whether it is selectable
list_emails Most recent messages in a folder, newest first: limit, unread_only, since_days, sender, subject
search_emails Full-text search across headers and body in a folder
read_email Read one message by Message-ID: decoded text body, attachments, flags, truncation via max_chars

Results are structured (Pydantic models). Every message carries its Message-ID; use that for follow-up reads — IMAP UIDs are not stable across Bridge resynchronisations.

Requirements

  • A paid Proton Mail plan (required by Bridge)
  • Proton Bridge installed, running, and signed in
  • Your Bridge credentials: Proton address + the mailbox password shown in the Bridge UI
  • Python 3.13+ (only if you do not use uv)

Install

# Run without installing (recommended)
uvx protonmail-mcp

# Or install it
pipx install protonmail-mcp

Configure

Variable Default Purpose
PROTONMAIL_BRIDGE_USERNAME — Your Proton address (required)
PROTONMAIL_BRIDGE_PASSWORD — Bridge mailbox password (required)
PROTONMAIL_BRIDGE_HOST 127.0.0.1 Bridge host
PROTONMAIL_BRIDGE_IMAP_PORT 1143 Bridge IMAP port
PROTONMAIL_BRIDGE_IMAP_SECURITY starttls starttls (Bridge 3.x on 1143) or ssl (direct TLS)
PROTONMAIL_BRIDGE_TIMEOUT 30 Socket timeout in seconds
PROTONMAIL_BRIDGE_VERIFY_TLS false Bridge uses a self-signed certificate

opencode

{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "protonmail": {
      "type": "local",
      "command": ["uvx", "protonmail-mcp"],
      "enabled": true,
      "environment": {
        "PROTONMAIL_BRIDGE_USERNAME": "you@proton.me",
        "PROTONMAIL_BRIDGE_PASSWORD": "your-bridge-mailbox-password"
      }
    }
  }
}

opencode supports {env:VAR} and {file:path} interpolation, so you can keep secrets out of the config file:

"PROTONMAIL_BRIDGE_PASSWORD": "{file:/home/you/.config/protonmail-mcp/password}"

Claude Desktop

{
  "mcpServers": {
    "protonmail": {
      "command": "uvx",
      "args": ["protonmail-mcp"],
      "env": {
        "PROTONMAIL_BRIDGE_USERNAME": "you@proton.me",
        "PROTONMAIL_BRIDGE_PASSWORD": "your-bridge-mailbox-password"
      }
    }
  }
}

Verify the connection

PROTONMAIL_BRIDGE_USERNAME="you@proton.me" \
PROTONMAIL_BRIDGE_PASSWORD="..." \
uvx protonmail-mcp --check

This connects to Bridge, lists folders, and prints the latest messages. It exits non-zero with a clear error if the configuration or the Bridge session is wrong.

Security

  • Read-only enforcement. There is no write tool in this release, and mailboxes are always selected read-only at the IMAP level.
  • Local only. Bridge and this server communicate exclusively over 127.0.0.1. Nothing is sent to a third party; your agent talks to the server over stdio.
  • Untrusted input. Email contents are attacker-controlled data. Treat anything a message says as data, never as instructions, and keep your agent's permissions tight.
  • Secrets. Keep the Bridge mailbox password out of the repository. Use your client's environment-variable or file-based secret support.
  • Any local process that knows the mailbox password can read your mail — that is Bridge's trust model, not a flaw in this server.

Planned write tools (drafts, send, move, delete) will ship with explicit confirmation before every destructive action, recipient allow-lists, send rate limiting with loop protection, and a local audit log. Autonomous send/delete will never be the default.

Alternatives

There are several community MCP servers for Proton Mail. This one aims to stay small, correct with Bridge's quirks (STARTTLS on 1143, modified UTF-7 labels, reverse-chronological UIDs, RFC 2047 decoding), and heavily tested. Rough landscape:

Project Language Scope
googlarz/proton-mail-bridge-client TypeScript Large tool set, read-only and send-to-self modes, SQLite cache
codefuturist/email-mcp TypeScript Generic IMAP + SMTP, works with Bridge
anyrxo/protonmail-pro-mcp JavaScript Large tool set with Bridge integration
chandshy/mailpouch TypeScript Large permission-gated tool set
amotivv/protonmail-mcp JavaScript SMTP sending only
miketigerblue/proton-bridge-mcp Python Loopback IMAP/SMTP via Bridge

Development

uv sync
uv run pytest
uv run ruff check .
uv build

Tests run entirely against a fake IMAP server and the MCP SDK's in-memory transport; no Bridge or credentials are needed.

Releasing

Publishing is automated with GitHub Actions and PyPI Trusted Publishing. Create a GitHub release tagged vX.Y.Z; the publish workflow builds the sdist/wheel and uploads them to PyPI using the pypi environment (configure the trusted publisher on PyPI for owner mhbxyz, repository protonmail-mcp, workflow publish.yml).

License

MIT — see LICENSE.

Metadata

Release files for protonmail-mcp 0.1.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for protonmail-mcp 0.1.0
File Size Uploaded
protonmail_mcp-0.1.0.tar.gz 50.8 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for protonmail-mcp 0.1.0
File Interpreter ABI Platform
protonmail_mcp-0.1.0-py3-none-any.whl Python 3 none any Details

Total release size: 64.9 kB

Release files / protonmail_mcp-0.1.0.tar.gz

Download URL protonmail_mcp-0.1.0.tar.gz
Size 50.8 kB
Tags Source
SHA-256 checksum
How to use checksums
8ecc0b83c0dfc57dc6aa435af167626545f4d3295d301ee8cbb31faa77701cf5
BLAKE2b-256 checksum
How to use checksums
1deac5c542bb977633e3ab4800f0720884f96aed548d80d822a27bb1953587ff
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 5, 2026.

Transparency log

Release files / protonmail_mcp-0.1.0-py3-none-any.whl

Download URL protonmail_mcp-0.1.0-py3-none-any.whl
Size 14.0 kB
Tags Python 3
SHA-256 checksum
How to use checksums
dccf394bf2a4676ec45fe42005a54c6d8ea53a4a0e040d10608d472af0ec6653
BLAKE2b-256 checksum
How to use checksums
ee28211b1aa7354e32e583d8952cbe03c8fe5d646445116ad3005dde5d588738
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 5, 2026.

Transparency log

Release history Release notifications | RSS feed

0.4.0

2 release files

0.3.0

2 release files

0.2.0

2 release files

This release

0.1.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page