gmail-mcp
MCP server for Gmail with full read/write coverage: search, send, reply, drafts, labels, filters, vacation responder, auto-forwarding, signature, and attachment handling (download and PDF export). Uses the Gmail API with the gmail.modify scope to prevent permanent deletion, and requires explicit confirmation for sensitive actions.
README
gmail-mcp
MCP server for Gmail with full read/write coverage: search, send, reply, drafts, labels, filters, vacation responder, auto-forwarding, signature, and attachment handling (download + render to PDF).
Built because the commonly available Gmail MCP integrations are read/label-only (no sending, no attachment export, no settings management). This one closes that gap using the standard Gmail API with your own OAuth client.
Why it's safe by design
The OAuth scope used is gmail.modify, not the full https://mail.google.com/
scope. This means the Gmail API itself rejects permanent delete
(messages.delete, batchDelete, threads.delete) — the only "removal" tool
is trash/untrash, which is reversible.
Tools (34)
Read / search
| Tool | What it does |
|---|---|
get_profile |
Account email and message/thread totals |
list_messages |
Search with Gmail query syntax (query, label_ids, pagination) |
get_message |
Parsed message: from/to/cc/subject/date/body/labels/attachments |
get_thread |
Full thread with all messages parsed |
list_attachments |
Real attachment metadata for a message (with attachment_id) |
download_attachment |
Download an attachment to disk |
export_message_to_pdf |
Render a message (HTML + inline images resolved) to PDF via WeasyPrint |
export_thread_to_pdf |
Same, for a full thread (one message per page) |
Send / reply (require confirmed=True)
| Tool | What it does |
|---|---|
send_message |
Send a new email (text/HTML, attachments) |
reply_message |
Reply within a thread, auto-generating In-Reply-To/References |
Drafts
| Tool | What it does |
|---|---|
list_drafts / get_draft |
List and read drafts |
create_draft / update_draft / delete_draft |
Manage drafts |
send_draft |
Send an existing draft (confirmed=True) |
Labels
| Tool | What it does |
|---|---|
list_labels / create_label / update_label |
Label management |
delete_label |
Delete a label (confirmed=True) |
modify_message_labels / modify_thread_labels |
Add/remove labels on a message or full thread |
Organization (trash only, reversible)
| Tool | What it does |
|---|---|
trash_message / untrash_message |
Move to trash / restore |
batch_modify_messages |
Change labels on several messages at once |
Settings
| Tool | What it does |
|---|---|
get_vacation / update_vacation |
Vacation auto-responder |
get_auto_forwarding / update_auto_forwarding |
Auto-forwarding (confirmed=True when enabling — this is a data-exfiltration vector, double check the destination address) |
list_filters / create_filter / delete_filter |
Filters (delete_filter requires confirmed=True) |
list_send_as / update_signature |
Send-as aliases and HTML signature (confirmed=True) |
Confirmation pattern
Tools that send mail, delete something, or change externally-visible settings
take confirmed: bool = False. Called without it, they return
{"requires_confirmation": true, ...} with a preview of what would happen —
the calling agent must show that preview to the user and only repeat the call
with confirmed=True after explicit approval. confirmed=True is a technical
flag, not a substitute for actually asking.
Setup
- Create a Google Cloud project (or reuse one) and enable the Gmail API.
- Create an OAuth 2.0 Client ID of type "Desktop app" and download it as
client_secret.json. - On the OAuth consent screen, add these scopes:
gmail.modify,gmail.settings.basic,gmail.settings.sharing. - If the app is in "Testing" mode, add your own Google account as a test user.
- Install dependencies:
python3 -m venv .venv source .venv/bin/activate pip install -r requirements.txt # weasyprint also needs a system package for PDF rendering: # macOS: brew install pango # Debian/Ubuntu: apt install libpango-1.0-0 libpangocairo-1.0-0 - Run the OAuth flow once per account:
This opens a browser — log in and grant access. Run it again with a differentCLIENT_SECRET_PATH=~/.config/gmail-mcp/client_secret.json \ TOKEN_OUT=~/.config/gmail-mcp/token.json \ python3 setup_auth.pyTOKEN_OUTfor each additional Gmail account you want to expose as a separate MCP server instance.
MCP client configuration
{
"mcpServers": {
"gmail": {
"command": "/path/to/.venv/bin/python3",
"args": ["/path/to/gmail-mcp/server.py"],
"env": {
"GMAIL_TOKEN_PATH": "~/.config/gmail-mcp/token.json"
}
}
}
}
To expose a second account, add another entry (e.g. gmail-work) pointing at
the same server.py with a different GMAIL_TOKEN_PATH.
| Env var | Default | Purpose |
|---|---|---|
GMAIL_TOKEN_PATH |
~/.config/gmail-mcp/token.json |
Path to the OAuth token for this account |
Notes on usage (for the calling agent)
- API quota: 6,000 units/user/minute.
messages.getcosts 20 units,messages.listcosts 5. Filter with Gmail'squerysyntax instead of fetching everything and filtering client-side. - Use
get_threadinstead of Nget_messagecalls when you need a whole conversation. attachment_idis not stable across calls — always use the one from the same response you're about to calldownload_attachmentwith.- Prefer
body_htmloverbody_textfor anything with lists, bold text or links — Gmail does not reflow plain text, so\nbecomes a hard line break. - No automatic retry on 429 — back off manually if you hit a rate limit.
License
MIT — see LICENSE.
Recommended Servers
playwright-mcp
A Model Context Protocol server that enables LLMs to interact with web pages through structured accessibility snapshots without requiring vision models or screenshots.
Magic Component Platform (MCP)
An AI-powered tool that generates modern UI components from natural language descriptions, integrating with popular IDEs to streamline UI development workflow.
Audiense Insights MCP Server
Enables interaction with Audiense Insights accounts via the Model Context Protocol, facilitating the extraction and analysis of marketing insights and audience data including demographics, behavior, and influencer engagement.
VeyraX MCP
Single MCP tool to connect all your favorite tools: Gmail, Calendar and 40 more.
graphlit-mcp-server
The Model Context Protocol (MCP) Server enables integration between MCP clients and the Graphlit service. Ingest anything from Slack to Gmail to podcast feeds, in addition to web crawling, into a Graphlit project - and then retrieve relevant contents from the MCP client.
Kagi MCP Server
An MCP server that integrates Kagi search capabilities with Claude AI, enabling Claude to perform real-time web searches when answering questions that require up-to-date information.
E2B
Using MCP to run code via e2b.
Neon Database
MCP server for interacting with Neon Management API and databases
Exa Search
A Model Context Protocol (MCP) server lets AI assistants like Claude use the Exa AI Search API for web searches. This setup allows AI models to get real-time web information in a safe and controlled way.
Qdrant Server
This repository is an example of how to create a MCP server for Qdrant, a vector search engine.