Gmail SMTP MCP Server
Enables sending emails via Gmail using SMTP and app passwords without OAuth. It provides a custom authorization flow and encrypted credential storage for multi-user access.
README
Gmail SMTP MCP Server (Python)
Sends email as a teammate's Gmail account via SMTP + an App Password,
instead of Google OAuth. No Google Cloud project, no client secret, no
redirect_uri allowlist, no consent screen. This is a Python port of the
Node.js version — same architecture, same endpoints.
How auth works
claude.ai's connector setup still expects a normal OAuth 2.1 + PKCE dance — that part of the MCP spec doesn't change. What changes is who the "identity provider" is:
- User adds your connector in claude.ai → claude.ai opens
/authorize. - Instead of "Sign in with Google", they see a form asking for their Gmail address + an App Password (requires 2-Step Verification on their Google account).
- The server test-sends an email to confirm the credentials work, encrypts and stores the app password, then redirects back to claude.ai with an auth code — same as a normal OAuth flow.
- claude.ai exchanges that code at
/tokenfor a bearer token. - Every
send_email_toolcall carries that bearer token; the server looks up which Gmail account it maps to (via the token'ssubject) and sends via SMTP using only Python's standard library (smtplib).
Nothing here talks to Google's OAuth API. There's no client secret to leak or rotate.
Setup
pip install -r requirements.txt
# Generate a 32-byte encryption key for storing app passwords at rest
export MASTER_KEY=$(python3 -c "import secrets; print(secrets.token_hex(32))")
export BASE_URL=http://localhost:3000
uvicorn server:app --port 3000
Add both MASTER_KEY and BASE_URL to a .env file if you'd rather not
export them each time — just make sure something loads it before uvicorn
starts (e.g. python-dotenv, or your platform's env var settings).
Deploying to Render
- Push this repo, create a new Web Service pointing at it.
- Build command:
pip install -r requirements.txt - Start command:
uvicorn server:app --host 0.0.0.0 --port $PORT
- Build command:
- Set env vars:
MASTER_KEY(generate as above),BASE_URL(your Render URL, e.g.https://your-app.onrender.com). - Important:
data.json(where users/tokens live) is written to local disk. Render's free web services have ephemeral disks — a redeploy wipes it and every teammate has to reconnect. For anything beyond testing, either add a Render persistent disk mount, or swapstore.pyfor Postgres/SQLite (the function signatures instore.pyare the only thing you'd need to keep the same). - In claude.ai, add a custom connector pointing at
https://your-app.onrender.com/mcp.
Files
server.py— FastAPI app: OAuth-shaped/authorize+/tokenendpoints, the MCP server (built withmcp'sFastMCP) mounted at/mcpwith bearer-token auth enforced automatically by the SDK.store.py— encrypted (AES-256-GCM) storage for app passwords, auth codes, and access tokens.mailer.py— sends viasmtp.gmail.com:465using Python's built-insmtplib, no extra package needed.
A gotcha worth knowing about if you modify this
FastMCP's streamable_http_app() normally manages its own startup/shutdown
(a "session manager") when run standalone. When you mount it inside another
FastAPI app with app.mount("/mcp", ...), FastAPI does not automatically
run the sub-app's lifespan — so streaming requests fail with
RuntimeError: Task group is not initialized. The fix already in
server.py is wiring mcp.session_manager.run() into the outer FastAPI
app's own lifespan. If you restructure this file, keep that wiring intact.
Security notes
- App passwords are encrypted at rest with
MASTER_KEY, but they're still bearer credentials with full mail-send access — treatdata.json(or your DB) like you would a password table. - Access tokens are long-lived (90 days) bearer tokens with no rotation. Fine for an internal team tool; add refresh tokens or shorter expiry if this ever leaves that trust boundary.
- Anyone who can reach
/authorizecan register any Gmail address they control an app password for — there's no allowlist. Add one (e.g. only@caratlane.comaddresses) if you want to restrict this before sharing the connector link.
Recommended Servers
playwright-mcp
A Model Context Protocol server that enables LLMs to interact with web pages through structured accessibility snapshots without requiring vision models or screenshots.
Magic Component Platform (MCP)
An AI-powered tool that generates modern UI components from natural language descriptions, integrating with popular IDEs to streamline UI development workflow.
Audiense Insights MCP Server
Enables interaction with Audiense Insights accounts via the Model Context Protocol, facilitating the extraction and analysis of marketing insights and audience data including demographics, behavior, and influencer engagement.
VeyraX MCP
Single MCP tool to connect all your favorite tools: Gmail, Calendar and 40 more.
graphlit-mcp-server
The Model Context Protocol (MCP) Server enables integration between MCP clients and the Graphlit service. Ingest anything from Slack to Gmail to podcast feeds, in addition to web crawling, into a Graphlit project - and then retrieve relevant contents from the MCP client.
Kagi MCP Server
An MCP server that integrates Kagi search capabilities with Claude AI, enabling Claude to perform real-time web searches when answering questions that require up-to-date information.
E2B
Using MCP to run code via e2b.
Neon Database
MCP server for interacting with Neon Management API and databases
Exa Search
A Model Context Protocol (MCP) server lets AI assistants like Claude use the Exa AI Search API for web searches. This setup allows AI models to get real-time web information in a safe and controlled way.
Qdrant Server
This repository is an example of how to create a MCP server for Qdrant, a vector search engine.