Apple Mail MCP Server
io.github.JonathanRReed/apple-mcp-mail
Read, search, compose, and send emails via Apple Mail on macOS through AI agents.
What is the Apple Mail MCP server?
The Apple Mail MCP server enables AI clients to interact with Apple Mail on macOS, allowing you to read, search, compose, and send emails programmatically. It requires macOS, Python 3.11+, and appropriate Mail automation permissions.
This server bridges AI agents to Apple Mail, letting you search messages, read threads, compose emails, and send them directly from your Mac. It's useful for email automation, research, and integrating mail workflows into AI-assisted tasks. Mail attachments require explicit directory configuration for security.
How to install Apple Mail
Copy-paste configuration for popular MCP clients.
APPLE_MAIL_MCP_SAFETY_PROFILESafety mode for Mail operations: safe_readonly, safe_manage, or full_access.
APPLE_MAIL_MCP_ALLOWED_ATTACHMENT_ROOTDirectory attachments may be saved to or attached from. Unset disables attachment file access.
APPLE_MAIL_MCP_VISIBLE_DRAFTSWhether compose tools open visible draft windows in Mail.app.
Tools & capabilities
Tools this server exposes to the agent.
mail_search— Search emails by sender, subject fragment, or wildcard querymail_get_thread— Retrieve a complete email threadmail_reply_latest_in_thread— Reply to the most recent message in a threadmail_archive_thread— Archive an email threadmail_compose_and_send— Compose and send an email messagemail_health— Check Mail app health and permissions statusmail_permission_guide— Get guidance on granting Mail automation permissionsmail_recheck_permissions— Recheck Mail app permissions
Use cases
- Search and retrieve emails by sender or subject for research or information gathering
- Read and analyze email threads to understand conversations and context
- Compose and send emails programmatically as part of automated workflows
- Archive or organize email threads based on AI-driven decisions
- Check Mail app permissions and troubleshoot access issues
Apple Mail MCP server FAQ
It's an MCP server that gives AI agents like Claude access to Apple Mail on macOS. You can search emails, read threads, compose messages, and send them directly from your Mac.
Yes, the Apple Mail MCP server is open-source under the MIT license and free to use.
Download the `.mcpb` bundle from the GitHub releases page and double-click it. For other clients, use `uvx apple-mcp-mail` or register it in your client's configuration with the stdio transport.
The server requires Mail automation access on macOS. You'll be prompted to grant permission in System Settings. Mail attachments are disabled by default; you must set `APPLE_MAIL_MCP_ALLOWED_ATTACHMENT_ROOT` to enable them.
Attachments are disabled until you explicitly configure `APPLE_MAIL_MCP_ALLOWED_ATTACHMENT_ROOT` to a dedicated directory for security.
The server runs on your Mac, but your MCP client may send returned email data to its model provider, and Mail may sync through iCloud or another account. Local execution does not guarantee data stays local.
README (reference)
Source of truth, from the repository.
Apple-MCPs
MCP servers that let an AI client use Apple apps and macOS tools. Create reminders, send messages, check calendars, search mail, manage files, and get directions.
The servers run on your Mac. Your MCP client may send returned data to its model provider, and Apple apps may sync through iCloud or another account. Local execution does not mean the data stays local.
Requires Python 3.11+ and macOS. Uses MCP specification 2026-07-28 and Python SDK 2.x, with support for older client protocol revisions. MIT license.
Install
Install uv, then register the unified server with your client.
Claude Code:
claude mcp add --transport stdio --scope project apple-tools -- uvx apple-tools-mcp
Codex:
codex mcp add apple-tools -- uvx apple-tools-mcp
Other stdio clients:
{
"mcpServers": {
"apple-tools": {
"command": "uvx",
"args": ["apple-tools-mcp"]
}
}
}
Run uvx apple-tools-mcp to start the server directly. Standalone servers use the same approach, such as uvx apple-mcp-mail or uvx apple-calendar-mcp.
Restart your client after installing or upgrading. Call search_tools with calendar health to check discovery without reading app data.
For Claude Desktop, download a server's .mcpb bundle from Releases and double-click it.
Set app-specific safety modes and directories in your client's env settings. The configuration guide lists defaults and options. Mail attachments are disabled until you set APPLE_MAIL_MCP_ALLOWED_ATTACHMENT_ROOT to a dedicated directory. Files tools only access APPLE_FILES_MCP_ALLOWED_ROOTS; macOS may impose further restrictions.
Choose a server
Start with Apple-Tools-MCP. It combines all ten apps and tools below, plus saved defaults, contact routing, Mail thread helpers, undo, briefings, and cross-app workflows.
Choose a standalone server to expose fewer apps to your client:
| Server | macOS access | Health tool | Permission help |
|---|---|---|---|
| Automation access to Mail | mail_health | mail_permission_guide, mail_recheck_permissions | |
| Calendar | Calendar access | calendar_health | calendar_permission_guide, calendar_recheck_permissions |
| Reminders | Reminders access | reminders_health | reminders_permission_guide, reminders_recheck_permissions |
| Messages | Automation; Full Disk Access for history | messages_health | messages_permission_guide, messages_recheck_permissions |
| Contacts | Contacts access | contacts_health | contacts_permission_guide, contacts_recheck_permissions |
| Notes | Automation access to Notes | notes_health | notes_permission_guide, notes_recheck_permissions |
| Shortcuts | Usually no separate prompt | shortcuts_health | shortcuts_permission_guide, shortcuts_refresh_state |
| Files | Allowed roots and protected-folder access | files_health | files_permission_guide |
| System | Some actions need System Events, Accessibility, or Automation | system_health | system_permission_guide |
| Maps | No privacy prompt; Swift helper needs Xcode command line tools | maps_health | maps_permission_guide |
The unified server uses apple_health, apple_permission_guide, and apple_recheck_permissions. You must approve permissions yourself in the macOS prompt or System Settings.
Find and use tools
MCP tools/list returns each tool's schemas and read or write annotations. Use search_tools to search names, descriptions, and aliases; use get_tool_info for one tool's schema and examples.
Resolve recipients through Contacts before sending, unless you have the exact address. For Mail conversations, use mail_get_thread, mail_reply_latest_in_thread, or mail_archive_thread. Pass an exact sender email in from_account when the sending identity matters.
Mail search requires a query: a sender, subject fragment, or *. Reminders due_date requires a timezone offset, such as yyyy-MM-ddTHH:mm:ss-08:00. Omit service_name when sending iMessages.
The unified server also provides apple_generate_daily_briefing, apple_generate_weekly_briefing, and apple_triage_communications_task. Clients without prompt support can use apple_list_prompts, apple_get_prompt, and their per-server equivalents.
For calls from Python, use the metadata in generated/tool_catalogs/ and wrappers in generated/tool_wrappers/python/. See code-mode.md.
Transport and stored state
stdio is the default. To use Streamable HTTP, set APPLE_<DOMAIN>_MCP_TRANSPORT=streamable-http and the matching _HOST and _PORT variables.
HTTP must bind to 127.0.0.1, ::1, or localhost. The servers have no remote authentication and reject network and wildcard binds. Do not expose them through a tunnel or public proxy.
Apple-Tools-MCP stores defaults in ~/.apple-tools-mcp/preferences.json, configurable through APPLE_AGENT_MCP_STATE_FILE. It stores recent actions in ~/.apple-tools-mcp/actions.json for audit and undo.
Develop
git clone https://github.com/JonathanRReed/Apple-MCPs.git
cd Apple-MCPs
uv sync --all-packages
The uv workspace installs every server into .venv/bin. Each server folder also has a start.sh for clients; it uses uv when available and otherwise creates a virtual environment. Root pyproject.toml defines workspace members, and uv.lock pins dependencies.
| Path | Contents |
|---|---|
Apple-Tools-MCP/ | Unified server; module apple_agent_mcp, environment prefix APPLE_AGENT_MCP_* |
Apple<Domain>-MCP/ | Standalone servers; Calendar uses Apple-Calendar-MCP |
AppleMCPCommon/ | Shared discovery and search, published as apple-mcp-common |
generated/ | Tool catalogs and Python wrappers |
scripts/ | Installation, checks, generation, and bundle builds |
docs/ | Project and launch documentation |
Run smoke checks:
bash scripts/inspector_smoke.sh
uv run python scripts/protocol_smoke.py
For the official conformance suite, start the server in a separate terminal:
APPLE_AGENT_MCP_TRANSPORT=streamable-http \
APPLE_AGENT_MCP_PORT=8765 \
APPLE_AGENT_MCP_CONFORMANCE_MODE=1 \
./Apple-Tools-MCP/start.sh
npx -y @modelcontextprotocol/conformance@0.2.0-alpha.11 server --url http://127.0.0.1:8765/mcp --requirements 2026-07-28
Conformance mode registers test fixtures. Use it only for protocol validation. CI runs lint, macOS and Linux tests, generated-file checks, Inspector smoke checks, and conformance tests.
Documentation
Contributing · Security · Troubleshooting · MCP compatibility · Publishing · Changelog · Trademark notice · Launch docs
Related MCP servers

Apple Notes
Inspect, search, create, edit, move, and organize notes in Apple Notes on macOS via MCP.

Apple Reminders
Control Apple Reminders from Claude and Cursor—create, update, complete, and delete reminders on macOS.

Apple Shortcuts
List, inspect, and run Apple Shortcuts on macOS through MCP.

Apple System
Read and manage macOS system settings and perform scoped desktop actions from Claude or Cursor.

Apple Tools (Unified)
Control Apple apps from Claude and Cursor—Mail, Calendar, Notes, Messages, Reminders, and more on your Mac.