
Agent Mail Gateway
io.github.dominikamannv0.1.4Updated Oct 2, 2026
Self-hosted email for AI agents: own IMAP/SMTP mailbox per key, allow lists, calendar invites.
Overview
Self-hosted gateway giving each AI agent its own IMAP/SMTP mailbox with allow lists, attachments and calendar invites.
- What it does
- Agent Mail Gateway is a self-hosted Docker service that sits between agents and ordinary IMAP/SMTP mailboxes. Each agent gets one API key bound to exactly one mailbox, and can read mail, send mail with attachments, and create, update or cancel calendar invitations. Mail bodies are converted between HTML and Markdown, and per-mailbox allow lists control who an agent may receive from and write to. It exposes both a REST API and an MCP server with tools such as list_messages, read_message, send_message, create_event and cancel_event.
- When to use it
- Use it when agents need real email: sending reports, alerts or summaries, receiving tasks or documents and replying in the same thread, or scheduling meetings by calendar invitation. It also suits running several agents on separate mailboxes of an existing mail server without exposing mailbox passwords, and locking an agent down to approved contacts.
- Requirements
- A local Docker runtime (or the bundled Node.js stdio bridge) plus an IMAP/SMTP mail account with TLS. Configuration lives in config.yaml and .env, including an API key per agent and an optional webhook secret. Clients authenticate with an Authorization Bearer header. Network access to the mail server is required.
Installation
In SourceWeft
- Open Agent Mail Gateway in the dashboard and add it to a workspace.
- Enable the server for the chats that should use its tools.
Desktop only via STDIO. STDIO servers start a local process, so they need the SourceWeft desktop host.
Other MCP clients
Follow the launch instructions in the repository.
README
Agent Mail Gateway
Give every AI agent its own email mailbox — without giving it the keys to that mailbox.
Agent Mail Gateway is a small self-hosted Docker service that sits between your agents and ordinary IMAP/SMTP mailboxes (Plesk, IONOS, Outlook, your own server — any provider). Each agent gets one API key bound to exactly one mailbox. Through the gateway it can read mail, send mail with attachments, and send, update or cancel calendar invitations. You decide who each agent may receive mail from and who it may write to; everything else is filtered out.
Mail bodies are delivered to the agent as Markdown (converted from HTML) and the agent writes Markdown that is sent as HTML — far fewer tokens than raw HTML email.
In short: a self-hosted email MCP server and REST API for AI agents — IMAP/SMTP mailbox access with sender/recipient allow lists, HTML-to-Markdown, attachments and calendar invites, packaged as one Docker container.
Typical use cases
- An assistant agent that sends you daily reports, summaries or alerts by email.
- Agents that receive tasks or documents by email and answer them in the same thread.
- Agents that schedule, move and cancel meetings with you via calendar invitations.
- Giving several agents separate mailboxes on your existing mail server (Plesk, IONOS, Outlook, Postfix/Dovecot, …) without exposing the mailbox passwords to them.
- Locking an agent down so it can only talk to approved people — useful against prompt injection by email and against agents mailing the wrong people.
Works with any MCP client (for example Hermes Agent, Cursor, VS Code, n8n, LangChain/LangGraph MCP adapters) and with anything that can make HTTP requests.
Features
- N mailboxes, one key each — a key can never reach another mailbox.
- Allow lists per mailbox for receiving and sending (
name@domainor*@domain). - Filtered mail is invisible — not listed, not readable, not even by guessing an id. Non-allowed mail is moved to Trash (default) or left untouched.
- Spoofing protection — senders must pass SPF/DKIM/DMARC as reported by your mail server.
- HTML ⇄ Markdown conversion in both directions.
- Attachments in and out.
- Calendar invites (iCalendar) that update or cancel cleanly in Outlook, Gmail and Apple Calendar.
- REST API with OpenAPI docs at
/docs, and an MCP server at/mcpwith the same tools. - Webhooks (HMAC-signed) when an allowed message arrives; new mail is detected instantly via IMAP IDLE.
- Send rate limit per mailbox and an audit log of every send, rejection and deletion.
- Works with any IMAP/SMTP server: TLS on 993/465 or STARTTLS on 143/587.
How it works
The gateway stores no mail content; mail stays on your mail server.
Quick start
- Get the files:
- Edit
config.yaml: one entry per agent with its mailbox server, login and allow lists. - Fill
.envwith the secrets referenced inconfig.yaml: - Start it:
Every option is explained in docs/configuration.md.
Using it
REST — send a message:
Read new mail:
MCP — point any MCP client at http://<host>:8080/mcp with the header
Authorization: Bearer <api key>. Tools: get_mailbox_info, list_messages, read_message,
get_attachment, mark_message, delete_message, send_message, create_event,
update_event, cancel_event, list_events.
stdio — clients that can only start local processes use the bundled bridge
node dist/stdio.js with AGENT_MAIL_URL and AGENT_MAIL_API_KEY; see
docs/stdio.md.
See docs/api.md for every endpoint, the webhook format and examples.
Hermes Agent — connect the MCP server in ~/.hermes/config.yaml and install the plugin
that teaches your agents to use their mailbox safely:
Step by step: docs/hermes.md.
Documentation
- Configuration
- REST API, webhooks and MCP tools
- Hermes Agent integration and plugin
- stdio clients
- Security model
- Contributing
Security
Run the gateway behind a TLS reverse proxy when it is reachable from other machines. Report vulnerabilities privately as described in SECURITY.md.
License
Proudly provided by amannlabs.eu
Source: README.md at commit 6821eea
Tools
0Version history
1- v0.1.4LatestOct 2, 2026


