
Apple Mail MCP
io.github.jakobfigurv0.6.2Updated Oct 6, 2026
Privacy-first local MCP for Apple Mail on macOS: inbox context, drafts, approvals, and follow-ups.
Overview
A local macOS MCP server that lets an assistant read Apple Mail, draft and send approved messages, and track follow-ups.
- What it does
- It connects to the Apple Mail app already configured on the Mac and exposes tools for listing accounts and mailboxes, summarizing and searching messages, and reading a single message body. Write actions such as creating drafts, sending, marking, flagging, and moving require explicit user approval, and an approval queue plus a metadata-only audit log are kept locally. It also stores private contact notes, thread summaries, and follow-up reminders, and can produce a daily briefing.
- When to use it
- Use it when you want an assistant to work with an existing Apple Mail mailbox on macOS without configuring IMAP or SMTP credentials, for example to triage an inbox, prepare drafts for review, or keep track of follow-ups. It suits users who want human approval before anything is sent or changed.
- Requirements
- macOS with Apple Mail configured, Node.js 20+, and permission for the host application to control Mail under System Settings, Privacy & Security, Automation. It runs locally over stdio, needs no IMAP or SMTP passwords, and opens no network port. Optional environment variables configure an allowed sender list, audit log path, data store path, dry-run mode, recipient restrictions, and a sending window.
Installation
In SourceWeft
- Open Apple Mail MCP in the dashboard and add it to a workspace.
- Enable the server for the chats that should use its tools.
Desktop only via STDIO. STDIO servers start a local process, so they need the SourceWeft desktop host.
Other MCP clients
Follow the launch instructions in the repository.
README
Apple Mail MCP
A local, stdio-based Model Context Protocol server for Apple Mail on macOS.
It talks only to the Apple Mail app already configured on the user's Mac. It does not need IMAP/SMTP passwords or open a network port.
Safety model
- Mailbox and message tools are read-only by default.
create_draftopens an unsent, visible draft in Apple Mail.send_emailrequiresuser_approved: true. MCP clients should call it only after the user has approved the exact message.- Message changes such as marking, flagging, and moving also require
user_approved: true. - Dynamic content is passed to
osascriptas arguments, not interpolated into AppleScript source. - Every write action has a local, metadata-only JSONL audit entry. Bodies and credentials are never written to that log.
- The approval inbox and relationship context are stored only in the local JSON data store described below.
The MCP server itself is local. However, an MCP client may send tool results to an AI model or another service. Only connect clients and models you trust with mail content.
Requirements
- macOS with Apple Mail configured
- Node.js 20+
- Permission for the host application (for example Codex or Terminal) to control Mail under System Settings → Privacy & Security → Automation
Install
npm (recommended)
Then configure your MCP client with the installed command:
From source
Add to an MCP client
If you installed from source rather than npm, use the compiled server over stdio:
Restart the MCP client after saving its configuration. The first call will trigger the normal macOS automation permission prompt.
Optional sender policy
To allow sending only from specific configured Apple Mail addresses, configure a comma-separated allowlist when launching the server:
Write-action audit metadata is stored locally at ~/.apple-mail-mcp/audit.jsonl by default. Set APPLE_MAIL_MCP_AUDIT_LOG to use another local path.
AI-first local workspace
The approval inbox and relationship context share a local JSON store at ~/.apple-mail-mcp/data.json by default. It contains queued draft bodies and the contact notes you intentionally save, so treat it as private mail data. Set APPLE_MAIL_MCP_DATA_STORE to use another local path.
APPLE_MAIL_MCP_DRY_RUN=true validates sends but prevents delivery. You can also enforce recipient restrictions with APPLE_MAIL_MCP_ALLOWED_RECIPIENTS, APPLE_MAIL_MCP_ALLOWED_RECIPIENT_DOMAINS, and a local time window such as APPLE_MAIL_MCP_SENDING_WINDOW=09:00-18:00.
Tools
Scope and non-goals
This project is local-only. It is not an SMTP server, does not manage credentials, and does not bypass macOS privacy prompts. It deliberately excludes deletion, attachment export, background scheduling, and automatic sending.
Publishing and registry metadata
The package is published as @jakobf1/apple-mail-mcp. Its MCP Registry identity is io.github.jakobfigur/apple-mail-mcp; see server.json for portable install metadata.
License
MIT
Source: README.md at commit 275e7f9
Tools
0Version history
1- v0.6.2LatestOct 6, 2026

