
Apple Mail MCP
io.github.jakobfigurv0.6.2更新于 Oct 6, 2026
Privacy-first local MCP for Apple Mail on macOS: inbox context, drafts, approvals, and follow-ups.
概览
一个本地 macOS MCP 服务器,让助手读取 Apple Mail、起草并发送经批准的消息,并跟踪后续事项。
- 功能
- 它连接 Mac 上已配置好的 Apple Mail 应用,提供列出账户和邮箱、汇总和搜索邮件、读取单封邮件正文等工具。创建草稿、发送、标记已读、加旗标和移动邮件等写入操作都需要用户明确批准,并在本地保留审批队列和仅含元数据的审计日志。它还会保存私人的联系人备注、会话摘要和跟进提醒,并可生成每日简报。
- 适用场景
- 当你希望助手在 macOS 上处理已有的 Apple Mail 邮箱、又不想配置 IMAP 或 SMTP 凭据时使用,例如整理收件箱、准备待审阅的草稿或跟踪后续事项。它适合希望在发送或修改任何内容前先由人工批准的用户。
- 运行要求
- macOS 并已配置 Apple Mail、Node.js 20+,以及在系统设置、隐私与安全性、自动化中授予宿主应用控制 Mail 的权限。它通过 stdio 在本地运行,不需要 IMAP 或 SMTP 密码,也不开放网络端口。可选环境变量用于配置允许的发件人列表、审计日志路径、数据存储路径、试运行模式、收件人限制和发送时间窗口。
安装
在 SourceWeft 中
- 打开 控制台中的 Apple Mail MCP,将其添加到工作区。
- 为需要使用其工具的对话启用该服务。
Desktop only,通过 STDIO。 STDIO 服务会启动本地进程,因此需要 SourceWeft 桌面宿主。
其他 MCP 客户端
参照 仓库 中的启动说明。
README
Apple Mail MCP
A local, stdio-based Model Context Protocol server for Apple Mail on macOS.
It talks only to the Apple Mail app already configured on the user's Mac. It does not need IMAP/SMTP passwords or open a network port.
Safety model
- Mailbox and message tools are read-only by default.
create_draftopens an unsent, visible draft in Apple Mail.send_emailrequiresuser_approved: true. MCP clients should call it only after the user has approved the exact message.- Message changes such as marking, flagging, and moving also require
user_approved: true. - Dynamic content is passed to
osascriptas arguments, not interpolated into AppleScript source. - Every write action has a local, metadata-only JSONL audit entry. Bodies and credentials are never written to that log.
- The approval inbox and relationship context are stored only in the local JSON data store described below.
The MCP server itself is local. However, an MCP client may send tool results to an AI model or another service. Only connect clients and models you trust with mail content.
Requirements
- macOS with Apple Mail configured
- Node.js 20+
- Permission for the host application (for example Codex or Terminal) to control Mail under System Settings → Privacy & Security → Automation
Install
npm (recommended)
Then configure your MCP client with the installed command:
From source
Add to an MCP client
If you installed from source rather than npm, use the compiled server over stdio:
Restart the MCP client after saving its configuration. The first call will trigger the normal macOS automation permission prompt.
Optional sender policy
To allow sending only from specific configured Apple Mail addresses, configure a comma-separated allowlist when launching the server:
Write-action audit metadata is stored locally at ~/.apple-mail-mcp/audit.jsonl by default. Set APPLE_MAIL_MCP_AUDIT_LOG to use another local path.
AI-first local workspace
The approval inbox and relationship context share a local JSON store at ~/.apple-mail-mcp/data.json by default. It contains queued draft bodies and the contact notes you intentionally save, so treat it as private mail data. Set APPLE_MAIL_MCP_DATA_STORE to use another local path.
APPLE_MAIL_MCP_DRY_RUN=true validates sends but prevents delivery. You can also enforce recipient restrictions with APPLE_MAIL_MCP_ALLOWED_RECIPIENTS, APPLE_MAIL_MCP_ALLOWED_RECIPIENT_DOMAINS, and a local time window such as APPLE_MAIL_MCP_SENDING_WINDOW=09:00-18:00.
Tools
Scope and non-goals
This project is local-only. It is not an SMTP server, does not manage credentials, and does not bypass macOS privacy prompts. It deliberately excludes deletion, attachment export, background scheduling, and automatic sending.
Publishing and registry metadata
The package is published as @jakobf1/apple-mail-mcp. Its MCP Registry identity is io.github.jakobfigur/apple-mail-mcp; see server.json for portable install metadata.
License
MIT
来源:README.md,提交 275e7f9
工具
0版本历史
1- v0.6.2最新Oct 6, 2026

