
Apple Mail MCP
io.github.jakobfigurv0.6.2更新於 Oct 6, 2026
Privacy-first local MCP for Apple Mail on macOS: inbox context, drafts, approvals, and follow-ups.
概覽
一個本機 macOS MCP 伺服器,讓助理讀取 Apple Mail、起草並寄送經核准的郵件,並追蹤後續事項。
- 功能
- 它連接 Mac 上已設定好的 Apple Mail 應用程式,提供列出帳號與信箱、彙總與搜尋郵件、讀取單封郵件內文等工具。建立草稿、寄送、標示已讀、加上旗標和移動郵件等寫入操作都需要使用者明確核准,並在本機保留核准佇列與僅含中繼資料的稽核記錄。它也會儲存私人的聯絡人備註、郵件串摘要和後續提醒,並可產生每日簡報。
- 適用情境
- 當你希望助理在 macOS 上處理既有的 Apple Mail 信箱、又不想設定 IMAP 或 SMTP 憑證時使用,例如整理收件匣、準備待審閱的草稿或追蹤後續事項。它適合希望在寄送或修改任何內容前先由人工核准的使用者。
- 執行需求
- macOS 並已設定 Apple Mail、Node.js 20+,以及在系統設定、隱私權與安全性、自動化中授予主機應用程式控制 Mail 的權限。它透過 stdio 在本機執行,不需要 IMAP 或 SMTP 密碼,也不開放網路連接埠。選用環境變數可設定允許的寄件者清單、稽核記錄路徑、資料存放區路徑、試執行模式、收件者限制和寄送時間範圍。
安裝
在 SourceWeft 中
- 開啟 儀表板中的 Apple Mail MCP,將其新增到工作區。
- 為需要使用其工具的對話啟用該服務。
Desktop only,透過 STDIO。 STDIO 服務會啟動本機處理程序,因此需要 SourceWeft 桌面主機。
其他 MCP 客戶端
參照 儲存庫 中的啟動說明。
README
Apple Mail MCP
A local, stdio-based Model Context Protocol server for Apple Mail on macOS.
It talks only to the Apple Mail app already configured on the user's Mac. It does not need IMAP/SMTP passwords or open a network port.
Safety model
- Mailbox and message tools are read-only by default.
create_draftopens an unsent, visible draft in Apple Mail.send_emailrequiresuser_approved: true. MCP clients should call it only after the user has approved the exact message.- Message changes such as marking, flagging, and moving also require
user_approved: true. - Dynamic content is passed to
osascriptas arguments, not interpolated into AppleScript source. - Every write action has a local, metadata-only JSONL audit entry. Bodies and credentials are never written to that log.
- The approval inbox and relationship context are stored only in the local JSON data store described below.
The MCP server itself is local. However, an MCP client may send tool results to an AI model or another service. Only connect clients and models you trust with mail content.
Requirements
- macOS with Apple Mail configured
- Node.js 20+
- Permission for the host application (for example Codex or Terminal) to control Mail under System Settings → Privacy & Security → Automation
Install
npm (recommended)
Then configure your MCP client with the installed command:
From source
Add to an MCP client
If you installed from source rather than npm, use the compiled server over stdio:
Restart the MCP client after saving its configuration. The first call will trigger the normal macOS automation permission prompt.
Optional sender policy
To allow sending only from specific configured Apple Mail addresses, configure a comma-separated allowlist when launching the server:
Write-action audit metadata is stored locally at ~/.apple-mail-mcp/audit.jsonl by default. Set APPLE_MAIL_MCP_AUDIT_LOG to use another local path.
AI-first local workspace
The approval inbox and relationship context share a local JSON store at ~/.apple-mail-mcp/data.json by default. It contains queued draft bodies and the contact notes you intentionally save, so treat it as private mail data. Set APPLE_MAIL_MCP_DATA_STORE to use another local path.
APPLE_MAIL_MCP_DRY_RUN=true validates sends but prevents delivery. You can also enforce recipient restrictions with APPLE_MAIL_MCP_ALLOWED_RECIPIENTS, APPLE_MAIL_MCP_ALLOWED_RECIPIENT_DOMAINS, and a local time window such as APPLE_MAIL_MCP_SENDING_WINDOW=09:00-18:00.
Tools
Scope and non-goals
This project is local-only. It is not an SMTP server, does not manage credentials, and does not bypass macOS privacy prompts. It deliberately excludes deletion, attachment export, background scheduling, and automatic sending.
Publishing and registry metadata
The package is published as @jakobf1/apple-mail-mcp. Its MCP Registry identity is io.github.jakobfigur/apple-mail-mcp; see server.json for portable install metadata.
License
MIT
來源:README.md,提交 275e7f9
工具
0版本歷史
1- v0.6.2最新Oct 6, 2026

