Route WPT 04 GMAIL · Open source
gmail-mcp-server, Gmail for AI assistants
An MCP server that lets an AI assistant work across several Gmail accounts, each with only the access it needs.
3levels
read, modify, or send, per account
35tests
plus a secret scan on every push
12tools
search, read, draft, send, labels
01Context
AI assistants are useful in an inbox, and dangerous with full access to it. I wanted an assistant that could search every account but only send from the ones I allow.
02Key decisions
One permission level for every account is either too weak or too risky.
- Choice
- Pick an access level per account when it is added. Tools that need more access refuse with a clear message.
- Tradeoff
- Adding an account takes one more decision up front.
Local and hosted setups need different transports.
- Choice
- Stdio for a local client, or Streamable HTTP with bearer-token auth and a constant-time token check for hosted use.
- Tradeoff
- Two transports to test, so both run protocol checks in CI.
03Evidence
- Refresh tokens only, stored in a 0600 file inside a 0700 directory. No access tokens are persisted.
- Cross-account search that fans out and merges results by date.
- A Docker image that runs as a non-root user.
04Results
- Public, MIT-licensed, with CI green on every push.
05Stack
TypeScript · MCP SDK · Gmail API · Vitest · GitHub Actions · Docker
Want this kind of work on your product?
Email me