Are you the author? Sign in to claim
A reliable, native Gmail MCP server with full mailbox control — including snooze.
A reliable, native Gmail MCP server — full mailbox triage for AI assistants, with the feature nobody else ships: snooze.
is:unread in some operator
combinations — search re-verifies every hit against its live labels and discards the index's
false positives. Paginated via pageToken/nextPageToken.bulk_modify archives/labels everything matching a query at
1000 messages per API request — with per-chunk partial-success reporting instead of
all-or-nothing. The snooze sweep uses the same batch path.outputSchema and returns validated
structuredContent alongside fenced JSON text — no parsing guesswork for clients.=?UTF-8?B?…?= → readable text),
bodies decoded in their declared charset (no mojibake for ISO-8859-1/Shift_JIS mail),
429/5xx retried with exponential backoff.Connectors that sync or cache your mailbox can lag behind it — and even Gmail's own search index is sometimes loose (see below). mailwarden talks straight to the live Gmail API (no cached snapshot) and re-verifies what the index returns, so what you see is what's actually there. It's a generic Gmail capability layer — keep your own rules/logic in your AI client, not in the server.
search goes one step further than the raw API: Gmail's threads.list index is sometimes loose for read-state operators — is:unread is silently dropped in some operator combinations (e.g. category:updates is:unread -in:inbox returns read mail too). Since every hit is fetched live anyway, search re-checks the unambiguous predicates (is:unread/is:read/is:starred/in:inbox/category:…, with negation) against each thread's true labels and drops the index's false positives.
| Tool | What it does |
|---|---|
search | Gmail query syntax → thread summaries (from/subject/date/labels/snippet); read-state/category predicates are re-verified against each hit's live labels; paginated via pageToken/nextPageToken |
get_thread | Full thread: headers, plaintext + HTML bodies, attachment metadata |
list_labels | All labels (system + user) |
modify_labels | Add/remove labels (archive = remove INBOX, read = remove UNREAD) |
bulk_modify | Batch label changes for every message matching a query — 1000 messages per API request, partial success reported per chunk (thread-id list capped at 500, modifiedThreadCount has the total) |
archive / mark_read / mark_unread | Convenience wrappers |
trash / untrash | Move to / restore from Trash |
download_attachment | Save an attachment to a local path (never overwrites — collisions get a numeric suffix) |
snooze | Archive now, resurface on/after a date (YYYY-MM-DD) |
unsnooze | Cancel a snooze, return to inbox now |
list_snoozed | All snoozed threads + due dates |
sweep_snoozed | Resurface threads whose snooze is due (run on demand, via cron, or the daemon); batched, with partial-failure reporting |
All tools declare an outputSchema and return structured content (validated, machine-readable)
alongside the same JSON as fenced text — clients never have to parse prose.
snooze removes INBOX and applies a dated label MCP/Snoozed/<YYYY-MM-DD>. sweep_snoozed finds due labels and returns those threads to the inbox (marked unread). Run the sweep:
sweep_snoozed tool),mailwarden --sweep,MAILWARDEN_AUTO_SWEEP=1 (hourly sweep while the server runs).--http, optionally gated by a MAILWARDEN_TOKEN bearer token.MAILWARDEN_READONLY=1 and only the read tools (search, get_thread,
list_labels, list_snoozed) are registered — nothing that can change the mailbox or write
files is even advertised to clients. Recommended for shared/HTTP deployments that only triage.MAILWARDEN_DOWNLOAD_DIR set, attachment writes are confined to that
directory (realpath-canonicalized, symlink-aware) and never overwrite an existing file.<untrusted-tool-output> markers
and stripped of invisible/BiDi-override characters, so clients can tell quoted mail content from
instructions.~/.mailwarden/.claude mcp add mailwarden -- npx -y mailwarden
That's the whole install — npx fetches and runs the published package, no clone or build step. You only need Google OAuth credentials once (below).
credentials.json.credentials.json in ~/.mailwarden/ (or set MAILWARDEN_CREDENTIALS=/path/to/credentials.json).~/.mailwarden/token.json:
npx -y mailwarden --auth
https://www.googleapis.com/auth/gmail.modify.Claude Code (local stdio):
claude mcp add mailwarden -- npx -y mailwarden
Claude Desktop — add to claude_desktop_config.json:
{
"mcpServers": {
"mailwarden": { "command": "npx", "args": ["-y", "mailwarden"] }
}
}
Remote (Streamable HTTP) — for a VPS / claude.ai custom connector:
npx -y mailwarden --http # listens on :8787/mcp ; set PORT, optional MAILWARDEN_TOKEN bearer gate
Then in claude.ai: Settings → Connectors → Add custom connector → your https://your-host/mcp URL. In Claude Code: claude mcp add --transport http mailwarden https://your-host/mcp.
git clone https://github.com/csitte/mailwarden && cd mailwarden
npm install && npm run build
node dist/index.js --auth
| Var | Meaning |
|---|---|
MAILWARDEN_DIR | config dir (default ~/.mailwarden) |
MAILWARDEN_CREDENTIALS | path to credentials.json |
MAILWARDEN_AUTO_SWEEP | 1 → snooze sweep at startup + hourly while running |
MAILWARDEN_DOWNLOAD_DIR | restrict download_attachment to this directory (strongly recommended for HTTP hosting) |
MAILWARDEN_READONLY | 1 → register only the read tools (search/get_thread/list_labels/list_snoozed) |
PORT | HTTP port (default 8787) |
MAILWARDEN_TOKEN | optional bearer token for the HTTP endpoint |
0.1.7 — working. Core Gmail tools + snooze implemented against googleapis and used in daily mailbox automation. Covered by a vitest suite (116 tests, ~99 % statement coverage — npm run coverage). See the changelog / releases. PRs welcome.
MIT © C.Sitte Softwaretechnik
Run Claude Code as an MCP server so any agent can delegate coding tasks to it
Browser automation using accessibility snapshots instead of screenshots
Google's universal MCP server supporting PostgreSQL, MySQL, MongoDB, Redis, and 10+ databases
Official GitHub integration for repos, issues, PRs, and CI/CD workflows