Read Proton Mail, extract bounded attachment text, and create explicitly confirmed drafts.
Website & download · En français
A client-agnostic FastMCP server for Proton Mail through the official Proton Mail Bridge. It can read and search mail and create drafts with attachments. It deliberately cannot send email — you review every draft in Proton Mail and press Send yourself.
The server runs locally over STDIO for any MCP-compatible client (Claude Desktop, Claude Code, or anything else that speaks MCP). Received PDF, TXT, and CSV attachments can be inspected through bounded text extraction without exposing their raw bytes. Outgoing attachments are uploaded as bounded base64 chunks, so the server never receives or reads a client filesystem path.
Read the full documentation for setup, configuration, tool inputs, security boundaries, and troubleshooting.
Email is attacker-controlled input. Any sender can put adversarial instructions in a message body, and an AI agent that reads mail and holds write-capable tools is one prompt injection away from doing something you did not ask for. This project limits the blast radius by construction:
send_message tool in the codebase — a test asserts it.127.0.0.1.These controls reduce risk but do not make email trusted. Never expose unrelated write-capable tools in the same unattended agent workflow.

127.0.0.1 (PROTON_BRIDGE_HOST is intentionally unsupported).BODY.PEEK; attachment inspection returns bounded extracted text,
metadata, and a SHA-256 digest, never raw bytes or files.0700 directories, 0600 files and
O_NOFOLLOW. On Windows: a protected DACL granting only the owning user and the system
accounts, with reparse points refused in place of O_NOFOLLOW.uv for the command-line installation.gnome-keyring or compatible).Windows 11 x64 support is implemented in this repository but not released: automated checks run on Windows Server, while end-to-end Windows 11 acceptance remains untested. See the Windows installer notes and its acceptance sheet.
Download the installer,
open it with Ubuntu's package installer, then launch Proton Safe. The assistant guides
you through Bridge connection and plugin activation in a compatible local ChatGPT desktop
or Codex installation. Python and uv are included; no terminal setup is required.
You still need Proton Mail Bridge, a compatible Proton plan and a session keyring. See the desktop guide for prerequisites, screenshots and repair options. Checksums and build provenance are in the release.
Not available yet. The installer, the Windows platform layer and the build pipeline exist, but no acceptance scenario has been run on Windows and there is no download. Two external dependencies remain open: a Windows AI client whose full path is qualified, and a signing identity usable from CI.
Install the reviewed release from PyPI with uv:
uv tool install proton-safe-mcp==2.3.0
For development from source instead:
git clone https://github.com/fbossiere/proton-safe-mcp.git
cd proton-safe-mcp
uv sync --extra dev
Set the Proton address and Bridge IMAP port in the MCP process environment. No credential is ever set here:
export PROTON_BRIDGE_USER="your-address@proton.me"
export PROTON_IMAP_PORT="1143"
To draft as another Proton address of the same account, add the optional sender allowlist in that same environment, as comma-separated bare addresses:
export PROTON_BRIDGE_ALIASES="billing@example.com,legal@example.com"
Store the Bridge-generated IMAP password (shown in the Bridge UI), not your Proton account password:
proton-safe-mcp setup
The value shown by Bridge is installation-specific and works only against the local Bridge.
Configure a local STDIO server with these logical fields. Use command -v proton-safe-mcp
to obtain the absolute command path when your client does not inherit your shell PATH:
{
"name": "proton-safe",
"transport": "stdio",
"command": "/absolute/path/to/proton-safe-mcp",
"args": ["serve"],
"env": {
"PROTON_BRIDGE_USER": "your-address@proton.me",
"PROTON_IMAP_PORT": "1143"
}
}
PROTON_BRIDGE_ALIASES goes in the same env block when a draft may use more than one From
address. See Sender addresses.
Do not put PROTON_BRIDGE_PASSWORD in the client configuration. The server reads it from the OS keyring established by setup.
Copy-paste instructions are available for Claude Code, Cursor, and VS Code.
AI coding agents can follow the safety-constrained llms-install.md guide.
Verify the complete local setup without printing credentials, addresses, or mailbox data:
proton-safe-mcp doctor
The repository includes a private, local-first Proton Safe plugin for ChatGPT and Codex. It packages safety-focused mail review and draft workflows with the same restricted MCP server:
proton-safe-mcp and Proton Mail Bridge together, with IMAP
fixed to 127.0.0.1.See the OpenAI plugin guide for local ChatGPT desktop/Codex installation, direct MCP registration, and the optional remote tunnel.
Plugin installed but no Proton tools? The bundled MCP configuration forwards
PROTON_BRIDGE_USERandPROTON_IMAP_PORTfrom the environment that started Codex; it does not define their values. On Ubuntu, a correct~/.config/environment.d/*.conffile can still require a user-manager reload, while GNOME and already-running terminals can keep their earlier environment. If a menu relaunch still has no tools, start ChatGPT once from a terminal that has loaded the file. That terminal launch is a diagnostic, not a requirement for every start; the troubleshooting guide also provides a persistent per-user menu launcher. Follow the privacy-safe Ubuntu recovery procedure or the FAQ before reinstalling anything.
Help test the onboarding. Linux and Proton Mail Bridge users can run the 10-minute external test and submit privacy-safe installation feedback.
| Category | Tool | Notes |
|---|---|---|
| Read-only mail | mailbox_status | Bridge connectivity + INBOX counts |
list_folders | ||
list_sender_addresses | The fixed From allowlist a draft may use | |
list_messages | Never marks messages as read | |
search_messages | Injection-safe IMAP TEXT search | |
read_message | Bounded plain text; no attachment bytes | |
extract_attachment_text | Bounded PDF/TXT/CSV text; no raw bytes or files | |
get_reply_context | Candidate reply recipients, Re: subject, and a bounded quote — all suggestions | |
| Attachment staging | begin_attachment_upload | Declares filename, type, size, SHA-256 |
upload_attachment_chunk | Ordered base64 chunks | |
finish_attachment_upload | Verifies hash, returns single-use token | |
discard_attachment | ||
| Drafts | create_confirmed_draft | Requires exact confirmation; reply targets also require acceptance of a possibly separate draft |
There is deliberately no send_message tool.
The MCP client only needs the ability to obtain the bytes of a file and call tools. There is no dependency on a particular client, service, or local directory.
begin_attachment_upload(filename, content_type, size_bytes, sha256_hex).max_chunk_bytes.upload_attachment_chunk(upload_id, chunk_index, data_base64) for indexes 0, 1, 2….finish_attachment_upload(upload_id) and retain the returned attachment_token.create_confirmed_draft(..., user_confirmed=true, attachment_tokens=[token]).Step 8 is the human gate, and it is the only one that matters: the server has no SMTP implementation, so a draft it creates cannot leave your account until you press Send in Proton Mail. Uploaded attachments expire after 30 minutes if no draft consumes them.
proton-safe-mcp doctor # check the local setup without printing private data
proton-safe-mcp setup # store the Bridge-generated IMAP password in the OS keyring
proton-safe-mcp serve # run the MCP server over STDIO
| Variable | Default | Purpose |
|---|---|---|
PROTON_BRIDGE_USER | required | Proton address configured in Bridge |
PROTON_BRIDGE_ALIASES | empty | Comma-separated additional From addresses a draft may use |
PROTON_IMAP_PORT | 1143 | Local Bridge IMAP port |
PROTON_MCP_STATE_DIR | ~/.local/state/proton-safe-mcp | Private attachment staging state |
PROTON_MCP_MAX_ATTACHMENT_BYTES | 20971520 | Maximum per file and per draft, capped at 25 MiB |
PROTON_MCP_MAX_RECEIVED_ATTACHMENT_BYTES | 10485760 | Received-file extraction maximum, capped at 25 MiB |
PROTON_MCP_MAX_CHUNK_BYTES | 393216 | Decoded chunk maximum, capped at 1 MiB |
PROTON_MCP_UPLOAD_TTL_SECONDS | 1800 | Attachment staging lifetime |
PROTON_MCP_MAX_BODY_CHARS | 100000 | Maximum outgoing draft body length |
PROTON_BRIDGE_HOST is intentionally unsupported.
For isolated containers without a Secret Service keyring, PROTON_BRIDGE_PASSWORD may contain
the Bridge-generated IMAP password. Avoid this fallback in desktop MCP client configuration:
environment values may be visible to the client process or its diagnostics.
uv sync --extra dev
uv run pytest --cov # tests with coverage
uv run ruff check . # lint
uv run ruff format . # format
uv run mypy # strict type checking
Proton Bridge is not needed for development: the test suite fakes the IMAP layer. Tests cover path rejection, MIME restrictions, received-attachment size and format rejection, bounded PDF/text extraction, ordered chunks, size/hash verification, token consumption, header injection, draft confirmation, recipient and attachment bounds, and HTML-to-text sanitization.
See CONTRIBUTING.md for the design rules that reviews enforce.
Read this before relying on the server in an autonomous workflow:
user_confirmed: true is a client assertion, so the confirmation step depends on the client honoring the rule. It reduces accidents; it is not a boundary against a client under an attacker's influence.127.0.0.1.To report a vulnerability, use GitHub private vulnerability reporting — never a public issue. See SECURITY.md.
MIT © 2026 Francois Bossiere.
This project is not affiliated with or endorsed by Proton AG. "Proton Mail" and "Proton Mail Bridge" are trademarks of Proton AG.
Source-derived launch command. Check the maintainer’s required arguments and credentials before running:
uvx proton-safe-mcpMerge this template into ~/Library/Application Support/Claude/claude_desktop_config.json. Keep existing servers. Add any arguments, credentials, and permissions required by the maintainer; this template has not been install-tested.
{
"mcpServers": {
"io-github-fbossiere-proton-safe-mcp": {
"command": "uvx",
"args": [
"proton-safe-mcp"
]
}
}
}Restart Claude Desktop completely for changes to take effect. Confirm the server appears connected in the client’s tool list, then try a read-only example from its documentation.
Claude Desktop setup referenceproton-safe-mcppypiProton Safe MCP works with any MCP-compatible client. Copy the config snippet from the Configuration section above and add it to the file shown for your client, then restart the application.
~/Library/Application Support/Claude/claude_desktop_config.jsonRestart Claude Desktop completely for changes to take effect.~/.cursor/mcp.jsonRestart Cursor for changes to take effect..vscode/mcp.jsonReload VS Code window for changes to take effect.~/.codeium/windsurf/mcp_config.jsonRestart Windsurf for changes to take effect..mcp.jsonSave at the project root, then start Claude Code in that project and review the MCP server approval prompt. Keep real credentials out of shared files.