
Company News
Jerod Santo Joins Socket as Head of Media
Allow myself to introduce... myself.
mcp-google-gmail
Advanced tools
MCP server for the Gmail API — search, read and send email, manage drafts, labels and the trash. For Claude, Cursor, Codex and other AI clients.
English | Русский
A1 Gmail MCP lets an AI app work with your Gmail mailbox in plain language. Search and read mail, prepare replies as drafts, send them when you are ready, keep labels tidy and use the trash instead of permanent deletion.
It uses the Gmail API with your Google account. It distinguishes a draft you can still edit from a sent email that cannot be recalled, and makes the limits of the Gmail API explicit instead of implying that every mail task is reversible.
gmail.modify only — no permanent deletion and no access to Gmail settings.Start with a read-only question:
Show my unread emails from the last week and tell me which ones need a reply.
Connect the server · Explore use cases · Open technical documentation
You: What is unread in my inbox from this week about the Acme contract?
Assistant: Searches with Gmail query syntax and shows senders, subjects, dates and snippets. Nothing changes.
You: Draft a reply to the latest one: we send the signed copy on Friday.
Assistant: Creates a draft in the same thread and shows it for review. Nothing is sent.
You: Send it.
Assistant: Sends the draft. Sending is a separate, explicitly destructive step, so your AI app can ask for confirmation first.
You need Node.js 20+, a Google account and OAuth credentials from a Google Cloud project with the Gmail API enabled.
In the app: open Settings → Plugins → MCP servers, select Add server, then add npx -y mcp-google-gmail@latest with GOOGLE_GMAIL_CLIENT_ID, GOOGLE_GMAIL_CLIENT_SECRET and GOOGLE_GMAIL_REFRESH_TOKEN.
From the command line:
codex mcp add google-gmail \
--env GOOGLE_GMAIL_CLIENT_ID=your_client_id \
--env GOOGLE_GMAIL_CLIENT_SECRET=your_client_secret \
--env GOOGLE_GMAIL_REFRESH_TOKEN=your_refresh_token \
-- npx -y mcp-google-gmail@latest
codex mcp list
claude mcp add \
--env GOOGLE_GMAIL_CLIENT_ID=your_client_id \
--env GOOGLE_GMAIL_CLIENT_SECRET=your_client_secret \
--env GOOGLE_GMAIL_REFRESH_TOKEN=your_refresh_token \
--transport stdio --scope user google-gmail \
-- npx -y mcp-google-gmail@latest
claude mcp list
Open Settings → Developer → Edit Config and add:
{
"mcpServers": {
"google-gmail": {
"command": "npx",
"args": ["-y", "mcp-google-gmail@latest"],
"env": {
"GOOGLE_GMAIL_CLIENT_ID": "your_client_id",
"GOOGLE_GMAIL_CLIENT_SECRET": "your_client_secret",
"GOOGLE_GMAIL_REFRESH_TOKEN": "your_refresh_token"
}
}
}
}
If Edit Config is unavailable, edit ~/Library/Application Support/Claude/claude_desktop_config.json on macOS or %APPDATA%\Claude\claude_desktop_config.json on Windows.
Add this to ~/.cursor/mcp.json on macOS/Linux or %USERPROFILE%\.cursor\mcp.json on Windows:
{
"mcpServers": {
"google-gmail": {
"type": "stdio",
"command": "npx",
"args": ["-y", "mcp-google-gmail@latest"],
"env": {
"GOOGLE_GMAIL_CLIENT_ID": "your_client_id",
"GOOGLE_GMAIL_CLIENT_SECRET": "your_client_secret",
"GOOGLE_GMAIL_REFRESH_TOKEN": "your_refresh_token"
}
}
}
}
Run MCP: Open User Configuration and add:
{
"servers": {
"google-gmail": {
"type": "stdio",
"command": "npx",
"args": ["-y", "mcp-google-gmail@latest"],
"env": {
"GOOGLE_GMAIL_CLIENT_ID": "${input:gmail_client_id}",
"GOOGLE_GMAIL_CLIENT_SECRET": "${input:gmail_client_secret}",
"GOOGLE_GMAIL_REFRESH_TOKEN": "${input:gmail_refresh_token}"
}
}
},
"inputs": [
{ "type": "promptString", "id": "gmail_client_id", "description": "Google OAuth client ID" },
{ "type": "promptString", "id": "gmail_client_secret", "description": "Google OAuth client secret", "password": true },
{ "type": "promptString", "id": "gmail_refresh_token", "description": "Google OAuth refresh token", "password": true }
]
}
Check it with MCP: List Servers.
Receipts/2026 and apply it to the matching messages.create_draft prepares the email, get_draft shows it for review, send_draft sends it. send_message skips the draft and sends immediately.5xx error the server does not re-send; search in:sent before trying again, because a replayed send would be a double-sent email.manage_trash is reversible for about 30 days; there is deliberately no permanent-delete tool.update_draft replaces the whole draft (the API has no partial edit) and delete_draft is permanent, because drafts skip the trash.Every call works on one mailbox — the account that granted the token. Decoded bodies are truncated at a configurable limit with explicit flags, and attachments come back as metadata only; attachment content is fetched through raw_request deliberately.
| Operation | What happens | Confirmation boundary |
|---|---|---|
| Search and read messages, threads, drafts, labels, the profile | Reads mailbox data | No change |
| Create or update a draft | Prepares or replaces an unsent email | Changes the mailbox |
| Change read, starred or archived state, apply or strip labels | Changes how mail is organized | Changes the mailbox |
| Create or rename a label | Changes the label vocabulary | Changes the mailbox |
| Trash or untrash a message or thread | Moves mail to or from the trash; reversible for ~30 days | Destructive |
| Send an email or a draft | Delivers mail to real recipients; cannot be unsent | Destructive |
| Delete a draft or a label | Removes it permanently, skipping the trash | Destructive |
| Raw API request | Can call API methods without a dedicated tool | Potentially destructive |
The AI client controls confirmation prompts. The server marks reads, writes and destructive tools so the client can distinguish an inspection from a live change.
Gmail requires OAuth 2.0; an API key is not enough.
Create or select a Google Cloud project and enable the Gmail API.
Configure the OAuth consent screen and create a Desktop app OAuth client.
Authorize the Google account whose mailbox you want to connect — every call works on that one mailbox. The OAuth 2.0 Playground can obtain the refresh token when Use your own OAuth credentials is enabled.
Request the scope:
https://www.googleapis.com/auth/gmail.modify
It covers search, reading, sending, drafts, labels and the trash — but not permanent deletion and not Gmail settings. Permanent deletion through raw_request additionally requires the full https://mail.google.com/ scope.
Testing-mode OAuth refresh tokens can expire after seven days. Publish the OAuth app, or use an Internal app in a Workspace domain, when you need long-lived access. Treat the client secret and refresh token as passwords.
| Variable | Required | Description |
|---|---|---|
GOOGLE_GMAIL_CLIENT_ID | Yes* | OAuth client ID. |
GOOGLE_GMAIL_CLIENT_SECRET | Yes* | OAuth client secret. |
GOOGLE_GMAIL_REFRESH_TOKEN | Yes* | OAuth refresh token. |
GOOGLE_GMAIL_ACCESS_TOKEN | Yes* | Short-lived alternative to the OAuth trio (about 1 hour). |
GOOGLE_GMAIL_API_BASE | No | Gmail API base URL override. |
GOOGLE_GMAIL_TIMEOUT_MS | No | Per-request timeout; default 60000 ms. |
GOOGLE_GMAIL_MAX_RETRIES | No | Temporary-error retries; default 3. |
* Provide either the OAuth trio or an access token.
ASKADS_TELEMETRY=0 to opt out.429, the server uses backoff; reads also retry after network and 5xx errors, while sends and other writes are never replayed after an uncertain failure.raw_request can also reach history.list for incremental sync.Found a bug or need a scenario? Create an issue or write in Telegram.
You made it to the end!
FAQs
MCP server for the Gmail API — search, read and send email, manage drafts, labels and the trash. For Claude, Cursor, Codex and other AI clients.
The npm package mcp-google-gmail receives a total of 40 weekly downloads. As such, mcp-google-gmail popularity was classified as not popular.
We found that mcp-google-gmail demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Company News
Allow myself to introduce... myself.

Research
/Security News
A Twitch browser extension on Chrome and Firefox forwards users’ live OAuth session tokens through proxies controlled by a Russian bot service.

Security News
Anthropic found biased reasoning and recklessness drove Claude Mythos 5 to publish malware on PyPI and compromise a security vendor.