Proton Mail Bridge ClientBLOCK
Local-first Proton Mail MCP server and CLI via Proton Bridge. Search, draft, send and organize mail from Claude Desktop, Claude Code or any MCP client. 96 tools, read-only and send-to-self modes.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
____ ____ ___ _____ ___ _ _ __ __ _ ___ _ | _ \| _ \ / _ \_ _/ _ \| \ | | | \/ | / \ |_ _| | | |_) | |_) | | | || || | | | \| | | |\/| | / _ \ | || | | __/| _ <| |_| || || |_| | |\ | | | | |/ ___ \ | || |___ |_| |_| \_\\___/ |_| \___/|_| \_| |_| |_/_/ \_\___|_____| Bridge Client · CLI + Claude Desktop MCP for Proton Mail
[](https://www.npmjs.com/package/proton-mail-bridge-client) [](https://github.com/googlarz/proton-mail-bridge-client/actions/workflows/ci.yml) [](LICENSE) [](https://nodejs.org) [](https://www.typescriptlang.org) [](https://modelcontextprotocol.io) [](https://github.com/googlarz/proton-mail-bridge-client) [](https://github.com/googlarz/proton-mail-bridge-client/commits/main) [](https://github.com/googlarz/proton-mail-bridge-client) [](https://glama.ai/mcp/servers/googlarz/proton-mail-bridge-client)
Give Claude Desktop (or Cline, or any MCP client) full access to your Proton Mail inbox: read, search, send, draft, triage threads, manage folders, save
a27d1c5fe30aOBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add proton-mail-bridge-client --env PROTONMAIL_PASSWORD=${PROTONMAIL_PASSWORD} -- npx -y [email protected]Exposed tools (60)
25 read · 21 write · 14 destructive. Blast radius: 14 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
a | read | desc |
archive_email | write | Move a single email to the standard Archive folder. Use for messages that are resolved but worth keeping long-term. Prefer trash_email when the message is no longer needed. Prefer move_email to route to a custom folder. Prefer batch_email_action for archiving multiple emails at once. |
b | read | desc |
bulk_move | write | Move multiple emails to a target folder in one IMAP pass. Accepts either explicit emailIds[] or a match criteria object (XOR). Supports dryRun to preview. For single-message moves use move_email. |
bulk_update_labels | destructive | Add or remove Proton labels on multiple messages simultaneously. Use when the same label change should apply to several messages. Labels are IMAP folders under Labels/ namespace. Accepts emailIds[] OR match+folder (XOR). |
cancel_reply_reminder | destructive | Delete a reply reminder by the id set_reply_reminder or list_reply_reminders gave. |
cancel_send | write | Cancel a send_email call that was queued because PROTONMAIL_SEND_DELAY_SECONDS is set. Only works while the item is still pending — once it has actually sent, this returns canceled: false. No effect (throws) if PROTONMAIL_SEND_DELAY_SECONDS is 0, since nothing is ever queued in that case. |
cancel_snooze | read | Wake a snoozed email immediately, moving it back to its original folder before wakeAt. No effect (throws) if the snooze has already woken or was already canceled. |
clear_cache | destructive | Evict all in-memory caches: folder list, message metadata, and analytics data. Use when cached data appears stale after external mailbox changes (e.g. folders modified via Proton webmail). Does NOT affect the persistent SQLite index — use clear_index for that. |
clear_index | destructive | Delete the entire persistent SQLite mailbox index from disk. Use only to reset a corrupted or schema-incompatible index. After clearing, call sync_emails to rebuild. Irreversible — all indexed metadata and search history is lost. Does NOT clear in-memory caches — use clear_cache for that. |
create_folder | write | Create a new mailbox folder via IMAP. Use |
create_label | write | Create a Proton label (IMAP folder under Labels/ namespace). Idempotent — safe to call if the label may already exist. For folder creation use create_folder with a Folders/ prefix. |
create_template | write | Save a reusable email template. Subject and body may contain {{variable}} placeholders (e.g. {{firstName}}), auto-detected and stored on the template. Fails if a template with the same name already exists — delete it first to replace it. |
delete_draft | destructive | Permanently delete a locally saved draft from SQLite. Use to discard a draft you no longer need. Does NOT remove a matching draft from the Proton Drafts IMAP folder — that requires a separate mailbox action. Irreversible; requires confirmed:true when PROTONMAIL_CONFIRM_DESTRUCTIVE is enabled. |
delete_email | destructive | Permanently delete a single email via IMAP expunge. Use only when certain the message is no longer needed. Prefer trash_email if recovery may be required. Prefer bulk_delete to delete multiple emails at once. Prefer delete_thread to delete all messages in a conversation. Irreversible. |
delete_folder | destructive | Delete an empty mailbox folder via IMAP. The folder must contain no messages — move or trash all messages first. Do NOT delete system folders (INBOX, Sent, Trash, Archive, Spam). Irreversible; messages already removed cannot be recovered this way. |
delete_label | destructive | Delete a Proton label (IMAP folder under Labels/ namespace). Deletes the label itself, not the messages — they remain in their other folders/labels. Irreversible. For deleting a folder use delete_folder with a Folders/ prefix. |
delete_template | destructive | Delete a saved email template. Irreversible; requires confirmed:true when PROTONMAIL_CONFIRM_DESTRUCTIVE is enabled. |
delete_thread | destructive | Delete all messages in a thread, identified by RFC 5322 Message-ID header. permanent:true permanently expunges; false moves to Trash. Use when you have the raw Message-ID. Prefer apply_thread_action with action |
empty_folder | destructive | Permanently delete ALL messages in a folder at once. Prefer bulk_delete when removing a subset of messages rather than everything in the folder. Use only when the goal is to clear an entire folder (e.g. emptying Trash or Spam). Only available when PROTONMAIL_ALLOW_EMPTY_FOLDER=true. Irreversible. |
export_email | write | Save a message |
flag_thread | destructive | Add or remove IMAP flags across all messages in a thread, identified by RFC 5322 Message-ID header. Use when you have the raw Message-ID and want to flag an entire conversation at once. Prefer apply_thread_action with action |
forward_email | read | Immediately forward an existing email to new recipients, preserving original attachments and prepending an optional note. Use when you have an emailId and want to re-route the message without review. Prefer create_forward_draft to stage a forward for review first. Requires PROTONMAIL_ALLOW_SEND. |
get_audit_logs | write | Return recent entries from the persistent on-disk audit log of all write operations performed by this server. Use to review what mutations (sends, moves, deletes, draft operations) were executed across sessions. Prefer get_logs for debugging in-session behavior and transient connection errors. |
get_connection_status | read | Check whether Proton Bridge SMTP and IMAP are reachable and return authentication status for each. Use to diagnose connectivity before sending or syncing, or when tools return connection errors. Returns individual pass/fail for each protocol, plus this server |
get_emails_by_ids | read | Fetch full content for multiple emails by composite id in one call (max 25). Use to read a batch of specific messages from a prior get_emails/search_emails/search_indexed_emails result without one get_email_by_id round trip per message. One failed id does not fail the whole batch — check each result |
get_follow_up_candidates | read | Return threads that appear overdue for follow-up based on age and pending-on state. Use when looking for outbound messages you sent that haven |
get_inbox_digest | read | Return a structured inbox summary: unread counts, top actionable threads, and overdue threads where a reply is pending from you. Use as the starting point for an inbox review session to get an at-a-glance picture. Prefer get_actionable_threads for a deeper, filterable list of threads needing action. |
get_index_status | write | Return metadata about the local SQLite email index: row count, last sync timestamp, index schema version, and per-folder coverage. Use to verify the index is fresh and complete before querying it with search_indexed_emails or get_threads. If the index is empty or stale, call sync_emails first. |
get_labels | read | Return normalized Proton folders and labels from the local mailbox index, including message counts per label. Use to enumerate available labels before filtering with search_indexed_emails or get_threads. Prefer get_folders for live IMAP folder counts when the index may be stale. |
get_runtime_status | read | Return the server |
get_template | read | Get a single saved email template by id. |
get_thread_by_id | read | Fetch the complete normalized thread record from the local index, including all messages, participants, labels, and full metadata. Use when you need all messages in a thread. Prefer get_thread_brief for a summarized quick view that avoids returning the full message list. |
get_unsubscribe_info | read | Read the List-Unsubscribe header of a message and report how to unsubscribe from it — a mailto address, an https link, or both. Does not take any action. Use before unsubscribe_sender to see what |
import_email | write | Import a raw RFC822 message (.eml content) into a folder via IMAP APPEND. Use to restore a backed-up message or migrate mail from another provider |
list_accounts | read | List every configured Proton address (the primary Bridge login plus any additional addresses from PROTONMAIL_ACCOUNTS_JSON), each with its own IMAP/SMTP connection status and local index freshness. Use to see which accounts this server is managing, and each account |
list_remote_drafts | read | List draft messages currently stored in the Proton Drafts IMAP folder on the server. Use to see drafts created via Proton webmail or mobile app that have not been synced locally. Prefer list_drafts to see drafts managed by this server. Requires an active IMAP connection. |
list_snoozed | read | List every snoozed email, including its id, status, and wakeAt — use this to rediscover the id needed for cancel_snooze if it was lost with the conversation. |
list_templates | read | List all saved email templates. |
mark_email_read | read | Mark a single email as read or unread by setting the IMAP Seen flag. Use for individual triage or to reset read state. Prefer batch_email_action with action |
move_email | write | Move a single email to any specified mailbox folder. Use when routing a message to a custom folder. Prefer archive_email to move to the standard Archive folder, or trash_email to move to Trash. Use get_folders first to confirm the target folder path. |
move_thread | write | Move all messages in a thread to a destination folder, identified by its RFC 5322 Message-ID header. Use when you have the raw Message-ID (e.g. from email headers) and want to move the full conversation. Prefer apply_thread_action with action |
prepare_meeting_context | read | Fetch recent threads and communication history for a person or company domain to prepare for a meeting or call. Use before a scheduled meeting to surface relevant recent correspondence. Provide at least one of person (name or email fragment) or domain. Returns matched threads sorted by recency. |
rename_folder | write | Rename or move a mailbox folder to a new IMAP path. Existing messages are preserved in place. Do NOT rename system folders (INBOX, Sent, Trash, Archive, Spam). Refreshes the local folder cache after the operation. |
rename_label | write | Rename a Proton label (IMAP folder under Labels/ namespace). Messages keep the label, just under the new name. For renaming a folder use rename_folder with a Folders/ prefix. |
render_template | read | Render a saved template |
restore_email | write | Move an email from Trash back to INBOX or to a specified folder. Use to undo a trash_email operation. Does not work on permanently deleted messages — only messages currently in Trash can be restored. |
run_doctor | write | Run a comprehensive production health check covering SMTP auth, IMAP auth, optional IMAP IDLE probe, SQLite index integrity, sync-failed drafts, runtime policy validation, and what this server can/cannot do (capabilities). Also reports this server |
schedule_draft | write | Queue a saved draft to send at a future time instead of immediately. IMPORTANT: this only fires while this MCP server process stays running (it |
search_emails | read | Search emails via live IMAP filters, across ALL configured accounts by default (accounts are queried one at a time; pass |
search_indexed_emails | read | Search the local SQLite mailbox index (of ALL configured accounts by default; pass |
star_email | read | Star or unstar a single email using the IMAP Flagged flag. Use to bookmark an important message for later follow-up. Prefer batch_email_action with action |
sync_draft_to_remote | destructive | Force-push a locally saved draft to the Proton Drafts IMAP folder and return the remote UID. Use when a draft was created with syncToRemote:false or when the automatic sync failed. Do NOT use this if PROTONMAIL_ALLOW_REMOTE_DRAFT_SYNC is false — the call will be rejected. |
sync_folders | write | Refresh the in-memory folder list from the IMAP server and return the updated list. Use when folders have been created, renamed, or deleted externally (e.g. via Proton webmail) and get_folders is returning stale data. Prefer get_folders for a read-only view that does not force a refresh. |
top_senders | read | Return a frequency table of the top senders in a folder over a date range. Keyed on the sender address, not the display name, so display-name spoofing does not conflate different senders. Use for inbox analytics, unsubscribe triage, and contact discovery. |
trash_email | write | Move a single email to the Trash folder. Messages in Trash can be recovered with restore_email. Use instead of delete_email when you may want to recover the message later. Prefer batch_email_action with action |
unsubscribe_sender | write | Execute the mailto: variant of a message |
update_draft | write | Update an existing locally saved draft |
update_message_labels | destructive | Add or remove Proton labels on a single message without moving it. Prefer bulk_update_labels to apply label changes across multiple messages. Labels live under the Labels/ namespace (e.g. |
wait_for_mailbox_changes | read | Open an IMAP IDLE session and block until a mailbox change event arrives or the timeout expires. Use to detect real-time inbox activity without polling. Returns whether a change was observed. Always returns within timeoutSeconds plus a few seconds |
Trust audit
BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (3 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (17)
tls: this.shouldRelaxTlsVerification() ? { rejectUnauthorized: false } : undefined,tls: isLocalhost ? { rejectUnauthorized: false } : undefined,bulk_update_labels, cancel_reply_reminder, clear_cache, clear_index, delete_draft, delete_email, delete_folder, delete_label, delete_template, delete_thread, empty_folder, flag_thread, sync_draft_to_r
assert.match(sanitizeFileName("../../etc/passwd"), /^_+etc_passwd$/, "no dots or separators survive");import { LocalIndexService } from "../../dist/services/local-index-service.js";import { DraftStoreService } from "../../dist/services/draft-store-service.js";import { DeliveryQueueService } from "../../dist/services/delivery-queue-service.js";import { withFileLock } from "../../dist/utils/file-lock.js";const { configPath } = await configFixture('{"theme":"dark"}');@modelcontextprotocol/sdk, better-sqlite3, imapflow, mailparser, nodemailer, sanitize-html, turndown, @types/better-sqlite3
Give Claude Desktop (or Cline, or any MCP client) full access to your Proton Mail inbox: read, search, send, draft, triage threads, manage folders, save attachments, and more — 100 MCP tools in total.
1. **Install and sign in to [Proton Mail Bridge](https://proton.me/mail/bridge)**, and leave it running. In the Bridge app, open your account and copy the **Bridge password** (it is not your Proton pa
- Investigated `get_inbox_digest`, `find_document_threads`, and `prepare_meeting_context` for a prompt-injection surface (these tools feed raw, unfiltered email content — including from strangers — in
> **Using Proton Drive too?** See [**proton-drive-mcp**](https://github.com/googlarz/proton-drive-mcp), the companion MCP server and CLI for Proton Drive (upload, download, share and manage your encry
If you use Claude Desktop with the default Anthropic API, conversation content (including email snippets) is sent to Anthropic per their [privacy policy](https://www.anthropic.com/privacy). If you sel
- **Each `update_draft` uploads the whole draft to the Drafts folder** (the full message, attachment bytes included — about 1.4 MB of MIME for a 1 MiB attachment) unless you pass `syncToRemote:false`.
- **[proton-drive-mcp](https://github.com/googlarz/proton-drive-mcp)** — the companion MCP server and CLI for **Proton Drive**: upload, download, share and manage your end-to-end encrypted files from
Gates applied: no_behavioural_pass.
a27d1c5fe30afull audit observations/trust-audit/mcp-server/googlarz__proton-mail-bridge-client.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | a27d1c5fe30a | BLOCK | D | 69 | first audit |
Questions
What is the Proton Mail Bridge Client MCP server?
Local-first Proton Mail MCP server and CLI via Proton Bridge. Search, draft, send and organize mail from Claude Desktop, Claude Code or any MCP client. 96 tools, read-only and send-to-self modes.
What tools does Proton Mail Bridge Client expose?
60 in total: 25 read-only, 21 that write, and 14 that can delete or overwrite (bulk_update_labels, cancel_reply_reminder, clear_cache, clear_index, delete_draft). Every one is listed on this page with its risk.
Is Proton Mail Bridge Client safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (69/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 14 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Proton Mail Bridge Client need?
It reads PROTONMAIL_IMAP_PASSWORD, PROTONMAIL_PASSWORD, PROTONMAIL_PASSWORD_COMMAND and PROTONMAIL_PASSWORD_FILE from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Proton Mail Bridge Client run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as proton-mail-bridge-client at 2.8.1.
How current is this page?
The grade is for one exact copy of the source (a27d1c5fe30a), read on 2026-10-08. The repository is watched and re-audited when it changes.