JMAPSAFE
A Model Context Protocol (MCP) server that provides tools for interacting with JMAP (JSON Meta Application Protocol) email servers. Built with Deno and using the jmap-jam client library.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://jsr.io/@wyattjoh/jmap-mcp) [](https://jsr.io/@wyattjoh/jmap-mcp) [](https://jsr.io/@wyattjoh/jmap) [](https://jsr.io/@wyattjoh)
A Deno workspace containing a functional JMAP email client and a Model Context Protocol (MCP) server built on top of it. The client package uses jmap-jam for JMAP protocol access; the MCP package adapts those typed operations into tools.
Features
Email Management Tools
- Search Emails: Search emails with text queries, sender/recipient filters,
date ranges, and keywords. All filters are AND'd together.
- Get Emails: Retrieve specific emails by ID with configurable property
selection
- Get Threads: Retrieve email threads (conversation chains)
- Mark Emails: Mark emails as read/unread, flagged/unflagged
- Move Emails: Move emails to one mailbox
- Patch Email Mailboxes: Add or remove selected mailbox memberships while
preserving unspecified memberships
- Delete Emails: Delete emails permanently
Mailbox Management
- Get Mailboxes: List all mailboxes/folders with hierarchy support. Use this
to find mailbox IDs needed by other tools.
Incremental Sync
- Get Email Changes: Get IDs of emails created, updated, or destroyed since
a previous state (state-based delta tracking)
- Get Search Updates: Get additions/removals within a previous search query
since its last queryState
Email Composition
- Send Email: Compose and send new emails with support for plain text and
HTML
- Reply to Email: Reply to existing emails with automatic header handling
and reply-all support
Key Capabilities
- Full JMAP RFC 8620/8621 compliance via jmap-jam
- Comprehensive input validation with Zod schemas
- P
772d00cd1bdbOBSERVED · 2026-10-06Exposed tools (12)
7 read · 3 write · 2 destructive. Blast radius: 2 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
delete_emails | destructive | Delete emails permanently. This action cannot be undone. Prefer move_emails to Trash mailbox for safer deletion — use this only when permanent deletion is explicitly requested. |
get_email_changes | read | Get IDs of emails created, updated, or destroyed since a previous state. Use the state string from a get_emails response. Supports optional auto-fetching of full email details. If the state is too old, falls back with an error suggesting a fresh search_emails call. |
get_emails | read | Get specific emails by their IDs. Use the |
get_mailboxes | read | |
get_search_updates | read | Get changes within a previous search query since its last queryState. You MUST pass the same filter parameters as the original search_emails call. Returns added and removed email IDs relative to that search. |
get_threads | read | Get email threads by their IDs. Thread IDs are available from get_emails responses (threadId property). Returns a list of email IDs in each thread — use get_emails on those IDs to fetch the actual email content. |
mark_emails | write | Mark emails as read/unread or flagged/unflagged. You can update multiple keywords at once. |
move_emails | write | Move emails to a different mailbox. Requires a mailbox ID — use get_mailboxes first to find the target mailbox ID by name. |
patch_email_mailboxes | destructive | Add or remove mailbox memberships without changing unspecified memberships. Use this to apply multiple labels or archive an email while preserving other labels. |
reply_to_email | read | Reply to an existing email. Automatically sets correct To/CC, subject (Re: prefix), and threading headers (In-Reply-To, References). Use replyAll=true to include all original recipients. The identityId parameter is optional — if omitted, the server uses the default sending identity. |
search_emails | read | Search emails with filters (text, sender/recipient, dates, keywords). All filters are AND |
send_email | write | Send a new email. Requires either textBody or htmlBody (or both). The identityId parameter is optional — if omitted, the server uses the default sending identity. |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (5)
delete_emails, patch_email_mailboxes
.gitmodules
.release-please-manifest.json
AGENTS.md
import { registerEmailTools } from "../../src/tools/email.ts";Gates applied: no_behavioural_pass.
772d00cd1bdbfull audit observations/trust-audit/mcp-server/wyattjoh__jmap-1.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-06 | 772d00cd1bdb | SAFE | B | 89 | first audit |
Questions
What is the JMAP MCP server?
A Model Context Protocol (MCP) server that provides tools for interacting with JMAP (JSON Meta Application Protocol) email servers. Built with Deno and using the jmap-jam client library.
What tools does JMAP expose?
12 in total: 7 read-only, 3 that write, and 2 that can delete or overwrite (delete_emails, patch_email_mailboxes). Every one is listed on this page with its risk.
Is JMAP safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 2 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does JMAP need?
No credential environment variables were found in its source, so it appears to need none.
How does JMAP run?
It speaks stdio, so it runs as a local process your client starts.
How current is this page?
The grade is for one exact copy of the source (772d00cd1bdb), read on 2026-10-06. The repository is watched and re-audited when it changes.