MCP.so
Sign In
P

PROTON-MCP

@just-an-oldsalt

About PROTON-MCP

A local-only macOS Model Context Protocol server that exposes your Proton Mail account to Claude Desktop and Claude Code via Touch-ID-gated tool calls.

Overview

What is PROTON-MCP?

A signed, notarized, Touch‑ID‑gated bridge between Proton Mail and Claude — running entirely on your Mac. It exposes 29 Model Context Protocol (MCP) tools that let Claude Desktop and Claude Code read, search, compose, label, and send Proton Mail. Designed for personal‑use, technical‑audience early access on macOS 13+.

How to use PROTON-MCP?

Install via Homebrew (once a tagged release is available) or build from source. Run protonmcp login, protonmcp backfill, protonmcp daemon install, and protonmcp install to register the shim with Claude clients. The 29 tools then appear under protonmcp in /mcp. Policy can be overridden via ~/Library/Application Support/protonmcp/policy.yaml.

Key features of PROTON-MCP

  • 29 MCP tools for reading, searching, composing, labeling, and sending Proton Mail
  • Touch ID per‑call approval for all write operations (recipients and subject shown)
  • Per‑tool YAML policy with rate limiting and domain restrictions
  • Auto‑lock on screen lock, sleep, or idle timeout
  • Redacted audit log with SHA‑256 body references and caller PID/UID
  • Hardened‑runtime, signed, and notarized macOS binaries with binary integrity check

Use cases of PROTON-MCP

  • Read and search Proton Mail directly from Claude Desktop or Claude Code
  • Compose and send emails with biometric verification of recipients and subject
  • Automate email labeling, moving, and organization with safety gates and audit trails
  • Share a single daemon across multiple Claude sessions to avoid repeated logins

FAQ from PROTON-MCP

Is PROTON-MCP production‑ready?

No, it is v1.0.0‑alpha, intended for personal use by a technical audience. Read the caveats before installing.

What macOS versions are supported?

macOS 13+ is required.

How does PROTON-MCP handle email sending security?

Every write tool (especially mail_send) requires a Touch ID prompt showing the literal recipients and subject. No message is sent without biometric confirmation.

What are the known limitations?

Plaintext email bodies are cached in SQLite until Phase 8 adds encryption. The AppVersion header currently uses Proton Bridge’s identifier, not a dedicated one. Do not rate‑abuse, scrape, or run multi‑account automation.

Is PROTON-MCP free?

Yes, it is open‑source and free for personal use under its

Comments

More Desktop Chat MCP clients