KotMail: a read-only Yandex Mail connector for ChatGPT
KotMail
A read-only Yandex Mail MCP connector for ChatGPT via OAuth and IMAP XOAUTH2, with no sending, deleting or changing mail
Medium risk
We rate an entry medium when the tool runs code, makes network calls or reads project files. Check what exactly it does before installing.
Why this level
- It reads the content of personal correspondence, though no tool can send, delete or change a message
- Access tokens are stored locally in an encrypted vault on the user's machine
Install
In your terminal, with SkillFoxx CLI
npx skillfoxx add mcp/kotmailDetects the agents on your machine, checks the risk and pins the version.
Other ways to install
Assembled automatically, review before installing.
Run in a terminal
claude mcp add --transport stdio --env 'CLIENT_ID=<your CLIENT_ID>' --env 'CLIENT_SECRET=<your CLIENT_SECRET>' --env 'RUNTIME_API_KEY=<your RUNTIME_API_KEY>' KotMail -- nodeOr add to the file .mcp.json, in the project
{
"mcpServers": {
"KotMail": {
"command": "node",
"args": [],
"env": {
"CLIENT_ID": "<your CLIENT_ID>",
"CLIENT_SECRET": "<your CLIENT_SECRET>",
"RUNTIME_API_KEY": "<your RUNTIME_API_KEY>"
}
}
}
}If the file already exists, add the server inside the mcpServers key.
Keys and settings
CLIENT_IDsecret, required- Yandex OAuth Client ID
CLIENT_SECRETsecret, required- Yandex OAuth Client Secret
RUNTIME_API_KEYsecret, required- OpenAI Secure MCP Tunnel runtime API key
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
The button opens the agent and offers to add the server. If nothing happens, copy the config below.
Add to the file ~/.cursor/mcp.json, for all projects
{
"mcpServers": {
"KotMail": {
"command": "node",
"args": [],
"env": {
"CLIENT_ID": "<your CLIENT_ID>",
"CLIENT_SECRET": "<your CLIENT_SECRET>",
"RUNTIME_API_KEY": "<your RUNTIME_API_KEY>"
}
}
}
}If the file already exists, add the server inside the mcpServers key. For a single project, put the same block into .cursor/mcp.json.
Keys and settings
CLIENT_IDsecret, required- Yandex OAuth Client ID
CLIENT_SECRETsecret, required- Yandex OAuth Client Secret
RUNTIME_API_KEYsecret, required- OpenAI Secure MCP Tunnel runtime API key
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
The button opens the agent and offers to add the server. If nothing happens, copy the config below.
Run in a terminal
code --add-mcp '{"name":"KotMail","type":"stdio","command":"node","args":[],"env":{"CLIENT_ID":"<your CLIENT_ID>","CLIENT_SECRET":"<your CLIENT_SECRET>","RUNTIME_API_KEY":"<your RUNTIME_API_KEY>"}}'Or add to the file .vscode/mcp.json, in the project
{
"servers": {
"KotMail": {
"type": "stdio",
"command": "node",
"args": [],
"env": {
"CLIENT_ID": "<your CLIENT_ID>",
"CLIENT_SECRET": "<your CLIENT_SECRET>",
"RUNTIME_API_KEY": "<your RUNTIME_API_KEY>"
}
}
}
}If the file already exists, add the server inside the servers key.
Keys and settings
CLIENT_IDsecret, required- Yandex OAuth Client ID
CLIENT_SECRETsecret, required- Yandex OAuth Client Secret
RUNTIME_API_KEYsecret, required- OpenAI Secure MCP Tunnel runtime API key
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Run in a terminal
codex mcp add KotMail --env 'CLIENT_ID=<your CLIENT_ID>' --env 'CLIENT_SECRET=<your CLIENT_SECRET>' --env 'RUNTIME_API_KEY=<your RUNTIME_API_KEY>' -- nodeOr add to the file ~/.codex/config.toml, for all projects
[mcp_servers.KotMail]
command = "node"
args = []
env = { CLIENT_ID = "<your CLIENT_ID>", CLIENT_SECRET = "<your CLIENT_SECRET>", RUNTIME_API_KEY = "<your RUNTIME_API_KEY>" }If the file already exists, append the block to the end.
Keys and settings
CLIENT_IDsecret, required- Yandex OAuth Client ID
CLIENT_SECRETsecret, required- Yandex OAuth Client Secret
RUNTIME_API_KEYsecret, required- OpenAI Secure MCP Tunnel runtime API key
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Run in a terminal
gemini mcp add -s user -e 'CLIENT_ID=<your CLIENT_ID>' -e 'CLIENT_SECRET=<your CLIENT_SECRET>' -e 'RUNTIME_API_KEY=<your RUNTIME_API_KEY>' KotMail nodeOr add to the file ~/.gemini/settings.json, for all projects
{
"mcpServers": {
"KotMail": {
"command": "node",
"args": [],
"env": {
"CLIENT_ID": "<your CLIENT_ID>",
"CLIENT_SECRET": "<your CLIENT_SECRET>",
"RUNTIME_API_KEY": "<your RUNTIME_API_KEY>"
}
}
}
}If the file already exists, add the server inside the mcpServers key.
Keys and settings
CLIENT_IDsecret, required- Yandex OAuth Client ID
CLIENT_SECRETsecret, required- Yandex OAuth Client Secret
RUNTIME_API_KEYsecret, required- OpenAI Secure MCP Tunnel runtime API key
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Add to the file ~/.config/devin/mcp_config.json, for all projects
{
"mcpServers": {
"KotMail": {
"command": "node",
"args": [],
"env": {
"CLIENT_ID": "<your CLIENT_ID>",
"CLIENT_SECRET": "<your CLIENT_SECRET>",
"RUNTIME_API_KEY": "<your RUNTIME_API_KEY>"
}
}
}
}If the file already exists, add the server inside the mcpServers key. Legacy Cascade keeps the MCP config in ~/.codeium/windsurf/mcp_config.json.
Keys and settings
CLIENT_IDsecret, required- Yandex OAuth Client ID
CLIENT_SECRETsecret, required- Yandex OAuth Client Secret
RUNTIME_API_KEYsecret, required- OpenAI Secure MCP Tunnel runtime API key
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Formerly Windsurf.
Add to the file cline_mcp_settings.json, for all projects
{
"mcpServers": {
"KotMail": {
"command": "node",
"args": [],
"env": {
"CLIENT_ID": "<your CLIENT_ID>",
"CLIENT_SECRET": "<your CLIENT_SECRET>",
"RUNTIME_API_KEY": "<your RUNTIME_API_KEY>"
}
}
}
}If the file already exists, add the server inside the mcpServers key. Open the settings file in Cline: MCP Servers tab, Configure MCP Servers.
Keys and settings
CLIENT_IDsecret, required- Yandex OAuth Client ID
CLIENT_SECRETsecret, required- Yandex OAuth Client Secret
RUNTIME_API_KEYsecret, required- OpenAI Secure MCP Tunnel runtime API key
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Add to the file .roo/mcp.json, in the project
{
"mcpServers": {
"KotMail": {
"command": "node",
"args": [],
"env": {
"CLIENT_ID": "<your CLIENT_ID>",
"CLIENT_SECRET": "<your CLIENT_SECRET>",
"RUNTIME_API_KEY": "<your RUNTIME_API_KEY>"
}
}
}
}If the file already exists, add the server inside the mcpServers key.
Keys and settings
CLIENT_IDsecret, required- Yandex OAuth Client ID
CLIENT_SECRETsecret, required- Yandex OAuth Client Secret
RUNTIME_API_KEYsecret, required- OpenAI Secure MCP Tunnel runtime API key
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
A fork of Roo Code, same .roo folders.
Add to the file opencode.json, in the project
{
"mcp": {
"KotMail": {
"type": "local",
"command": [
"node"
],
"environment": {
"CLIENT_ID": "<your CLIENT_ID>",
"CLIENT_SECRET": "<your CLIENT_SECRET>",
"RUNTIME_API_KEY": "<your RUNTIME_API_KEY>"
}
}
}
}If the file already exists, add the server inside the mcp key.
Keys and settings
CLIENT_IDsecret, required- Yandex OAuth Client ID
CLIENT_SECRETsecret, required- Yandex OAuth Client Secret
RUNTIME_API_KEYsecret, required- OpenAI Secure MCP Tunnel runtime API key
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Add to the file ~/.config/zed/settings.json, for all projects
{
"context_servers": {
"KotMail": {
"command": "node",
"args": [],
"env": {
"CLIENT_ID": "<your CLIENT_ID>",
"CLIENT_SECRET": "<your CLIENT_SECRET>",
"RUNTIME_API_KEY": "<your RUNTIME_API_KEY>"
}
}
}
}If the file already exists, add the server inside the context_servers key.
Keys and settings
CLIENT_IDsecret, required- Yandex OAuth Client ID
CLIENT_SECRETsecret, required- Yandex OAuth Client Secret
RUNTIME_API_KEYsecret, required- OpenAI Secure MCP Tunnel runtime API key
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Add to the file .codeassistant/mcp.json, in the project
{
"mcpServers": {
"KotMail": {
"command": "node",
"args": [],
"env": {
"CLIENT_ID": "<your CLIENT_ID>",
"CLIENT_SECRET": "<your CLIENT_SECRET>",
"RUNTIME_API_KEY": "<your RUNTIME_API_KEY>"
}
}
}
}If the file already exists, add the server inside the mcpServers key.
Keys and settings
CLIENT_IDsecret, required- Yandex OAuth Client ID
CLIENT_SECRETsecret, required- Yandex OAuth Client Secret
RUNTIME_API_KEYsecret, required- OpenAI Secure MCP Tunnel runtime API key
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Install dependencies with npm install, run npm run bootstrap and npm run setup, register a Yandex app, open the local page and confirm OAuth with a one-time code, then run Start KotMail.cmd or npm run tunnel:setup to connect to the OpenAI Secure MCP Tunnel.
Other ways from the author
npm install
npm run bootstrap
npm run check
npm testLocal preparation; bootstrap creates .env.local with a new master key.
This is third-party code. Review the repository files before installing.
What it does
KotMail links ChatGPT to Yandex Mail through a chain of the OpenAI Secure MCP Tunnel, an MCP server, Yandex OAuth and IMAP over XOAUTH2. Login uses Yandex device OAuth scoped to mail:imap_ro and login:email only, the Yandex password is never given to the app, and tokens and mailbox data are stored locally encrypted with AES-256-GCM. The INBOX is always opened with EXAMINE in read-only mode. Five tools provide recent messages, search by sender, subject, text, date and unread status, one message's metadata and text, and a list of attachments without downloading them. Message ids are opaque and HMAC-signed, message text is capped at 50000 characters and eight text parts, and the server explicitly tells the agent that message content and headers are untrusted data. There is no sending, deleting, moving, or flag and folder changes anywhere in the project.
Who it is for. For a single user who wants to give ChatGPT read access to their Yandex Mail with zero risk of sending or deleting anything.
Good fit when
- You want to browse and search mail in ChatGPT without standing up your own public HTTPS server
- You care that the connector has zero write tools, even in theory
- A one-time setup for a single test mailbox and one operator is fine
Not a fit when
- You need to send or change mail: the project deliberately does not do that
- You need permanent multi-user operation: the author explicitly calls this a simplified single-user spike
Example request
Through KotMail, show 10 unread emails from this week, just sender, subject and dateLimitations
The project is at version 0.3 and targets a single test mailbox and one operator, not permanent multi-user operation. It needs Node.js 24 and Windows scripts to run the tunnel, though the core code is not platform-locked. Attachment downloads are deliberately not implemented. Public multi-user operation would need separate work with a callback on a stable domain.
How to disable. Stop the KotMail and tunnel processes, and revoke the app's access on Yandex's authorized-apps page.
MCP
- Transport
- stdio
- Authentication
- OAuth
Security check
- It reads the content of personal correspondence, though no tool can send, delete or change a message
- Access tokens are stored locally in an encrypted vault on the user's machine
README in short
The README describes the ChatGPT, OpenAI tunnel, MCP server, Yandex OAuth and IMAP chain, a table of five tools with limits, how search and pagination work, why no public callback is needed, and step-by-step local setup with bootstrap, setup and the Secure MCP Tunnel via Start KotMail.cmd on Windows.
FAQ
Can KotMail send an email?
No, the project has no tool for sending, deleting, moving or changing mail at all.
Do I need my Yandex Mail password?
No, login uses Yandex device OAuth, and the password is never given to the app.
Related
A self-hosted knowledge base with block-level references and a built-in MCP server for connecting AI agents to your notes
A CLI for every Google Workspace API with JSON output and agent skills: Drive, Gmail, Calendar, Sheets and more
Local search over Markdown notes, docs and meeting transcripts: keywords, semantic search and reranking, with an MCP server
A task manager for AI-driven development: breaks a PRD into dependent tasks and guides the agent through them via MCP or CLI