Blog Log in Start free trial

Blog / Agents

Give Claude, ChatGPT or Cursor safe access to email

· 4 min read · También en español

Short answer: don't hand your agent your whole mailbox. Connect it to MailTag's MCP server (https://mailtag.app/mcp, on every plan, including Free), and on the consent screen choose what it may see: which mailboxes, which categories or saved views, how far back, whether it sees the sender and subject, and whether it can change anything. The agent gets a short, sorted list instead of your inbox, and never the text of your emails.

Why "full access" is the wrong default

Most ways of connecting an agent to email give it everything: every message, every attachment, years of history, and often the power to send. That's convenient, and it's also the setup security researchers warn about. An agent that can read your private data, reads text written by strangers (every email is), and can send things out is exactly what a malicious email tries to exploit. We explain how in Prompt injection through email.

The fix is the same as for any other access: give the agent only what the task needs.

What your agent gets through MailTag

MailTag already sorts every new email into your own categories. The MCP server lets an agent work with that sorting, within limits you set per agent:

You chooseOptions
Mailboxesall of them, or some
Emailsall, some categories (for example only Urgent and Needs reply), or the emails in some of your saved views
How far back30 days, 7 days, today, or only from the moment you connect it
Senderhidden, only the domain, or name and address
Subjectshown or not
Read stateshown or not
Changesnone, or also relabel emails and edit categories or views (editing only for an agent that sees all emails)
Dangerous emailsshown marked, or hidden: dangerous ones, or dangerous and doubtful (when you turn on the safety check)

What it always gets, within that scope: each email's category, date, mailbox and Message-ID, and a link to open it. What it never gets from MailTag: the email's text, snippets or attachments. It also can never send, delete or move email out of your mailbox.

If the agent needs to read an email in full, it opens that one email through its own mail access, using the Message-ID. The point is that it only opens the few emails that matter, instead of reading everything to find them.

Connect it

You need a MailTag account (any plan, including Free) with your mailbox connected. Then:

Claude (web and desktop)

  1. Go to Customize → Connectors, click + and Add custom connector.
  2. Paste https://mailtag.app/mcp and click Add.
  3. Claude opens MailTag's sign-in. Choose the permissions, step by step, and allow.

On Team and Enterprise, an owner first adds it under Organization settings → Connectors. Custom connectors also work on Claude's free plan, limited to one.

Claude Code

claude mcp add --transport http mailtag https://mailtag.app/mcp

Then run /mcp in a session (or claude mcp login mailtag) to sign in and choose the permissions.

ChatGPT

  1. In Settings → Security and login, turn on Developer mode (Plus, Pro, Business, Enterprise and Education, on the web).
  2. Add an app with the URL https://mailtag.app/mcp and OAuth sign-in.
  3. In a chat, pick it from the + menu under Developer mode.

ChatGPT renames these menus now and then; if a step doesn't match, look for "Developer mode" in its settings.

Cursor, VS Code and scripts

Create a key in MailTag under Settings → Agents → For developers, with the same permission steps, and add it to your client's MCP config:

{
  "mcpServers": {
    "mailtag": {
      "url": "https://mailtag.app/mcp",
      "headers": { "Authorization": "Bearer mta_…" }
    }
  }
}

In Cursor that file is .cursor/mcp.json (project) or ~/.cursor/mcp.json (all projects). The full reference is in the MCP docs.

A setup that works for most people

Ask it "what needs a reply today?" and it answers from a handful of emails, not thousands.

What you can see and undo

Every agent is listed under Settings → Agents, with when it was last used and which tools it called (never the emails or your questions). You can change its permissions or disconnect it there at any time, and it loses access on the spot.

FAQ

Does MailTag send my email to Anthropic or OpenAI?

No. MailTag sorts your email on its own servers in the EU and never stores the content. Through the MCP server, the agent only receives what you allowed: categories, dates, and the sender and subject if you chose so. If the agent then opens an email through its own access, that part is between you and the agent's provider.

Can the agent send or delete email through MailTag?

No. MailTag's MCP server has no tools to send, delete or move email out of your mailbox.

Which plan do I need?

Any plan. The MCP server is included on every plan, including Free. On Free, MailTag sorts 100 emails a month, so those are the emails your agent can see.

Can I give two agents different access?

Yes. Each agent has its own permissions: one can see only Receipt from the last 30 days, another only Urgent from today.

Your inbox, sorted on its own. Privately.7 days free · no card
Start free →

Keep reading

Agents · 30 Sept 2026

Email prompt injection: how one email hijacks an AI agent

An email can hide instructions your AI assistant follows. How it works, real cases in Copilot and Gemini, and how to protect an agent that reads mail.

Read →
Guides · 30 Sept 2026

Organize iCloud, Yahoo or Fastmail email automatically

What iCloud, Yahoo and Fastmail can sort on their own, where their rules stop, and how to sort each new email into your own categories over IMAP.

Read →