mcp-ecc aggregates your mail, calendar and contacts into standardised MCP tools (mail.*, calendar.*, contacts.*, accounts.*) so any MCP client β Claude, Cursor, and others β can work with all of them uniformly.
- One OAuth consent per cloud provider covers mail + calendar + contacts
- Multi-user β users self-manage their own accounts, each with a per-user MCP API key
- Credentials encrypted at rest (AES-256-GCM)
- Self-hostable β single container serving a web admin UI, REST API and the MCP endpoint on one port
Quick start
Docker
docker run -d --name mcp-ecc \
-p 3001:3001 \
-e MCP_ENCRYPTION_KEY="$(openssl rand -hex 32)" \
karljsamuel/mcp-ecc:latest
Open http://localhost:3001 β create the admin account β add your provider accounts.
CLI (npm)
npm install -g mcp-ecc
mcp-ecc
mcp-ecc start
From source
git clone https://github.com/karljsamuel/mcp-ecc.git
cd mcp-ecc
npm install
npm run build
node packages/cli/dist/bin.js --help
Upgrade and encryption migration
Important for existing installations: install and run the latest 0.6.x migration release before upgrading to 0.7.x.
The migration release changes credential encryption from the discontinued CryptoJS implementation to platform cryptography APIs:
- Node.js SQLite uses
node:crypto with authenticated AES-256-GCM.
- Cloudflare D1 uses the Workers Web Crypto API with authenticated AES-256-GCM.
- Existing
0.6.x ciphertext is read once and automatically re-encrypted in the new format.
- New AES-256-GCM values are authenticated and migration is fail-closed.
- Legacy CryptoJS ciphertext has no authentication tag; if it is tampered with, its integrity cannot be cryptographically verified. Back up the database and treat failed or unexpected legacy decryptions as migration failures; values are never overwritten unless decryption succeeds.
- Keep the same
MCP_ENCRYPTION_KEY during the upgrade.
After the migration release has successfully started and accessed the existing data, upgrade to 0.7.x. Version 0.7.x removes the legacy CryptoJS reader. Back up the SQLite database or D1 database before upgrading.
Connecting an MCP client
Point your client at the HTTP endpoint with your per-user API key (shown in the web UI under Settings):
{
"mcpServers": {
"mcp-ecc": {
"type": "http",
"url": "http://localhost:3001/mcp",
"headers": { "Authorization": "Bearer <your-api-key>" }
}
}
}
Agents can read SKILL.md or llms.txt for guided, automated setup.
Providers
| Provider | Mail | Calendar | Contacts | Authentication |
|---|
| Google (Gmail, Calendar, People) | β
| β
| β
| OAuth 2.0 |
| Microsoft 365 / Outlook (Graph) | β
| β
| β
| OAuth 2.0 |
| Zoho (Mail, Calendar, Contacts) | β
| β
| β
| OAuth 2.0 |
| IMAP / SMTP (any mail server) | β
| β | β | App password |
| CalDAV (Nextcloud, Radicale, BAIKAL) | β | β
| β | Password |
| CardDAV | β | β | β
| Password |
Microsoft 365: app passwords are being retired β use OAuth (Microsoft Graph) only.
CalDAV/CardDAV compatibility: the providers implement standard WebDAV (CalDAV RFC 4791, CardDAV RFC 6352) with Basic auth and should work with any standards-compliant server. Tested against Radicale 3.7.8. Not tested against other servers; OAuth-only providers (e.g. iCloud without an app-specific password) are not supported.
Deployment notes: Google/Microsoft/Zoho/IMAP/SMTP/CalDAV/CardDAV run under Node.js (CLI or Docker). Cloudflare D1 can be used as a hosted alternative for the local SQLite database.
mail.listFolders Β· mail.listMessages Β· mail.getMessage Β· mail.sendMessage
mail.searchMessages Β· mail.moveMessage Β· mail.setFlags Β· mail.deleteMessage
calendar.listCalendars Β· calendar.listEvents Β· calendar.getEvent Β· calendar.freeBusy
calendar.createEvent Β· calendar.updateEvent Β· calendar.deleteEvent
contacts.list Β· contacts.get Β· contacts.create Β· contacts.update
contacts.delete Β· contacts.search
accounts.list Β· accounts.get Β· accounts.add Β· accounts.remove Β· accounts.sync
Full reference with input schemas: docs/mcp-tools.md
Documentation
Contributing
Feature branches off dev; PRs against dev. Run npm run build to compile all packages. Keep Changelog.md and docs/ in sync.
Support & Contributions
If you find mcp-ecc useful, consider supporting its development:
License