Search

Sign in to launch Copilot/Codex from the palette.

Back to prompts

inbox.dog

Give your AI agent Gmail superpowers. Full read/write/search/send via MCP, npm, or browser connect — no Google security audit required.

Tools Updated Feb 23, 2026 ~696 tokens
0.3% of 200k
You have access to inbox.dog — a Gmail OAuth bridge that gives AI agents full Gmail read, write, search, and send capabilities. It has already passed Google's CASA Tier 2 security audit so you don't have to.

## Why this exists

Google requires a CASA Tier 2 security audit ($550+, weeks to months) before any app can get Gmail write access. inbox.dog already passed it. You piggyback on those credentials.

## 3 ways to install

### Option 1: MCP Server (recommended for AI agents)

Add to your Claude Desktop, Cursor, or Windsurf config:

{
  "mcpServers": {
    "inbox-dog": {
      "command": "npx",
      "args": ["-y", "inbox.dog", "mcp"],
      "env": {
        "INBOXDOG_KEY": "YOUR_CLIENT_ID",
        "INBOXDOG_SECRET": "YOUR_CLIENT_SECRET"
      }
    }
  }
}

Available MCP tools after setup:
- read_emails   — List emails from inbox
- read_email    — Read a specific email
- send_email    — Send an email
- search_emails — Search Gmail with queries
- get_profile   — Get account info

### Option 2: npm package (full control)

npm install inbox.dog

import InboxDog from 'inbox.dog';
const dog = new InboxDog();

// 1. Generate auth URL
const authUrl = dog.getAuthUrl({
  clientId: 'YOUR_KEY',
  redirectUri: 'http://localhost:3000/callback',
});

// 2. Exchange code for tokens (after user authorizes)
const { access_token, refresh_token, email } =
  await dog.exchangeCode(code, 'YOUR_KEY', 'YOUR_SECRET');

// 3. Use access_token with Gmail API directly
// Auto-refresh is handled for you

### Option 3: Browser connect (no code)

Visit https://inbox.dog/connect to link your Gmail account.
Retrieve tokens later via getGmailTokens(clientId, clientSecret).

## Gmail scopes

gmail:read   — Read-only access
gmail:send   — Send-only access
gmail:full   — Full access (read, send, modify, label, draft)

## OAuth flow (if building custom)

1. GET  /oauth/authorize?client_id=...&redirect_uri=...&scope=gmail:full
2. User authorizes → redirected with code
3. POST /oauth/token  { code, client_id, client_secret }
4. Response: { access_token, refresh_token, email }

Tokens auto-refresh. No manual refresh logic needed.

## Create API keys

POST https://inbox.dog/api/keys
{ "name": "my-app", "redirect_uris": ["https://myapp.com/callback"] }

## Key facts

- Free, no credit card, unlimited Gmail requests
- MIT licensed, open source (github.com/acoyfellow/inbox.dog)
- Self-hostable on your own Cloudflare account
- Built with Effect-TS + Hono on Cloudflare Workers
- Works with any MCP-compatible agent (Claude, Cursor, Windsurf, etc.)

## Quick start for agents

1. Get credentials at inbox.dog/connect
2. Add the MCP config above to your agent
3. Start using read_emails, send_email, search_emails tools
4. That's it. No OAuth dance, no security audit, no waiting.

How to use this prompt

  1. Copy the prompt using the button above
  2. Paste it into your preferred AI coding assistant
  3. Adjust any placeholders or context as needed
  4. Let the agent implement the changes