Oryah Mail documentation
Last updated: October 1, 2026 · Setup and usage for the Oryah Mail connector for Claude.
1. What Oryah Mail is
Oryah Mail is a hosted remote MCP server from InfiniHash. One connector gives Claude access to several mailboxes and calendars at once: Gmail and Google Calendar accounts, Microsoft 365 mail and calendars (including shared mailboxes you have access to), and IMAP mailboxes such as Yahoo, AOL, iCloud, Zoho and Fastmail. Claude can read, search and draft email, work with calendar events, and send email when the mailbox's permissions allow it.
Oryah Mail does not host your mail. Messages and events stay with your provider. Oryah Mail relays each request to the provider (the Google or Microsoft API, or the provider's IMAP, SMTP and CalDAV servers) on your behalf and applies the permissions you set for that mailbox.
- MCP endpoint:
https://mail-mcp.infinihash.com/mcp - Admin console: https://mail-mcp.infinihash.com/admin
- Pricing: 14-day free trial, then a paid plan. See the pricing page for current prices.
2. Limits and defaults
- New mailboxes start with Full access. Full access includes sending, organizing and deleting. If you want Claude to prepare drafts that you send yourself, set the mailbox to Read + draft; if Claude should not change anything, set it to Read only. See Permissions.
- No extra confirmation step on the server. When a mailbox's permissions allow a send, Oryah Mail carries it out as soon as Claude asks. Your permission settings, and Claude's own prompts to confirm actions, are what stand between a request and a sent message.
- Sends can be limited to domains you choose. If a mailbox has a send-allowed-domains list, sends, replies and forwards to recipients outside those domains are refused. Calendar invitations are not checked against the list.
- IMAP mailboxes use app passwords. Yahoo, AOL, iCloud, Zoho, Fastmail and other IMAP providers connect with an app password you create in that provider's security settings. Oryah Mail uses the same app password to send (SMTP) and, where the provider offers it, for calendars (CalDAV). Calendar tools work for Yahoo, iCloud, Zoho and Fastmail, and for custom accounts where you enter a CalDAV address. AOL, GMX, Mail.com and Yandex mailboxes have mail only.
- Google verification is not finished. Oryah Mail's Google OAuth app has not completed Google's verification, so Google shows an "unverified app" screen when you add a Google account. See Troubleshooting.
- Deleting moves mail to trash.
delete_messagemoves a message to the provider's trash or Deleted Items folder. One exception: on IMAP mailboxes, labels are folders, and removing a message from the folder it is in withlabel_messagedeletes it permanently. - No mailbox hosting, sync or backup. Oryah Mail is not an email client or archive. It fetches what each request needs.
- No model training or advertising. Mailbox content is not used to train models or for advertising. See the privacy policy.
3. Connect in Claude
Option A: add it as a custom connector
- In Claude, open Settings → Connectors.
- Choose Add custom connector.
- Name it
Oryah Mailand enter the URLhttps://mail-mcp.infinihash.com/mcp. - Select Connect. A browser window opens for sign-in.
On Team and Enterprise plans, an organization owner may need to add the connector before members can use it.
Option B: from the Connectors Directory
When Oryah Mail is listed in the Claude Connectors Directory, open Settings → Connectors, browse the directory, find Oryah Mail and select Connect. You do not need to enter the URL.
Signing in
The connector uses OAuth 2.1. Claude registers itself with Oryah Mail automatically (dynamic client registration) and uses PKCE, so there is no client ID or secret to copy. When the sign-in window opens:
- Sign in with Google, Microsoft or a passkey you have added. If you are new, this creates your Oryah Mail account.
- Approve the access request for Claude.
- The window closes and Claude shows the connector as connected.
New accounts start the 14-day free trial with Start free trial on mail.infinihash.com, or with the upgrade button in the admin console. Until the trial or a plan is active, tools report that the subscription is inactive.
The account you sign in with identifies you to Oryah Mail. The mailboxes Claude can use are the ones you add in the admin console, described next.
4. Add mailboxes in the admin console
- Open https://mail-mcp.infinihash.com/admin and sign in.
- Go to Mailboxes and choose Add mailbox. Pick Google, Microsoft, or Other email (Yahoo, AOL, iCloud, Zoho, GMX, Mail.com, Fastmail, Yandex or any IMAP mailbox).
- For Google or Microsoft, complete the provider's consent screen. For other email, enter the address and then an app password created in that provider's security settings. Oryah Mail fills in the server settings for providers it recognizes; for others it asks for the IMAP and SMTP servers, ports and security, and an optional CalDAV address. Test & connect checks the connection before saving.
- New mailboxes start with Full access. Open Controls and choose the access level you want before you use Claude with the mailbox.
Microsoft 365 shared mailboxes you can access can be added too, each with its own permissions. In Claude, ask "Which mailboxes can you see?" to confirm. Claude calls list_accounts and account_status and lists each mailbox with its alias and provider.
5. Permissions, the send allowlist and the audit log
Every mailbox has its own access level under Controls in the admin console. Settings apply to that mailbox only.
| Access level | What Claude can do |
|---|---|
| Full access | Everything: read and search mail, create and edit drafts, send, reply and forward, organize (labels, folders, archive, read/unread), delete to trash, view calendars and free/busy, and create, change, delete or respond to events. This is the default for new mailboxes. |
| Read + draft | Read and search mail, create and edit drafts, and view calendars and free/busy. No sending, organizing, deleting or calendar changes. You review and send drafts yourself. |
| Read only | Read and search mail, and view calendars and free/busy. No drafts or changes. |
| Off | Claude cannot read or change the mailbox, and it is left out of searches across all mailboxes. It still appears, with its setting, when Claude lists your mailboxes. |
| Custom | Turn individual permissions on or off: Read mail, Write drafts, Send mail, Organize mail, Delete mail, View calendar, Change calendar, and Include in searches across all mailboxes. |
Send-allowed domains
For a mailbox that can send, you can list the domains it may send to, for example yourcompany.com. Domains must match exactly, so list subdomains such as eu.yourcompany.com separately. When a message is sent with a recipient outside the list, the send is refused and the refusal is recorded in the audit log. Leave the list empty to allow any recipient. The list applies to send_mail, reply, forward and send_draft. It does not apply to calendar invitations, which your calendar provider sends to the attendees you add.
Audit log
The audit log in the admin console records every draft, send, organize, delete and calendar change, and refused actions, with the actor: a Claude session (OAuth) or a named API key. Entries can include recipients and subjects for messages, and titles and times for events. They never include message bodies or attachment contents. Successful reads, such as searches, opened messages and calendar views, are not logged individually.
How permissions combine
When Claude connects through OAuth, the mailbox's Controls apply. When an API key is used, a request must be allowed by both the mailbox's Controls and the key's access for that mailbox. If both set send-allowed domains, only domains on both lists are allowed.
6. API keys for agents
For agents and scripts that cannot complete an interactive sign-in, create an API key in the admin console under API keys → Create API key. Choose a name, an expiry (never, 30, 90 or 365 days), the access level for all mailboxes (Full access, Read + draft, Read only, Off or Custom; Read only is the default), optional send-allowed domains, and optional overrides for individual mailboxes. The key is shown once; Oryah Mail stores only a hash of it.
Keys begin with omk_ and are sent as a bearer token:
Authorization: Bearer omk_your_key_here
Point any MCP client that supports custom headers at https://mail-mcp.infinihash.com/mcp with that header.
- Give each key only the access it needs. Key access is combined with each mailbox's Controls as described above.
- Actions taken with a key are recorded in the audit log under the key's name.
- Treat a key like a password. Revoke it under API keys if it is exposed or no longer needed; revocation takes effect immediately.
- Claude.ai and the Claude apps use OAuth. You do not need an API key to use Oryah Mail in Claude.
7. Tool reference
Most tools take an account argument: a mailbox alias or email address, or all where noted. Each tool is subject to the mailbox's permissions.
Read
| Tool | What it does |
|---|---|
account_status | Checks connection and token status for one mailbox or all. |
list_accounts | Lists connected mailboxes with alias, email, provider, type (personal or shared), whether each is enabled, and its permissions. |
unified_inbox | Lists recent inbox messages across one or all mailboxes. |
search_mail | Searches one or all mailboxes using the provider's search syntax. |
read_message | Reads one message, including its attachment list. |
read_thread | Reads a full conversation. |
read_attachment | Reads attachment contents: text from PDF, DOCX, CSV, plain text and HTML; CSV text from spreadsheets; images returned for viewing. |
get_attachment | Reads a single attachment. Same behavior as read_attachment. |
list_folders | Lists folders (Microsoft 365, IMAP) or labels (Gmail). |
list_calendars | Lists calendars for one or all mailboxes. |
list_events | Lists events on a calendar within an optional time range. |
get_event | Gets one calendar event. |
find_free_time | Merges free/busy across the calendars of one or all mailboxes and suggests open slots of a given length. |
check_upload | Lists the files uploaded so far to an upload link. |
Write
| Tool | What it does |
|---|---|
create_draft | Creates a draft, with optional attachments. Nothing is sent. |
update_draft | Edits an existing draft. |
mark_read | Marks a message read or unread. |
move_message | Moves a message to another folder or label. |
archive | Removes a message from the inbox without deleting it. |
create_upload_link | Creates a link that anyone who has it can use, without signing in, to drop files for Claude to attach to a message. The link stops accepting files after 24 hours. |
create_event | Creates a calendar event, optionally with attendees, who receive an invitation from your calendar provider. |
update_event | Changes fields on a calendar event. Attendees may receive an update. |
respond_to_event | Accepts, declines or tentatively accepts an invitation. The organizer is notified. |
Send and delete
These tools send email to other people or remove items. Sending needs the Send mail permission, deleting needs Delete mail, label_message needs Organize mail, and delete_event needs Change calendar. Sends are checked against the send-allowed-domains list.
| Tool | What it does |
|---|---|
send_mail | Sends a new email from the chosen mailbox, immediately. |
send_draft | Sends an existing draft, immediately. |
reply | Replies (or replies all) to a message from the mailbox it belongs to. |
forward | Forwards a message to new recipients, keeping its attachments by default. |
delete_message | Moves a message to the provider's trash or Deleted Items. |
label_message | Adds or removes Gmail labels or Microsoft 365 categories. On IMAP, labels are folders: removing one deletes the message's copy in it, and removing the folder the message is in deletes it permanently. |
delete_event | Deletes a calendar event. Attendees may be notified. |
Attachments on sends and drafts can come from another message in any of your mailboxes, from an https URL the server fetches, from an upload link, or as a small inline file. The total per message is capped at 25 MB. When Claude asks for an attachment it cannot display, Oryah Mail returns a download link that works for 15 minutes for anyone who has it.
8. Example prompts
- "Which mailboxes can you see, and are they all connected?"
- "Summarize unread email from the last two days across all my inboxes. Group it by mailbox."
- "Find the latest invoice from Acme in any of my accounts and tell me the total and due date."
- "Draft a reply to Priya's last message from my work account saying Thursday works. Don't send it."
- "Find a free 45-minute slot next week that works across my work and personal calendars."
- "Put a 30-minute call with [email protected] on my work calendar for that slot."
- "Archive the newsletters in my personal inbox from this week."
- "Forward the signed contract to [email protected] from my work mailbox."
Claude will ask which mailbox to use if a request is ambiguous. For anything that sends, it is good practice to ask Claude to show you the draft first.
9. Data and privacy
Summary only. The privacy policy is the authoritative document.
- Oryah Mail stores your sign-in identities, the encrypted OAuth tokens or IMAP app passwords for each mailbox, your Controls settings, hashes of your API keys, and the audit log.
- Message and calendar content is fetched from your provider when a request needs it, passed to Claude, and not stored by Oryah Mail. Files dropped on an upload link are stored on our servers so they can be attached.
- Content returned by a tool goes to the Claude conversation that asked for it. How Anthropic handles conversation data is covered by Anthropic's own terms and privacy policy.
- Mailbox content is not used for advertising or to train models, and is not sold.
- Google user data is handled under the Google API Services User Data Policy, including its Limited Use requirements.
- Removing a mailbox in the admin console deletes its stored tokens or app password from Oryah Mail. It does not revoke the access you granted at Google or Microsoft: revoke it in your Google Account or Microsoft account security settings, or delete the app password at your IMAP provider. To delete your Oryah Mail account, email us.
Email content is untrusted
Emails are written by other people, and a message can contain text that tries to instruct an AI assistant. Oryah Mail labels email content it returns to Claude as untrusted data, but no connector can guarantee a model will never act on such text. Permissions are the control that does not depend on the model: use Read only or Read + draft on mailboxes where you do not want Claude to send, keep a send-allowed-domains list on mailboxes that can send, and review the audit log.
10. Troubleshooting
Google shows "Google hasn't verified this app"
Expected while Google verification is in progress. To continue, choose Advanced, then the link to continue to the app, and review the requested access before approving. Some Google Workspace admins block unverified apps; in that case your admin must allow the app, or you can wait for verification. Microsoft 365 and IMAP mailboxes do not show this screen.
Claude says the subscription is inactive
Start the 14-day trial or choose a plan from the admin console. Tools that need a mailbox stay unavailable until the trial or a plan is active.
Claude says it cannot send
The mailbox does not have the Send mail permission, a recipient's domain is not on that mailbox's send-allowed-domains list, or the API key in use does not allow sending. Check Controls and the audit log entry for the refused action.
A mailbox is missing or shows as disconnected
Ask Claude to run account_status. If a token has expired or was revoked (for example after a password change), or an IMAP app password was revoked, reconnect the mailbox in the admin console. Mailboxes set to Off cannot be read or changed by Claude.
The connector will not connect in Claude
Check the URL is exactly https://mail-mcp.infinihash.com/mcp. Disconnect and reconnect the connector to repeat sign-in. Allow pop-ups for claude.ai if the sign-in window does not open.
My Yahoo, iCloud or other IMAP account will not connect
IMAP mailboxes need an app password, not your normal account password. Create one in the provider's security settings (most providers require two-step verification to be on first) and enter it in the admin console. Some providers also require IMAP access to be turned on in their mail settings. For a provider Oryah Mail does not recognize, check the IMAP and SMTP server names, ports and security settings in the provider's help pages.
A search misses messages I can see in Gmail or Outlook
search_mail uses each provider's search syntax and returns a limited number of results per call. Ask Claude to narrow the search to one mailbox or a date range, or to fetch more results.
11. Support
Email [email protected]. Include the mailbox provider, what you asked Claude, the approximate time, and any error text. Do not send API keys or passwords.
Related: Pricing · Privacy policy · Terms of service