Cloud Deployment
Cloud Deployment
Section titled “Cloud Deployment”Deploy gmail-mcp-server to EC2, DigitalOcean, or any cloud VPS so ChatGPT can access it.
Why Deploy?
Section titled “Why Deploy?”- ChatGPT Integration: Use Gmail tools in ChatGPT custom connectors
- Remote Access: Reach your server from anywhere
- Shared Setup: Single server, multiple clients
Prerequisites
Section titled “Prerequisites”- Linux server (Ubuntu 20.04+)
- Domain pointing to your server
- Docker & Docker Compose
- A reverse proxy (Caddy or Nginx)
Step 1: Set Up HTTPS
Section titled “Step 1: Set Up HTTPS”Option A: Caddy (Simplest)
Section titled “Option A: Caddy (Simplest)”Install Caddy:
sudo apt-get update && sudo apt-get install -y caddyCreate /etc/caddy/Caddyfile:
gmail-mcp.example.com { reverse_proxy localhost:8811}Replace gmail-mcp.example.com with your domain.
sudo systemctl start caddysudo systemctl enable caddyCaddy auto-handles HTTPS with Let’s Encrypt. Done!
Option B: Nginx
Section titled “Option B: Nginx”Install Nginx:
sudo apt-get install -y nginxCreate /etc/nginx/sites-available/gmail-mcp:
server { listen 80; server_name gmail-mcp.example.com; return 301 https://$server_name$request_uri;}
server { listen 443 ssl http2; server_name gmail-mcp.example.com;
ssl_certificate /etc/letsencrypt/live/gmail-mcp.example.com/fullchain.pem; ssl_certificate_key /etc/letsencrypt/live/gmail-mcp.example.com/privkey.pem;
location / { proxy_pass http://localhost:8811; proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; }}Get SSL cert with Certbot:
sudo certbot certonly --standalone -d gmail-mcp.example.comsudo systemctl start nginx && sudo systemctl enable nginxStep 2: Prepare Credentials
Section titled “Step 2: Prepare Credentials”Upload secrets/credentials.json from your local machine:
scp secrets/credentials.json user@your-server:~/gmail-mcp-server/secrets/Step 3: Authorize
Section titled “Step 3: Authorize”On your server:
cd ~/gmail-mcp-serverpython -m venv .venvsource .venv/bin/activatepip install -e .python authorize.pyIf you can’t open a browser, use SSH port forwarding:
# On your local machine:ssh -L 8080:localhost:8080 user@your-server# Visit http://localhost:8080 in your browserStep 4: Configure .env
Section titled “Step 4: Configure .env”Copy template:
cp .env.example .envEdit .env with your values:
GMAIL_MCP_CREDENTIALS=secrets/credentials.jsonGMAIL_MCP_TOKEN=secrets/token.jsonGMAIL_MCP_ALLOWED_HOSTS=gmail-mcp.example.com
GMAIL_MCP_ENABLE_OAUTH=1GMAIL_MCP_ISSUER_URL=https://gmail-mcp.example.comGMAIL_MCP_OAUTH_CLIENT_ID=gmail-mcp-abc123GMAIL_MCP_OAUTH_REDIRECT_URIS=https://chatgpt.com/connector/oauth/your_idGMAIL_MCP_OAUTH_PASSPHRASE=$(python -c "import secrets; print(secrets.token_urlsafe(24))")GMAIL_MCP_OAUTH_STATE=secrets/oauth_state.jsonStep 5: Start Server
Section titled “Step 5: Start Server”docker compose up -d --builddocker compose logs gmail-mcpShould show: INFO: Uvicorn running on http://0.0.0.0:8811
Step 6: Connect ChatGPT
Section titled “Step 6: Connect ChatGPT”- In ChatGPT, Settings → Tools → Create action
- Fill in:
- Name: gmail-mcp
- Server URL:
https://gmail-mcp.example.com/mcp - Authentication: OAuth
- Client ID:
gmail-mcp-abc123(from .env) - Token endpoint auth: None
- Save → auto-discovers endpoints
- First use → consent page → enter passphrase → done!
Security
Section titled “Security”- ✅ Only
gmail.readonlyandgmail.composerequested - ✅ Your token is local, never sent to us
- ✅ Passphrase protects the consent screen
- ✅ DNS rebinding protection (
GMAIL_MCP_ALLOWED_HOSTS) - ✅ Only drafts are writable—never send, modify, delete
Stuck? See Troubleshooting.
