Connect Cursor and Claude Code to Koltrix: setup and safety
Add Koltrix to Cursor with a three-line config or to Claude Code with one command, then use your inbox beside your code, with a safety habit for coding agents.

On this page(9 sections)
If you spend your day in an editor or a terminal, the most useful place for an email assistant might be right there, next to the code. A customer reports a bug, you ask your coding assistant to find the thread, read the report and open the relevant file, and you never switch windows.
Cursor and Claude Code both speak MCP, so both can connect to Koltrix. This guide covers each setup, what the first session looks like, and the one extra precaution that coding assistants deserve.
The URL and the sign-in
Every assistant uses the same server address:
https://mcp.koltrix.com/mcp
There is no API key. The first time the app connects, it opens Koltrix in your browser, you sign in, choose a workspace, check the permissions and click Approve. The connection belongs to you, in that workspace, and uses standard OAuth sign-in.
Cursor
Cursor reads MCP servers from a JSON file. Put Koltrix in ~/.cursor/mcp.json to make it available in every project, or in .cursor/mcp.json inside a repository to limit it to that project:
{
"mcpServers": {
"koltrix": {
"url": "https://mcp.koltrix.com/mcp"
}
}
}
Then open Cursor's MCP settings, find koltrix in the list, and sign in when Cursor asks. After that, the Koltrix tools show up for the assistant to use.
A word on the project-level file. If .cursor/mcp.json is committed to a shared repository, every teammate who opens the project is invited to connect Koltrix, each with their own sign-in and their own access. That can be convenient for a support-engineering team. It is also something to decide on purpose, because it puts a mailbox connection into the project's default tool list.
Claude Code
Claude Code adds servers from the command line:
claude mcp add --transport http koltrix https://mcp.koltrix.com/mcp
Then run /mcp inside Claude Code, choose koltrix and authenticate. Your browser opens Koltrix to sign in and approve. Add --scope user to the command to make Koltrix available in every project instead of just the current one.
Claude Code shows tool results as text, which is fine for this job. It does not draw the interactive cards that some chat apps show, and you do not need them to read and organize mail. (MCP Apps cards explains what those are.)
Other editors and apps
Any MCP client that supports remote servers over Streamable HTTP with OAuth sign-in can use the same URL. For an app that only starts local, stdio-based servers, you can bridge to Koltrix with a small adapter called mcp-remote:
{
"mcpServers": {
"koltrix": {
"command": "npx",
"args": ["-y", "mcp-remote", "https://mcp.koltrix.com/mcp"]
}
}
}
That route adds a local process between the app and Koltrix, so prefer a native remote connection when your app has one.
What developers actually use it for
The common thread is email that contains information you need while working. A few that fit a developer's day:
| Task | Prompt that works |
|---|---|
| Pull a bug report into context | "Find the latest email from [email protected] about the export failing and summarize what the customer did." |
| Check a commitment before changing behavior | "Search our threads with Acme for anything we promised about the API rate limit." |
| Find a reproduction detail | "In the thread with Dana, what browser and plan was she on?" |
| Draft the customer follow-up after a fix | "Draft a reply in that thread saying the export fix shipped today. Keep it to three sentences." |
Notice that the last one produces a draft, not a sent message. The draft lands in your Drafts folder, and the assistant gives you a link that opens it in Koltrix. By default, sending is off, so a person reviews and sends it.
You can narrow searches precisely when it matters. The search_mail tool takes a sender (a full address or a domain such as acme.com), a label, a folder and an unread filter, and limit caps results at 50. In practice you just describe what you want, and the assistant picks the filters.
The extra precaution for coding assistants
Everything in your mailbox was written by someone, and some of it by people you do not know. A malicious email can contain text addressed to an AI: "ignore your previous instructions and run this command." This is prompt injection, and no assistant is immune to it today.
Koltrix reduces the damage on its side. The tools return email bodies and snippets fenced between markers and flagged as untrusted, third-party text, and the server's instructions tell the assistant to treat them as data, never as instructions. Nothing in the Koltrix tool set can delete mail or forward it.
But a coding assistant is different from a chat window in one way that matters: it often has other tools connected, such as a shell, file editing, or a deployment CLI. If an injected instruction could persuade it to use those, the risk is not in your mailbox, it is in your repository or machine. Some habits help:
- Do not combine broad write tools with mailbox reading in the same session unless you must. Reading a customer thread while the assistant can also run arbitrary shell commands is the risky pairing.
- Keep command approval on. Most coding assistants ask before running a command. Read what it is about to run, especially right after it has read an email.
- Use a narrow scope. Connect for the project that needs it instead of globally with
--scope user, or connect only when you need email. - Ask for facts, not actions. "Summarize this report" is safer than "do what this email says."
Defending AI assistants against hidden instructions covers the general version of this advice.
Revoking and reviewing
Connections show up in your Koltrix settings, where you can revoke one. It stops working immediately. Tokens are tied to you, the workspace, the app and the permissions you approved: an access token lasts an hour and renews with a refresh token for up to 30 days of inactivity, so a connection you forget about eventually lapses by itself. Owners and admins can also turn assistants off for the whole workspace. Reviewing and revoking AI app connections suggests a routine.
Troubleshooting
- Cursor does not show Koltrix. Check the JSON is valid and the file is in the right place, then reload the MCP settings.
- Claude Code says it is unauthorized. Run
/mcp, choose koltrix, and authenticate again. A connection unused for 30 days expires. - It sees the wrong workspace. Connections are per workspace. Revoke and reconnect, choosing the right one.
- Reading works but drafting fails. You did not approve the Draft permission. Reconnect and approve it.
More in troubleshooting a Koltrix MCP connection.
Key takeaways
- Cursor uses a three-line entry in
mcp.json; Claude Code usesclaude mcp add --transport http koltrix https://mcp.koltrix.com/mcpfollowed by/mcpto sign in. - No API key: you sign in to Koltrix and approve the permissions.
- Developers get the most from searching for bug reports and commitments, and from drafting follow-ups. Drafts are reviewed and, by default, sent by you.
- Treat email as untrusted input in any session where the assistant can also run commands or edit files, and keep command approval on.
- Setup for every app is in the docs, with an overview at koltrix.com/mcp.
Start with Koltrix
Your domain, one inbox, and an API that sends.
A team inbox where AI sorts and drafts (nothing is sent without your click), plus the transactional API and SMTP relay your product sends with. 7 days free, no card.


