Concepts
Architecture
The Go MCP boundary, OAuth resource server, mail transports, and durable send records.
Architecture
Angelos has a small, account-specific server boundary. A deployment has one configured mailbox and an explicit list of OAuth subjects allowed to access it. Multiple allowed subjects share that same mailbox; they are not separate tenants.
Request path
- The MCP client obtains an access token from the configured external issuer.
- The authentication middleware verifies the JWT, owner allowlist, audience, and base
mail.readscope. - A typed MCP tool validates its input and checks the operation’s scope and deployment gate.
- The mail backend opens a bounded TLS connection to the configured IMAP or SMTP server.
- The result returns structured data, warnings, or an error to the client.
The official Go MCP SDK handles stateless Streamable HTTP with JSON responses. An MCP session is not a durable transaction or approval record. The mailbox remains the provider’s source of truth.
Packages
| Package | Responsibility |
|---|---|
internal/auth |
Protected-resource metadata, token verification, public signing-key cache, and scope checks |
internal/config |
Administrator-configured mailbox credentials and TLS endpoints |
internal/mail |
IMAP reads and guarded mutations, MIME parsing, and SMTP transport |
internal/compose |
Validated recipient envelope, MIME construction, and immutable content digest |
internal/dispatch |
Durable preparation, atomic send claim, and outcome recording |
internal/app |
MCP tool names, schemas, annotations, and operation boundaries |
The root Go service is independent of the static docs/ workspace. Documentation builds need no mailbox access.
State
- Mail and folder state live at the IMAP provider.
- Credentials live in the API environment.
- Public issuer signing keys have a bounded in-memory cache.
- Prepared sends and dispatch records live in an optional external Redis REST store.
Sending is disabled without that store. Mailbox reads and ordinary mailbox writes do not require it. A function instance’s memory is never used as the sole duplicate-send guard.
Deliberate boundaries
Tools cannot choose arbitrary mail hosts or supply credentials. OAuth access to Angelos and the backend’s mailbox login are separate credentials with separate purposes.
UIDVALIDITY guards against stale message identity. Conditional flag updates use CONDSTORE where supported. Other clients can still modify the account concurrently; there is no global mailbox lock or cross-protocol transaction.
The trusted MCP client handles human confirmation. An exact payload digest ensures consistency between preparation and dispatch, while the durable claim limits a preparation to one dispatch attempt. Neither mechanism guarantees final delivery or proves human consent. See Safety and concurrency.