Guides
Deploy the API
Deploy the Go MCP API separately from the existing static documentation site.
Deploy the API
The repository contains two independent applications:
- The Go MCP API at the repository root
- The Astro/ZueDocs documentation site under
docs/
Use separate Vercel projects. The existing documentation project and domain remain dedicated to static documentation. Do not point that project at the API root or place mailbox credentials in its build environment.
Prerequisites
- A mailbox with IMAP and SMTP access
- An existing OAuth issuer meeting the authentication requirements
- A Vercel account and the official Vercel CLI
- The Go toolchain declared by
go.modfor local checks
Vercel’s Go framework preset supports a root main.go server listening on PORT. The root vercel.json selects that preset and builds the API. Vercel reads the Go version/toolchain from go.mod. See Vercel’s Go runtime documentation.
Create a separate API project
Run these commands from the repository root, not from docs/:
vercel login
vercel link
Choose or create a distinct API project and confirm its root directory is the repository root. Check the project selected by the CLI before adding secrets or deploying. Keep .vercel/ untracked.
Add each required variable from Configuration to that project’s production environment. Prefer Vercel’s sensitive environment settings for the mailbox password and any durable-store credentials. Enter secret values interactively instead of placing them in command history:
vercel env add MAIL_PASSWORD production
Use a stable production API hostname in MCP_RESOURCE_URL, including /mcp, and configure the issuer for that exact audience. An automatically generated preview URL is a different audience. See the official CLI linking and environment-variable references.
Once configuration and local/CI checks are ready, publish the API intentionally:
vercel --prod
Deploying code does not complete OAuth client registration, create a mailbox, configure DNS, or connect ChatGPT.
Verify before granting write access
- Fetch the API’s
/.well-known/oauth-protected-resourcedocument and verify its resource URL and issuer. - Confirm that
/mcprejects an unauthenticated request with401and a discovery challenge. - Connect with an allowlisted account and verify folder names and a small read-only search.
- Open a message and confirm that it remains unread in another client when it was unread before.
- Enable and test optional operations only against messages and folders you intend to change.
Run checks against the actual production API URL rather than assuming a successful docs deployment means the API is running.
Serverless limits
Keep mail operation timeouts inside the selected function duration. Do not rely on background goroutines continuing after an HTTP response. Vercel blocks outgoing SMTP port 25; authenticated submission on 465 or 587 is the intended path. See Vercel’s SMTP guidance.
Durable send state must live outside a function instance. A process restart, scale-out, or deployment can discard local memory. See Safety and concurrency.