Gateway adapter only: no external dependenciesThis page covers the Email gateway adapter, which uses Python’s built-in
imaplib, smtplib, and email modules. No additional packages or external services are required for this gateway path.himalaya CLI plus a Himalaya config file.
Prerequisites
- A dedicated email account for your Mibyan agent (don’t use your personal email)
- IMAP enabled on the email account
- An app password if using Gmail or another provider with 2FA
Gmail Setup
- Enable 2-Factor Authentication on your Google Account
- Go to App Passwords
- Create a new App Password (select “Mail” or “Other”)
- Copy the 16-character password — you’ll use this instead of your regular password
Outlook / Microsoft 365
- Go to Security Settings
- Enable 2FA if not already active
- Create an App Password under “Additional security options”
- IMAP host:
outlook.office365.com, SMTP host:smtp.office365.com
Other Providers
Most email providers support IMAP/SMTP. Check your provider’s documentation for:- IMAP host and port (usually port 993 with SSL)
- SMTP host and port (usually port 587 with STARTTLS)
- Whether app passwords are required
Proton Mail Bridge / local relays
Proton Mail Bridge (and similar local relays such as a self-hosted MTA) listen on loopback with STARTTLS and a self-signed certificate, so the defaults (implicit TLS on IMAP 993, verified certificates) won’t connect. Override the transport in~/.mibyan/config.yaml:
EMAIL_IMAP_PORT=1143 / EMAIL_SMTP_PORT=1025 alongside your Bridge
credentials in ~/.mibyan/.env. Unknown *_security values log a warning and
fall back to the secure default. Only disable *_tls_verify for loopback hosts —
Mibyan logs a warning when verification is off for any other host.
Step 1: Configure Mibyan
The easiest way:Manual Configuration
Add to~/.mibyan/.env:
Step 2: Start the Gateway
- Tests IMAP and SMTP connections
- Marks all existing inbox messages as “seen” (only processes new emails)
- Starts polling for new messages
How It Works
Receiving Messages
The adapter polls the IMAP inbox for UNSEEN messages at a configurable interval (default: 15 seconds). For each new email:- Subject line is included as context (e.g.,
[Subject: Deploy to production]) - Reply emails (subject starting with
Re:) skip the subject prefix — the thread context is already established - Attachments are cached locally:
- Images (JPEG, PNG, GIF, WebP) → available to the vision tool
- Documents (PDF, ZIP, etc.) → available for file access
- HTML-only emails have tags stripped for plain text extraction
- Self-messages are filtered out to prevent reply loops
- Automated/noreply senders are silently ignored —
noreply@,mailer-daemon@,bounce@,no-reply@, and emails withAuto-Submitted,Precedence: bulk, orList-Unsubscribeheaders
Sending Replies
Replies are sent via SMTP with proper email threading:- In-Reply-To and References headers maintain the thread
- Subject line preserved with
Re:prefix (no doubleRe: Re:) - Message-ID generated with the agent’s domain
- Responses are sent as plain text (UTF-8)
File Attachments
The agent can send file attachments in replies. IncludeMEDIA:/path/to/file in the response and the file is attached to the outgoing email.
Skipping Attachments
To ignore all incoming attachments (for malware protection or bandwidth savings), add to yourconfig.yaml:
Access Control
Email access is stricter by default than chat-style platforms:EMAIL_ALLOWED_USERSset → only emails from those addresses (and fromGATEWAY_ALLOWED_USERSor an approved pairing) are processed- No allowlist set → unknown senders are ignored silently
EMAIL_ALLOW_ALL_USERS=true→ any sender is accepted (use with caution)platforms.email.unauthorized_dm_behavior: pair→ unknown senders receive a pairing codeplatforms.email.unauthorized_dm_behavior: decline→ an unknown sender receives one polite refusal, then nothing more for 24 hours
alice (a chat username in GATEWAY_ALLOWED_USERS, say) never admits alice@ at any domain, and mail from such an address is dropped rather than paired or declined.
Unless open access is on, Mibyan acts on a message only when the Authentication-Results header stamped by your receiving server authenticates its From: domain (DMARC, or aligned SPF/DKIM). GATEWAY_ALLOW_ALL_USERS counts as open access only while no allowlist is set, as it does for the gateway itself. Pairing codes and declines need an authenticated From: even with open access on, so neither is mailed to a forged address. If your mail server does not stamp that header, set platforms.email.require_authenticated_sender: false to accept the risk.
Troubleshooting
Security
- Use App Passwords instead of your main password (required for Gmail with 2FA)
- Set
EMAIL_ALLOWED_USERSto restrict who can interact with the agent - The password is stored in
~/.mibyan/.env— protect this file (chmod 600) - IMAP uses SSL (port 993) and SMTP uses STARTTLS (port 587) by default — connections are encrypted

