GPTmail is an MIT-licensed FastAPI project with a password-protected mail dashboard and OAuth-protected tools for ChatGPT. I'm sharing the source architecture for feedback from other Vercel builders.
The application starts from a root FastAPI module. Upstash Redis holds owner sessions, OAuth records, account data, permissions, and pending actions, so these survive individual runtime instances. Mail credentials, provider tokens, and pending drafts are encrypted before storage. Deployment configuration and secrets belong in environment variables; the repository includes an example configuration without credentials.
Tool discovery reflects enabled permissions, but call_tool() checks policy again when a request arrives. With outgoing approval enabled, sending creates a pending request. The dashboard approval handler consumes that request once, then rechecks account access and the original permission before attempting delivery. Failed attempts are not automatically requeued.
During development, 69 automated tests passed. Provider calls use mocks or fakes; live mailbox IMAP/SMTP and Gmail/Microsoft OAuth testing remains pending. Provider OAuth requires your own app registrations.
Source and setup: https://github.com/ozandikici/GPTmail. Feedback on serverless state handling and approval failure behavior is welcome.
Disclosure: AI assisted the implementation, documentation, branding, and this post.