Free and open source. For Gmail.
Clean up your Gmail filters. Keep your mail to yourself.
3B Mailbox shows all your Gmail filters in one clear view. It finds duplicates and conflicts, merges filters that do the same job, and helps you make new ones. It runs fully in your browser. Your data goes only between your browser and Google.
- Free, with no account and no subscription
- No server, no analytics, no cookies
- Built to WCAG 2.2 AA, with AAA where we can
The demo uses made-up data. It does not connect to Google. To use your own Gmail, set up your own client ID first. This takes about 10 minutes. Or use it without signing in: export your filters from Gmail, change them here, then import the new file.
What it does
Gmail lets you keep up to 1,000 filters. Most people add them one at a time and never look at them again. 3B Mailbox helps you see and fix what you have.
-
See every filter clearly
Each filter gets a plain-English summary, for example "Mail from amazon.co.uk: skip the inbox, apply label Receipts". Search, sort and group by label, action or sender.
-
Find problems
The app finds duplicate filters, filters that conflict, labels that no longer exist and forwarding addresses that are not verified. Filters that delete or forward mail get a clear warning.
-
Merge and tidy
Filters that do the same thing can become one filter. You see the result before anything changes, and the app shows how many filters you save.
-
Change many at once
Select many filters and change their label, add or remove an action, or delete them. Every bulk change shows a preview first. An undo list keeps a copy of each filter you delete.
-
Make new filters easily
Use a simple form or write a Gmail search. A live counter shows how close you are to the length limit. Ready-made suggestions cover receipts, newsletters, deliveries, one-time codes and more.
-
Stay inside the limits
The app knows the Gmail limits. It warns you at 80% and 95%, and it stops a change that Gmail would refuse.
Use it without signing in
You do not need a Google Cloud client ID, and Google does not show an "unverified app" warning. The app reads only the file you choose. Nothing leaves your browser.
-
In Gmail, open Settings, then See all settings, then
Filters and blocked addresses. Select all your filters and choose
Export. Your browser saves a file called
mailFilters.xml. - Open the setup page and choose Work without signing in. Choose the file, or drag it onto the page.
- Use the app as normal: see your filters, tidy them up, make bulk changes, add suggestions and undo.
- Choose Download for Gmail to save the new file.
- In Gmail, select all your filters and choose Delete. Then choose Import filters, choose the new file, and choose Create filters.
Do step 5 in that order. Gmail import adds filters and never deletes them, so if you do not delete the old filters first, you get two of each. Keep your original file as a backup. If something goes wrong, import it again.
What you give up
- The app cannot show the mail that a filter matches.
- The app cannot apply a filter to mail you already have.
- You delete and import your filters in Gmail yourself.
- Gmail matches labels by name and makes any label that is missing. Forwarding works only to addresses you have already verified in Gmail.
- Your changes stay in the browser tab until you download them. The app warns you before you close or reload the tab with changes you have not downloaded.
How privacy works
3B Mailbox is a set of static files. When you open it, your browser downloads the files and runs them. After that, the app talks only to Google.
- You create your own Google Cloud client ID. It belongs to you, in your own Google Cloud project.
- You sign in with Google. Google gives your browser a short-lived access token. The token lasts about 1 hour. The app keeps it in memory only and never saves it.
- Your browser asks the Gmail API for your filters and labels. The answers come back to your browser only.
- The maintainer has no server. The maintainer gets no data, no usage counts and no error reports. Because the client ID is yours, the usage numbers show only in your own Google Cloud console.
Permissions, one step at a time
The app asks Google only for the permission that a feature needs, and only when you turn that feature on.
| Tier | What it lets the app do | Google scopes |
|---|---|---|
| Basic | Read and change filters and labels. Read your list of forwarding addresses. | gmail.settings.basic, gmail.labels |
| Preview | Show the mail that a filter matches (sender, subject and date). | Basic, plus gmail.readonly |
| Apply | Apply a filter to mail you already have. | Preview, plus gmail.modify |
Set up your own client ID
You need a Google Cloud OAuth client ID. It is free. You do not need a billing account. Setup takes about 10 minutes, and you do it once.
Before you start
-
Know the web address where you will use the app. You need its
origin: the scheme, the host and the port, if there is one. For
example
https://filters.example.comorhttp://localhost:8080. An origin has no path and no slash at the end. - Sign in to Google Cloud with the same Google account that you use for Gmail. This makes the test-user step simple.
- Google changes the Cloud console from time to time. If a label on your screen is different, look for the nearest match.
Personal Gmail account
Use these steps for an address that ends in @gmail.com or
@googlemail.com.
-
Create a project
Go to console.cloud.google.com. Open the project picker at the top of the page and select New project. Give it a name, for example "3B Mailbox". Select Create, then make sure the new project is selected.
-
Turn on the Gmail API
Go to APIs & Services, then Library. Search for "Gmail API", open it and select Enable.
-
Register your app with Google Auth Platform
Go to Google Auth Platform (search for it in the console search bar). If you see Get started, select it. Google asks for:
- App information: an app name that only you will see, for example "My mail filters", and a user support email (your own address). Do not put the word "Google" in the name.
- Audience: select External.
- Contact information: your own email address.
- Finish: agree to the Google API Services User Data Policy, then select Create.
Google may also show a Branding page. You can leave the logo and links empty for an app that only you use.
-
Add yourself as a test user
Go to Audience. Leave the publishing status at Testing. Under Test users, select Add users, enter your Gmail address and select Save. Testing mode allows up to 100 test users, so you can add family members too.
-
Optional: list the scopes
Go to Data access and select Add or remove scopes. You can add
gmail.settings.basicandgmail.labels, and alsogmail.readonlyandgmail.modifyif you plan to use preview and apply. The app asks for each scope when it needs it, so this step only makes the list visible in your console. -
Create the client ID
Go to Clients and select Create client. Set Application type to Web application and give it a name. Under Authorized JavaScript origins, select Add URI and enter the origin of the app, for example
https://filters.example.com. Leave Authorized redirect URIs empty. Select Create. -
Copy the client ID
Copy the Client ID. It ends in
.apps.googleusercontent.com. The app does not use the client secret. Do not paste the secret anywhere. -
Paste it into the app
Open the app, go to Set up, paste the client ID and select Sign in with Google. Google shows a warning that it has not verified the app. This is your own app, so it is safe to continue. Select Continue, then tick the permissions you want to give.
Google Workspace account
Use these steps for a work or school address that your organisation manages with Google Workspace. The steps are the same as for a personal account, with three differences.
-
Create the project in your organisation
In the project picker, make sure the Organization or Location is your Workspace organisation. If you cannot create a project, ask your Workspace admin.
-
Set the audience to Internal
On the Audience step, select Internal. Only people in your organisation can sign in. Google does not show the "unverified app" warning, and the app needs no verification. You do not need to add test users.
-
Check your admin settings
Your admin can block apps from using Gmail data. If sign-in fails with an "access blocked" message, ask your admin to trust your client ID in the Admin console API controls. Your admin can also turn off automatic forwarding, so filters that forward mail may not work.
Common mistakes
- The origin has a path or a slash at the end
-
Enter
https://filters.example.com. Do not enterhttps://filters.example.com/orhttps://filters.example.com/app/. Google refuses a path, and the sign-in fails with an "origin" error. - The origin does not match exactly
-
httpandhttpsare different origins. So arelocalhostand127.0.0.1, and each port number. Add every origin you use. - You are not a test user
- For a personal account in Testing mode, Google blocks sign-in with an "access denied" error until you add your address under Audience, Test users.
- The Gmail API is not turned on
- Sign-in works, but the app shows an error that says the Gmail API is not used or is disabled in your project. Go to APIs & Services, Library and enable it.
- The wrong Google account is signed in
- If you use more than one Google account, choose the one you added as a test user in the Google sign-in window.
- The change has not taken effect yet
- Google can take from a few minutes to a few hours to apply a new origin. Wait, then try again.
- The wrong client type
- The client must be a Web application. A Desktop, Android or iOS client does not work in a browser.
Questions and answers
Is it really free?
Yes. The app is free and open source. A Google Cloud project with the Gmail API costs nothing at personal use levels, and you do not need to add a billing account.
Why must I make my own client ID?
The permission to manage Gmail filters is a restricted scope. A shared client ID for many people would need a long Google review and maybe a paid security assessment. Your own client ID needs none of that. It also means that nobody else, including the maintainer, can see that you use the app.
Can I use it without a client ID?
Yes. Use it without signing in. You export your filters from Gmail, change them in the app, then import the new file in Gmail. The app does not contact Google at all in this mode.
Can the maintainer see my mail or my filters?
No. There is no server to send data to. The app loads no analytics, no fonts and no scripts from other sites, except the Google sign-in script. The code is open, so you or someone you trust can check it.
Why does Google say the app is not verified?
Google shows this warning for every app in Testing mode. The app here is the one you made in your own Google Cloud project, so you are the developer. Workspace users who set the audience to Internal do not see the warning.
Why must I sign in again after an hour?
Google access tokens last about 1 hour. The app does not ask for a long-lived refresh token, so nothing long-lived exists to steal. The app warns you before the token ends and lets you renew it without losing your work.
Will my client ID stop working after 7 days?
No. In Testing mode Google ends refresh tokens after 7 days. This app never gets a refresh token, so the rule does not affect it. You sign in for each session.
Does the app change anything without asking?
No. Every change shows a preview first. Filters that delete or forward mail need an extra confirmation. Before a bulk change, you can download a full backup.
Do new filters apply to mail I already have?
Not by default. A filter made through the Gmail API acts only on new mail. To apply a filter to old mail, turn on the Apply tier. The app then asks Google for the extra permission.
Does it work on a phone?
Yes. The app works in a mobile browser, and you can install it to your home screen.
Does it work with Outlook or other mail services?
No. It works only with Gmail and Google Workspace mail.
Is this a Google product?
No. 3B Mailbox is an independent open-source project. Google does not make, endorse or support it.
Privacy policy
Summary
3B Mailbox runs fully in your browser. It sends your data only to Google, and only to do what you ask. In no sign-in mode it sends nothing at all. The maintainer receives no data about you. There is no server, no account, no analytics, no cookies and no tracking.
Who this policy covers
This policy covers the 3B Mailbox app and this web page, in the copy that the maintainer hosts and in the source code. If someone else hosts a copy, they are responsible for their own host.
The data the app uses
The app reads only what the permissions you give allow. It uses this data:
- Basic tier: your Gmail filters, your labels and your list of forwarding addresses. Filters can contain email addresses and words that you chose.
- Preview tier (optional): the sender, subject and date of messages that match a filter. The app does not read the body of a message.
- Apply tier (optional): the IDs of messages that match a filter, so the app can add or remove labels on them.
No sign-in mode: the app reads only the mailFilters.xml
file you choose. It keeps the filters in the browser tab while you work. Nothing leaves
your browser, and the app does not contact Google. The file you download goes only to
your own device.
Where the data goes
Your browser sends requests straight to Google at accounts.google.com (to
sign in) and gmail.googleapis.com (the Gmail API). Nothing goes through a
server of ours. We do not sell, share or transfer your data, because we never receive
it.
What the app stores on your device
The app uses your browser's local storage. This data stays on your device. It does not leave your device, except in files that you choose to download.
- Your client ID.
- Your settings, for example theme, density, hints you closed and the tier you want.
- An undo list with copies of filters that the app deleted or replaced for you, so you can restore them. These copies can contain email addresses and words from your filters.
The app never stores your access token. It keeps the token in memory, and the token goes away when you close the tab or sign out. The app never stores message content.
How long we keep data
We keep nothing, because we receive nothing. The data on your device stays until you delete it. To delete it, use Delete all local data in the app settings, or clear the site data in your browser. The undo list keeps the last 200 entries and removes older ones.
The web host
The company that serves the files can record technical data such as your IP address when your browser downloads the files. Every web server does this. The hosted copy runs on Cloudflare, so Cloudflare's privacy policy covers these records. The hosted copy has no server code and Cloudflare Web Analytics is turned off. The maintainer does not use these records to identify or track people.
The app loads the Google sign-in script from accounts.google.com. When you
sign in and use the Gmail API, the
Google Privacy Policy applies to what
Google does with that data.
Google API Services User Data Policy
3B Mailbox's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In plain terms: the app uses Gmail data only to show and manage your filters. It does not use the data for advertising. It does not transfer the data to anyone. No person reads it.
How to remove access
Select Sign out in the app. This revokes the access token at Google. You can also remove access at any time at myaccount.google.com/permissions. To remove everything, delete the client ID or the whole project in your Google Cloud console.
Children
The app is not for children under 13, or under the minimum age for a Google Account in your country. We do not knowingly process data about children, and we receive no data at all.
Changes to this policy
We will update the date at the top when this policy changes. The full history of every change is public in the source code repository.
Contact
Ask a question or report a problem in GitHub issues. Do not put email content or email addresses in an issue. For a security problem, use a private security report.
Accessibility statement
Our target
We aim for full conformance with WCAG 2.2 at level AA. Where we can, we also meet level AAA. For example:
- Text contrast of at least 7:1 in light and dark themes.
- Targets of at least 44 by 44 pixels.
- No time limits that can lose your work. The app warns before your sign-in ends.
- Plain English, short sentences and help text on each form.
What we support
- Full keyboard use, with a visible focus outline and a skip link.
- Screen readers, with landmarks, headings and live updates for progress.
- Light and dark themes that follow your system setting.
- Windows high contrast (forced colours) and the "more contrast" setting.
- Reduced motion, zoom up to 400% and text spacing changes.
- Status never shown by colour alone.
How we test
- Automated checks with axe-core in Playwright on every page and app state, on every pull request.
- Keyboard-only checks of each task.
- Manual checks with VoiceOver (macOS and iOS), NVDA (Windows) and TalkBack (Android) before each release.
Known issues
- The app is pre-release. We have not finished manual screen reader tests for the first release.
- Google makes the sign-in window and the permission screens. We cannot change how they work.
- Google access tokens end after about 1 hour. We cannot make them longer. The app warns you first and keeps your work.
Tell us about a problem
If something is hard to use, please open a GitHub issue and say that it is about accessibility. Tell us the page, what you tried to do, and the browser and assistive technology you use. We aim to reply within 2 weeks.
Host your own copy
3B Mailbox is static files with no build step. You can host the
site/ folder on any static host that serves HTTPS, for example GitHub
Pages, Cloudflare Pages, Netlify or a home server.
-
Give the app its own origin, for example a subdomain such as
https://filters.example.com. All GitHub Pages project sites underhttps://<user>.github.ioshare one origin, so they share browser storage. A custom domain or subdomain keeps the app on its own. - Add your origin to Authorized JavaScript origins on your client ID.
- If your host lets you set headers, send a strict Content Security Policy. The source code repository has an example.
Run it on your computer
You need Node.js 22 or later.
git clone https://github.com/3bdigital/3b-mailbox.git
cd 3b-mailbox
npm install
npm run dev
The dev server picks a free port at random and prints the address. For sign-in you need the same origin each time, so choose a fixed port:
npm run dev -- --port 8080
Then add http://127.0.0.1:8080 as an authorised origin on your client ID,
and open that exact address.
Licence and source code
3B Mailbox is free software under the GNU Affero General Public Licence, version 3 only (AGPL-3.0-only). You can use, study, change and share it. If you run a changed copy for other people, you must give them its source code.
Read the code, report a problem or help at github.com/3bdigital/3b-mailbox.
Trademarks
Gmail, Google, Google Cloud and Google Workspace are trademarks of Google LLC. Email Filter is an independent project. It is not made, endorsed or supported by Google.