Email username/password credentials
Description
Pure function: builds an email credentials object from a host, port, username, password, and encryption (SSL_TLS, STARTTLS, or NONE). Wire the credentials output into any email operation node. A port of 0 selects the encryption default (993 for SSL_TLS, 143 for STARTTLS and NONE). Use this for servers that still accept password login; Microsoft 365 requires Email OAuth2 credentials instead.
When to use
Use this when the mail server still accepts a username and password over IMAP — most self-hosted and small-provider mailboxes do. Gmail accepts it with an app password (a normal account password will be refused). Microsoft 365 does not accept it at all any more: use Email OAuth2 credentials there.
Keep the password out of the pipeline definition. Create an organization variable marked secret, then wire a Read variable node into the Password pin — a value typed directly into the node is stored verbatim with the pipeline.
Connections are pooled per execution: every email node in one run that names the same host, port, and username shares a single IMAP connection, so wiring one credentials node into several operations costs one login.
The address those connections come from changes over time, so a mail server that allowlists client IPs will eventually lock the pipeline out. See Outbound connections and IP addresses.
Pins
Input pins
| Pin | Type | Default | Notes |
|---|---|---|---|
| Host | string | — | IMAP hostname of the mail server, e.g. `imap.gmail.com` or `imap.one.com`. Must not be blank. |
| Port | integer | — | IMAP port. `0` (the default) selects the port implied by Encryption: 993 for `SSL_TLS`, 143 for `STARTTLS` and `NONE`. |
| Username | string | — | Mailbox login, usually the full email address. |
| Password | string | — | Mailbox password, or an app-specific password where the provider requires one (Gmail does). Wire this from a secret variable rather than typing it into the node — a value typed here is stored in the pipeline definition. |
| Encryption | Email encryption | SSL_TLS | `SSL_TLS` connects over TLS from the first byte (the modern default). `STARTTLS` connects in the clear and upgrades. `NONE` never encrypts — only appropriate for a server on a trusted network. |
Output pins
| Pin | Type | Notes |
|---|---|---|
| Credentials | Email credentials | Opaque credentials object. Wire it into Find emails, Get email, Find email folders, or Create email folder. Nodes that take an email or attachment object need no credentials — those objects carry their own server connection. |
Example
Read an order mailbox on a small hosting provider. Create a secret variable
orders-imap-password, then wire Read variable into this node’s Password,
set Host to imap.one.com, Username to orders@acme.com, Port to 0 and
Encryption to SSL_TLS. Feed the Credentials output into Find emails with
Folder INBOX and State UNREAD.