Select a message to read.
Session: not signed in.
Remote images in message bodies are blocked by CSP (img-src 'self' data: only; no https:). There is no toggle that can enable them under the current policy.
Paste a read-scoped API token to browse mail. Optionally add a send-scoped token (or a dual-cap identity token with read+send) to compose and reply. A dual-cap token may be pasted once in the read field; send falls back to it when the send field is empty. Tokens stay in this browser tab only (sessionStorage), never sent anywhere but the API you name below.