Email for AI agents
An inbox for your agent.
On terms you set.
Connect Claude Code, Codex, Cursor or any MCP client to a real mailbox. It reads, replies and sends from your addresses, within the access you approve, for as long as you allow.
No key to paste. The client signs in through your browser, and you approve it like any other app.
One address to paste.
Any MCP client.
The server speaks MCP over HTTP. Add its address to your client, sign in once in the browser and approve what it may reach.
Or let the agent set itself up
Paste this into any agent that can run a terminal command. It reads a guide written for agents, then tells you the one step that needs you.
Run `npx @openemail/cli agents` and read the guide it prints. Then tell me what I need to do to sign you in to my OpenEmail mailbox, and wait for my go-ahead before you send anything.
You approve it.
Like any other app.
When the client signs in, you pick the workspace, what it may do, which addresses it reaches and for how long. Account → Connected apps changes or removes it later.
- Your role is the ceiling
- An app never holds a permission you lack, and when your role loses one, the app loses it on its next call.
- Some things are never granted
- No app can create or rotate API keys, open billing or manage the workspace, whatever you tick.
- Risky changes wait for you
- Adding a webhook, writing a rule, changing roles or removing a domain needs your verification code, or a 60-minute allowance you switch on for that app.
Whole jobs.
Call by call.
Every step below is a real tool, command or event. Pick a job to follow it through.
Agents slip.
The mailbox catches it.
Agents retry and misread. These are the parts that keep one bad call small.
API and command line
POST /emails Idempotency-Key: reply:thr_7c1e4a90
- Attempt 1msg_4b7e05d3862c1f0a44b19e2cSent
- Attempt 2msg_4b7e05d3862c1f0a44b19e2cReplayed
Same key, same result. A retry never sends twice.
1Emails sent: 1
MCP
tools/call sendEmail
- Attempt 1msg_4b7e05d3862c1f0a44b19e2cSent
- Attempt 2msg_91c2f7a04d3b6e8c15a0f2d7Sent
An MCP send leaves at once, and a repeat sends again.
2Emails sent: 2
- Dry runs first
- Add --dry-run to any command and it prints the request it would make instead of making it.
- Deletes ask first
- A destructive command run without a person refuses, unless the agent was told to pass --yes.
- Forged mail stays out
- Mail its own sending domain disowns goes to Spam, away from the inbox your agent reads.
- Keys leave a trail
- Every call made with an API key is logged with its path, status and timing, and the log is kept.
128 tools.
Each named for what it does.
An app gets only the tools its approval covers, so one held to reading has no sending tool at all.
- getThreadSummary
- composeEmail
- sendEmail
- replyToEmail
- listThreads
- getThread
- markThreadsRead
- markThreadsUnread
- modifyLabels
- getCurrentDate
- getUserLabels
- createLabel
- updateLabel
- deleteLabel
- listContacts
- getContact
- createContact
- updateContact
- deleteContact
- listPeople
- saveContact
- deleteContacts
- blockContact
- unblockContact
- listContactThreads
- getContactActivity
- listAudiences
- getAudience
- createAudience
- updateAudience
- deleteAudience
- listAudienceContacts
- addContactToAudience
- removeContactFromAudience
- addContactsToAudience
- removeContactsFromAudience
- importContactsToAudience
- emptyAudience
- setContactAudiences
- getAudienceGrowth
- previewAudienceSend
- sendToAudience
- listBroadcasts
- getBroadcast
- cancelBroadcast
- listBroadcastRecipients
- getBroadcastRecipient
- getBroadcastStats
- listTemplates
- getTemplate
- getTemplateVersion
- previewTemplate
- createTemplate
- updateTemplate
- publishTemplate
- duplicateTemplate
- replaceTemplateContent
- restoreTemplateVersion
- deleteTemplateVersion
- deleteTemplate
- listTemplateStarters
- getTemplateStarter
- getTemplateAnalytics
- listTemplateSends
- sendWithTemplate
- listFiles
- getFile
- deleteFile
- deleteFiles
- uploadFile
- getFileStats
- createFileLink
- revokeFileLink
- listRules
- getRule
- createRule
- testRule
- setRuleEnabled
- getEmailTracking
- getFileDownloads
- listTrackedEmails
- getEngagementStats
- previewTranslation
- listTranslationLanguages
- listSuppressions
- addSuppression
- removeSuppression
- getConnections
- getActiveConnection
- setActiveConnection
- getLabel
- whoAmI
- listRoles
- listWorkspaceMembers
- listInvitations
- revokeInvitation
- resendInvitation
- listDomains
- getDomain
- addDomain
- verifyDomain
- setDomainCatchAll
- removeDomain
- listDomainAddresses
- addDomainAddress
- updateDomainAddress
- removeDomainAddress
- getDomainLogo
- setDomainLogo
- removeDomainLogo
- setDomainLogoCertificate
- removeDomainLogoCertificate
- setDomainDmarcPolicy
- setAddressPhoto
- removeAddressPhoto
- listApiKeys
- listWebhookEvents
- listWebhooks
- rotateApiKey
- setApiKeyEnabled
- revokeApiKey
- setApiKeySendScope
- listApiKeyRequests
- listApiKeyActivity
- listWebhookDeliveries
- getWebhookDelivery
- replayWebhookDelivery
- listWebhookActivity
Asks for your code first
What is missing
Four things.
Know them before you connect.
- Keys cannot open MCP
- The MCP server takes an approved sign-in, never an API key. A script holding a key uses the command line or the API instead.
- MCP sends leave at once
- An email sent through MCP goes immediately, and sending it twice sends it twice. For an undo window or a safe retry, send through the command line or the API.
- A person signs in once
- The browser sign-in, and the code for a risky change, need you. After that the agent works alone until its access runs out.
- No test mode
- Every key delivers for real. Try a change with --dry-run first, or send to a disposable inbox.
Asked first.
Answered plainly.
Who it is for
One mailbox.
Four ways in.
A free address at openemail.uk, with the client behind it.
The same mailbox over an API, an SDK, a CLI and MCP.
An inbox your agent can work, with access you approve.
Give it an address.
Watch it work.
MCP, the API and the command line come with every plan, the free one included. Connect a client and approve exactly what it reaches.