Email for AI agents

An inbox for your agent.
On terms you set.

Connect Claude Code, Codex, Cursor or any MCP client to a real mailbox. It reads, replies and sends from your addresses, within the access you approve, for as long as you allow.

No key to paste. The client signs in through your browser, and you approve it like any other app.

An agent finds a refund request in [email protected], answers it in the thread and files it under refunds.

One address to paste.
Any MCP client.

The server speaks MCP over HTTP. Add its address to your client, sign in once in the browser and approve what it may reach.

claude mcp add --transport http openemail https://api.openemail.uk/mcp

Run it in a terminal, then type /mcp in Claude Code to sign in.

[mcp_servers.openemail]url = "https://api.openemail.uk/mcp"

Add it to ~/.codex/config.toml, then run codex mcp login openemail.

{ "mcpServers": { "openemail": { "url": "https://api.openemail.uk/mcp" } } }

Add it to ~/.cursor/mcp.json for every project, or to .cursor/mcp.json for one.

{ "servers": { "openemail": { "type": "http", "url": "https://api.openemail.uk/mcp" } } }

Add it to .vscode/mcp.json in your workspace.

{ "mcpServers": { "openemail": { "serverUrl": "https://api.openemail.uk/mcp" } } }

Add it to ~/.codeium/windsurf/mcp_config.json.

https://api.openemail.uk/mcp

Open Settings, then Connectors, choose Add custom connector and paste this address.

Or let the agent set itself up

Paste this into any agent that can run a terminal command. It reads a guide written for agents, then tells you the one step that needs you.

Prompt for your agent

Run `npx @openemail/cli agents` and read the guide it prints. Then tell me what I need to do to sign you in to my OpenEmail mailbox, and wait for my go-ahead before you send anything.

You approve it.
Like any other app.

When the client signs in, you pick the workspace, what it may do, which addresses it reaches and for how long. Account → Connected apps changes or removes it later.

Your role is the ceiling
An app never holds a permission you lack, and when your role loses one, the app loses it on its next call.
Some things are never granted
No app can create or rotate API keys, open billing or manage the workspace, whatever you tick.
Risky changes wait for you
Adding a webhook, writing a rule, changing roles or removing a domain needs your verification code, or a 60-minute allowance you switch on for that app.

Whole jobs.
Call by call.

Every step below is a real tool, command or event. Pick a job to follow it through.

A disposable inbox takes the verification mail, and the agent reads the code back itself. No account and no key.

  1. Command lineopenemail temp new --ttl 30

    Gets an address that takes mail for the next 30 minutes

  2. Browser

    Fills in the sign-up form at acme.com with it

  3. Command lineopenemail temp watch --first

    Waits for the first message to land

  4. Command lineopenemail temp read thr_9e3b7c1a

    Reads the code out of the message

  5. Browser

    Enters the code and finishes signing up

Inboxk7x2m9qfd4pa@shared domain

Acme

Your Acme code is 847 293

Your endpoint hears about new mail as it lands, and the agent answers inside the thread from the address the mail came to.

  1. Webhookemail.received

    New mail arrives for [email protected]

  2. MCPgetThread

    Reads the whole thread, oldest message first

  3. MCPreplyToEmail

    Answers in the thread, from [email protected]

  4. MCPmodifyLabels

    Files it under refunds

Ada Park

My parcel arrived damaged. Can I get a refund for order 4821?

[email protected]

Sorry about the parcel. Your refund for order 4821 is on its way.

The agent schedules a reminder for next week and cancels it if the reply comes first. Sent twice with the same key, it is scheduled once.

  1. Command lineopenemail send --to [email protected] … --at 7d --idempotency-key quote-311

    Schedules a follow-up for seven days from now

  2. Webhookemail.replied

    Noor replies before the week is out

  3. Command lineopenemail emails cancel msg_4b7e05d3

    Cancels the follow-up before it leaves

[email protected]Cancelled

Just checking you saw the quote I sent last week.

Noor Haddad

Thanks, we are going ahead with the quote.

A person writes and publishes the template. The agent only fills in its fields, and a missing field is refused rather than sent blank.

  1. You

    Writes and publishes the welcome template

  2. MCPpreviewTemplate

    Renders it with Ada's details and reads the result

  3. MCPsendWithTemplate

    Sends it to [email protected]

  4. Webhookemail.delivered

    Hears that the receiving server accepted it

Welcome, version 3, published

[email protected]

Welcome to Acme, Ada. Your team plan is ready.

Agents slip.
The mailbox catches it.

Agents retry and misread. These are the parts that keep one bad call small.

API and command line

POST /emails Idempotency-Key: reply:thr_7c1e4a90

  1. Attempt 1msg_4b7e05d3862c1f0a44b19e2cSent
  2. Attempt 2msg_4b7e05d3862c1f0a44b19e2cReplayed

Same key, same result. A retry never sends twice.

1Emails sent: 1

MCP

tools/call sendEmail

  1. Attempt 1msg_4b7e05d3862c1f0a44b19e2cSent
  2. Attempt 2msg_91c2f7a04d3b6e8c15a0f2d7Sent

An MCP send leaves at once, and a repeat sends again.

2Emails sent: 2

Dry runs first
Add --dry-run to any command and it prints the request it would make instead of making it.
Deletes ask first
A destructive command run without a person refuses, unless the agent was told to pass --yes.
Forged mail stays out
Mail its own sending domain disowns goes to Spam, away from the inbox your agent reads.
Keys leave a trail
Every call made with an API key is logged with its path, status and timing, and the log is kept.

128 tools.
Each named for what it does.

An app gets only the tools its approval covers, so one held to reading has no sending tool at all.

  • getThreadSummary
  • composeEmail
  • sendEmail
  • replyToEmail
  • listThreads
  • getThread
  • markThreadsRead
  • markThreadsUnread
  • modifyLabels
  • getCurrentDate
  • getUserLabels
  • createLabel
  • updateLabel
  • deleteLabel
  • listContacts
  • getContact
  • createContact
  • updateContact
  • deleteContact
  • listPeople
  • saveContact
  • deleteContacts
  • blockContact
  • unblockContact
  • listContactThreads
  • getContactActivity
  • listAudiences
  • getAudience
  • createAudience
  • updateAudience
  • deleteAudience
  • listAudienceContacts
  • addContactToAudience
  • removeContactFromAudience
  • addContactsToAudience
  • removeContactsFromAudience
  • importContactsToAudience
  • emptyAudience
  • setContactAudiences
  • getAudienceGrowth
  • previewAudienceSend
  • sendToAudience
  • listBroadcasts
  • getBroadcast
  • cancelBroadcast
  • listBroadcastRecipients
  • getBroadcastRecipient
  • getBroadcastStats
  • listTemplates
  • getTemplate
  • getTemplateVersion
  • previewTemplate
  • createTemplate
  • updateTemplate
  • publishTemplate
  • duplicateTemplate
  • replaceTemplateContent
  • restoreTemplateVersion
  • deleteTemplateVersion
  • deleteTemplate
  • listTemplateStarters
  • getTemplateStarter
  • getTemplateAnalytics
  • listTemplateSends
  • sendWithTemplate
  • listFiles
  • getFile
  • deleteFile
  • deleteFiles
  • uploadFile
  • getFileStats
  • createFileLink
  • revokeFileLink
  • listRules
  • getRule
  • createRule
  • testRule
  • setRuleEnabled
  • getEmailTracking
  • getFileDownloads
  • listTrackedEmails
  • getEngagementStats
  • previewTranslation
  • listTranslationLanguages
  • listSuppressions
  • addSuppression
  • removeSuppression
  • getConnections
  • getActiveConnection
  • setActiveConnection
  • getLabel
  • whoAmI
  • listRoles
  • listWorkspaceMembers
  • listInvitations
  • revokeInvitation
  • resendInvitation
  • listDomains
  • getDomain
  • addDomain
  • verifyDomain
  • setDomainCatchAll
  • removeDomain
  • listDomainAddresses
  • addDomainAddress
  • updateDomainAddress
  • removeDomainAddress
  • getDomainLogo
  • setDomainLogo
  • removeDomainLogo
  • setDomainLogoCertificate
  • removeDomainLogoCertificate
  • setDomainDmarcPolicy
  • setAddressPhoto
  • removeAddressPhoto
  • listApiKeys
  • listWebhookEvents
  • listWebhooks
  • rotateApiKey
  • setApiKeyEnabled
  • revokeApiKey
  • setApiKeySendScope
  • listApiKeyRequests
  • listApiKeyActivity
  • listWebhookDeliveries
  • getWebhookDelivery
  • replayWebhookDelivery
  • listWebhookActivity

Asks for your code first

What is missing

Four things.
Know them before you connect.

Keys cannot open MCP
The MCP server takes an approved sign-in, never an API key. A script holding a key uses the command line or the API instead.
MCP sends leave at once
An email sent through MCP goes immediately, and sending it twice sends it twice. For an undo window or a safe retry, send through the command line or the API.
A person signs in once
The browser sign-in, and the code for a risky change, need you. After that the agent works alone until its access runs out.
No test mode
Every key delivers for real. Try a change with --dry-run first, or send to a disposable inbox.

Asked first.
Answered plainly.

Who it is for

One mailbox.
Four ways in.

Individuals

A free address at openemail.uk, with the client behind it.

acme.comacme.devstudio.acme.com
hello@acme.comdelivered
billing@acme.comdelivered
oct-2026-signup@acme.comdelivered
anything-at-all@acme.comdelivered
Businesses

Addresses for everyone, members never counted as seats.

SSarahAAliJJamieNNadia
No seat added. The bill does not move.
Developers

The same mailbox over an API, an SDK, a CLI and MCP.

/threads?query=invoice
{ "threads": 12 }
Same mailbox, whether a person or a program is holding it.
AI agents

An inbox your agent can work, with access you approve.

listThreads(folder: "inbox", query: "is:unread")
3 unread
It reads and sends mail for [email protected] only.

Give it an address.
Watch it work.

MCP, the API and the command line come with every plan, the free one included. Connect a client and approve exactly what it reaches.

Your inbox,
on your own terms.

Email infrastructure for businesses, AI, agents and personal email. Built for scale, privacy and control. Everything email should have had from day one.

OpenEmail

Email infrastructure for businesses, AI, agents and personal email. Built for scale, privacy and control. Everything email should have had from day one.

© 2026 OpenEmail. All rights reserved.