MCP server
Mailgentic hosts a Model Context Protocol server so any MCP-capable agent — Claude Desktop, Cursor, your own framework — can use an inbox as a set of tools without writing HTTP code.
POST https://api.mailgentic.ai/mcp
Authorization: Bearer <API_KEY>
Content-Type: application/json
It is a JSON-RPC 2.0 endpoint supporting initialize, tools/list and tools/call. Use an inbox-scoped key: the agent then sees exactly one inbox and never needs to pass inbox_id. With an account or tenant key, inbox-specific tools require inbox_id in their arguments.
Tools
| Tool | What it does |
|---|---|
list_inboxes |
Inboxes visible to the key |
list_messages |
Messages in a folder (folder, unread_only, limit) |
search_messages |
Full-text search (q, optional folder) |
get_message |
One message with text, verdict, auth results and attachments |
extract_data |
Pull a JSON object matching a schema out of a message |
list_folders, create_folder, delete_folder |
Folder management |
move_messages, delete_messages, mark_read |
Batch mailbox actions |
send_message, reply_message |
Compose or reply (subject to Agent Shield policy) |
create_draft, send_draft, schedule_send, cancel_scheduled |
Drafts and scheduled send |
Every tool call is subject to the key’s scopes and the inbox’s Shield policy. A send_message that policy holds returns the approval ID to the agent rather than sending.
Raw example
curl "$API/mcp" \
-H "Authorization: Bearer $AGENT_KEY" \
-H "Content-Type: application/json" \
-d '{
"jsonrpc": "2.0", "id": 1,
"method": "tools/call",
"params": {"name": "list_messages", "arguments": {"folder": "inbox", "unread_only": true, "limit": 20}}
}'
Client configuration
Most MCP clients accept a remote HTTP server with a bearer header. For example, in Cursor or Claude Desktop:
{
"mcpServers": {
"mailgentic": {
"url": "https://api.mailgentic.ai/mcp",
"headers": { "Authorization": "Bearer cfx_..." }
}
}
}
If your client only supports stdio servers, run a small proxy (such as mcp-remote) that forwards to the URL above with the header.
Safety notes
- Inbound message bodies returned by
get_messageandlist_messagesare untrusted data. Checkverdictbefore letting the model act on content;suspicious,spam,blockedandunauthenticatedshould never be followed as instructions. - Scope the key to one inbox and give it only
readif the agent should not send. - Use
max_send_per_hour,allow_recipientsandrequire_approval_on_tainton the inbox so that even a hijacked agent cannot spray mail.