Connect any agent

Give every agent its own address to send and receive mail, with each reply checked for prompt injection. Hosted MCP, the CLI, SDKs and REST all work.

Chat and coding agents

  • Claude

    Add mails as a custom connector on claude.ai or Claude Desktop, then use it in any chat.

  • Claude Code

    Add the hosted server with one command and sign in from /mcp in any session.

  • Codex

    Add the server with codex mcp add; the CLI, IDE extension and app share it.

  • Cursor

    Add the server to mcp.json and Cursor’s Agent can send, reply and read threads.

  • GitHub Copilot

    Add mails in VS Code with MCP: Add Server, or give the cloud agent an API key.

  • Gemini

    Add it with gemini mcp add and sign in with /mcp auth; Code Assist reads it too.

  • Windsurf

    Add the server to mcp_config.json in Windsurf, now Devin Desktop, for Cascade.

  • Cline

    Add the server in the MCP Servers panel; with auto-approve off, Cline asks first.

  • Continue

    Add the server to config.yaml and use it in Agent mode in VS Code or JetBrains.

Apps built from a prompt

  • Lovable

    Connect mails as an MCP server while you build; your app keeps its key in secrets.

  • Replit

    Add the server once under Integrations and Replit Agent uses it in every project.

  • v0

    Pick MCPs in v0’s + menu to use mails while it builds; your app reads its key from env.

  • Bolt

    Add a custom connector, turn it on per project, and keep the API key in secrets.

Agent frameworks

  • OpenAI Agents SDK

    Attach the MCP server to an agent, or wrap the SDK in function tools you control.

  • Anthropic SDK

    Let Claude’s API call the hosted server through the MCP connector, or use the SDK.

  • Vercel AI SDK

    Load the server’s tools with createMCPClient, or wrap the SDK in tool() calls.

  • LangGraph

    Wrap the Python SDK as tools and bind them to any node in a StateGraph.

  • Pydantic AI

    Give a typed Python agent tools to send and read mail, or load the MCP server.

Hosted MCP

One server, every MCP client

Point any MCP client at https://api.mails.ai/mcp and sign in. Your agent can send, reply, read threads and check its reputation, with nothing to install.

# Add the hosted server, then
# sign in from /mcp
claude mcp add --transport http \
  mails https://api.mails.ai/mcp

Under the hood

What every agent gets

Most email assumes a person at a keyboard. Here every agent has its own address and reputation.

  • MCP server

    Send, reply, read threads and stage drafts from any MCP client, hosted or run with npx.

  • Inbound mail

    Replies reach the agent’s own address, are scanned for prompt injection, and arrive as webhooks or through the API.

  • CLI

    The API from your terminal: readable output for people and JSON for scripts and agents.

Frequently asked questions

How does an agent get its own email address?
Create an agent in the dashboard, with the API or from your MCP client, and it gets an address of its own: name@yourcompany.mails.ai. Mail sent to that address reaches that agent, and its sending reputation is its own.
What is the hosted MCP server, and how do I connect it?
It is mails.ai as MCP tools at https://api.mails.ai/mcp. Add that URL in your client and sign in with your mails.ai account; nothing runs on your machine. A client that cannot sign in can send an API key as a Bearer header instead, or run @mailsai/mcp-server with npx.
What can’t an app connected over MCP do?
An app you connect by signing in cannot create API keys or webhooks and cannot open billing. It can read your usage. Keys and webhooks stay with you in the dashboard.
Can my agent read the replies it gets?
Yes. Replies arrive on the agent’s own address with the quoted history stripped, an injection score and the sender’s reputation. Read them over MCP with mails_list_replies, through the API, or have each one pushed to your webhook.
What stops a malicious email from steering my agent?
Inbound mail is scanned for prompt injection before your agent reads it. High-risk mail is flagged as quarantined, and every event carries an injection_score your code can check before it acts.
How do I use mails.ai with Claude Code?
Run claude mcp add --transport http mails https://api.mails.ai/mcp, then type /mcp in a session and sign in. The guide also covers an API key and the npx server.
How do I use mails.ai with Cursor?
Add the hosted server to ~/.cursor/mcp.json, or to .cursor/mcp.json in one project; Cursor supports OAuth sign-in for servers that need it. Cursor’s Agent can then send, reply and read threads.
Can apps I build in Lovable, Replit, v0 or Bolt send email?
Yes. Each builder can use the MCP server while it builds, and the app itself calls the REST API with an API key kept in that builder’s secrets or environment variables. Each guide shows where that setting lives.
Is mails.ai free to try?
Yes. The Free plan covers 3,000 emails and 3,000 inbound replies a month with no card. Paid plans add more volume when your agents get busy.

“Replies come back as events with an injection score already on them. We deleted a whole layer of parsing code the week we switched, and we gate on the quarantine flag, so our agent never sees the ones that look like attacks.”

Tomás VargaStaff Engineer, Cinderjay

“Moving our agent onto our own domain was a few DNS records at the registrar. No nameserver move, and our existing mail kept working. Replies to the agent still come back to its inbox, threaded with the message they answer.”

Ishani VaidyaCTO, Sedgequay

“The 422 on cold outreach is the feature I didn’t know I wanted. An agent can’t talk itself into emailing strangers.”

Marcus FeldFounder, Marrowkite

“Our tests send to the test address and wait for the real reply, so the whole loop is covered before a customer ever writes in. It answers in about a second, which keeps the suite fast.”

Ana Lucía RíosEngineering Lead, Gorsefinch

“Adding the MCP server was one JSON block. Claude Code could send and read its own inbox a minute later.”

Jonah AbramsDeveloper, Wickerjay

“A reputation score per agent tells us exactly which one needs attention, instead of one number for the whole account. It comes from each agent’s own replies, bounces and complaints, and we read it from the API.”

Mei Lin ZhouOperations, Larchwhistle

“Sends and replies have separate allowances, so a busy inbox never eats our sending quota. Pricing was the easy part.”

Kwabena AdomakoFounder, Oxbowlark

“Half our agents are LangGraph in Python and half are Node. Both SDKs make the same calls, so the team doesn’t have to think about it.”

Sofia BrandtEngineer, Moss & Ladder

“Signed webhooks, retries with backoff and an event id to dedupe on. The boring plumbing, done properly.”

Nikhil BhonsleBackend Lead, Thimblecrow

“We signed up, made a key and sent our first message without talking to anyone, and the free tier never asked for a card. That’s how infrastructure should feel.”

Frieda WesselFounder, Ploverwick Studio

Give your first agent an inbox

Free covers 3,000 emails and 3,000 inbound replies a month, with no card. Upgrade when your agents get busy.

Get your API key