Mails.ai
for Cline
Built in
Email tools inside Cline
Cline asks before each mails tool runs, unless you auto-approve it, and shows every call and its result in the chat.
Email reply@test.mails.ai from the hello agent when the build passes, then confirm it was answered
- tool mails_sendagent: "hello"to: "reply@test.mails.ai"subject: "Build passed"body_text: "The build passed."
{ "id": "msg_01K…", "status": "delivered", … }
- tool mails_list_repliesagent: "hello"
{ "data": [{ "type": "reply.received", "data": { "subject": "Re: Build passed", … } }] }
Sent from the hello agent, and the reply is in the same thread.
Setup
Add mails to Cline
Open Cline → MCP Servers icon → Configure tab → Configure MCP Servers. Add to mcpServers and save the file.
{
"mcpServers": {
"mails": {
"command": "npx",
"args": ["-y", "@mailsai/mcp-server"],
"env": {
"MAILS_API_KEY": "mk_live_..."
}
}
}
}We auto-approve the read tools in Cline and keep mails_send on approval.
Hosted or local
Or add the hosted server
In Cline’s MCP Servers panel, open Remote Servers, name it mails, enter https://api.mails.ai/mcp and choose Streamable HTTP. In the JSON, keep "type": "streamableHttp", or Cline uses the older SSE transport. The MCP server page has the rest.
{
"mcpServers": {
"mails": {
"type": "streamableHttp",
"url": "https://api.mails.ai/mcp",
"headers": {
"Authorization": "Bearer mk_live_..."
},
"disabled": false,
"autoApprove": []
}
}
}Know-how
Teach Cline about email
Three open-source skills teach Cline to send, receive and safely act on email. The command asks which to add.
npx skills add mailsai/skills -a clineIn action
See the skills
in action
With the skills added, Cline checks a message before it answers it, and replies in the same thread.
This guide adds email to Cline, the open-source coding agent for VS Code, JetBrains and the terminal. You’ll paste a JSON config into Cline’s MCP Settings panel — that’s it. After that, your agent can send emails, read replies, and check thread history as part of any task. Cline asks before each mails_* call unless you turn on MCP auto-approve.
Cline is the open-source autonomous coding agent for VS Code, JetBrains and the terminal. Add the mails.ai MCP server in Cline’s MCP Settings panel and your in-IDE agent gets the same tools (including mails_send, mails_reply, mails_list_threads, mails_list_replies, mails_get_reputation) that Claude Code and Cursor get — auto-discovered and ready to use.
Why Cline + mails.ai
Cline’s autonomous-loop architecture (read → plan → act → verify) maps cleanly onto agent-mail workflows. Common patterns:
- Code review → email reviewer. Cline reviews a PR, summarizes findings, and uses
mails_sendto email the author with the writeup. - Long-running refactor → status email. Cline works through a long refactor and emails a digest to the team when blocked or done.
- Issue triage → reply automation. Cline reads incoming bug reports via
mails_list_messages, classifies them via the typed-eventintentfield (classify_inboundon, paid plans), and replies with a triage summary or escalation. - Documentation update → reviewer notification. After landing docs changes, Cline emails the docs maintainers via
mails_sendfor a sanity check.
Setup
- Get an API key. Sign in at
app.mails.ai/api-keysand mint one — self-serve, free tier, no card. - Open Cline’s MCP Settings. In the Cline panel header, click the MCP Servers icon. Open the Configure tab and click “Configure MCP Servers” to open the JSON settings.
- Add the snippet from the install card above. Replace
mk_live_...with your key. Save the file. - Verify. The MCP Settings panel should show
mailsunder configured servers with its tools listed.
First commands to test
# In a new Cline task, in Act mode
> What mails_* tools are available to me?
# Send a test (auto-approve off: Cline asks before it sends)
> Send myself a test hello via mails_send, subject "Cline test".
# Verify the send
> List the most recent threads.Common patterns
- Approval on for production sends. For any task that might send to customer addresses, leave MCP auto-approve off, so Cline asks before every
mails_send. - Per-workspace key scoping. Use a workspace-specific MCP config (in a project .cline/mcp.json, documented for the CLI) so different projects use different agent-bound mails.ai keys.
- Suppress before send. If your agent might send to addresses that have unsubscribed in your own system, filter them out first.
mails_check_suppressionshows whether mails.ai already suppresses an address, and a live send to one fails loud (422) rather than silently bouncing. - Read injection_score on every reply handler. The Cline agent reading inbound is exactly the prompt-injection RCE class — check
event.injection_scoreat the top of any handler that consumes inbound.
Security considerations
- Per-key scope. One agent-bound mails.ai key (
agent_id) per Cline agent identity. Each project can carry its own.cline/mcp.json(documented for the CLI); rotate keys per-agent without affecting others. - Approval discipline. Cline’s autonomous loop is powerful; combined with mails_send, it can fire emails the user did not explicitly approve. Leave MCP auto-approve off, so Cline asks before every mails_send.
- Checkpoints don’t roll back sends. Cline’s checkpoint system snapshots the workspace; it does not undo sent emails. Treat sends as irrevocable.
Compare against the Claude Code integration for the same MCP setup with a different config path, or read the MCP-native email post for the broader distribution thesis.
Read next: Mails.ai for Claude Code and Mails.ai for Cursor.
Questions developers ask after wiring this up.
Does mails.ai work in Cline’s plan-mode and act-mode?
Cline supports per-server toggles. Can I disable mails_* for some tasks?
What about Cline’s checkpoint feature — does it interact with sent emails?
Does this work with Cline’s CLI / non-VS-Code use?
“Replies come back as events with an injection score already on them. We deleted a whole layer of parsing code the week we switched, and we gate on the quarantine flag, so our agent never sees the ones that look like attacks.”
“Moving our agent onto our own domain was a few DNS records at the registrar. No nameserver move, and our existing mail kept working. Replies to the agent still come back to its inbox, threaded with the message they answer.”
“The 422 on cold outreach is the feature I didn’t know I wanted. An agent can’t talk itself into emailing strangers.”
“Our tests send to the test address and wait for the real reply, so the whole loop is covered before a customer ever writes in. It answers in about a second, which keeps the suite fast.”
“Adding the MCP server was one JSON block. Claude Code could send and read its own inbox a minute later.”
“A reputation score per agent tells us exactly which one needs attention, instead of one number for the whole account. It comes from each agent’s own replies, bounces and complaints, and we read it from the API.”
“Sends and replies have separate allowances, so a busy inbox never eats our sending quota. Pricing was the easy part.”
“Half our agents are LangGraph in Python and half are Node. Both SDKs make the same calls, so the team doesn’t have to think about it.”
“Signed webhooks, retries with backoff and an event id to dedupe on. The boring plumbing, done properly.”
“We signed up, made a key and sent our first message without talking to anyone, and the free tier never asked for a card. That’s how infrastructure should feel.”
Give your first agent an inbox
Free covers 3,000 emails and 3,000 inbound replies a month, with no card. Upgrade when your agents get busy.
Get your API key