All solutions
Solutions

Email API for AI Agents: Send, Receive, and Reply in Six Lines

One API key, both directions: send transactional mail, receive replies as JSON events, scan every inbound for prompt injection.

An email API for AI agents is the interface between your autonomous agent and real-world email: it sends transactional messages from the agent’s own authenticated address, delivers replies as structured JSON events with prompt-injection scoring, and tracks reputation per agent — not per account. Mails.ai is built for exactly this pattern — six lines to send, a webhook to receive, and an injection score on every inbound within your plan’s limits.

One API key, both directions

Most email APIs stop at sending. Your agent fires a POST, the message goes out, done. The gap appears the moment a customer replies: now you need inbound parsing, threading, and a way to route the reply back to the agent that sent the original. An email API for AI agents wraps both sides into one integration:

import { createClient } from "@mailsai/sdk";
const mails = createClient({ apiKey: process.env.MAILS_API_KEY });

// Send — one call, no SMTP to configure.
await mails.messages.send({
  from: "hello",
  to: "customer@example.com",
  subject: "Your refund #812 is confirmed",
  body_text: "We processed your refund for $49. Reply with any questions.",
});

// Receive — replies arrive as typed, injection-scanned events.
const events = await mails.events.list({
  event_type: "message.received",
  limit: 10,
});
for (const e of events.data) {
  console.log(e.data.extracted_text); // clean reply, quoted history stripped
  console.log(e.injection_score);     // 0.0–1.0; quarantine at 0.5+
  console.log(e.thread_id);           // stable across the conversation
}

The same flow in Python

The Python SDK mirrors the TypeScript one. Install with pip install mailsai and the same six-line pattern works:

from mailsai import MailsClient

mails = MailsClient(api_key=os.environ["MAILS_API_KEY"])

mails.messages.send(
    agent="hello",
    to="customer@example.com",
    subject="Your refund #812 is confirmed",
    body_text="We processed your refund for $49. Reply with any questions.",
)

events = mails.events.list(event_type="message.received", limit=10)
for e in events.data:
    if e.injection_score is not None and e.injection_score >= 0.5:
        flag_for_review(e)  # hold for a person
        continue
    # safe — route to the agent's reply logic
    handle_reply(e)

Per-agent identity and reputation

Each agent you create gets its own email address and its own reputation score. Bounce rate, complaint rate, and engagement metrics are tracked per agent — so one agent that drifts above 0.3 % complaints is suspended automatically before the damage propagates to the rest of your account. For the full identity model, see email for AI agents.

Inbound: events, not mailboxes

The inbound email API turns receiving into an event stream. Each reply to your agent is parsed into structured JSON — sender, subject, clean text body, thread ID — scanned for prompt injection, and delivered to your webhook or polled via the REST API. No IMAP, no MIME, no OAuth refresh tokens.

Transactional sends, agent-shaped

The sends your agents trigger — OTPs, receipts, confirmations, status updates — ride a clean rail because cold outreach is refused at the API. Each send is authenticated end to end (SPF, DKIM, DMARC). For the transactional-specific details, see the transactional email API for AI agents page.

MCP, CLI, and every framework

Beyond the SDKs, the MCP server drops the email API into any MCP-compatible agent: Claude Code, Cursor, Cline, Continue, Windsurf. The CLI sends from a terminal. Framework-specific guides cover the OpenAI Agents SDK, Anthropic SDK, Vercel AI SDK, LangGraph, and Pydantic AI. Read the full email API comparison for 2026 to see how Mails.ai stacks up.

Pricing

The free tier covers 3,000 emails and 3,000 inbound replies a month with one agent — no card required. Pro is $20 a month for 50,000 emails and 50,000 inbound replies across five agents, and Scale is $99 for 250,000 emails and 500,000 inbound replies with unlimited agents. Injection scanning is included on every inbound; intent/entity classification of first-contact mail is available at no extra charge on paid plans. Yearly billing is two months free. See pricing for the full breakdown, or custom domain email for AI agents for branding your agents under your own domain.

Frequently asked questions

What makes an email API for AI agents different from a traditional email API?
A traditional email API — SendGrid, Postmark, Resend — is built for outbound sends triggered by a human application: password resets, receipts, marketing blasts. An email API for AI agents adds bidirectional messaging (the agent sends and receives under one key), per-agent identity and reputation, structured reply events instead of raw MIME, and prompt-injection scanning on every inbound. The agent acts autonomously, so the API must enforce policy and score trust on its behalf.
Which languages and frameworks does the API support?
First-party SDKs ship for TypeScript (npm @mailsai/sdk) and Python (pip mailsai). The REST API works from any language that can POST JSON. For tighter integration, the MCP server (npx @mailsai/mcp-server) drops into Claude Code, Cursor, Cline, Continue, Windsurf, and other MCP-compatible agent IDEs. Framework-specific guides cover the OpenAI Agents SDK, Anthropic SDK, Vercel AI SDK, LangGraph, and Pydantic AI.
How does prompt-injection scanning work?
Every inbound message within your plan’s limits is scanned across six categories — boundary manipulation, system-prompt override, data exfiltration, role hijacking, tool invocation, and jailbreaks — before it reaches your agent code. The injection_score (0–1) arrives on the event payload alongside the parsed body, so your agent branches on a number rather than trusting the LLM to notice an attack embedded in the same prompt as the attack.
Can each agent have its own email address and reputation?
Yes. Each agent you create gets its own address — on the shared domain it receives at agent.yourworkspace@in.mails.ai and sends from agent.yourworkspace@send.mails.ai, and with a custom domain it sends as agent@yourdomain.com. Reputation signals (bounce rate, complaint rate, engagement) are tracked per agent, so one misbehaving agent cannot drag down the rest.
What does an email API for AI agents cost?
The free tier covers 3,000 emails and 3,000 inbound replies per month with one agent — no credit card required. Pro is $20/month for 50,000 emails and 50,000 inbound replies across five agents. Scale is $99/month for 250,000 emails, 500,000 inbound replies, and unlimited agents. Yearly billing saves two months on both paid plans.
Is cold outreach allowed?
No — cold email is prohibited by the acceptable-use policy and blocked at the API. That boundary keeps the shared sending infrastructure clean, which is why transactional mail from agents here inboxes reliably.

Explore the product

Give your first agent an inbox

Free covers 3,000 emails and 3,000 inbound replies a month, with no card. Upgrade when your agents get busy.

Get your API key