← All servers

mailbox

warnings

mailbox.bot

Physical mail API for AI agents. Send letters, certified mail. Sandbox + live keys via MCP.

https://mailbox.bot/api/mcpWebsiteOAuthMCP 2025-11-25v1.0.1last checked 8 Oct 2026spoke MCP on 100% of 90 checks (30 days)initialize in 528 ms

Will my client connect?

Decided from what the probe found at the endpoint, and from what each client's own documentation says it can complete. Every row carries the day that documentation was read.

✕Claude CodeNot supported

The authorization server advertises no S256 challenge method, which MCP's authorization spec requires — no compliant client has a method in common with it.

Claude Code docs · read on 2026-08-30

✕Claude (claude.ai & Desktop)Not supported

The authorization server advertises no S256 challenge method, which MCP's authorization spec requires — no compliant client has a method in common with it.

Claude (claude.ai & Desktop) docs · read on 2026-08-30

✕ChatGPTNot supported

The authorization server advertises no S256 challenge method, which MCP's authorization spec requires — no compliant client has a method in common with it.

ChatGPT docs · read on 2026-08-30

✕CursorNot supported

The authorization server advertises no S256 challenge method, which MCP's authorization spec requires — no compliant client has a method in common with it.

Cursor docs · read on 2026-08-30

✕VS Code (Copilot)Not supported

The authorization server advertises no S256 challenge method, which MCP's authorization spec requires — no compliant client has a method in common with it.

VS Code (Copilot) docs · read on 2026-08-30

How to authenticate

Checked against the endpoint by our probe on 8 Oct 2026. These are the capabilities the server advertises, not a prediction about any particular client.

Scheme
OAuth
Issuer
https://mailbox.bot
Dynamic client registration
✕Not advertised

A client that cannot register itself needs credentials issued out of band before it can begin the flow.

Client ID Metadata Document
✕Not advertised
PKCE
✕None advertised

MCP requires S256; a client that implements only that has no method in common with this server.

Scopes
agent.inbox.read, agent.inbox.report, agent.inbox.propose, agent.read, agent.write, mailbox.read, mailbox.write, inbound.item.read, inbound.item.action, inbound.item.scan.read, inbound.read, message.send, webhook.read, webhook.manage, billing.read, mail.send, document.read
Protected-resource metadata
✓Published (RFC 9728)
Anonymous access
Handshake succeeds; 45 tools listable
Credentials demanded in prose
✕send_outbound_mail, list_agent_inbox, get_agent_inbox_context, get_agent_inbox_sources, list_agent_inbox_scans, get_agent_inbox_scan, get_agent_inbox_activity, report_agent_inbox_outcome, get_agent_inbox_handling, propose_agent_inbox_handling, seed_agent_inbox_sandbox, create_webhook_endpoint, list_inbound_items, get_inbound_item_sources

These tools are listed anonymously and their own descriptions ask for an account or key, but no challenge is issued — so a client has nothing to act on and the refusal arrives as a tool error.

What the probe found

warningTools needing credentials are listed without a challenge

14 of the 45 tools listed anonymously say in their own descriptions that they need an account or a key (send_outbound_mail, list_agent_inbox, get_agent_inbox_context, get_agent_inbox_sources, list_agent_inbox_scans, get_agent_inbox_scan, get_agent_inbox_activity, report_agent_inbox_outcome, get_agent_inbox_handling, propose_agent_inbox_handling, seed_agent_inbox_sandbox, create_webhook_endpoint, list_inbound_items, get_inbound_item_sources), but the endpoint issued no WWW-Authenticate challenge. The requirement is stated only in prose, so a call reaches the tool and comes back as a tool error instead of an authorization step.

No CORS headers for browser-based clients

A cross-origin preflight came back without Access-Control-Allow-Origin, so the endpoint is reachable from native clients only — code running in a web page is stopped by the browser before a request is ever sent.

45 tools usable without signing in

The server exposes a public surface before authorization: get_mailbox, get_usage, list_inbound_forwarding_addresses, list_inbound_mail, get_inbound_mail, list_postal_threads, get_postal_thread, get_mailbox_md, propose_mailbox_md_edit, send_facility_message, list_facility_conversations, get_facility_messages, update_webhook, send_outbound_mail, list_outbound_mail, get_outbound_mail, cancel_outbound_mail, create_test_outbound_mail, advance_test_outbound_mail, list_agent_inbox, get_agent_inbox_context, get_agent_inbox_sources, list_agent_inbox_scans, get_agent_inbox_scan, get_agent_inbox_activity, report_agent_inbox_outcome, get_agent_inbox_handling, propose_agent_inbox_handling, seed_agent_inbox_sandbox, list_webhook_endpoints, create_webhook_endpoint, update_webhook_endpoint, test_webhook_endpoint, test_webhook_endpoint_with_sample, rotate_webhook_endpoint_secret, list_webhook_deliveries, replay_webhook_delivery, list_inbound_items, get_inbound_item_sources, search_inbound_items, get_inbound_item, get_inbound_pages, quote_inbound_forward, request_inbound_action, get_inbound_activity.

Tools

advance_test_outbound_mailcancel_outbound_mailcreate_test_outbound_mailcreate_webhook_endpointget_agent_inbox_activityget_agent_inbox_contextget_agent_inbox_handlingget_agent_inbox_scanget_agent_inbox_sourcesget_facility_messagesget_inbound_activityget_inbound_itemget_inbound_item_sourcesget_inbound_mailget_inbound_pagesget_mailboxget_mailbox_mdget_outbound_mailget_postal_threadget_usagelist_agent_inboxlist_agent_inbox_scanslist_facility_conversationslist_inbound_forwarding_addresseslist_inbound_itemslist_inbound_maillist_outbound_maillist_postal_threadslist_webhook_deliverieslist_webhook_endpointspropose_agent_inbox_handlingpropose_mailbox_md_editquote_inbound_forwardreplay_webhook_deliveryreport_agent_inbox_outcomerequest_inbound_actionrotate_webhook_endpoint_secretsearch_inbound_itemsseed_agent_inbox_sandboxsend_facility_messagesend_outbound_mailtest_webhook_endpointtest_webhook_endpoint_with_sampleupdate_webhookupdate_webhook_endpoint

Contract history

29 Sep 2026v1.0.11 compatible7 cosmeticinstructions rewritten

Instructions rewritten: get_inbound_activity, get_inbound_item, get_inbound_pages, get_mailbox, list_inbound_items, quote_inbound_forward, request_inbound_action, search_inbound_items. The description an agent follows changed; the callable contract may not have.

29 Sep 2026v1.0.125 cosmetic
27 Sep 2026v1.0.11 compatible
24 Sep 2026v1.0.12 compatibleinstructions rewritten

Instructions rewritten: get_inbound_item, get_inbound_pages. The description an agent follows changed; the callable contract may not have.

24 Sep 2026v1.0.13 compatible5 cosmeticinstructions rewritten

Instructions rewritten: get_agent_inbox_scan, get_inbound_item, list_agent_inbox, list_agent_inbox_scans, request_inbound_action. The description an agent follows changed; the callable contract may not have.

23 Sep 2026v1.0.16 breaking1 compatible2 cosmeticinstructions rewritten

Breaking: create_webhook_endpoint, list_webhook_deliveries, list_webhook_endpoints, rotate_webhook_endpoint_secret, update_webhook_endpoint, verify_webhook_endpoint

Instructions rewritten: create_webhook_endpoint, list_webhook_deliveries, list_webhook_endpoints, replay_webhook_delivery, rotate_webhook_endpoint_secret, test_webhook_endpoint, update_webhook_endpoint. The description an agent follows changed; the callable contract may not have.

22 Sep 2026v1.0.12 breaking

Breaking: get_inbound_item, request_inbound_action

20 Sep 2026v1.0.13 compatible11 cosmeticinstructions rewritten

Instructions rewritten: get_agent_inbox_activity, get_agent_inbox_context, get_agent_inbox_handling, get_agent_inbox_scan, get_agent_inbox_sources, get_inbound_item_sources, list_agent_inbox, list_agent_inbox_scans, propose_agent_inbox_handling, report_agent_inbox_outcome, seed_agent_inbox_sandbox. The description an agent follows changed; the callable contract may not have.

20 Sep 2026v1.0.14 cosmeticinstructions rewritten

Instructions rewritten: get_agent_inbox_sources, get_inbound_item_sources, list_agent_inbox, list_inbound_items. The description an agent follows changed; the callable contract may not have.

19 Sep 2026v1.0.12 compatible
19 Sep 2026v1.0.15 compatible1 cosmeticinstructions rewritten

Instructions rewritten: get_agent_inbox_context, list_agent_inbox. The description an agent follows changed; the callable contract may not have.

18 Sep 2026v1.0.11 breaking

Breaking: get_agent_inbox_context

15 Sep 2026v1.0.115 compatible
11 Sep 2026v1.0.13 cosmeticinstructions rewritten

Instructions rewritten: get_facility_messages, list_facility_conversations, send_facility_message. The description an agent follows changed; the callable contract may not have.

8 Sep 2026v1.0.12 cosmeticinstructions rewritten

Instructions rewritten: create_test_outbound_mail, send_outbound_mail. The description an agent follows changed; the callable contract may not have.

24 Aug 2026v1.0.1first recorded contract

Watch this server

Save its public contract as a baseline and manage breaking-change email alerts.

Set up a watch

Own this server?

Sign in to claim this listing by proving control of its host.

Status badge

Status for a README, from the last probe — cached an hour, so up to seven hours behind the endpoint. Links back to this page.

MCP status badge for mailbox
[![MCP status](https://mcpi.app/servers/mailbox/badge.svg)](https://mcpi.app/servers/mailbox)