Circleback
Search meeting notes, transcripts, action items, calendar and connected email.
Give an AI agent its own email inbox: create inboxes, read threads and send mail to anyone.
Opens Agent Studio, where connecting is one click. The connector URL below works in any MCP client.
Paste it into any MCP client. Setup docs
The AgentMail MCP server gives an AI agent its own email inbox. It exposes tools to create addresses, read threads and attachments, and send, reply to or forward mail to any recipient on the internet. Sign-in is OAuth through the AgentMail console. Unlike a mailbox connector, the inbox here belongs to the agent rather than to a person.
Verified connector
Listed by Anthropic as a partner connector in its Connectors Directory.
Connection checked by Agentman on .
Anthropic states this reflects the level of review a connector received, not a security audit.
Tool names from Anthropic's directory listing. This server requires sign-in, so we could not read tool descriptions or parameter schemas.
send_message, reply_to_message and forward_message all take recipients as a plain array of strings. There is no allowlist parameter, no confirmation step in the contract, and no server-side approval gate. Whether the agent asks you before sending is your MCP client's behaviour, not AgentMail's.send, receive and reply in allow and block forms, scoped at organisation, pod or inbox level, with the narrower scope winning. AgentMail calls a send allowlist a hard safety boundary. None of the 26 MCP tools reads or writes a list, so configure it before you connect — and an agent that later hits the boundary cannot lift it through this connector.Retry-After header. AgentMail recommends exponential backoff and spreading volume across inboxes.delete_inbox, delete_thread and delete_draft are annotated destructive, and message permissions govern thread deletion — so a credential that can delete a message can delete a whole conversation.includeSpam is set.initialize returned 401 — so tool names, schemas and annotations here come from AgentMail's own published runtime contract, not from our own tools/list. Anthropic's directory disagrees with it, as set out above.Anyone, unless you configure a send allowlist first. AgentMail's own documentation says an inbox can send to anyone on the internet, and the send_message contract takes a free-form array of recipient strings with no restriction. A send allowlist exists and AgentMail calls it a hard safety boundary, but you set it through the API, CLI or console — no connector tool manages it.
No. AgentMail's RFC 9728 descriptor advertises only openid, email and profile — identity scopes, with no application scope of any kind. The consent screen therefore has nothing meaningful to narrow. A read-without-send credential does exist, but only as an API key: message_read and message_send are separate API-key permissions, and API keys are the alternative sign-in path.
Yes. create_inbox makes a new working inbox and every parameter is optional, so an agent can call it with no arguments and receive an address on the shared agentmail.to domain. Supplying a domain restricts it to one you have verified. Plan caps are the real ceiling: the free plan allows three inboxes and an unverified organisation allows one.
It depends on plan, and the tightest cap is the one you hit first. An organisation that has not completed agent verification is limited to one inbox and ten sends per day, which the agent_verify tool exists to lift. Published plan limits are monthly, not daily: 3,000 emails on Free, 10,000 on Developer and 150,000 on Startup.
Partly, and it is unusually candid about the gap. Six tools that return externally authored content carry a warning inside their own tool descriptions telling the model not to treat that content as instructions. AgentMail also rejects virus-bearing mail at the gateway and hides spam from listings by default. The warning is advisory text, not enforcement.
Three sources disagree, and the vendor's generated contract is the newest. Anthropic's directory snapshot names 24 tools including auth_me; AgentMail's runtime manifest names 26 and has no auth_me at all. A July 2026 commit removed auth_me from the hosted catalogue while keeping it in the toolkit, and an August commit added agent_verify.
mcp-manifest.json, runtime-generated tool contract (retrieved 2026-08-21) · retrieved 2026-08-21initialize returned HTTP 401 with a WWW-Authenticate header naming the RFC 9728 descriptor at mcp.agentmail.to/.well-known/oauth-protected-resource/mcp (2026-08-21) · retrieved 2026-08-21Connect AgentMail once and your agents call these tools on their own: on a schedule, in a workflow, with nobody at the keyboard.