AgentMail
Give an AI agent its own email inbox: create inboxes, read threads and send mail to anyone.
Search meeting notes, transcripts, action items, calendar and connected email.
Opens Agent Studio, where connecting is one click. The connector URL below works in any MCP client.
Paste it into any MCP client. Setup docs
The Circleback MCP server connects a Circleback meeting archive to Claude, ChatGPT, Claude Code and any MCP-compatible agent. It searches meeting notes, opens verbatim transcripts with speaker labels, and reaches action items, calendar events, people, companies and connected email. Every documented tool reads. Sign-in is OAuth with dynamic client registration.
Verified connector
Listed by Anthropic as a partner connector in its Connectors Directory.
Connection checked by Agentman on .
Anthropic states this reflects the level of review a connector received, not a security audit.
Tool names from Anthropic's directory listing. This server requires sign-in, so we could not read tool descriptions or parameter schemas.
scopes_supported as the single value user, observed live on 2026-08-22. There is no scope for meetings versus email, and none for reading titles versus reading verbatim transcripts. The only place to narrow access is your MCP client's own tool toggles.readOnlyHint and destructiveHint are unknown for all twelve tools.FindDomains is unexplained. Anthropic's directory lists it; no Circleback surface names it. Our reading is that it renamed to FindCompanies, but the endpoint would not enumerate to us and we cannot rule out a tool that exists and is undocumented.privateNotes reaches the agent is unresolved. The field exists on the meeting record and Circleback publishes no MCP response schema.circleback.ai/docs/mcp returns 307 to Circleback's Intercom-hosted support centre. The redirect target is the real documentation and is cited below.Twelve by Circleback's own support article, against nine in Anthropic's directory snapshot. The three the snapshot omits are SearchActionItems, FindCompanies and ListTags. Circleback's CLI documents the same twelve capabilities command for command, so the vendor list is corroborated twice. Build allowlists from Circleback's article, not from the directory listing.
No. All twelve documented tools read. Every name begins with Search, Read, Get, Find or List, and Circleback's article describes each as finding or retrieving. Circleback's REST API does expose delete for meetings, action items and tags, plus update for meetings — none of those verbs appears among the MCP tools, so the connector reaches a strictly narrower surface than the API key does.
Yes, verbatim and speaker-attributed. GetTranscriptsForMeetings returns full transcripts with speaker labels and timestamps, and SearchTranscripts finds where something was said across the whole archive. Circleback's transcript schema pairs each line with a named speaker. Everyone else in the room consented to Circleback recording, not necessarily to an AI agent replaying what they said.
Exactly one, called user, and it draws no line anywhere. Circleback's RFC 9728 descriptor and its authorization server metadata both advertise scopes_supported as that single value, confirmed live on 2026-08-22. So the consent screen cannot grant meeting titles without also granting verbatim transcripts and connected email. Access narrowing has to happen client-side, by disabling tools.
Yes, if you connected a mailbox to Circleback. SearchEmails queries connected Gmail or Outlook accounts by keyword, sender, recipient or date range. Circleback states it reads email on demand rather than storing copies, so the tool reaches your live mailbox at query time. Disconnecting the account from Settings, Connected accounts is what removes that reach.
It depends which capture mode you use. The Circleback bot joins Zoom, Google Meet, Microsoft Teams and Webex as a visible participant, which is the notice. The desktop and mobile apps record locally with nothing joining the call, and Circleback presents that as the option for when you would prefer the bot not appear. The MCP connector adds no consent check either way.
No. Sharing exists in Circleback, and an automation can share every matching meeting with a whole workspace, but no documented MCP tool triggers one. Automations run on meeting completion, not on tool calls, and none of the twelve tools creates, edits or runs one. The connector reads what automations already produced; it cannot start an outbound path.
The underlying meeting record carries a privateNotes field alongside shared notes, and ReadMeetings is documented as returning detailed meeting information including notes. Circleback does not publish the MCP tool's response schema, so we could not confirm whether private notes cross that boundary. Treat it as unresolved and check one meeting yourself before granting broad access.
circleback.ai/docs/mcp 307-redirects here. · retrieved 2026-08-22https://circleback.ai/.well-known/oauth-protected-resource/api/mcp, with authorization server metadata at https://circleback.ai/.well-known/oauth-authorization-server (2026-08-22). circleback.ai/robots.txt permits the paths fetched and carries no Content-Signal line. · retrieved 2026-08-22Connect Circleback once and your agents call these tools on their own: on a schedule, in a workflow, with nobody at the keyboard.