AgentMail
Give an AI agent its own email inbox: create inboxes, read threads and send mail to anyone.
Give an AI agent its own email address, phone number and iMessage line.
Opens Agent Studio, where connecting is one click. The connector URL below works in any MCP client.
Paste it into any MCP client. Setup docs
The Inkbox MCP server connects Claude, ChatGPT or any MCP client to Inkbox, which gives an AI agent its own communication identity — a real email address, phone number and iMessage line. Fifty-nine tools send mail and texts, read call transcripts, and manage contacts. No tool places a call: the Claude endpoint withholds voice deliberately.
Verified connector
Listed by Anthropic as a partner connector in its Connectors Directory.
Connection checked by Agentman on .
Anthropic states this reflects the level of review a connector received, not a security audit.
Tool names from Anthropic's directory listing. This server requires sign-in, so we could not read tool descriptions or parameter schemas.
inkbox.full_service, over all 59 tools. Consent cannot be narrowed to reads. Inkbox's own documentation describes it as full-service access until revoked.inkbox_email_forward moves a message whose contents are not visible in the tool call.inkbox_email_thread_delete, which removes a whole correspondence.remote segments are the other person./anthropic path, not of Inkbox. The generic and OpenAI endpoints are documented as serving what Inkbox calls the same catalog. Register the Claude path.409 customer_campaign_required. Only the consent *reads* appear in the tool list.It can send both, but only when you ask it to. Four tools transmit to outside parties: email send, reply, reply-all and forward, plus SMS and iMessage sends. Anthropic's directory record states plainly that Inkbox does not watch your inbox in the background or send anything on its own. Every send is a tool call your client can hold for approval.
No, and that is a deliberate cap. Inkbox's REST API documents a place-call operation that dials a number and can run a hosted voice agent on the line. Inkbox's own MCP documentation states the Claude endpoint excludes hosted voice tools — placing and ending calls, call settings and voice-agent configuration. Call history and transcripts stay readable. No tool in the 59 dials anyone.
Verbatim text of phone conversations. Inkbox documents transcripts as generated automatically during calls, returned as ordered segments tagged with the speaking party — local, remote or system — and a millisecond offset. The remote segments are the other person's words. Access is scoped to the connected identity; Inkbox states transcripts for any other identity's calls return a masked 404.
Not in the documentation we read. Inkbox documents SMS consent in detail — a per-recipient opt-in registry updated automatically from STOP and START keywords — but we found no equivalent guidance on call-recording notice or announcement anywhere in its published docs. We state that as an observed gap. This page gives no legal advice and asserts nothing about what any law requires.
Twenty-five contacts per call, returned inline. Inkbox's OpenAPI spec caps the export request at 25 contact identifiers, minimum one, and the response carries the vCard text directly in the JSON body alongside a contact count. There is no download URL and no signed link. The vCard payload is capped at one million characters.
No. The OAuth metadata advertises exactly one scope, inkbox.full_service, and it does not divide by verb. The same grant that reaches call transcripts also reaches the sends, the deletes and the contact export. Inkbox's own documentation describes the grant as full-service access to the selected identity until you revoke it. Per-call approval in your client is the only remaining control.
An Inkbox account and an identity to connect. Inkbox operates a free plan alongside paid tiers, and its documentation gates specific features rather than API access as a whole — outbound mail carries a footer on the free plan, and SMS consent writes require your own registered 10DLC campaign. We could not verify from public docs whether any plan floor applies to MCP itself.
documentation URL in Anthropic's directory) · retrieved 2026-08-19llms.txt — https://inkbox.ai/llms.txt (fetched 2026-08-19; identity-layer positioning, capability list covering email, phone, iMessage and vault, and the pointers to the single-file docs export, sitemap and OpenAPI spec used throughout this page) · retrieved 2026-08-19X-API-Key alternative; the prompt list that conflicts with the directory snapshot) · retrieved 2026-08-19place-call operation, client_websocket and hosted_agent modes, the voice-agent reason brief, and voicemail detection — all absent from this connector) · retrieved 2026-08-19party of local/remote/system and millisecond offsets, identity-scoped access masked as 404, and the deprecated number-scoped route) · retrieved 2026-08-19.vcf download route) · retrieved 2026-08-19opted_in/opted_out states, and the customer_campaign_required 409 gating consent writes to customer-managed 10DLC campaigns) · retrieved 2026-08-19vcard-export request cap of 25 contact identifiers, the inline vcard response field capped at 1,000,000 characters, and the absence of any contact-restore operation) · retrieved 2026-08-19robots.txt — https://inkbox.ai/robots.txt (fetched 2026-08-19; User-agent: * with Allow: / and Disallow: /api/ and /rpc/, plus per-crawler blocks repeating the same rules. No Content-Signal directives were present in the file or the response headers) · retrieved 2026-08-19www-authenticate header. HTTP 200, application/json, 194 bytes, resource https://inkbox.ai/mcp/anthropic, authorization server https://inkbox.ai/mcp/oauth. The root form returns HTTP 200 JSON of 184 bytes echoing resource https://inkbox.ai/mcp — a genuinely distinct document, confirming a real per-client family. The path-insert form returns HTTP 404 with a zero-byte body and no content type) · retrieved 2026-08-19https://inkbox.ai/mcp/oauth, authorization_code and refresh_token grants, PKCE S256, a registration_endpoint, resource_indicators_supported true, client_id_metadata_document_supported true, and scopes_supported of exactly ["inkbox.full_service"]) · retrieved 2026-08-19https://inkbox.ai/mcp/anthropic returned HTTP 401 with body {"error":"authorization_required"} and header www-authenticate: Bearer resource_metadata="https://inkbox.ai/.well-known/oauth-protected-resource/mcp/anthropic". No tool was ever called and no authentication was attempted · retrieved 2026-08-19inkbox_, prompt_names an empty list, no permissions field on the record, author Inkbox, partner tier, added 2026-08-05. Source for the identity-scoping statement, the no-background-watching statement, and the explicit denial that the connector can place, answer or end calls or generate audio) · retrieved 2026-08-16Connect Inkbox once and your agents call these tools on their own: on a schedule, in a workflow, with nobody at the keyboard.