AgentMail
Give an AI agent its own email inbox: create inboxes, read threads and send mail to anyone.
Send push, email and SMS and manage subscribers from an AI chat.
Opens Agent Studio, where connecting is one click. The connector URL below works in any MCP client.
Paste it into any MCP client. Setup docs
The OneSignal MCP server lets Claude, ChatGPT or any MCP client operate a customer-messaging platform in plain language — look up subscribers, build segments, manage templates, and send push notifications, email and SMS to real end users. Two of its tools export bulk subscriber data to CSV. Access is free with a OneSignal account and browser sign-in.
Verified connector
Listed by Anthropic as a partner connector in its Connectors Directory.
Connection checked by Agentman on .
Anthropic states this reflects the level of review a connector received, not a security audit.
Tool names from Anthropic's directory listing. This server requires sign-in, so we could not read tool descriptions or parameter schemas.
send_message reaches real end users. This connector is not capped below the send line. OneSignal marks the tool high-impact so compatible clients may prompt, but that gate is client-side; a client without high-impact confirmation has nothing standing between an agent and a live push, email or SMS.unsubscribe_email is a reversible status change.scopes_supported key is absent from the resource descriptor, so no client can distinguish or narrow read, export and send at connect time.inputSchema and no readOnlyHint or destructiveHint annotations were readable. Every capability claim here comes from OneSignal's documentation or Anthropic's listing, not from annotations we inspected.Yes. A tool named send_message dispatches push notifications, email and SMS to a segment or individual subscribers, and OneSignal documents it plainly rather than burying it. This is not a draft-only connector. OneSignal marks the tool high-impact so compatible clients may prompt for confirmation, and it advises reviewing every send request before approving it.
They export per-subscriber records to a downloadable URL, not into the chat. Subscription exports carry push tokens, email addresses or phone numbers in an identifier column, plus device, language, spend and tag data. Audience activity exports carry per-recipient sends, clicks, failures and unsubscribes for one message. Both links stay valid three days.
OneSignal's documentation lists 34 across nine categories; Anthropic's 2026-08-16 directory snapshot names 29. The directory list is a strict subset, missing app listing, two Live Activities tools and two custom-event tools. Neither source contradicts the other on any shared name, so the listing understates the surface rather than misdescribing it.
No delete tool appears in either list. All 34 documented tools create, read, update, export or send, and the closest thing to removal is unsubscribing an email address, which changes status rather than erasing a record. OneSignal's own product terms describe delete capability as a documented status, but the page they cite does not state it.
None are published. The RFC 9728 protected-resource descriptor at api.onesignal.com carries resource, authorization_servers and bearer_methods_supported, but no scopes_supported key at all, verified live on 2026-08-19. Over a surface that can send messages and export subscriber personal data, no wire metadata separates reading from exporting or sending.
No. OneSignal states the MCP server itself is free and that tool calls count against normal API usage limits. You need an account with access to the apps you want to manage and permission to complete the browser OAuth flow. OneSignal notes that during open beta, app access may need enabling before non-utility tools work.
No. OneSignal documents OAuth sign-in for every supported client, with no App ID or REST API key to paste. Directory and marketplace installs supply the server URL and client identity automatically, and OneSignal warns that filling the OAuth client fields manually causes the connection to fail because it registers your client itself.
documentation URL resolves into. The 34-tool capability tables across 9 categories, the send_message guardrails, setup for five client families, Connected apps revocation, the free-of-charge and no-API-key statements, and the open-beta limitation) · retrieved 2026-08-19POST /players/csv_export) · retrieved 2026-08-19POST /notifications/{message_id}/export_events) · retrieved 2026-08-19conflicting_aliases structure returned on a cross-user alias collision) · retrieved 2026-08-19send_after and delayed_option scheduling parameters on the endpoint beneath send_message) · retrieved 2026-08-19documentation.onesignal.com/robots.txt publishes Content-Signal: ai-train=yes, search=yes, ai-input=yes — all three axes affirmative (fetched 2026-08-19). It references a sitemap, which lists exactly one MCP page. The host serves an 84 KB llms.txt machine index at documentation.onesignal.com/llms.txt and clean Markdown when .md is appended to any documentation URL — which is how every page above was read · retrieved 2026-08-19initialize call to https://api.onesignal.com/mcp/oauth returns HTTP 401 with a plain-text body naming an API key header, and no www-authenticate header. No tool was called and no authentication was attempted · retrieved 2026-08-19scopes_supported). Root and path-append forms return byte-identical 200 bodies; the path-insert form under /mcp/oauth/ returns 401 · retrieved 2026-08-19dashboard.onesignal.com/oauth/authorize, authorization_code and refresh_token grants, PKCE S256, client_secret_post and none, and a present registration_endpoint). The OpenID Connect discovery path returns 400 from a generic API error handler · retrieved 2026-08-19auth_required posture) · retrieved 2026-08-16Connect OneSignal once and your agents call these tools on their own: on a schedule, in a workflow, with nobody at the keyboard.