ZeptoMail Templates MCP
ZeptoMail Templates MCP
一个 MCP 服务器,让 AI 代理(opencode、Claude Desktop、Cursor 等)能够检查并管理你 Zoho 账户中所有 ZeptoMail Agent 的邮件模板。
它特意不发送邮件、不创建/删除 Agent、不暴露 Send Mail Token,也不管理域名。它只读取 Agent 列表并管理模板。
快速开始(本地,约 5 分钟)
1. 安装服务器
npm i -g zeptomail-mcp这会在你的 PATH 上提供 zeptomail-mcp 命令。如果你更愿意从仓库的本地克隆运行,可以跳过这一步(node /path/to/zeptomail-mcp/dist/src/server.js)。
2. 创建 Zoho OAuth 应用
打开 Zoho API 控制台。
创建一个基于服务器的应用:
客户端名称:
zeptomailmcp(不要用连字符——Zoho 会拒绝)主页 URL:任意,例如
https://github.com/P4rthPat3l/zeptomail-mcp授权重定向 URI:
http://localhost:4567/callback
记下客户端 ID 和客户端密钥。
Self Client 也可以。它没有重定向 URI 字段,因此不用第 2 步,而是使用它的 Generate Code 标签页(见下文 Self Client 设置)。
3. 获取刷新令牌
ZOHO_CLIENT_ID=<your-client-id> ZOHO_CLIENT_SECRET=<your-secret> zeptomail-mcp-login你的浏览器会打开 Zoho 的同意屏幕,请求作用域 Zeptomail.MailAgents.READ + Zeptomail.MailTemplates.All。批准后,脚本会打印一个刷新令牌。
如果你是从本地克隆而不是全局安装运行,同样的命令是
npm run login。
4. 配置你的 MCP 主机
你可以将 Zoho 凭据内联传入主机配置,或者从 .env 文件加载它们,这样配置文件本身就不含机密。两种方式都可行;任选其一。
选项 A — 从 .env 文件加载(推荐)
将机密放入 .env 文件(将其加入 gitignore——它是凭据):
# .env
ZOHO_CLIENT_ID=<your-client-id>
ZOHO_CLIENT_SECRET=<your-secret>
ZOHO_REFRESH_TOKEN=<your-refresh-token>
ZOHO_ACCOUNTS_URL=https://accounts.zoho.com然后用 --env-file 将服务器指向它。路径相对于主机的当前工作目录解析;如果不确定,请使用绝对路径。
opencode — opencode.json(或 .opencode/opencode.json):
{
"mcp": {
"zeptomail": {
"type": "local",
"command": ["zeptomail-mcp", "--env-file=/absolute/path/to/.env"],
"enabled": true
}
}
}Claude Desktop — claude_desktop_config.json:
{
"mcpServers": {
"zeptomail": {
"command": "zeptomail-mcp",
"args": ["--env-file=/absolute/path/to/.env"]
}
}
}选项 B — 在主机配置中内联
opencode — opencode.json(或 .opencode/opencode.json):
{
"mcp": {
"zeptomail": {
"type": "local",
"command": ["zeptomail-mcp"],
"enabled": true,
"environment": {
"ZOHO_CLIENT_ID": "...",
"ZOHO_CLIENT_SECRET": "...",
"ZOHO_REFRESH_TOKEN": "...",
"ZOHO_ACCOUNTS_URL": "https://accounts.zoho.com"
}
}
}
}Claude Desktop — claude_desktop_config.json:
{
"mcpServers": {
"zeptomail": {
"command": "zeptomail-mcp",
"env": {
"ZOHO_CLIENT_ID": "...",
"ZOHO_CLIENT_SECRET": "...",
"ZOHO_REFRESH_TOKEN": "...",
"ZOHO_ACCOUNTS_URL": "https://accounts.zoho.com"
}
}
}
}从本地克隆而不是全局安装运行
直接用 node 运行构建好的启动器。它解析 --env-file 的方式与全局 zeptomail-mcp 命令相同,因此该标志放在脚本之后:
opencode(选项 A env-file):
["node", "/absolute/path/to/zeptomail-mcp/dist/src/cli.js", "--env-file=/absolute/path/to/.env"]opencode(选项 B 内联):
["node", "/absolute/path/to/zeptomail-mcp/dist/src/cli.js"]+environment块Claude Desktop:
"command": "node","args": [".../dist/src/cli.js", "--env-file=..."](或仅[".../dist/src/cli.js"]加上env块)
5. 使用它
让你的代理调用这些工具:
“列出我的 ZeptoMail agents”
“找到别名为
team_invite的模板”“显示 sandbox agent 中的 OTP 模板”
Related MCP server: mcp-imap
Self Client 设置
Self Client 没有重定向 URI,因此 zeptomail-mcp-login 无法捕获其回调。请改为:
API 控制台 → Self Client → Generate Code。
作用域:
Zeptomail.MailAgents.READ,Zeptomail.MailTemplates.All→ CREATE。复制生成的代码并交换:
curl -X POST https://accounts.zoho.com/oauth/v2/token \
-d "code=<generated code>" \
-d "client_id=<client id>" \
-d "client_secret=<client secret>" \
-d "grant_type=authorization_code" \
-d "redirect_uri=https://api-console.zoho.com/"JSON 响应中包含 refresh_token。
工具
MCP 工具 | 用途 | 是否修改数据 |
| 列出可访问的 Agent 及确切的 Agent 键/别名 | 否 |
| 列出一个明确 Agent 中的模板 | 否 |
| 按名称/别名/主题搜索一个 Agent 或所有 Agent | 否 |
| 从一个 Agent 读取一个完整模板 | 否 |
| 在一个明确 Agent 中创建模板 | 是 |
| 部分更新,带 Agent + 过期写入保护 | 是 |
| 永久删除,带 Agent/名称/时间戳检查 | 是 |
写入工具需要两者:
服务器环境中设置
ZEPTOMAIL_MCP_ALLOW_WRITES=true。单个工具调用中设置
confirm=true。
每次写入还要求来自一次新的 zeptomail_list_agents 调用的确切 agentKey 和 expectedAgentName。更新/删除还要求当前的模板安全值(expectedModifiedTime、expectedTemplateName),因此过期的读取永远不会覆盖较新的编辑。
配置参考
变量 | 必需 | 默认 | 用途 |
| 是 | — | Zoho OAuth 应用客户端 ID |
| 是 | — | Zoho OAuth 应用客户端密钥 |
| 是 (stdio) | — | 长期令牌;服务器从中生成 1 小时访问令牌 |
| 否 |
| Zoho 数据中心( |
| 否 |
| ZeptoMail API 基础 URL |
| 否 |
| 设置为 |
| 否 | 所有 agent | 逗号分隔的 |
| 否 |
|
|
所有变量都可以作为进程环境变量(由主机配置设置)提供,或通过 --env-file=<path> 参数提供给服务器(见上文 配置你的 MCP 主机)。进程变量优先;文件只填充未设置的变量。
托管(远程)模式,使用 OAuth 2.0 + PKCE
对于共享/公共 MCP 端点,使用 ZEPTOMAIL_MCP_TRANSPORT=http 运行。服务器成为 OAuth 授权服务器,代理到 Zoho 作为上游授权服务器:
MCP client ⇄ this MCP server (OAuth AS + resource server) ⇄ Zoho (upstream AS) ⇄ ZeptoMail APIZEPTOMAIL_MCP_TRANSPORT=http \
ZEPTOMAIL_MCP_SERVER_URL=https://mcp.example.com \
ZEPTOMAIL_MCP_PORT=3006 \
ZEPTOMAIL_MCP_TOKEN_STORE=/var/lib/zeptomail-mcp/tokens.json \
node dist/src/server.js客户端在
/.well-known/oauth-protected-resource和/.well-known/oauth-authorization-server发现元数据,动态注册,并在浏览器中同意。服务器使用客户端的 PKCE S256 挑战和
access_type=offline重定向到 Zoho,使用服务器的 Zoho 客户端密钥交换代码,并存储一个每客户端 Zoho 刷新令牌,该令牌永远不会离开服务器。每个用户的工具操作他们自己的 ZeptoMail 账户。
主机配置(opencode):
{
"mcp": {
"zeptomail": {
"type": "remote",
"url": "https://mcp.example.com/mcp",
"oauth": {}
}
}
}托管模式的要求:HTTPS(SDK 拒绝非 HTTPS 的 issuer URL,localhost 除外)、在 API 控制台中注册的 Zoho 回调 URI(https://mcp.example.com/callback),以及持久化令牌存储。重启服务器会使已颁发的令牌失效——客户端会重新同意一次。
开发
npm install
npm run typecheck
npm test
npm run build安全说明
Agent 发现是只读的;没有用于创建 Agent、生成 API 密钥或访问 Send Mail Token 的工具。
MCP 从不发送邮件。
ZEPTOMAIL_MCP_ALLOWED_AGENT_KEYS限制了 MCP 可以接触的 Agent,即使 OAuth 账户可以看到更多。刷新令牌是长期凭据:将其保存在服务器端,像密码一样对待,如果泄露,请在 Zoho 控制台中撤销它。
Available Tools
8 toolszeptomail_create_templateCreate ZeptoMail templateA
Create a template in one explicit Agent. Requires agentKey plus expectedAgentName from a fresh zeptomail_list_agents call, server writes enabled, and confirm=true.
| Name | Required | Description | Default |
|---|---|---|---|
| confirm | No | ||
| subject | Yes | ||
| agentKey | Yes | Exact mailagent_key / Agent alias returned by zeptomail_list_agents. Never guess this value. | |
| htmlBody | No | ||
| textBody | No | ||
| templateName | Yes | ||
| templateAlias | No | ||
| expectedAgentName | Yes |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already convey that this is a write, non-idempotent, non-destructive operation. The description adds useful behavioral context beyond those hints: the agentKey must come from a fresh list call, server writes must be enabled, and confirm=true is required. No contradiction with annotations exists.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is a single dense sentence with no filler. It front-loads the action and immediately states the most important prerequisites and safety requirements. Every clause earns its place.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a mutating tool with no output schema and sparse parameter documentation, the description includes the critical preconditions to avoid mis-keying an Agent. However, it omits any guidance on the remaining parameters, expected response behavior, or duplicate-template handling, so it is only minimally complete.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is only 13%, so the description must compensate. It does helpfully explain agentKey, expectedAgentName, and confirm usage, but leaves templateName, subject, htmlBody, textBody, and templateAlias entirely to name-based inference. This is adequate but not thorough for an 8-parameter tool.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description states a clear verb-resource pair: create a template, and identifies the target scope as a specific ZeptoMail Agent. It is distinguishable from the list/get/update/delete siblings, though the phrase 'one explicit Agent' is slightly awkward and could be clearer.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description gives concrete invocation prerequisites: obtain agentKey and expectedAgentName from a fresh zeptomail_list_agents call, ensure server writes are enabled, and set confirm=true. It does not explicitly contrast this with zeptomail_update_template, but the prerequisites and confirmation gate provide strong usage direction.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
zeptomail_delete_templateDelete ZeptoMail templateADestructiveIdempotent
Permanently delete a template from one explicit Agent. Requires expectedAgentName, expectedTemplateName, and expectedModifiedTime from fresh reads. Requires writes enabled and confirm=true.
| Name | Required | Description | Default |
|---|---|---|---|
| confirm | No | ||
| agentKey | Yes | Exact mailagent_key / Agent alias returned by zeptomail_list_agents. Never guess this value. | |
| templateKey | Yes | ||
| expectedAgentName | Yes | ||
| expectedModifiedTime | Yes | ||
| expectedTemplateName | Yes |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already indicate destructive and non-read-only behavior. The description adds valuable context: deletion is permanent, expected values must come from fresh reads to prevent stale operations, and confirm=true is required. This goes meaningfully beyond the structured annotations.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Three short sentences with no filler. The destructive action, freshness requirement, and confirmation gate are all stated efficiently and front-loaded.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a destructive tool with six parameters and no output schema, the description covers the critical preconditions: fresh reads, writes enabled, confirm=true, and explicit agent scope. It doesn't describe behavior when confirm=false or when expected values mismatch, but the essentials for safe invocation are present.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema coverage is only 17%, so the description must compensate. It does explain that expectedAgentName, expectedTemplateName, and expectedModifiedTime must come from fresh reads, and that confirm must be true. However, templateKey is left undocumented in both schema and description, so coverage is not complete.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly identifies the action ('Permanently delete'), the resource ('a template'), and the scope ('from one explicit Agent'). This distinguishes it from listing, getting, creating, and updating templates, even without naming a sibling.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description gives clear usage context: the tool should only be used after fresh reads, with writes enabled, and with confirm=true. It doesn't explicitly contrast with sibling tools, but the destructive delete semantics and prerequisites make the appropriate use case clear.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
zeptomail_export_templatesExport all ZeptoMail templates from one AgentARead-onlyIdempotent
Fetch every full template (HTML body, text body, subject, alias, attachments metadata) from one explicit Agent and return them as a single JSON dump. Read-only. Use when the caller wants to back up an Agent templates to local files; the caller writes the files itself — this tool returns the data, it does not write to disk.
| Name | Required | Description | Default |
|---|---|---|---|
| agentKey | Yes | Exact mailagent_key / Agent alias returned by zeptomail_list_agents. Never guess this value. |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare readOnlyHint, idempotentHint, and destructiveHint, and the description reinforces these by saying 'Read-only' and adding valuable clarification that the tool does not write to disk—the caller handles file writing. This goes beyond the annotations by explicitly addressing side-effect expectations.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Two sentences deliver both the functional scope and the usage context with no wasted words. The key behavior is front-loaded, and the clarifying 'does not write to disk' earns its place in the same sentence.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a simple one-parameter, read-only export tool, the description covers what is returned, the scope, the caller's responsibility, and the primary use case. It does not describe output size or pagination, but the absence of an output schema and the straightforward nature of the operation make this adequate.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 100% and the sole parameter agentKey is already well documented as an exact mailagent_key/alias returned by zeptomail_list_agents. The description mentions 'one explicit Agent' but adds no new parameter-level meaning beyond the schema.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description uses a specific verb 'Fetch' with a precise resource: every full template from one explicit Agent, returned as a single JSON dump. It lists the exact fields included, which clearly distinguishes it from sibling list/find/get tools even without naming them.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description explicitly states the intended use case: backing up an Agent's templates to local files, and clarifies that the caller writes files while this tool only returns data. It does not explicitly name alternatives or say when not to use it, but the use-case framing provides clear directional guidance.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
zeptomail_find_templatesFind ZeptoMail templatesARead-onlyIdempotent
Search template name, alias and subject. Omit agentKey to search across every accessible Agent; provide agentKey to restrict the search to one Agent. Results always include the owning Agent.
| Name | Required | Description | Default |
|---|---|---|---|
| query | Yes | ||
| agentKey | No | Exact mailagent_key / Agent alias returned by zeptomail_list_agents. Never guess this value. | |
| maxResults | No |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare readOnlyHint, idempotentHint, and destructiveHint, so the safety profile is covered. The description adds useful behavioral context beyond that: the scope of the search with and without agentKey, and that results always include the owning Agent.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Three sentences, each earning its place: the search action, the scoping behavior, and the guaranteed result field. No redundancy or filler.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given the safe annotations and simple parameter set, the description covers the essential behavior: what is searched, how to scope the search, and what results always include. The absence of an output schema is partially mitigated by the 'owning Agent' note, though full result shape is still not described.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is only 33%, but the description compensates by explaining that query searches name, alias, and subject, and by clarifying agentKey's optionality. maxResults is not mentioned, though its schema defaults, min, and max make its behavior reasonably inferable.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description opens with a specific verb and resource: 'Search template name, alias and subject.' It clearly separates this search-oriented tool from sibling list/get/create/update/delete operations, and the agentKey scoping further sharpens its purpose.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description gives clear context for use: omit agentKey to search all accessible Agents, or provide it to restrict to one Agent. It does not explicitly name alternatives or state when not to use the tool, but the search scope guidance is straightforward.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
zeptomail_get_templateGet ZeptoMail templateARead-onlyIdempotent
Fetch one complete template from one explicit Agent by exact template key. Always call this before updating or deleting.
| Name | Required | Description | Default |
|---|---|---|---|
| agentKey | Yes | Exact mailagent_key / Agent alias returned by zeptomail_list_agents. Never guess this value. | |
| templateKey | Yes |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
The annotations already declare readOnlyHint, idempotentHint, and destructiveHint, covering the safety profile. The description adds a workflow rule ('before updating or deleting') and indicates the return is a 'complete template', but does not describe error conditions, auth, or pagination. This is adequate given annotation coverage, but not richly transparent.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Two sentences with no fluff. The primary action is front-loaded, and the workflow requirement is stated immediately after. Every word earns its place.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a simple read-only fetch with two required parameters and no output schema, the description covers what is returned ('complete template'), the key inputs, and when to call it. It does not enumerate the template fields or failure modes, but that level of detail is not essential for invoking it correctly.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The schema already gives a thorough description for agentKey, but templateKey is only a bare string. The description adds that both keys must be 'exact' and that agentKey comes from zeptomail_list_agents, but it does not say where templateKey originates (e.g., zeptomail_list_templates). With 50% schema coverage, the description partially compensates but leaves a meaningful gap.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description states a specific verb ('Fetch'), a clear resource ('one complete template'), and the selection criteria ('from one explicit Agent by exact template key'). It clearly distinguishes this tool from siblings like list_templates or find_templates by emphasizing exactness and a single full template, and from update/delete by explicitly positioning it as a prerequisite before those operations.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The directive 'Always call this before updating or deleting' provides explicit when-to-use guidance and places this tool in a workflow. It does not explicitly state when not to use it or name alternatives for searching/listing, but the context is clear enough for an agent to select this over mutation or search tools.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
zeptomail_list_agentsList ZeptoMail AgentsARead-onlyIdempotent
List accessible Agents in the ZeptoMail account. Returns each Agent name and exact mailagent_key (Agent alias). Always use the returned key for template tools; do not guess Agent identifiers.
| Name | Required | Description | Default |
|---|---|---|---|
No parameters | |||
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare this as read-only and idempotent. The description adds meaningful behavioral context by explaining that the tool returns exact mailagent_key values and warning against guessing identifiers, which goes beyond the annotation baseline.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is two sentences with no filler. It front-loads the primary action, then provides the essential output detail and a practical warning.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given that there is no output schema, the description adequately explains the return contents: Agent name and exact mailagent_key. It also explains why this matters for subsequent template tools, making it complete for a simple list operation.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The tool has zero parameters, so no parameter documentation is needed. The description correctly focuses on what the tool returns rather than input semantics.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description states a specific verb and resource: 'List accessible Agents in the ZeptoMail account.' It also clarifies the exact output value, the mailagent_key (Agent alias), and distinguishes this tool from the template-focused siblings.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description gives a clear usage directive: always use the returned key for template tools and do not guess Agent identifiers. It doesn't name explicit alternatives or exclusion conditions, but the context makes the intended workflow clear.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
zeptomail_list_templatesList ZeptoMail templatesARead-onlyIdempotent
List templates in one explicit ZeptoMail Agent. Use zeptomail_list_agents first and pass the exact returned mailagent_key.
| Name | Required | Description | Default |
|---|---|---|---|
| limit | No | ||
| offset | No | ||
| agentKey | Yes | Exact mailagent_key / Agent alias returned by zeptomail_list_agents. Never guess this value. |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already communicate readOnlyHint, idempotentHint, and destructiveHint, so the safety profile is covered. The description adds that the tool is scoped to one explicit Agent and depends on the prior agent lookup. It does not disclose pagination, ordering, or return format, but these are minor given the annotations.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is two tight sentences with no filler. The core action and the most important usage note are front-loaded, and every word contributes to correct invocation.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a read-only listing tool, the critical dependency on zeptomail_list_agents is explicit and the schema covers pagination bounds. The absence of an output schema means the return shape is not described, which is a minor gap but not a blocker since the resource and listing behavior are clear.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is only 33%, and the description mostly restates what the agentKey schema field already says: pass the exact mailagent_key returned by zeptomail_list_agents. It adds little meaning for limit and offset, which rely on names and numeric constraints rather than explanatory descriptions.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description states a specific verb and resource: 'List templates in one explicit ZeptoMail Agent.' It also conveys the agent-scoped nature, which separates it from listing agents or cross-agent template operations. However, it does not explicitly distinguish itself from sibling tools like zeptomail_find_templates or zeptomail_export_templates.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
It gives a clear prerequisite: use zeptomail_list_agents first and pass the exact returned mailagent_key. This is strong contextual guidance for when this tool should be called. It does not, however, state when to prefer alternatives such as zeptomail_find_templates instead.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
zeptomail_update_templateUpdate ZeptoMail templateADestructiveIdempotent
Partially update a template in one explicit Agent. Requires expectedAgentName and expectedModifiedTime from fresh reads so a stale or wrong-Agent edit is rejected. Requires writes enabled and confirm=true.
| Name | Required | Description | Default |
|---|---|---|---|
| confirm | No | ||
| subject | No | ||
| agentKey | Yes | Exact mailagent_key / Agent alias returned by zeptomail_list_agents. Never guess this value. | |
| htmlBody | No | ||
| textBody | No | ||
| templateKey | Yes | ||
| templateName | No | ||
| templateAlias | No | ||
| expectedAgentName | Yes | ||
| expectedModifiedTime | Yes |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already mark this as non-read-only and destructive. The description adds meaningful guardrail context beyond annotations: stale or wrong-Agent edits are rejected, confirmation is mandatory, and writes must be enabled. This goes beyond what the schema or annotations alone convey.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is two dense sentences with no filler. The core action is front-loaded, and the critical requirements are stated immediately after, making it easy for an agent to parse and act on.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a destructive, mutation-focused tool with 10 parameters and no output schema, the description covers the key invocation requirements: partial update, single Agent, fresh expected values, writes enabled, and confirmation. It does not describe return values or detailed error behavior, but the lack of an output schema lowers that burden.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is only 10%, so the description must compensate. It usefully explains expectedAgentName and expectedModifiedTime as optimistic-concurrency guards and mentions confirm=true, but it does not clarify the semantics of subject, htmlBody, textBody, templateName, or templateAlias beyond their raw string types.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description uses a specific verb and resource: 'Partially update a template in one explicit Agent.' It distinguishes this from create, delete, get, and export sibling tools by emphasizing partial update and single-Agent scope, so an agent can tell what the tool is for without opening the schema.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description clearly states preconditions: expectedAgentName and expectedModifiedTime must come from fresh reads, writes must be enabled, and confirm=true. It shows when to use the tool but does not explicitly contrast it with related tools or state when not to use it.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections.
8 tool updates
v0.3.7- First observed
zeptomail_create_template - First observed
zeptomail_delete_template - First observed
zeptomail_export_templates - First observed
zeptomail_find_templates - First observed
zeptomail_get_template - First observed
zeptomail_list_agents - First observed
zeptomail_list_templates - First observed
zeptomail_update_template
TDQS
Scored across 8 tools
Each tool targets a distinct resource and action: agents vs templates, and list/search/get/export/create/update/delete are clearly separated. Even the similar list_templates and find_templates are disambiguated by one being an enumeration and the other being a search across name, alias, and subject.
All tool names use the consistent zeptomail_ prefix followed by verb_noun snake_case, such as zeptomail_list_agents and zeptomail_update_template. The naming pattern is uniform and predictable across the entire set.
Eight tools is well-scoped for a ZeptoMail template management server. Each tool covers a necessary operation without redundancy or bloat, and the count is within the ideal range for a focused domain server.
The tool surface provides full lifecycle coverage for templates: list, search, get, export, create, update, and delete. Agent enumeration supports the required context for template operations, so agents can accomplish end-to-end template management without dead ends.
Maintenance
Related MCP Connectors
Governed email for agents: Gmail, M365 and IMAP; per-mailbox permissions, send allowlist, audit log
Email inboxes and calendars for AI agents: send, receive, search, draft and schedule.
Email inboxes and calendars for AI agents: send, receive, search, draft and schedule.
Let AI agents send email from your own Gmail, Microsoft 365 or SMTP inbox, with guardrails.
Related MCP Servers
- AlicenseNot gradedqualityBmaintenanceProvides full access to Zoho Mail accounts, enabling email search, read, send, reply, thread management, folder/label operations, and more via 14 tools.MIT
- AlicenseNot gradedqualityDmaintenanceEnables AI agents to interact with email accounts via IMAP and SMTP, supporting mailbox listing, email search, retrieval, sending, and management.MIT
- AlicenseNot gradedqualityDmaintenanceEnables AI assistants to read, send, search, reply to, and delete emails directly from a Zoho Mail account.7MIT
- FlicenseCqualityDmaintenanceEnables AI assistants to manage Zoho Mail accounts, including sending/receiving emails, folder and label management, organization administration, and productivity tools like tasks and notes.782-