Mailbuttons MCP Server
OfficialMailbuttons MCP server
Governed email for AI agents, over the Model Context Protocol. Give an agent a scoped mailbox where the server enforces the guardrails, not the prompt: sandbox-by-default inboxes, a policy gate on every send, and a tamper-evident audit log. External sending and scope changes are human-approved, never granted by the agent itself.
Registry:
com.mailbuttons/mcp-serverPlatform: mailbuttons.com · agent front door: mbag.ai
Use it
Hosted (recommended) — a streamable-HTTP endpoint served by the platform:
https://mailbuttons.com/api/v1/mcp/rpc
Authorization: Bearer <your Mailbuttons MCP token> # mb_sandbox_... (or mb_prod_...)Local (stdio) — run the npm package and let your agent launch it:
{
"mcpServers": {
"mailbuttons": {
"command": "npx",
"args": ["-y", "@mailbuttons/mcp-server"],
"env": { "MAILBUTTONS_API_KEY": "mb_sandbox_..." }
}
}
}Get a scoped token from the dashboard or POST /api/v1/mcp/sandbox-inboxes.
Sandbox tokens can never send externally until a human promotes them.
Related MCP server: RadMail MCP
What the server enforces
Inbound — a per-mailbox sender policy, fail-closed: mail from strangers bounces by default, so nobody can prompt-inject your agent just by emailing it.
Outbound — a recipient blocklist the agent can read but not change; a blocked send returns a normal
{"status":"blocked"}result, not an error.Caps + audit — per-account send caps and a hash-chained audit log that records refusals too.
Escalation — sending externally or widening scope is propose-only; a named human approves. The agent cannot approve its own request.
Install as an agent skill
This repo ships a root SKILL.md, so any skills-aware agent can add it:
npx skills add mailbuttons/mcp-serverDocs
Agent signup (for agents): https://mbag.ai/docs/agent-signup.md
Trust model: https://mbag.ai/docs/trust-model.md
OpenAPI: https://mbag.ai/api/openapi.json
Framework recipes:
references/(Claude Agent SDK, LangChain, plain SDK)
Mailbuttons is a trading name of Code Cutter Limited (UK, no. 08453060). MIT licensed.
This server cannot be deployed
Maintenance
Related MCP Connectors
Let AI agents send email from your own Gmail, Microsoft 365 or SMTP inbox, with guardrails.
1Authenticated email gateway for AI agents — per-agent inboxes, HITL approval, SPF/DKIM verified.
Authenticated email gateway for AI agents — per-agent inboxes, HITL approval, SPF/DKIM verified.
- PO6 MailboxOAuthcom.po6
Give AI agents secure access to your email via private aliases with dedicated mailbox storage.
Related MCP Servers
- AlicenseNot gradedqualityCmaintenanceEnables AI agents to read, triage, respond to, and calendar-manage Gmail with a production-grade MCP control plane and human-in-the-loop safety.3MIT
- AlicenseAqualityFmaintenanceAn email operating system for AI agents that provides safe triage, drafting, and searching of emails with unbypassable hard-stops on money, banking changes, first-contact senders, and prompt injection.12102 npmMIT
- AlicenseAqualityBmaintenanceGives AI agents their own email address with inbound parsing, classification, extraction, and prompt injection screening, plus tools to manage mailboxes, send/receive emails, and handle draft approval workflows.1456 npmMIT
- AlicenseAqualityBmaintenanceEnables AI agents to send, receive, and reply to email through dedicated thread-aware mailboxes, with sandbox testing and compatibility across MCP clients.966 npmMIT