Agentmail MCP

Live

OAUTH 2.0

COMMUNICATION

Communication

Agentmail MCP gives agents their own inboxes: send, receive, and manage email threads and attachments with vaulted credentials.

  • Per-user credentials: each call uses the actual user's token, never a shared bot.
  • Encrypted per-tenant vault: AES-256, resolved at request time, never in LLM context.
  • Scoped before every call: pre-call scope check, 90-day SIEM-exportable audit chain.
Agentmail MCP
agent · Acme Q3
Run
Create Draft in Agentmail MCP
S
agentmailmcp_create_draft
85ms
Agentmail MCP agent
Create a draft email in an inbox, optionally scheduling it to send at a future time..
Sources: Agentmail MCP
agentmailmcpmcp
1 tool call
18:29
Message Claude...

Agentmail MCP tools for AI agents

CALL ANY TOOL
12 tools covering create, delete.
agentmailmcp_create_draft
Create draft
Create a draft email in an inbox, optionally scheduling it to send at a future time.
Parameters
Name
Type
Required
Description
inboxId
string
Required
ID of inbox
attachments
array
Optional
Attachments
bcc
array
Optional
BCC recipients
cc
array
Optional
CC recipients
html
string
Optional
HTML body
inReplyTo
string
Optional
Message ID this draft is replying to
labels
array
Optional
Labels
replyTo
array
Optional
Reply-to addresses
sendAt
string
Optional
ISO 8601 datetime to schedule sending (e.g. 2026-04-01T09:00:00Z)
subject
string
Optional
Subject
text
string
Optional
Plain text body
to
array
Optional
Recipients
agentmailmcp_create_inbox
Create inbox
agentmailmcp_delete_draft
Delete draft
agentmailmcp_delete_inbox
Delete inbox
agentmailmcp_forward_message
Forward message
agentmailmcp_get_attachment
Get attachment
agentmailmcp_get_draft
Get draft
agentmailmcp_get_inbox
Get inbox
agentmailmcp_get_thread
Get thread
agentmailmcp_list_drafts
List drafts
agentmailmcp_list_inboxes
List inboxes
agentmailmcp_list_threads
List threads
agentmailmcp_reply_to_message
Reply to message
agentmailmcp_send_draft
Send draft
agentmailmcp_send_message
Send message
agentmailmcp_update_draft
Update draft
agentmailmcp_update_message
Update message
Build your Agent
Same auth pattern across every framework.
Python · LlamaIndex
from langchain_mcp_adapters.client import MultiServerMCPClient
from scalekit import ScalekitClient

client = ScalekitClient(env_url=ENV_URL, client_id=CLIENT_ID, client_secret=SECRET)
token = client.agent.get_token(user_id="user_id", connector="agentmailmcp")

mcp = MultiServerMCPClient({
"agentmailmcp": {
"url": "https://mcp.scalekit.com/agentmailmcp",
"headers": {"Authorization": "Bearer " + token}
}
})
tools = await mcp.get_tools()
import OpenAI from "openai";
import { ScalekitClient } from "@scalekit-sdk/node";

const client = new ScalekitClient({ envUrl, clientId, clientSecret });
const token = await client.agent.getToken({ userId: "user_id", connector: "agentmailmcp" });

const openai = new OpenAI();
// Connect to MCP at https://mcp.scalekit.com/agentmailmcp
// Pass: Authorization: Bearer + token
import Anthropic from "@anthropic-ai/sdk";
import { ScalekitClient } from "@scalekit-sdk/node";

const client = new ScalekitClient({ envUrl, clientId, clientSecret });
const token = await client.agent.getToken({ userId: "user_id", connector: "agentmailmcp" });

const anthropic = new Anthropic();
// Connect to MCP at https://mcp.scalekit.com/agentmailmcp
// Pass: Authorization: Bearer + token
from google.adk.agents import LlmAgent
from scalekit import ScalekitClient

client = ScalekitClient(env_url=ENV_URL, client_id=CLIENT_ID, client_secret=SECRET)
token = client.agent.get_token(user_id="user_id", connector="agentmailmcp")
# Connect to MCP at https://mcp.scalekit.com/agentmailmcp
# Pass: Authorization: Bearer + token
Try these prompts
Paste any prompt into your agent to get started.
Get started
Copy the prompt
Copied
Update a message’s labels by adding or removing label values?
Copy the prompt
Copied
Send a new email message from an inbox to one or more recipients?
Advanced
Copy the prompt
Copied
Reply to a specific message, optionally replying to all recipients?
Copy the prompt
Copied
List message threads in an inbox with optional label filtering and pagination?
SEE HOW AUTH WORKS
User authorises once. Every agent call after uses their token with scope enforcement.
1
Authorize
Your user connects
Agentmail MCP
once. We tie it to their identity and the meetings they approved — no shared bot account, no org-wide access
Who:
user ‘A’
when:
Once per user
access:
Limited to user
2
Store
Their
Agentmail MCP
token lives in a vault scoped to them. User A's meetings are never reachable by an agent acting for user B, even on the same connection
vault:
encrypted
scope:
per-user
tokens:
auto-refreshed
3
Resolve
When your agent calls a
Agentmail MCP
tool, we fetch the right token server-side. It never touches your agent, never appears in the LLM context, never shows up in your logs
speed:
~40ms
check:
before every call
seen by:
nobody
4
Audit
Every
Agentmail MCP
tool call is logged — who triggered it, which meeting was fetched, what came back. 90 days of history, tied to the user who authorized it
history:
90 days
export:
SIEM-ready
logged:
every call
Test other agents
See the same per-user auth pattern across other connectors.
GTM and RevOps Teams
Outbound prospecting agent
Searches Apollo for prospects matching your ICP, scores and ranks them, drafts personalized outreach in Gmail, and logs every send to Google Sheets. Mail goes out as the rep, not from a shared inbox.
Support and Ops Teams
Email-to-calendar agent
Reads scheduling intent out of Gmail threads, resolves the times everyone actually has free, and creates the event on the user's own Google Calendar. No shared service account.
GTM and RevOps Teams
CRM AI agent
Reads the Granola transcript after every call, extracts next steps and updates the HubSpot record, drafts the follow-up in Gmail, and confirms in Slack, all on the rep's own delegated OAuth.
Support and Ops Teams
Freshdesk CSAT agent
Watches Freshdesk for resolved tickets, emails each requester a CSAT survey from Gmail, and writes the score and the verbatim back onto the ticket, every call on the support rep's own delegated OAuth.
Test other agents
See the same per-user auth pattern across other connectors.
OPS
Email-to-calendar scheduling agent
Read scheduling intent out of Gmail threads, resolve mutual free time, and create the Google Calendar event.
SALES
Outbound prospecting agent
Search Apollo for ICP matches, rank them, draft personalised Gmail outreach, and log every send to Google Sheets.
GTM
CRM AI agent
Turn each Granola call transcript into a HubSpot record update, a drafted Gmail follow-up, and a Slack recap.
SUPPORT
Freshdesk CSAT follow-up agent
Spot resolved Freshdesk tickets, email the CSAT survey from Gmail, and write the score back onto the ticket.
Why Scalekit
Secure your agent's access. Connectors ship in minutes
01.
Shared tokens break per-user analytics
A shared token looks fine in a demo. In production every call looks like a service account. Scalekit resolves the real user credential.
// shared token
audit → bot_service_account

// scalekit
audit → user_abc ✓
02.
Authentication is not authorization
03.
Multi-tenancy is architectural
04.
One connector today. Ten tomorrow.
“Our agents act across Salesforce, Gong, Google Drive, and more, on behalf of every customer. Scalekit behind the scenes meant we can keep adding tools without ever rebuilding how credentials or tool calling work.”
Venu Madhav Kattagoni
Head of Engineering / Von
FAQs
Frequently Asked Questions

Does the agent access Agentmail as the user or as a shared key?
As the user. Each workspace member authorizes once and Scalekit resolves their credential at request time. Audit logs attribute every action to that user, not a shared service account.

Where is the Agentmail OAuth token stored?
In Scalekit's managed AES-256 token vault, namespaced per tenant. Refresh is automatic. Revocation is a single dashboard action. Tokens never appear in prompts, logs, or LLM context.

Can I limit what the agent is allowed to do in Agentmail?
Yes. Pass a tool name filter to listScopedTools so the messaging agent only sees the subset you authorize. Pre-API-call scope checks block out-of-policy actions before the request reaches Agentmail.

What happens when a user revokes Agentmail access?
The connection is invalidated on the next tool call. Subsequent requests for that user fail closed with a clear error. Other users in the tenant remain unaffected. The event is logged for audit.

Can one agent's inbox read another agent's mail?
No. Inboxes, drafts, and threads are scoped to the authorizing user's Agentmail account with per-tenant vault isolation. Each agent inbox stays its own mailbox.

Start in your coding agent
Up and running in one command
Install the Scalekit skill in your editor of choice. Connector, auth, tools, prompt, all wired up
Claude Code REPL
/plugin marketplace add scalekit-inc/claude-code-authstack
/plugin install agentkit@scalekit-auth-stack
Cursor Code REPL
# ~/.cursor/mcp.json
{
""mcpServers"": {
""agentmailmcp"": {
""url"": ""https://mcp.scalekit.com/agentmailmcp"",
""headers"": { ""Authorization"": ""Bearer $SCALEKIT_TOKEN"" }
}
}
}
Codex Code REPL
# ~/.codex/config.toml
[mcp_servers.agentmailmcp]
url = ""https://mcp.scalekit.com/agentmailmcp""
auth_env = ""SCALEKIT_TOKEN""
Copilot Code REPL
# .vscode/mcp.json
{
""servers"": {
""agentmailmcp"": {
""url"": ""https://mcp.scalekit.com/agentmailmcp"",
""type"": ""http""
}
}
}