{"name":"io.github.openagentemail/mcp","slug":"openagentemail-mcp","title":null,"description":"Unlimited agent mailboxes — create identities, read/wait for mail, extract OTPs, send email.","url":"https://mcp.market/server/openagentemail-mcp","rating":null,"grade":"B","score":74,"certified":false,"status":"active","category":"email","tags":["email","scraping","ai"],"presence":{"score":31,"stars":44,"forks":8,"downloads_week":null,"last_push_at":"2026-09-19T17:36:19.000Z","license":"Apache-2.0"},"uptime":null,"claimed":false,"transport":"npm","callable_via_gateway":false,"default_price_micros":0,"repository":"https://github.com/openagentemail/openagentemail","website":null,"version":"0.7.3","remotes":[],"packages":[{"registryType":"npm","identifier":"@openagentemail/mcp","version":"0.7.3","transport":{"type":"stdio"},"environmentVariables":[{"description":"Bearer key for the openagent.email API — best: the identity token (oa_…) returned by POST /v1/identities.","isRequired":true,"format":"string","isSecret":true,"name":"OPENAGENTEMAIL_API_KEY"},{"description":"Base URL of the openagent.email API.","format":"string","default":"http://localhost:3100","name":"OPENAGENTEMAIL_API_URL"}]}],"tools":[{"name":"mail_list_identities","description":"List all email identities (addresses) on this server.","write_action":false,"price_micros":0,"input_schema":null},{"name":"mail_list_messages","description":"List messages received by an identity address (newest first), with id/from/to/subject/date/seen/snippet/hasOtp/source.","write_action":false,"price_micros":0,"input_schema":null},{"name":"mail_mark_seen","description":"Mark a message as read (seen=true) or unread (seen=false). Call this after processing a message so the unseen count reflects what is still unhandled. Reading a message never changes this flag by itself.","write_action":false,"price_micros":0,"input_schema":null},{"name":"mail_new_identity","description":"Admin only: create a new email identity (mailbox address) on this openagent.email server. Pass 'localpart' for a custom address (e.g. 'qa-bot' gives qa-bot@domain), or omit it for a random one. Returns the full address and a one-time API token; omit scopes for legacy full identity permissions.","write_action":false,"price_micros":0,"input_schema":null},{"name":"mail_read_message","description":"Read a full message: text, html (if any), and extracted OTP verification codes and links.","write_action":false,"price_micros":0,"input_schema":null},{"name":"mail_send","description":"Send an email from an existing identity address. 'from' must be an identity created with mail_new_identity.","write_action":true,"price_micros":0,"input_schema":null},{"name":"mail_wait_for","description":"Wait for an incoming message matching optional from/subject filters. Returns the full message (with OTP codes/links) or a timeout error.","write_action":false,"price_micros":0,"input_schema":null},{"name":"mail_webhook_create","description":"Create an outbound webhook subscription. Returns subscription metadata and the displayed signing secret (whs_...). Deny-by-default for OAuth tokens.","write_action":true,"price_micros":0,"input_schema":null},{"name":"mail_webhook_delete","description":"Permanently delete an outbound webhook subscription and cancel any pending retries.","write_action":true,"price_micros":0,"input_schema":null},{"name":"mail_webhook_disable","description":"Pause an active webhook subscription by marking it disabled.","write_action":false,"price_micros":0,"input_schema":null},{"name":"mail_webhook_list","description":"List outbound webhook subscriptions. Identity callers see only their own subscriptions; admin callers may see all or filter by address.","write_action":false,"price_micros":0,"input_schema":null},{"name":"mail_webhook_test","description":"Send an immediate probe ping to test webhook connectivity.","write_action":true,"price_micros":0,"input_schema":null},{"name":"notify_agent","description":"Wake a named agent through the server-side notification route. The server owns topics and credentials; pass the target agent's identity localpart only.","write_action":false,"price_micros":0,"input_schema":null},{"name":"notify_check","description":"Read recent notifications for this identity only. The server maps the token to its own topic, so no topic name or ntfy credential is exposed.","write_action":false,"price_micros":0,"input_schema":null},{"name":"notify_user","description":"Send a human-alert notification. Identity tokens need the server-side can_notify_user grant; this tool never needs a topic or ntfy credential.","write_action":true,"price_micros":0,"input_schema":null},{"name":"notify_verify","description":"Send a harmless server-side notification check and poll it back. Requires the same human-alert permission as notify_user.","write_action":true,"price_micros":0,"input_schema":null},{"name":"task_claim","description":"Claim a submitted task as its managed recipient for a bounded lease. Each generation is capped at 24 hours and the task cannot claim or renew at or after its first claim plus seven days; a working task may otherwise be reclaimed with an authenticated expired or released lease receipt.","write_action":false,"price_micros":0,"input_schema":null},{"name":"task_create","description":"Assign a task to another managed identity. The server creates a stamped email thread and wakes that identity's agent route. Typed approval actions are JSON-only, at most 65,536 canonical UTF-8 bytes and depth 10, with expiry at most 30 days from the server clock; approval_action_too_large, approval_action_too_deep, and approval_expiry_too_far are stable client errors. With wait=true it waits up to","write_action":true,"price_micros":0,"input_schema":null},{"name":"task_decide","description":"Approve or reject an approval task as the identity bound to this MCP token. This records a decision only; it never executes the action.","write_action":false,"price_micros":0,"input_schema":null},{"name":"task_get","description":"Read one task thread and its server-stamped state history. A durable lease retained while leases are disabled is visible with leaseStatus=disabled.","write_action":false,"price_micros":0,"input_schema":null},{"name":"task_list","description":"List this identity's email-backed tasks, optionally filtered by their current state. A durable lease retained while leases are disabled is visible with leaseStatus=disabled.","write_action":false,"price_micros":0,"input_schema":null},{"name":"task_list_children","description":"List only direct readable children of a readable parent. Results are viewer-filtered before paging and contain no totals or descendants.","write_action":false,"price_micros":0,"input_schema":null},{"name":"task_release","description":"Release a task lease only with its current active opaque lease token.","write_action":false,"price_micros":0,"input_schema":null},{"name":"task_renew","description":"Renew a task lease only with its current active opaque lease token. Renewal never resets its generation's 24-hour cap or the task's first-claim seven-day cap; equality is rejected.","write_action":false,"price_micros":0,"input_schema":null},{"name":"task_update","description":"Advance a task as one of its two participants. The API stamps the state header; completed and failed are terminal. For an active recipient lease, omitting leaseToken retains task_already_terminal, while a supplied wrong or expired token returns task_lease_required. Put structured output in result, which the server writes as a JSON result block in the reply body.","write_action":true,"price_micros":0,"input_schema":null}],"scan":{"score":74,"grade":"B","scanned_at":"2026-09-19T20:05:16.859Z","report":{"scannerVersion":"0.1.5","scannedAt":"2026-09-19T20:05:16.810Z","components":{"code":{"score":20,"max":25,"notes":["3 source files scanned"]},"reliability":{"score":-1,"max":20,"notes":["no gateway calls yet and no remote to probe"]},"poisoning":{"score":-1,"max":15,"notes":["tools not inspected (local package is not executed); not counted"]},"auth":{"score":6,"max":15,"notes":["static API keys via environment variables"]},"maintenance":{"score":15,"max":15,"notes":["last push 0 days ago"]},"identity":{"score":7,"max":10,"notes":["registry namespace matches repository owner"]}},"findings":[{"id":"exec.eval","severity":"medium","component":"code","title":"eval / new Function used","evidence":"dist/main.js: …ourceCode, sch); const validate = new Function(`${names_1.default.self}`, `${names_1.de…"}],"inputs":{"packages":[{"registryType":"npm","identifier":"@openagentemail/mcp","version":"0.7.3","found":true,"license":"Apache-2.0","hasInstallScripts":false,"dependencyCount":0,"publishedAt":"2026-09-13T14:00:38.561Z","repositoryUrl":"git+https://github.com/openagentemail/openagentemail.git"}],"repo":{"found":true,"owner":"openagentemail","repo":"openagentemail","archived":false,"pushedAt":"2026-09-19T17:36:19Z","stars":44,"forks":8,"openIssues":46,"ownerType":"Organization","ownerAvatarUrl":"https://avatars.githubusercontent.com/u/309239157?v=4","ownerCreatedAt":"2026-07-26T00:27:38Z","license":"Apache-2.0"},"icon":{"url":"https://avatars.githubusercontent.com/u/309239157?v=4&s=128","source":"registry","width":128,"height":128},"presence":{"stars":44,"forks":8,"downloadsWeek":null,"license":"Apache-2.0","lastPushAt":"2026-09-19T17:36:19.000Z","score":31}}}},"grade_history":[],"reviews":[]}