Mmcp.market

webhook-inbox

by inbox.kymac.co·co.kymac.inbox/webhook-inbox·v0.4.1

Ephemeral HTTPS inbox for bots: mint URL, capture POSTs, list JSON. TEST. https://inbox.kymac.co

C63/100grade C
What users say
No reviews yet
Be the first
Safety scan
C63/100

full report

Adoption
Not measured yet

Usage numbers are collected on the next scan

Reviews

Write one

Nobody has reviewed webhook-inbox yet.

If you have run it, two minutes of your experience saves the next person an afternoon.

Tools (15, 10 write)

write = sends, deletes, buys or posts
  • capture_inboxwrite actionFree

    Public capture (POST /c/{id}). No API key. No debit. Not an install entry. Stores raw body + headers for list_inbox_events. Rejects revoked (410 inbox_revoked) or expired (410 inbox_expired) inboxes. Body limit 1MB.

  • checkout_creditswrite actionFree

    Stripe TEST PaymentIntent for a pack (POST /credits/checkout). Intent only — returns credits_pending; credits are not granted or spendable until confirm_credits succeeds. Requires a caller key.

  • confirm_creditswrite actionFree

    Confirm a TEST PaymentIntent with Stripe test card pm_card_visa (POST /credits/confirm). This is when credits become granted/spendable (appends credit.purchase with credits_added). TEST only.

  • credit_balanceFree

    Derived prepaid balance for this caller_id (GET /credits/balance).

  • credit_eventswrite actionFree

    Append-only Ledger events for this caller_id (GET /credits/events): credit.grant (first_key), credit.purchase, credit.debit reason=inbox_mint, optional credit.balance_snapshot.

  • healthFree

    Public readiness (GET /health): billing (test|live|gated) and runner_ready. No key.

  • issue_keywrite actionFree

    Mint a caller key (POST /keys). Bot install starts at GET https://inbox.kymac.co/llms.txt (sole advertised entry). Secret whi_… is returned once. Prefer Authorization: Bearer; X-API-Key is an alias. First issue grants 1 free credit (credit.grant reason=first_key). Quote cost with quote_credits before mint_inbox.

  • list_credit_packsFree

    Prepaid TEST packs (GET /credits/packs). checkout_credits is intent only; credits grant after confirm_credits.

  • list_inbox_eventsFree

    Owner list (GET /inbox/{id}/events). Returns captured POSTs as JSON (headers + body). Does not debit. Other callers see 404.

  • mint_inboxwrite actionFree

    Mint a capture URL (POST /inbox). Install via GET https://inbox.kymac.co/llms.txt only. Prefer Authorization: Bearer; X-API-Key is an alias. First key includes 1 free credit. Quote first with quote_credits (no debit). Debits 1 credit on success (credit.debit reason=inbox_mint, request_id=inbox id). 201 body includes id, capture_url, expires_at, credits_remaining. HTTP fails use code/message/retryable/next (error aliases message). 401 next=refresh key. 402: code=insufficient_credits, retryable=false, next=buy credits.

  • quote_creditswrite actionFree

    Dry-run cost for an op without debit (GET /credits/quote?op=inbox). Returns cost, balance, and would_succeed.

  • revoke_inboxwrite actionFree

    Stop further captures (DELETE /inbox/{id}). Does not refund the mint debit. Owner only.

  • revoke_keywrite actionFree

    Invalidate the presented secret (POST /keys/revoke). Same id is revoked; old secret then fails 401 invalid_api_key. Prefer Authorization: Bearer; X-API-Key is an alias only. No ops file-edit.

  • rotate_keywrite actionFree

    Replace the presented secret (POST /keys/rotate). Same id/caller_id and credits. New whi_… is returned once. Old secret then fails 401 invalid_api_key. Prefer Authorization: Bearer; X-API-Key is an alias only. No ops file-edit.

  • verify_keyFree

    Confirm WEBHOOK_INBOX_API_KEY or Authorization: Bearer (GET /keys/verify). X-API-Key is an alias only. Does not echo the secret.

Public scan report

scanner v0.1.2 · 2026-09-18 · same rubric, same numbers if you re-run it

1 low
  • Code scanremote-only server, no package to scann/a
  • Live reliabilityremote reachable in 2006ms17/20
  • Tool poisoning15 tool descriptions checked15/15
  • Auth qualityAPI key sent as a header8/15
  • Maintenanceno repository listed3/15
  • Maintainer identityverified namespace with website, no repo4/10

Findings (1)

  • lowNo source repository listedmaint.no-repo
Overall 63/100. Components that don't apply are left out of the denominator. Any critical finding is an F.RubricAppeal a findingJSON

Install directly

claude mcp add --transport http webhook-inbox https://inbox.kymac.co/mcp
Add to Cursor

Alternatives to webhook-inbox

Same job, ranked by rating then adoption.

See all →
  • mailmcp
    Your mailboxes in ChatGPT and Claude: Gmail, iCloud, Fastmail, any IMAP. Passwords stay yours.
    A
  • FGAC.ai: Multiple Gmail Accounts, Google Sheets & Docs
    Multiple Gmail accounts, editable Google Sheets & Docs for AI agents. Deny-by-default access rules.
    A
  • mailwarden
    Gmail MCP server for email triage: search, labels, archive, trash, unsubscribe, snooze.
    A
  • workspace-mcp
    Google Workspace MCP server for Gmail, Drive, Calendar, Docs, Sheets, Slides, Forms, Tasks, Chat.
    A
  • mcp-outlook
    Outlook mail and OneDrive files via Microsoft Graph — read, search, send and organize.
    B