machine-inbox
Task-scoped email inboxes for AI agents: read mail, extract verification codes, and reply.
Should I use this
Quality & Safety
Findings (2)
- LOWin create_inbox
- LOWin set_webhook
Based on automated analysis of tool definitions and protocol compliance.
Context Cost
This is the approximate number of tokens consumed each time the server's tools are loaded into a model's context. Higher counts reduce the attention available for other tasks.
Install
One-Click Install
Add this to your `claude_desktop_config.json` file:
{
"mcpServers": {
"machine-inbox": {
"url": "https://machineinbox.com/mcp"
}
}
}Remote endpoints
https://machineinbox.com/mcpstreamable-httpWhat it can do
Tool inventory
Tools (11)
🟢get_service_info
Read the Machine Inbox service instructions: pricing, payment rails, endpoints, and limits.
Input Schema
{
"type": "object",
"properties": {},
"additionalProperties": false
}🟡create_inbox(idempotency_key)
Request a new paid inbox. Buying requires an out-of-band payment (Stripe MPP or x402 USDC on Base); this tool returns the live HTTP 402 payment challenge plus exact instructions to complete the purchase. Standard inbox: $2.00.
Input Schema
{
"type": "object",
"properties": {
"idempotency_key": {
"type": "string",
"minLength": 16,
"maxLength": 200,
"description": "High-entropy key to bind the eventual paid retry to this request."
}
},
"additionalProperties": false
}🟢get_inbox(token, inbox_id)
Read an inbox: address, status, expiry, limits, and usage.
Input Schema
{
"type": "object",
"properties": {
"token": {
"type": "string",
"description": "Mailbox bearer token (mi_live_...) returned when the inbox was purchased. Optional when the MCP request itself carries Authorization: Bearer."
},
"inbox_id": {
"type": "string",
"description": "Inbox UUID."
}
},
"required": [
"inbox_id"
],
"additionalProperties": false
}🟢list_messages(token, inbox_id, limit, after, before)
List messages in an inbox, newest first. Pass after=<newest createdAt seen> to poll for only new mail.
Input Schema
{
"type": "object",
"properties": {
"token": {
"type": "string",
"description": "Mailbox bearer token (mi_live_...) returned when the inbox was purchased. Optional when the MCP request itself carries Authorization: Bearer."
},
"inbox_id": {
"type": "string",
"description": "Inbox UUID."
},
"limit": {
"type": "integer",
"minimum": 1,
"maximum": 100
},
"after": {
"type": "string",
"description": "ISO date-time; only messages created after this instant."
},
"before": {
"type": "string",
"description": "ISO date-time cursor for older mail."
}
},
"required": [
"inbox_id"
],
"additionalProperties": false
}🟢get_message(token, inbox_id, message_id)
Fetch one message with parsed text, HTML, and attachment download URLs.
Input Schema
{
"type": "object",
"properties": {
"token": {
"type": "string",
"description": "Mailbox bearer token (mi_live_...) returned when the inbox was purchased. Optional when the MCP request itself carries Authorization: Bearer."
},
"inbox_id": {
"type": "string",
"description": "Inbox UUID."
},
"message_id": {
"type": "string"
}
},
"required": [
"inbox_id",
"message_id"
],
"additionalProperties": false
}🟢get_verification_code(token, inbox_id, sender)
Extract the newest one-time verification code or confirmation link from inbound mail. Ideal for signup and login flows.
Input Schema
{
"type": "object",
"properties": {
"token": {
"type": "string",
"description": "Mailbox bearer token (mi_live_...) returned when the inbox was purchased. Optional when the MCP request itself carries Authorization: Bearer."
},
"inbox_id": {
"type": "string",
"description": "Inbox UUID."
},
"sender": {
"type": "string",
"description": "Only consider senders whose address contains this substring."
}
},
"required": [
"inbox_id"
],
"additionalProperties": false
}🟡reply_to_message(token, inbox_id, message_id, text, idempotency_key)
Send an included plain-text reply to the authenticated sender of an inbound message.
Input Schema
{
"type": "object",
"properties": {
"token": {
"type": "string",
"description": "Mailbox bearer token (mi_live_...) returned when the inbox was purchased. Optional when the MCP request itself carries Authorization: Bearer."
},
"inbox_id": {
"type": "string",
"description": "Inbox UUID."
},
"message_id": {
"type": "string"
},
"text": {
"type": "string",
"minLength": 1,
"maxLength": 20000
},
"idempotency_key": {
"type": "string",
"minLength": 16,
"maxLength": 200,
"description": "New unique key for this reply; reuse only to retry the identical reply."
}
},
"required": [
"inbox_id",
"message_id",
"text",
"idempotency_key"
],
"additionalProperties": false
}🟡set_webhook(token, inbox_id, url)
Register or replace the inbox webhook: an HMAC-signed POST fires on every inbound message with metadata, extracted verification codes, and injection risk (never the body). Returns the signing secret.
Input Schema
{
"type": "object",
"properties": {
"token": {
"type": "string",
"description": "Mailbox bearer token (mi_live_...) returned when the inbox was purchased. Optional when the MCP request itself carries Authorization: Bearer."
},
"inbox_id": {
"type": "string",
"description": "Inbox UUID."
},
"url": {
"type": "string",
"description": "Public https URL that receives the signed POST."
}
},
"required": [
"inbox_id",
"url"
],
"additionalProperties": false
}🟡get_webhook(token, inbox_id)
Read the inbox webhook state: URL, delivery counters, and whether it is disabled. The secret is only returned by set_webhook.
Input Schema
{
"type": "object",
"properties": {
"token": {
"type": "string",
"description": "Mailbox bearer token (mi_live_...) returned when the inbox was purchased. Optional when the MCP request itself carries Authorization: Bearer."
},
"inbox_id": {
"type": "string",
"description": "Inbox UUID."
}
},
"required": [
"inbox_id"
],
"additionalProperties": false
}🔴delete_webhook(token, inbox_id)
Remove the inbox webhook.
Input Schema
{
"type": "object",
"properties": {
"token": {
"type": "string",
"description": "Mailbox bearer token (mi_live_...) returned when the inbox was purchased. Optional when the MCP request itself carries Authorization: Bearer."
},
"inbox_id": {
"type": "string",
"description": "Inbox UUID."
}
},
"required": [
"inbox_id"
],
"additionalProperties": false
}🔴delete_inbox(token, inbox_id)
Delete an inbox: revokes the token and erases stored mail.
Input Schema
{
"type": "object",
"properties": {
"token": {
"type": "string",
"description": "Mailbox bearer token (mi_live_...) returned when the inbox was purchased. Optional when the MCP request itself carries Authorization: Bearer."
},
"inbox_id": {
"type": "string",
"description": "Inbox UUID."
}
},
"required": [
"inbox_id"
],
"additionalProperties": false
}Community
Evidence