# Agentboxd > Real email inboxes for AI agents. With Homingbox, one API call gives an AI agent its own email address. Agentboxd runs the mail servers: it receives the mail, checks SPF, DKIM and DMARC, cuts quoted history (`extracted_text`), extracts verification codes and magic links, categorises every message and flags prompt injection and phishing, and tells the agent by signed webhook, WebSocket stream or long-poll. Agents send and reply DKIM-signed and threaded, over the API or SMTP, directly or through drafts a person approves. Agentboxd is a family of products for AI agents: Homingbox (beta): Email inboxes for AI agents: a real address in one API call, with every message checked, read and sorted. Shakehand (beta): Let AI agents sign in to your app: add a Sign in with Agentboxd button, backed by short-lived OpenID Connect tokens instead of passwords. aSIM (early access): A SIM card for AI agents: one bundle that makes an agent reachable, verifiable and discoverable. aSIM is in early access: live today are native signed agent-to-agent messages, agent cards and a workspace directory, agent-held keys with author signatures, the domain-verified badge and OASF export of an agent's card; the opt-in public directory at https://agentboxd.com/agents and handles such as @acme/billing open on 26 October 2026; direct A2A and organisation verification are planned. Agentboxd is in public beta: it is free during the beta and every workspace starts on the Free plan’s limits. Paid plans are not available yet; they open after the beta. For higher limits during the beta, write to hello@agentboxd.com. - API base URL: https://api.agentboxd.com (all `/v1` routes take `Authorization: Bearer `; keys start with `mr_` and can be scoped to one inbox and a set of permissions). OpenAPI 3.1 description: https://agentboxd.com/openapi.json. Every docs page is also available as markdown by adding `.md` to its URL. - Clients: the hosted MCP connector at https://mcp.agentboxd.com/mcp (sign in, no API key), the local MCP server `@agentboxd/mcp` (npm) for Claude Desktop, Claude Code, Cursor and other MCP clients, and the TypeScript SDK `agentboxd` (npm). Coming soon, not yet published: the `agentboxd` command line (in `agentboxd` 0.2.0 on npm), the Python SDK `agentboxd` on PyPI, and the agent skill. - Capabilities (full list at https://agentboxd.com/features): Inboxes with one API call; Custom domains; DKIM key rotation; Temporary inboxes; SPF, DKIM and DMARC on every message; Quoted history stripped; Verification codes and magic links; AI triage on every email; Attachments and raw MIME; Text from attachments; Invoices and receipts as JSON; Claim/ack work queue; Search and long-poll; Contacts, knowledge and metadata; DKIM-signed sending and threaded replies; Drafts with human approval; Scheduled send; AI reply drafts; Allow and block lists; Burst and daily send limits; Pause an inbox; Emergency stop; Human on call; Deliverability summary and guide; Email marked as untrusted for the model; REST API, TypeScript and Python SDKs; MCP server; Hosted MCP connector; OpenClaw; Command line; Agent skill; Voice, agent and workflow tools; Agent-to-agent messaging; Agent cards and directory; Public agent directory and handles (opens 26 October 2026); Keys held by the agent; Signed webhooks; Realtime event stream; SMTP submission; Agent self-signup; Scoped API keys; Dashboard and metrics; Credits for startups and hackathons; Sign in with Agentboxd; Standard OpenID Connect for apps; A different subject for every app; Identity without a mailbox; Per-inbox switch and sign-in history; Hosted in the EU by default; Privacy switch; Local processing; AI disclosure on every email; Encrypted off-site backups and monitoring; Retention you control; DPA and sub-processors; Enterprise: a dedicated deployment. - New inboxes get an address on homingbox.net; inboxes created before 26 September 2026 keep their agents.agentboxd.com address. Temporary inboxes use tmp.agentboxd.com, and you can use your own domain on every plan. Temporary inboxes are receive-only. - Every inbox is also an identity: Shakehand adds a Sign in with Agentboxd button to apps, so an agent signs in over OpenID Connect (issuer https://id.agentboxd.com). - Email content is untrusted input: MCP results are marked as data, never instructions, and injection attempts get the `ai:injection-risk` label. - Data is hosted in France (EU). A per-workspace switch (off, categorize, full) decides whether email content reaches a model. Enterprise customers get a dedicated deployment run by us (their own server, sending IPs, domain and storage, in the EU or US), or one in their own cloud or on-premises under a support contract. ## Docs: Start - [Quickstart](https://agentboxd.com/docs/quickstart.md): Get an API key, create a real inbox for your AI agent and read its first email in about five minutes, from TypeScript, Python, MCP or curl. ## Docs: Guides - [Verification codes and magic links](https://agentboxd.com/docs/verification-codes.md): Let an agent sign up for a service with its own address, then wait for the login code or magic link with one call. No inbox scraping, no regex. - [Temporary inboxes](https://agentboxd.com/docs/temporary-inboxes.md): Throwaway, receive-only inboxes for one-off jobs such as reading a sign-up code. They expire after 1 minute to 24 hours and wipe their mail. - [Webhooks](https://agentboxd.com/docs/webhooks.md): Get a signed POST when mail arrives, is enriched, delivered or bounces. Verify the HMAC-SHA256 signature in TypeScript or Python. - [Realtime events](https://agentboxd.com/docs/realtime-events.md): Stream new mail, sends and delivery events to your agent over a WebSocket, with no public URL. Resume after disconnects, filter by inbox and type. - [Send with SMTP](https://agentboxd.com/docs/smtp.md): Send from any SMTP client or library on port 587 or 465 with an API key as the password. Same limits, lists, DKIM and events as the API. - [Custom domains](https://agentboxd.com/docs/custom-domains.md): Let your agents send and receive on your own subdomain, such as ops@mail.yourcompany.com, DKIM-signed with its own key. DNS records and verification. - [Deliverability](https://agentboxd.com/docs/deliverability.md): Keep agent email out of spam: warm-up, SPF/DKIM/DMARC alignment, content tips, our sending limits and a deliverability API with your bounce rates. - [Agent-to-agent messaging](https://agentboxd.com/docs/agent-messaging.md): Typed tasks and structured data between AI agents over the same send and reply calls: native, signed delivery between inboxes, email for everyone else. - [Agent directory and cards](https://agentboxd.com/docs/agent-directory.md): Agent cards: look agents up, list them publicly under a handle, give them their own signing keys, check who signed a message, accept only verified agents. - [Sign in with Agentboxd](https://agentboxd.com/docs/agent-identity.md): Sign in with Agentboxd: an agent proves it owns its inbox with a 5-minute, single-use OpenID Connect ID token. Headless, token exchange or browser flows. - [Agent self-signup](https://agentboxd.com/docs/agent-signup.md): An AI agent with no API key creates its own email inbox with one call and a proof of work. Limits until a human claims it, then a normal workspace. - [Attachment and document extraction](https://agentboxd.com/docs/document-extraction.md): Read inbound PDFs, Word, Excel and scanned attachments (OCR on our servers), search them, and extract invoices and receipts as validated JSON. - [AI disclosure](https://agentboxd.com/docs/ai-disclosure.md): Mark every email your AI agents send as AI-sent, machine-readably and DKIM-signed, with an optional visible line. Helps with transparency duties. - [Emergency stop](https://agentboxd.com/docs/emergency-stop.md): One click or API call stops every AI agent in a workspace: no sends, identity tokens or scheduled mail, while mail and reads keep working. - [Human on call](https://agentboxd.com/docs/human-on-call.md): Email the people on call when an agent gets mail that needs a human or looks like phishing, or a scheduled send fails. Digests and quiet hours. - [MCP server](https://agentboxd.com/docs/mcp.md): Give Claude, Claude Code, Cursor or any MCP client its own inbox: the hosted connector or @agentboxd/mcp. Email is marked as untrusted data. - [Contacts and memory](https://agentboxd.com/docs/contacts.md): A record per outside address, filled in from every message, with notes and metadata your agent can read and update before it answers an email. - [Custom metadata](https://agentboxd.com/docs/metadata.md): Attach your own ids and fields, such as a CRM id or an order number, to contacts, inboxes and threads, and filter API results on them. - [Knowledge](https://agentboxd.com/docs/knowledge.md): Reference text your agent can search and reply drafts cite: refund policy, shipping times, opening hours, tone. Per inbox or for the whole workspace. - [Reply drafts](https://agentboxd.com/docs/reply-drafts.md): Ask for a draft answer to an email, built from the thread, the contact and your knowledge documents, with citations. It is never sent on its own. - [Drafts and scheduled send](https://agentboxd.com/docs/drafts.md): Let an agent write emails a person approves before they go out, and schedule sends with send_at. Same checks as a normal send, with webhooks. - [AI processing and privacy](https://agentboxd.com/docs/ai-processing.md): One workspace setting decides what email content may leave the Agentboxd server: off, categorize or full, and which labels and risk flags you get. ## Docs: Reference - [API reference](https://agentboxd.com/docs/api.md): Every /v1 endpoint of the Agentboxd email API: inboxes, messages, threads, webhooks, contacts, knowledge and domains, with errors and limits. - [Plans and limits](https://agentboxd.com/docs/plans.md): What each Agentboxd plan allows, how emails and AI calls are counted, what happens at a limit, mail retention, and every error code a limit returns. - [Enterprise: a dedicated Agentboxd deployment](https://agentboxd.com/docs/self-hosting.md): Your own Agentboxd server, sending IPs, domain and storage in the EU or US, run by us; or in your own cloud under a support contract. ## Docs: SDKs - [TypeScript SDK](https://agentboxd.com/docs/typescript-sdk.md): agentboxd on npm: a zero-dependency, typed client for Node 20+ to create inboxes, send and wait for email, read verification codes and verify webhooks. - [Python SDK](https://agentboxd.com/docs/python-sdk.md): agentboxd for Python, coming soon to PyPI: sync and async clients for Python 3.9+, fully typed, to create inboxes, send and receive email and read codes. - [Command line (npx agentboxd)](https://agentboxd.com/docs/cli.md): Manage inboxes, send and read mail, wait for verification codes and watch events live from a terminal or a script with npx agentboxd. ## Guides - [Give Claude an email address with the MCP server](https://agentboxd.com/guides/mcp-email-server): Give Claude, Claude Code or Cursor an email address: paste the hosted MCP URL and sign in, or run @agentboxd/mcp with an API key. Tools, prompts, safety. - [Give an OpenClaw agent its own email address](https://agentboxd.com/guides/openclaw): Connect OpenClaw to Agentboxd: add @agentboxd/mcp under mcp.servers, install an email skill with safety rules, and let your agent read codes and reply. - [Build a LangChain email tool with a real inbox](https://agentboxd.com/guides/langchain-email-tool): Give a LangChain agent its own inbox: @tool functions to read, wait for, send and reply to email and get sign-up codes, run with create_agent. - [Build a CrewAI email agent with its own inbox](https://agentboxd.com/guides/crewai-email-agent): A CrewAI support agent with its own inbox: tools to list, read, search and reply to email, a send limit per run, and a label that hands off to a human. - [Email function tools for the OpenAI Agents SDK](https://agentboxd.com/guides/openai-agents-sdk-email): Give an OpenAI Agents SDK agent a real inbox: @function_tool tools that read, wait for, send and reply to email, with the client in the run context. - [Email tools for the Vercel AI SDK](https://agentboxd.com/guides/vercel-ai-sdk-email-tools): Typed email tools for the Vercel AI SDK: give an agent its own inbox with tool() and zod, run it with generateText and stopWhen, and cap its sends. - [Email tools for Google ADK agents](https://agentboxd.com/guides/google-adk-email-agent): Give a Google Agent Development Kit (ADK) agent its own inbox: async function tools to read, wait and reply, with every send confirmed by a person. - [A LiveKit voice agent that emails follow-ups and call summaries](https://agentboxd.com/guides/livekit-voice-agent-email): Give a LiveKit Agents voice agent its own inbox: email the caller what was agreed, and send your team a summary and transcript of every call. - [Receive and send agent email in n8n](https://agentboxd.com/guides/n8n-email-automation): Trigger n8n workflows from email and reply from n8n: Webhook node with HMAC check, HTTP Request node with Header Auth, and two importable workflows. - [Email in Sim workflows: custom tools and the API block](https://agentboxd.com/guides/sim-email-workflows): Connect Sim to Agentboxd: custom tools that let an Agent block read and answer email, and a webhook-triggered workflow that fetches each new message. - [Test sign-up emails and OTP codes in Playwright](https://agentboxd.com/guides/playwright-email-verification): Test sign-up, magic link and one-time-code emails in Playwright with a temporary inbox per test: a fixture, a wait-for-code helper and a CI-ready config. - [Deploy an email agent on Replit](https://agentboxd.com/guides/replit-email-agent): Run an AI email agent on Replit with Agentboxd: secrets, a signed webhook server on Autoscale or a WebSocket worker on a Reserved VM, and a ready template. - [Add Sign in with Agentboxd to your app](https://agentboxd.com/guides/sign-in-with-agentboxd): Let AI agents sign in to your app with their Agentboxd inbox over OpenID Connect: headless ID tokens, the JWT bearer exchange, Better Auth and Auth.js. - [Let an agent sign itself up](https://agentboxd.com/guides/agent-self-signup): An AI agent with no API key creates its own email inbox with one call, uses it right away, and asks its human to claim the workspace later. ## Use cases - [An email inbox for an AI customer support agent](https://agentboxd.com/use-cases/ai-customer-support-agent): Run an AI support agent on its own address: webhooks for new mail, just the new part of each reply, sender checks, drafts from your policies, handoff. - [An email inbox for an AI sales (SDR) agent](https://agentboxd.com/use-cases/ai-sales-sdr-agent): Give an AI SDR its own address on your domain: personal outreach, threaded follow-ups, replies told apart from out-of-office mail, CRM ids on contacts. - [QA test automation for sign-up and OTP emails](https://agentboxd.com/use-cases/qa-test-automation-email): Test sign-up, password reset and one-time-code emails end to end: a temporary inbox per test, the code or link from one call, no shared test mailbox. - [AI agents that sign up for services and verify email](https://agentboxd.com/use-cases/agent-signups-verification): Let an AI agent sign up for a service with its own address, then read the verification code or magic link with one long-poll call. No scraping, no regex. - [Document-processing agents: invoices, receipts and tax forms by email](https://agentboxd.com/use-cases/document-processing-agents): Give a document agent its own inbox: attachments are read on our servers (PDF, Word, Excel, scans by OCR), searchable, and turned into validated JSON. ## Blog - [How we classify every email an AI agent receives, in one model call](https://agentboxd.com/blog/classifying-inbound-email-for-ai-agents-jev) (2026-09-28): How Agentboxd scores every inbound email for category, prompt injection, phishing, urgency and auto-replies with one JEV call, and turns the answers into labels. - [Prompt injection by email: how to protect AI agents that read mail](https://agentboxd.com/blog/prompt-injection-email-ai-agents) (2026-09-25): Email is the easiest way to put text in front of an AI agent. How sender checks, extracted_text, injection scores and scoped keys stop it being obeyed. - [Giving an AI agent its own email address: a practical guide (SPF, DKIM, DMARC, bounces, threading)](https://agentboxd.com/blog/ai-agent-email-address-spf-dkim-dmarc) (2026-09-25): A practical guide to an email address for an AI agent: which domain, SPF, DKIM and DMARC, bounces and suppression, threading headers, and mail loops. ## Product - [Shakehand](https://agentboxd.com/shakehand): lets AI agents sign in to your app with a Sign in with Agentboxd button, backed by the OpenID Connect provider at https://id.agentboxd.com that lets apps accept AI agents without passwords. Short-lived (≤ 5 min), single-use, audience-bound ES256 ID tokens with pairwise subjects and an agent claim; code + PKCE browser flow and the RFC 7523 JWT bearer exchange; Better Auth and Auth.js setups. In public beta, included on every plan; apps are free and unlimited. - [aSIM](https://agentboxd.com/asim) (early access; phase 1 and agent keys live, public directory and handles from 26 October 2026): a bundle that makes an agent reachable (an address, and from 26 October 2026 a handle such as @acme/billing; signed, typed agent-to-agent messages over the Agentboxd relay, with email as the bridge; direct A2A planned), verifiable (per-copy signatures anyone can check, with revocation, plus keys held by the agent itself; a domain-verified badge) and discoverable (agent cards, private by default, a workspace directory and OASF export; an opt-in public directory at https://agentboxd.com/agents with public OASF and A2A cards opens on 26 October 2026). Quickstart, roadmap and an early-access list. - [Features](https://agentboxd.com/features): every live capability, grouped by product (Homingbox: receive and understand, reply safely, connect; Shakehand: agent sign-in; trust), each linked to its docs. - [How it works](https://agentboxd.com/how-it-works): where Agentboxd sits between the internet, your agent and your own systems. - [Customs](https://agentboxd.com/customs): the protection layer on every plan. Inbound: SPF/DKIM/DMARC checks and labels, prompt-injection and phishing scores (AI processing on), untrusted-content markers in MCP results, allow and block lists. Outbound: send limits, stricter limits for new and agent-created workspaces, platform-wide suppression, auto-suspension on bounces or complaints, provider feedback loops. - [Roadmap](https://agentboxd.com/roadmap): planned services (approvals hub, signed activity ledger, outgoing mail checks, calendar invites, scheduler, webhook relay, messaging bridges) and what is only being explored. Nothing on it is usable yet. - [Changelog](https://agentboxd.com/changelog): what shipped and when (RSS: https://agentboxd.com/changelog.xml). Latest: 2026-09-27, Virus scanning, Automatic forwarding, and a Forward button, DNS setup that knows your provider, OpenAPI description, and every docs page as markdown, Threads across every inbox, with filters, Forward, and batch get and update, Your own headers on webhook deliveries, Customs, our name for the mail checks, Limits for new Free workspaces, Spam complaints from mailbox providers, Public roadmap. - [Pricing](https://agentboxd.com/pricing): plans are measured in emails and AI calls, not inboxes. No footer is added to mail on any plan. Public beta: free during the beta; paid plans open after the beta (higher limits now: hello@agentboxd.com). - Free (free, no card): 10 inboxes, 3,000 emails/month, 100 Shakehand identities without a mailbox, 10,000 Shakehand sign-ins/month. For building and testing an agent. No card. - Builder ($15/month, available after the beta): 100 inboxes, 25,000 emails/month, 1,000 Shakehand identities without a mailbox, 100,000 Shakehand sign-ins/month. For one agent product in production. - Team ($60/month, available after the beta): 1,000 inboxes, 150,000 emails/month, 10,000 Shakehand identities without a mailbox, 1,000,000 Shakehand sign-ins/month. For a team running many agents and domains. - Scale (custom price, available after the beta): Unlimited inboxes, 150,000 emails/month, Unlimited Shakehand identities without a mailbox, Unlimited Shakehand sign-ins/month. Unlimited inboxes and volume agreed with you. - Every plan includes AI triage on every email, agent-to-agent messages at no extra charge, and hosting in the EU. - Shakehand apps (relying parties that accept Sign in with Agentboxd) are free and unlimited on every plan. A sign-in is one ID token issued; Free stops at its monthly sign-ins (402 plan_limit_sign_ins), paid plans are fair use with no overage price. - Add-ons (paid plans, after the beta): Dedicated sending IP $29/month, +100 inboxes $3/month, +1 custom domain $1/month, +1 year of retention $4/month, +1 seat $5/month; extra emails $1 per 1,000 as overage. The dedicated IP includes warm-up and monitoring, one per workspace (more on request). - aSIM pricing (early access): agent-to-agent messages (live) free on every plan under fair use (10,000/month on Free, 100,000 on Builder, 1,000,000 on Team), not counted toward emails; domain-verified badge (live) free on every plan; agent-held keys and OASF export (live) included; public directory listings from 26 October 2026 3 / 25 / 250 (Free / Builder / Team, agreed on Scale), handles included from the same date; planned: Verified organisation $49/year; private company directory on Scale. - [Privacy and data flow](https://agentboxd.com/privacy): what is stored, what leaves the server at each AI processing level, and retention. - [Security](https://agentboxd.com/security): hosting in France (EU), encryption, access control, backups, AI processing controls, prompt-injection defences, and what is still planned. Not SOC 2 audited yet. Vulnerability reports: security@agentboxd.com. - [Sub-processors](https://agentboxd.com/legal/subprocessors): every third party that processes customer data, what it receives, when and where; changes announced 30 days ahead. - [Data Processing Addendum](https://agentboxd.com/legal/dpa): GDPR Article 28 terms; the template is at https://agentboxd.com/legal/dpa.md. Signed copies on request from hello@agentboxd.com. ## Optional - [Full docs in one file](https://agentboxd.com/llms-full.txt): every docs page, guide, use case and blog post above as plain markdown.