Back to Browse

Mailbuttons MCP Server

Developer ToolsLow Risk9.7MCP RegistryLocalRemote
Free

Server data from the Official MCP Registry

Governed email for AI agents (Mailbuttons / mbag.ai): sandbox inboxes, policy gate, audit log.

About

Governed email for AI agents (Mailbuttons / mbag.ai): sandbox inboxes, policy gate, audit log.

Remote endpoints: streamable-http: https://mailbuttons.com/api/v1/mcp/rpc

Security Report

9.7
Low Risk9.7Low Risk

Valid MCP server (1 strong, 1 medium validity signals). No known CVEs in dependencies. ⚠️ Package registry links to a different repository than scanned source. Imported from the Official MCP Registry. 1 finding(s) downgraded by scanner intelligence.

Endpoint verified · Requires authentication · 2 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

HTTP Network Access

Connects to external APIs or services over the internet.

What You'll Need

Set these up before or after installing:

A scoped Mailbuttons MCP token (mb_sandbox_...). Sandbox-by-default; external send requires human promotion.Required

Environment variable: MAILBUTTONS_API_KEY

Backend base URL. Defaults to https://mailbuttons.com; set for self-hosted or local.Optional

Environment variable: MAILBUTTONS_API_URL

How to Install & Connect

Available as Local & Remote

This plugin can run on your machine or connect to a hosted endpoint. during install.

Documentation

View on GitHub

From the project's GitHub README.

Mailbuttons MCP server

Governed email for AI agents, over the Model Context Protocol. Give an agent a scoped mailbox where the server enforces the guardrails, not the prompt: sandbox-by-default inboxes, a policy gate on every send, and a tamper-evident audit log. External sending and scope changes are human-approved, never granted by the agent itself.

Use it

Hosted (recommended) — a streamable-HTTP endpoint served by the platform:

https://mailbuttons.com/api/v1/mcp/rpc
Authorization: Bearer <your Mailbuttons MCP token>   # mb_sandbox_... (or mb_prod_...)

Local (stdio) — run the npm package and let your agent launch it:

{
  "mcpServers": {
    "mailbuttons": {
      "command": "npx",
      "args": ["-y", "@mailbuttons/mcp-server"],
      "env": { "MAILBUTTONS_API_KEY": "mb_sandbox_..." }
    }
  }
}

Get a scoped token from the dashboard or POST /api/v1/mcp/sandbox-inboxes. Sandbox tokens can never send externally until a human promotes them.

What the server enforces

  • Inbound — a per-mailbox sender policy, fail-closed: mail from strangers bounces by default, so nobody can prompt-inject your agent just by emailing it.
  • Outbound — a recipient blocklist the agent can read but not change; a blocked send returns a normal {"status":"blocked"} result, not an error.
  • Caps + audit — per-account send caps and a hash-chained audit log that records refusals too.
  • Escalation — sending externally or widening scope is propose-only; a named human approves. The agent cannot approve its own request.

Install as an agent skill

This repo ships a root SKILL.md, so any skills-aware agent can add it:

npx skills add mailbuttons/mcp-server

Docs

Mailbuttons is a trading name of Code Cutter Limited (UK, no. 08453060). MIT licensed.

Reviews

No reviews yet

Be the first to review this server!