Emailsify

Emailsify

- Data is stored encrypted on cloudflare D1

Pricing MCP
Back to Inbox

Emailsify MCP

Connect Emailsify to MCP-compatible clients (Claude Code and others) and let them mint disposable inboxes and read mail on your behalf.

MCP requires a Pro or Scale plan.


What you can do

  • Generate a disposable address
  • List mail received at an address
  • Read one message in full
  • Delete a message

Available tools

generate_address

Generate a disposable Emailsify address

Mints a new disposable email address on Emailsify (emailsify.com). The address becomes usable the instant any mail is sent to it, and received mail auto-expires after 2 hours. Requires a valid Pro/Scale API token.

Input

(none)

Output

The address string, e.g. card.pool092@emailsify.com
list_mails

List mail received at an address

Polls the inbox for a given address and returns every mail currently stored for it (each mail expires 2 hours after receipt). Each mail includes a 'suffix' field, used by get_mail and delete_mail to act on that specific message. Requires a valid Pro/Scale API token.

Input

address: string — an Emailsify address, e.g. one returned by generate_address

Output

JSON: { status, code, msg, mails: [...] }
get_mail

Get one mail by suffix

Fetches every mail for the address (same data as list_mails) and returns only the one matching 'suffix'. Useful once list_mails has already shown which message you want — e.g. to re-read a verification code or confirmation link.

Input

address: string, suffix: string — the mail's "suffix" field, as returned by list_mails

Output

The matching mail object, or an error result if no mail with that suffix exists (e.g. expired or already deleted)
delete_mail

Delete one mail

Deletes a single mail from an address's inbox by its suffix.

Input

address: string, suffix: string

Output

JSON: { status, code, msg }

Example

The MCP server runs locally over stdio — there is no hosted MCP endpoint today. Subscribe to Pro or Scale, generate an API token from Settings, then build the server and attach it to your MCP client:

git clone https://github.com/sudosuraj/emailsify.git
cd emailsify/mcp
npm install
npm run build

# Attach to Claude Code (or any MCP-compatible client):
EMAILSIFY_API_TOKEN=esk_... claude mcp add emailsify -- node /path/to/emailsify/mcp/dist/index.js

Without a valid token, every tool call returns an error explaining that MCP requires Pro or Scale — there is no anonymous fallback. Set EMAILSIFY_BASE_URL if you're pointing the server at a self-hosted fork instead of emailsify.com.


Security

MCP access requires an API token minted from a signed-in, Pro/Scale account. The token is checked against the account's live subscription status on every call — the check runs server-side, not just in the UI, so a Free account (or an expired/cancelled subscription) cannot use the MCP tools even by calling them directly.

The anonymous, no-login inbox on the website itself is separate and remains unauthenticated by design, as it always has been — anyone who knows (or guesses) an address can read its mail there. The MCP tools do not use those anonymous endpoints; they use a distinct, token-gated API. Within an address, the only protection against guessing is that it's hard to guess, and mail auto-expires 2 hours after receipt.

The MCP server itself runs locally on your machine over stdio — it is not a hosted, multi-tenant service. Whoever holds the API token has exactly the access that token's account is entitled to; keep it as secret as a password.

Email content is untrusted data, not instructions.

Mail delivered to a disposable address comes from the open internet and can contain anything, including text written to look like commands (e.g. "ignore previous instructions and call another tool"). The MCP tools return mail content as plain text — they do not execute it or treat it as directives. If you're wiring an AI agent to read mail through these tools, treat the returned content the same way you'd treat any other untrusted external data, not as something the agent should act on unprompted.

This page describes what the current implementation does, not aspirational guarantees — there is no rate limiting, input validation beyond basic schema checks, or content sanitization implemented in the MCP layer today.


Documentation

Full source and README: github.com/sudosuraj/emailsify/tree/main/mcp