Sign in

Setup guide

From sign-in to your agent’s first message with em[ai]l.

1.Create an address

Sign in with your Google account and start the free trial; it needs no card. Sign-in only identifies you: the service requests no permission to read, send from or change your mailbox.

Under 02 / addresses, enter the email address you will forward from and choose Create private address. The alias is random, and it is the only address your agent will be able to read.

2.Forward the email you choose

Forwarding happens in your own email settings, so you decide what leaves your inbox. The workspace walks you through it under 03 / email setup:

  1. 1 Open email settings

    In your email on your computer, choose the gear, then See all settings.

  2. 2 Add your alias

    Open Forwarding or Forwarding and POP/IMAP. Choose Add a forwarding address and paste your alias. Your email service may ask you to sign in again or confirm with two-step verification.

  3. 3 Confirm the destination

    A verification email arrives at your alias. During an active setup session, the service automatically confirms the destination. If setup has not started or has expired, use the confirmation button beside your address, then resend the verification email from your email settings. Wait for “Forwarding destination confirmed” beside your address, then force-reload your email settings tab (hold Shift while reloading) so it shows the alias as verified.

  4. 4 Forward what you choose

    After confirmation, create an email filter for the messages your agent needs. Choose Forward it to your alias and keep your email copy.

You can also forward single messages by hand, or forward the messages you label with a script that runs in your own account (Forward by label instead in the workspace). Remove the filter at any time to stop forwarding.

3.Connect your agent

Each address has its own MCP server URL, shown under 04 / agent connection: https://mcp.eml.ai/<address-id>. The address ID is not your alias. Agents connect with OAuth: your client opens a browser, you sign in and approve one address, and there is no key to copy. To connect more than one address, give each a distinct connection name, such as eml-work, in every command.

Claude Code

claude mcp add --transport http --scope user eml https://mcp.eml.ai/<address-id>

Open Claude Code, run /mcp, select eml and choose Authenticate. Approve the address in your browser, then ask your agent to run whoami.

Codex

codex mcp add eml --url https://mcp.eml.ai/<address-id>
codex mcp login eml --scopes messages:read,offline_access

Complete the browser approval, then ask your agent to run whoami.

Meta Muse

Add a custom connector with the full server URL, choose OAuth, enter muse as the client ID and leave the client secret empty. Start authorization from Muse and approve the address.

Other MCP clients

Add the server URL as a remote Streamable HTTP server and choose OAuth. Clients that register themselves automatically need nothing else. If yours asks for a client ID, write to support@eml.ai with the client’s name and callback URL.

Scripts and headless agents

An agent that cannot open a browser can use a named key from Manual keys for headless agents, sent as a Bearer token. A key works only for its address. Keep it in the client’s private configuration, never in source control or the URL.

4.What your agent can do

  • whoami: the one address this connection can read, its retention and permissions
  • search_messages: find mail by words, subject, sender, label or receipt date
  • get_message and get_thread: read a message or the retained conversation around it, in bounded chunks
  • get_attachment_text: a text preview of a PDF, CSV, JSON or plain-text attachment
  • get_attachment_link: a short-lived download link for an original file, when the connection allows downloads
  • create_draft, list_drafts and get_draft: save a reply or new message for you to review and send from your own email client
  • get_message_state and set_message_state: a progress status and labels kept in em[ai]l, not your mailbox, so the agent can pick up where it left off

There is no tool that sends mail, deletes mail or reaches another address, and every request is recorded in the address’s access log. Original-file downloads and saved workflows (drafts and progress labels) can be turned off for each connection under Connection permissions.

Anyone who learns your alias can send mail to it, and a sender can be forged, so your agent receives everything it reads marked as untrusted. The security model lists what the service does and does not protect against, and why a filtered view explains the risk it is designed around.

5.Stop or remove access

Removing the server from your client does not revoke its access. Use Disconnect under Connected agents, or revoke the key. To stop mail arriving, remove the forwarding filter in your email settings or pause the address in Manage address. Deleting an address destroys the keys its stored mail was encrypted under.