Customer support agent
support@yourco.com answers routine questions in-thread, and a human opens the same inbox in webmail for anything tricky.
Real inboxes on your own domain — support-agent@yourco.com — that your agents read, send and reply from through a REST API, an MCP server or webhooks. Your team can open the very same inboxes in webmail.
How it works
Verify your domain once in the DNS wizard and create an API key. Then:
1. Create the inbox
curl -X POST https://havitomail.com/api/v1/inboxes \
-H "Authorization: Bearer $HAVITO_API_KEY" \
-H "Content-Type: application/json" \
-d '{"domain": "acme.com", "username": "support-agent", "name": "Acme Support Agent"}'2. Fetch unread mail
curl "https://havitomail.com/api/v1/inboxes/$INBOX_ID/messages?unread=true&limit=10" \
-H "Authorization: Bearer $HAVITO_API_KEY"3. Reply in-thread
curl -X POST https://havitomail.com/api/v1/inboxes/$INBOX_ID/messages/42/reply \
-H "Authorization: Bearer $HAVITO_API_KEY" \
-H "Content-Type: application/json" \
-d '{"text": "Thanks! Your refund was issued today."}'Use cases
support@yourco.com answers routine questions in-thread, and a human opens the same inbox in webmail for anything tricky.
Replies to inbound enquiries and demo requests within minutes, qualifies the lead, and books the call. Inbound only — not a cold-email cannon.
Forward invoices, receipts and supplier updates to ap@yourco.com; the agent extracts the data and files it in your system.
Give test or automation flows a real address that receives sign-up links and one-time codes, then read them over the API.
An assistant@ address that triages, summarises and drafts replies — on your domain, so it looks like part of your team.
Agents that sign up for tools, receive notifications or talk to vendors need an inbox that is theirs, not your personal Gmail.
Why HavitoMail
agent@yourcompany.com — authenticated with your own SPF, DKIM and DMARC, so replies look like your business and land in the inbox.
Every agent inbox is a full mailbox with IMAP/SMTP and webmail. Humans can read, audit or take over any conversation.
Create inboxes, list unread mail, send, reply in-thread, mark read — JSON over HTTPS with one Bearer key.
Connect Claude Code, Claude Desktop, Cursor or any MCP client in one command. No glue code.
A message.received event hits your URL (HMAC-SHA256 signed) within about 30 seconds of mail arriving.
20 mailboxes for $19/year (₹1,499 in India) — shared between your team and your agents. No per-seat or per-inbox fees.
Code
Fetch unread mail, let your model draft the answer, reply in the same thread, mark it handled.
// Node 18+ — poll an agent inbox and answer new mail
const API = "https://havitomail.com/api/v1";
const headers = {
Authorization: `Bearer ${process.env.HAVITO_API_KEY}`,
"Content-Type": "application/json",
};
const inboxId = process.env.INBOX_ID;
const res = await fetch(`${API}/inboxes/${inboxId}/messages?unread=true`, { headers });
const { messages } = await res.json();
for (const msg of messages) {
const answer = await myAgent.draftReply(msg.subject, msg.text); // your LLM call
await fetch(`${API}/inboxes/${inboxId}/messages/${msg.uid}/reply`, {
method: "POST",
headers,
body: JSON.stringify({ text: answer }), // threads under the original
});
await fetch(`${API}/inboxes/${inboxId}/messages/${msg.uid}`, {
method: "PATCH",
headers,
body: JSON.stringify({ seen: true }),
});
}# Python 3 — requests
import os, requests
API = "https://havitomail.com/api/v1"
H = {"Authorization": f"Bearer {os.environ['HAVITO_API_KEY']}"}
inbox = os.environ["INBOX_ID"]
msgs = requests.get(f"{API}/inboxes/{inbox}/messages",
params={"unread": "true", "limit": 20}, headers=H).json()["messages"]
for m in msgs:
answer = my_agent.draft_reply(m["subject"], m["text"]) # your LLM call
requests.post(f"{API}/inboxes/{inbox}/messages/{m['uid']}/reply",
json={"text": answer}, headers=H).raise_for_status()
requests.patch(f"{API}/inboxes/{inbox}/messages/{m['uid']}",
json={"seen": True}, headers=H)Full reference: REST API docs.
MCP
The HavitoMail MCP server turns your inboxes into tools your assistant can call — with the same API key.
get_accountShow the account, plan, limits and usage.list_domainsList your domains and whether each is verified.list_inboxesList the mailboxes on your account (people and agents).create_inboxCreate a new mailbox on one of your verified domains.list_messagesList recent messages in a folder, optionally unread only.read_messageRead one message: headers, plain text, HTML and attachment list.send_emailSend a new email from one of your mailboxes.reply_to_emailReply in-thread to a message (sets In-Reply-To and References).mark_readMark a message read (or unread), optionally moving it to another folder.Setup for every client: MCP guide.
claude mcp add --transport http havitomail https://havitomail.com/api/mcp \
--header "Authorization: Bearer hm_live_your_key_here"{
"mcpServers": {
"havitomail": {
"url": "https://havitomail.com/api/mcp",
"headers": {
"Authorization": "Bearer hm_live_your_key_here"
}
}
}
}{
"mcpServers": {
"havitomail": {
"command": "npx",
"args": [
"-y", "mcp-remote", "https://havitomail.com/api/mcp",
"--header", "Authorization: Bearer hm_live_your_key_here"
]
}
}
}Webhooks
Register a URL and receive a signed message.received event within about 30 seconds of a message arriving. Verify the HMAC-SHA256 signature, queue the work, reply when your agent is done.
// Express — verify X-Havito-Signature before trusting the payload
import crypto from "node:crypto";
import express from "express";
const app = express();
const SECRET = process.env.HAVITO_WEBHOOK_SECRET;
app.post("/havito-webhook", express.raw({ type: "application/json" }), (req, res) => {
const ts = req.header("X-Havito-Timestamp");
const sig = req.header("X-Havito-Signature") || "";
const expected = "sha256=" + crypto
.createHmac("sha256", SECRET)
.update(`${ts}.${req.body.toString("utf8")}`)
.digest("hex");
const ok = sig.length === expected.length &&
crypto.timingSafeEqual(Buffer.from(sig), Buffer.from(expected));
const fresh = Math.abs(Date.now() / 1000 - Number(ts)) < 300; // 5-minute window
if (!ok || !fresh) return res.status(401).end();
const event = JSON.parse(req.body.toString("utf8"));
// hand event.message to your agent (queue it — respond fast)
res.status(200).end();
});Compare
You can — but suite providers are built for people, not software. Here is what changes when the user is an agent.
| For agent inboxes | HavitoMail | Google Workspace | Microsoft 365 |
|---|---|---|---|
| Create a new address with one API call | Admin console or Directory API | Add a user in the admin console | |
| Simple API-key auth (no OAuth consent screens) | OAuth 2.0 + service accounts | OAuth 2.0 / Microsoft Graph | |
| Built-in MCP server for Claude / Cursor | Build or self-host one | Build or self-host one | |
| Pricing for 20 inboxes | One flat yearly price | Per user, per month | Per user, per month |
| Humans can open the same inbox | |||
| Your own domain with DKIM/SPF/DMARC | |||
| Full office suite (docs, calendar, video) |
Need docs, calendar and video too? A suite is the right tool for people. Many teams keep it for staff and put agents on HavitoMail. Longer write-up: HavitoMail API vs Gmail API.
Pricing & limits
Agent inboxes are ordinary mailboxes on your plan, shared with your team. No per-inbox or per-API-call fees.
EU-hosted
Mail is stored on servers in Strasbourg, France. We don’t scan it for ads or train models on it.
Hashed, revocable keys
API keys are shown once, stored hashed and can be revoked instantly. Use one key per agent.
Human in the loop
Every agent inbox opens in webmail, so you can audit, correct or take over any thread.
FAQ
It is a normal mailbox — such as support-agent@yourcompany.com — that software controls instead of a person. The agent reads incoming mail, decides what to do, and sends or replies through an API. With HavitoMail the mailbox is real: it has storage, IMAP/SMTP and webmail, so a human can open it any time.
Start a HavitoMail trial, verify your domain once with the DNS wizard, create an API key under Settings → API & Agents, then call POST /api/v1/inboxes with a username. The agent can then read and send mail through the REST API, the MCP server or IMAP/SMTP.
Any MCP client can connect to the HavitoMail MCP server at https://havitomail.com/api/mcp — including Claude Code, Claude Desktop (via the mcp-remote bridge) and Cursor. Frameworks that call HTTP APIs (LangChain, LlamaIndex, OpenAI or Anthropic tool calling, n8n, Make) can use the REST API directly.
Agent inboxes are ordinary mailboxes on your plan. Pro is $19/year (₹1,499/year in India) for 20 mailboxes on up to 5 domains, shared between people and agents. There is a 14-day free trial with 1 mailbox, no credit card needed to start.
No. HavitoMail is for conversational mail — support, operations, assistants and replying to inbound. Sending is capped at 50 recipients per message and, on Pro, 100 recipients per hour and 500 per day per mailbox. Bulk and cold-email blasting are not allowed; that is what keeps deliverability good for every customer.
Either poll GET /inboxes/{id}/messages?unread=true, or register a webhook and receive a signed message.received POST within about 30 seconds of the message arriving.
Mail is stored on HavitoMail’s servers in Strasbourg, France (EU). We do not scan mail for advertising and do not train AI models on it. Your agent only sees what you send it through the API key you created.
Treat every incoming email as untrusted input, since a message can contain instructions aimed at your agent. Give each agent its own inbox and API key, keep a human approval step for sensitive actions, and revoke a key instantly if something looks wrong.
Start the 14-day trial, verify your domain, create an API key — your first agent can be reading mail in minutes.