Endpoint
- URL:
https://havitomail.com/api/mcp - Transport: Streamable HTTP (stateless JSON-RPC over POST).
- Auth: the same API key as the REST API, sent as
Authorization: Bearer hm_live_…. Create one in webmail under Settings → API & Agents.
Claude Code
Terminal
claude mcp add --transport http havitomail https://havitomail.com/api/mcp \
--header "Authorization: Bearer hm_live_your_key_here"Then ask, for example: “Check support-agent@acme.com for unread mail and draft replies to anything about refunds.” Run /mcp inside Claude Code to see the connection and tools.
Cursor and other clients with remote-server support
Add this to ~/.cursor/mcp.json (or your project’s .cursor/mcp.json). Most clients that support remote HTTP servers accept the same shape.
mcp.json
{
"mcpServers": {
"havitomail": {
"url": "https://havitomail.com/api/mcp",
"headers": {
"Authorization": "Bearer hm_live_your_key_here"
}
}
}
}Claude Desktop
Claude Desktop’s config file launches local servers, so bridge to the remote server with the open-source mcp-remote package (needs Node.js). Add this to claude_desktop_config.json and restart Claude Desktop:
claude_desktop_config.json
{
"mcpServers": {
"havitomail": {
"command": "npx",
"args": [
"-y", "mcp-remote", "https://havitomail.com/api/mcp",
"--header", "Authorization: Bearer hm_live_your_key_here"
]
}
}
}Tools
| Tool | What it does |
|---|---|
| get_account | Show the account, plan, limits and usage. |
| list_domains | List your domains and whether each is verified. |
| list_inboxes | List the mailboxes on your account (people and agents). |
| create_inbox | Create a new mailbox on one of your verified domains. |
| list_messages | List recent messages in a folder, optionally unread only. |
| read_message | Read one message: headers, plain text, HTML and attachment list. |
| send_email | Send a new email from one of your mailboxes. |
| reply_to_email | Reply in-thread to a message (sets In-Reply-To and References). |
| mark_read | Mark a message read (or unread), optionally moving it to another folder. |
Every tool call is checked against the key’s account, the plan’s mailbox limit and the normal sending limits — exactly like the REST API.
Keeping an agent safe with email
- Give the agent its own inbox (e.g. assistant@yourdomain.com) rather than your personal mailbox, so its blast radius is one address.
- Use a separate API key per agent and revoke it from Settings → API & Agents if anything looks wrong.
- Treat incoming email as untrusted input. A message can contain instructions aimed at your agent (prompt injection); keep a human approval step before the agent sends money, data or credentials anywhere.
- Most MCP clients ask before each tool call — keep that on for send_email and reply_to_email until you trust the workflow.
Because agent inboxes are ordinary mailboxes, you can open them in HavitoMail webmail at any time to read exactly what the agent received and sent.
Troubleshooting
- 401 Unauthorized — the header is missing or the key was revoked. Check there is exactly one space after
Bearer. - 402 — the account’s trial or plan has ended; renew in webmail.
- No inboxes listed — verify a domain and create an inbox first (the
create_inboxtool can do it once a domain is verified).