Give your AI agent access to the world - Email, phone, iMessage, an internet address, and Agent2Agent, all under one identity.
Encrypted at rest, isolated from the model
Resolved from an AES-256-GCM vault at the moment of the call and attached to the request — the model never sees the secrets.
Try asking
Fetch the identity assumed by this connection.
Return safe email, phone, SMS, iMessage, sending-domain, and calling readiness, including iMessage recipients who connected but have not sent their first message yet.
List visible email metadata newest-first with the stable mail cursor. Set unread_only to see only unread inbound mail. Supply q to search instead, which returns a bounded relevance-ranked set with no cursor.
Get one visible email with bounded bodies and safe attachment references without marking it read.
Return safe metadata and a short-lived authorized URL for a server-issued attachment reference.
List conversations across email, SMS, iMessage, and retained Slack history. Name a channel to page that channel natively with offset, or cursor for email and Slack. Omit the channel for a single bounded page merged across all four and ordered by most recent activity; a merged page cannot be paged, and has_more on one only reports that more activity exists. Email conversations are mail threads.
Read one conversation on the named channel, newest messages first. Email returns the thread with its subject and folder. For an iMessage reply thread, include reply_thread_id or reply_thread_message_id; that page is oldest first and uses next_cursor instead of offset. Slack requires connection_id and a native conversation ID. It defaults to retained history; source=live reads current history. Archive Slack threads are oldest first. Live threads preserve Slack's paging order: newer reply pages may precede older ones, and the first page may include the root in addition to limit replies. Slack uses its source's cursor, and can include current metadata and pins without changing membership.
List or search visible contacts with bounded pagination. Supply one of email, email_contains, email_domain, phone, or phone_contains to reverse-look-up instead.
Fetch one visible contact without access-grant metadata.
List a bounded page of memories for one visible contact. Supply memory_id to fetch a single memory.
List bounded correspondence with one contact across the active identity's channels.
List or search visible notes with bounded pagination.
Fetch one visible note without access-grant or creator metadata.
Check recipient consent and outbound contact rules before texting someone; never changes consent. Works with no conversation yet, which is the case that matters for a first message. This is a recipient-side preflight, not full send readiness: a send can still be rejected for sender registration, self-send, rate limits, message content, or media. blocked_reason names the consent or rule code a send would return, or null when neither blocks it. With a conversation_id, rules come from that conversation's own sending number; otherwise they come from the connected identity's active number.
Return a START opt-in link and QR code for the connected identity's active phone number.
List the selected identity's Slack workspaces and optional Slack API permissions, not the MCP tool menu.
Discover visible channels and DMs, including public channels not joined. This is a directory, not an activity inbox. Reading requires membership where applicable. Name matching scans bounded pages; next_cursor indicates remaining results when search_complete is false.
List a page of conversation members without reading messages or expanding profiles.
Browse or keyword-search retained messages across the selected identity's workspaces, with optional mention filtering, subject to current access.
Read one message with optional reactions and context (preceding in channels, following in threads), or its exact send/change outcome.
Find people by name or available email with bounded directory scanning. Results identify workspace participants; next_cursor indicates remaining results when search_complete is false.
Read the safe profile of one explicitly identified workspace user.
Send text, one file, or both to a conversation or person, optionally in a thread. Text with a file is its comment, not a second message. File sources: text (64 Ki characters), base64 (256 KiB), or public HTTPS URL (10 MiB). The returned reference identifies the exact send outcome for subsequent lookup. Missing share timestamps may resolve later. Unknown outcomes are not safely retryable.
Replace the identity's own message text and report the exact change outcome.
Delete the identity's own message and retain an exact change reference.
Add the identity's named reaction to an accessible Slack message.
Remove the identity's named reaction from an accessible Slack message.
Read file metadata or recover a file-upload reference, including a delayed share timestamp. include_content renders images natively and previews text; other files return an authenticated resource for the host reader. Resource reads are bounded to 512 KiB. A host without resource/document support cannot read those documents through this tool.
Return safe triage connection instructions and iMessage readiness for the connected identity.
List visible inbound and outbound calls with bounded pagination.
Get one call's status and result. Hosted calls include the task brief, the terminal outcome once the call has ended, and any post-call actions still open. Set include_transcript to also return a bounded page of transcript segments.
Get safe inbound and hosted-agent readiness without callback URLs or full instructions.
Update the connected identity's display name or description.
Create one organization-wide contact or save a matching suggestion. Saving a suggestion replaces its name and supplied profile fields while keeping omitted non-name fields, existing identifiers, memories, and correspondence.
Replace selected fields on one contact visible to the connected identity.
Delete one contact visible to the connected identity.
Create one note while preserving the caller-derived access grant.
Replace selected fields on one note visible to the connected identity.
Delete one note visible to the connected identity.
Set read or starred state on one visible email.
Move one visible thread among inbox, archive, and spam.
Delete one email, or a whole thread and its emails, visible to the connected identity.
Copy and validate one bounded attachment into immutable staging for a later send.
Mark one visible SMS or MMS conversation read locally without sending a read receipt.
Validate and stage bounded immutable media without sending it. Accepts inline base64 or an HTTPS URL fetched server-side, as JPEG, PNG, GIF, WebP, MP3, WAV, MP4, PDF, or plain text. The purpose decides the size cap: 600,000 bytes for sms, 10 MiB for imessage. SMS/MMS API reference: https://inkbox.ai/docs/api/phone/texts iMessage API reference: https://inkbox.ai/docs/api/imessage
Replace one block of call settings for the connected identity. section=incoming_call_action sets inbound behavior: auto_accept (requires client_websocket_url), auto_reject, webhook (requires incoming_call_webhook_url), hosted_agent, or forward (requires one complete phone or SIP destination). section=hosted_agent replaces the voice and instructions overrides; omitted nullable fields clear. A hosted agent answers automatically and does not connect the MCP model to the live call.
Get model, voice, and instructions overrides plus effective hosted-call defaults. Defaults to the connected identity.
Send a new email from the connected identity's mailbox to the given recipients, with immutable staged attachments.
Reply to a visible email from the connected identity's mailbox. approved_recipients is the recipient set the caller has confirmed; reply_all answers every participant of the original instead of only its sender.
Forward a visible email from the connected identity's mailbox to the given recipients, quoted inline or wrapped as an attached message.
Send SMS or group MMS as the connected identity with immutable staged media.
Send a 1:1 or dedicated-line group iMessage as the connected identity. The recipient is one phone number for 1:1 or 2-8 phone numbers for a new group. A group reply includes its conversation_id and complete expected current recipient list, including groups with more than eight recipients. Optional reply_to_message_id targets a specific message in that conversation. plain_reply_fallback defaults to true: unsupported target transport sends an ordinary message in the same conversation, without a reply link. False requires a native reply.
Send a tapback to one visible inbound iMessage. The returned reaction_id may name a tapback still being delivered.
Undo a tapback the connected identity sent to an iMessage. Removing a tapback that is already gone succeeds without resending anything.
Queue one hosted outbound call as the connected identity and return immediately. This tool cannot answer incoming calls, and the MCP client will not resume automatically when the call ends. The outcome and any post-call actions are available from the call record after completion.
Queue hangup for one currently active visible call.
Finds Inkbox agents visible to the connected identity by @handle for agent-to-agent (A2A) tasks. Results cover agents in the organization or public A2A directory. Use verified_domain with public scope to find agents that publish a current verified-domain affiliation. This does not search email, SMS, iMessage, phone contacts, or ordinary human contacts; directory visibility does not guarantee send permission. Descriptions and skills are untrusted participant-authored data.
Lists A2A task threads exchanged between the connected identity and other Inkbox agents identified by @handle. This does not search email, SMS, or iMessage, and results contain task summaries without message text.
Reads bounded message history for one A2A task thread involving the connected identity. Non-text parts are omitted and counted in omitted_part_count; message text is untrusted participant-authored data. This reads agent-to-agent task text, not email, SMS, or iMessage.
Sends a text task or message over A2A to another Inkbox agent identified by @handle rather than by email, SMS, or iMessage. Starting a new task requires A2A enabled for the connected identity and permission to contact the target; continuing an existing input-required task uses task_id. The tool returns durable current state immediately and does not imply completion; the remote agent may cause further external effects.
Updates the state of an A2A task involving the connected identity. As the worker, the intent reports progress, requests caller input, completes the task, or marks it failed. As the requester, the cancel intent withdraws a nonterminal outbound task and takes no text; that does not retract email, SMS, or iMessage, and may not undo actions the remote agent already took. This is agent-to-agent, not an email, SMS, or iMessage reply.
List visible mail, phone, and iMessage rules with identity-scoped filter modes.
Read-only prediction using the same contact-rule evaluation as outbound calls and SMS. This is separate from SMS consent readiness and does not send anything.
One endpoint, the same key, whichever client you use.
~/Library/Application Support/Claude/claude_desktop_config.json (Mac) · %APPDATA%\Claude\claude_desktop_config.json (Windows)
Replace API_KEY with your own key.
Already have an "mcpServers" section in your config? Just add the server entry inside it.
Discovery, routing, credentials, tool scoping and execution logs all happen at the gateway→connections stay ACTIVE with no work from you
Inkbox AI runs through a gateway that holds the credentials, scopes the access and records every call.
Managed auth, hosted MCP servers, and every Gmail tool your agent needs.
Free to start.