{
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-10",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "tool": {
    "slug": "inboxapi",
    "name": "InboxAPI",
    "vendor": "Sitka Capital Pty Ltd",
    "vendorUrl": "https://inboxapi.ai",
    "kind": "mcp",
    "category": "agent-inboxes",
    "summary": "InboxAPI gives an AI agent its own email address on a subdomain of inboxapi.ai for sending, receiving, searching, replying and forwarding. Access is through MCP, by a local CLI that bridges stdio to the hosted service.",
    "url": "https://www.anchorterminal.com/tools/inboxapi",
    "markdownUrl": "https://www.anchorterminal.com/tools/inboxapi.md",
    "slimMarkdownUrl": "https://www.anchorterminal.com/tools/inboxapi.min.md",
    "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/inboxapi.json",
    "repo": "https://github.com/inboxapi/cli",
    "license": "Proprietary hosted service under InboxAPI's terms of service. The CLI on GitHub is MIT",
    "transports": [
      "stdio",
      "streamable-http"
    ],
    "remoteUrl": "https://mcp.inboxapi.ai/mcp",
    "packages": [
      {
        "registry": "npm",
        "name": "@inboxapi/cli"
      }
    ],
    "auth": "none",
    "authNotes": "Nothing to obtain. On first run the CLI computes a 20-bit hashcash stamp, creates an account with a generated name, and stores an access and a refresh token in a local credentials file written with mode 0600. It adds the token to every tool call and refreshes it, so the model never handles a credential. Tokens cover the whole account with no scopes. Linking an owner's address with `inboxapi verify-owner` (a six-digit code by email) is the only way to recover an account whose credentials file is lost.",
    "pricing": "free",
    "pricingNotes": "Free, with no card, no trial period and no usage tiers, per the home page and FAQ. No paid plan is on sale, and the FAQ says paid plans with more capabilities are planned. An account has five slots for external recipients, 100 requests a minute, and daily and hourly send quotas whose numbers aren't published (https://inboxapi.ai/limits/).",
    "priceSummary": "Free",
    "where": "both",
    "x402": {
      "level": "no",
      "evidence": "No x402, MPP or L402 in the docs, `llms.txt`, the 27 tool definitions or the CLI source. An unauthenticated `tools/list` call to https://mcp.inboxapi.ai/mcp returned 200 with the tool list, not a payment challenge (checked 2026-10-09).",
      "endpoints": []
    },
    "toolCount": 21,
    "popularity": {
      "githubStars": 12,
      "npmWeekly": 38,
      "pypiWeekly": null,
      "asOf": "2026-10-09"
    },
    "docsUrl": "https://inboxapi.ai/getting-started/",
    "mcpTools": {
      "url": "https://mcp.inboxapi.ai/mcp",
      "checkedAt": "2026-10-09T21:40:44.089418719Z",
      "status": "ok",
      "note": "answered without the initialize handshake",
      "tools": [
        {
          "name": "auth_revoke_all"
        },
        {
          "name": "rotate_encryption_secret"
        },
        {
          "name": "search_emails"
        },
        {
          "name": "get_addressbook"
        },
        {
          "name": "delete_email"
        },
        {
          "name": "send_email"
        },
        {
          "name": "forward_email"
        },
        {
          "name": "verify_owner"
        },
        {
          "name": "auth_introspect"
        },
        {
          "name": "auth_refresh"
        },
        {
          "name": "get_thread"
        },
        {
          "name": "custom_domain_claim"
        },
        {
          "name": "auth_exchange"
        },
        {
          "name": "get_email"
        },
        {
          "name": "enable_encryption"
        },
        {
          "name": "get_emails"
        },
        {
          "name": "get_attachment"
        },
        {
          "name": "get_announcements"
        },
        {
          "name": "get_last_email"
        },
        {
          "name": "account_create"
        },
        {
          "name": "reset_encryption"
        },
        {
          "name": "get_sent_emails"
        },
        {
          "name": "account_recover"
        },
        {
          "name": "get_email_count"
        },
        {
          "name": "send_reply"
        },
        {
          "name": "help"
        },
        {
          "name": "auth_revoke"
        }
      ],
      "schemaTokens": 6687,
      "changedAt": "2026-10-09T21:40:44.089418719Z",
      "check": {
        "checker": "anchor-check/1.0",
        "totalTokens": 6687,
        "counts": {
          "error": 2,
          "note": 1,
          "warn": 56
        },
        "findings": [
          {
            "rule": "TC19",
            "severity": "error",
            "tool": "forward_email",
            "message": "the definition asks the model to pass secrets as an argument",
            "fix": "Describe the tool; don't instruct the model."
          },
          {
            "rule": "TC19",
            "severity": "error",
            "tool": "send_reply",
            "message": "the definition asks the model to pass secrets as an argument",
            "fix": "Describe the tool; don't instruct the model."
          },
          {
            "rule": "TC11",
            "severity": "warn",
            "tool": "account_create",
            "message": "1 parameter without a description: name",
            "fix": "Describe each one: format, units, an example, and what happens when it's left out."
          },
          {
            "rule": "TC11",
            "severity": "warn",
            "tool": "auth_exchange",
            "message": "none of its 2 parameters has a description",
            "fix": "Describe each one: format, units, an example, and what happens when it's left out."
          },
          {
            "rule": "TC11",
            "severity": "warn",
            "tool": "auth_introspect",
            "message": "its one parameter, token, has no description",
            "fix": "Describe each one: format, units, an example, and what happens when it's left out."
          },
          {
            "rule": "TC11",
            "severity": "warn",
            "tool": "auth_refresh",
            "message": "none of its 2 parameters has a description",
            "fix": "Describe each one: format, units, an example, and what happens when it's left out."
          },
          {
            "rule": "TC11",
            "severity": "warn",
            "tool": "auth_revoke",
            "message": "its one parameter, token, has no description",
            "fix": "Describe each one: format, units, an example, and what happens when it's left out."
          },
          {
            "rule": "TC11",
            "severity": "warn",
            "tool": "auth_revoke_all",
            "message": "its one parameter, access_token, has no description",
            "fix": "Describe each one: format, units, an example, and what happens when it's left out."
          },
          {
            "rule": "TC11",
            "severity": "warn",
            "tool": "delete_email",
            "message": "1 parameter without a description: token",
            "fix": "Describe each one: format, units, an example, and what happens when it's left out."
          },
          {
            "rule": "TC11",
            "severity": "warn",
            "tool": "enable_encryption",
            "message": "its one parameter, token, has no description",
            "fix": "Describe each one: format, units, an example, and what happens when it's left out."
          },
          {
            "rule": "TC11",
            "severity": "warn",
            "tool": "forward_email",
            "message": "2 parameters without a description: domain, token",
            "fix": "Describe each one: format, units, an example, and what happens when it's left out."
          },
          {
            "rule": "TC11",
            "severity": "warn",
            "tool": "get_addressbook",
            "message": "none of its 2 parameters has a description",
            "fix": "Describe each one: format, units, an example, and what happens when it's left out."
          },
          {
            "rule": "TC11",
            "severity": "warn",
            "tool": "get_announcements",
            "message": "none of its 2 parameters has a description",
            "fix": "Describe each one: format, units, an example, and what happens when it's left out."
          },
          {
            "rule": "TC11",
            "severity": "warn",
            "tool": "get_email_count",
            "message": "2 parameters without a description: domain, token",
            "fix": "Describe each one: format, units, an example, and what happens when it's left out."
          },
          {
            "rule": "TC11",
            "severity": "warn",
            "tool": "get_emails",
            "message": "2 parameters without a description: domain, token",
            "fix": "Describe each one: format, units, an example, and what happens when it's left out."
          },
          {
            "rule": "TC11",
            "severity": "warn",
            "tool": "get_last_email",
            "message": "2 parameters without a description: domain, token",
            "fix": "Describe each one: format, units, an example, and what happens when it's left out."
          },
          {
            "rule": "TC11",
            "severity": "warn",
            "tool": "get_sent_emails",
            "message": "3 parameters without a description: limit, offset, token",
            "fix": "Describe each one: format, units, an example, and what happens when it's left out."
          },
          {
            "rule": "TC11",
            "severity": "warn",
            "tool": "get_thread",
            "message": "2 parameters without a description: domain, token",
            "fix": "Describe each one: format, units, an example, and what happens when it's left out."
          },
          {
            "rule": "TC11",
            "severity": "warn",
            "tool": "reset_encryption",
            "message": "1 parameter without a description: token",
            "fix": "Describe each one: format, units, an example, and what happens when it's left out."
          },
          {
            "rule": "TC11",
            "severity": "warn",
            "tool": "rotate_encryption_secret",
            "message": "none of its 3 parameters has a description",
            "fix": "Describe each one: format, units, an example, and what happens when it's left out."
          },
          {
            "rule": "TC11",
            "severity": "warn",
            "tool": "search_emails",
            "message": "4 parameters without a description: domain, limit, offset, token",
            "fix": "Describe each one: format, units, an example, and what happens when it's left out."
          },
          {
            "rule": "TC15",
            "severity": "warn",
            "tool": "forward_email",
            "message": "inputSchema uses $ref/$defs",
            "fix": "Inline the referenced schemas. Pydantic and zod-to-json-schema emit $defs for nested models; most can be told not to."
          },
          {
            "rule": "TC15",
            "severity": "warn",
            "tool": "get_email",
            "message": "inputSchema uses $ref/$defs",
            "fix": "Inline the referenced schemas. Pydantic and zod-to-json-schema emit $defs for nested models; most can be told not to."
          },
          {
            "rule": "TC15",
            "severity": "warn",
            "tool": "get_emails",
            "message": "inputSchema uses $ref/$defs",
            "fix": "Inline the referenced schemas. Pydantic and zod-to-json-schema emit $defs for nested models; most can be told not to."
          },
          {
            "rule": "TC15",
            "severity": "warn",
            "tool": "get_last_email",
            "message": "inputSchema uses $ref/$defs",
            "fix": "Inline the referenced schemas. Pydantic and zod-to-json-schema emit $defs for nested models; most can be told not to."
          },
          {
            "rule": "TC15",
            "severity": "warn",
            "tool": "get_sent_emails",
            "message": "inputSchema uses $ref/$defs",
            "fix": "Inline the referenced schemas. Pydantic and zod-to-json-schema emit $defs for nested models; most can be told not to."
          },
          {
            "rule": "TC15",
            "severity": "warn",
            "tool": "get_thread",
            "message": "inputSchema uses $ref/$defs",
            "fix": "Inline the referenced schemas. Pydantic and zod-to-json-schema emit $defs for nested models; most can be told not to."
          },
          {
            "rule": "TC15",
            "severity": "warn",
            "tool": "search_emails",
            "message": "inputSchema uses $ref/$defs",
            "fix": "Inline the referenced schemas. Pydantic and zod-to-json-schema emit $defs for nested models; most can be told not to."
          },
          {
            "rule": "TC15",
            "severity": "warn",
            "tool": "send_email",
            "message": "inputSchema uses $ref/$defs",
            "fix": "Inline the referenced schemas. Pydantic and zod-to-json-schema emit $defs for nested models; most can be told not to."
          },
          {
            "rule": "TC15",
            "severity": "warn",
            "tool": "send_reply",
            "message": "inputSchema uses $ref/$defs",
            "fix": "Inline the referenced schemas. Pydantic and zod-to-json-schema emit $defs for nested models; most can be told not to."
          },
          {
            "rule": "TC16",
            "severity": "warn",
            "tool": "account_create",
            "message": "no readOnlyHint or destructiveHint",
            "fix": "Set readOnlyHint: true if it only reads; otherwise set destructiveHint and idempotentHint."
          },
          {
            "rule": "TC16",
            "severity": "warn",
            "tool": "account_recover",
            "message": "no readOnlyHint or destructiveHint",
            "fix": "Set readOnlyHint: true if it only reads; otherwise set destructiveHint and idempotentHint."
          },
          {
            "rule": "TC16",
            "severity": "warn",
            "tool": "auth_exchange",
            "message": "no readOnlyHint or destructiveHint",
            "fix": "Set readOnlyHint: true if it only reads; otherwise set destructiveHint and idempotentHint."
          },
          {
            "rule": "TC16",
            "severity": "warn",
            "tool": "auth_introspect",
            "message": "no readOnlyHint or destructiveHint",
            "fix": "Set readOnlyHint: true if it only reads; otherwise set destructiveHint and idempotentHint."
          },
          {
            "rule": "TC16",
            "severity": "warn",
            "tool": "auth_refresh",
            "message": "no readOnlyHint or destructiveHint",
            "fix": "Set readOnlyHint: true if it only reads; otherwise set destructiveHint and idempotentHint."
          },
          {
            "rule": "TC16",
            "severity": "warn",
            "tool": "auth_revoke",
            "message": "no readOnlyHint or destructiveHint",
            "fix": "Set readOnlyHint: true if it only reads; otherwise set destructiveHint and idempotentHint."
          },
          {
            "rule": "TC16",
            "severity": "warn",
            "tool": "auth_revoke_all",
            "message": "no readOnlyHint or destructiveHint",
            "fix": "Set readOnlyHint: true if it only reads; otherwise set destructiveHint and idempotentHint."
          },
          {
            "rule": "TC16",
            "severity": "warn",
            "tool": "custom_domain_claim",
            "message": "no readOnlyHint or destructiveHint",
            "fix": "Set readOnlyHint: true if it only reads; otherwise set destructiveHint and idempotentHint."
          },
          {
            "rule": "TC16",
            "severity": "warn",
            "tool": "delete_email",
            "message": "no readOnlyHint or destructiveHint",
            "fix": "Set readOnlyHint: true if it only reads; otherwise set destructiveHint and idempotentHint."
          },
          {
            "rule": "TC16",
            "severity": "warn",
            "tool": "enable_encryption",
            "message": "no readOnlyHint or destructiveHint",
            "fix": "Set readOnlyHint: true if it only reads; otherwise set destructiveHint and idempotentHint."
          },
          {
            "rule": "TC16",
            "severity": "warn",
            "tool": "forward_email",
            "message": "no readOnlyHint or destructiveHint",
            "fix": "Set readOnlyHint: true if it only reads; otherwise set destructiveHint and idempotentHint."
          },
          {
            "rule": "TC16",
            "severity": "warn",
            "tool": "get_addressbook",
            "message": "no readOnlyHint or destructiveHint",
            "fix": "Its name starts with \"get\"; if it only reads, set readOnlyHint: true so harnesses can run it without asking."
          },
          {
            "rule": "TC16",
            "severity": "warn",
            "tool": "get_announcements",
            "message": "no readOnlyHint or destructiveHint",
            "fix": "Its name starts with \"get\"; if it only reads, set readOnlyHint: true so harnesses can run it without asking."
          },
          {
            "rule": "TC16",
            "severity": "warn",
            "tool": "get_attachment",
            "message": "no readOnlyHint or destructiveHint",
            "fix": "Its name starts with \"get\"; if it only reads, set readOnlyHint: true so harnesses can run it without asking."
          },
          {
            "rule": "TC16",
            "severity": "warn",
            "tool": "get_email",
            "message": "no readOnlyHint or destructiveHint",
            "fix": "Its name starts with \"get\"; if it only reads, set readOnlyHint: true so harnesses can run it without asking."
          },
          {
            "rule": "TC16",
            "severity": "warn",
            "tool": "get_email_count",
            "message": "no readOnlyHint or destructiveHint",
            "fix": "Its name starts with \"get\"; if it only reads, set readOnlyHint: true so harnesses can run it without asking."
          },
          {
            "rule": "TC16",
            "severity": "warn",
            "tool": "get_emails",
            "message": "no readOnlyHint or destructiveHint",
            "fix": "Its name starts with \"get\"; if it only reads, set readOnlyHint: true so harnesses can run it without asking."
          },
          {
            "rule": "TC16",
            "severity": "warn",
            "tool": "get_last_email",
            "message": "no readOnlyHint or destructiveHint",
            "fix": "Its name starts with \"get\"; if it only reads, set readOnlyHint: true so harnesses can run it without asking."
          },
          {
            "rule": "TC16",
            "severity": "warn",
            "tool": "get_sent_emails",
            "message": "no readOnlyHint or destructiveHint",
            "fix": "Its name starts with \"get\"; if it only reads, set readOnlyHint: true so harnesses can run it without asking."
          },
          {
            "rule": "TC16",
            "severity": "warn",
            "tool": "get_thread",
            "message": "no readOnlyHint or destructiveHint",
            "fix": "Its name starts with \"get\"; if it only reads, set readOnlyHint: true so harnesses can run it without asking."
          },
          {
            "rule": "TC16",
            "severity": "warn",
            "tool": "help",
            "message": "no readOnlyHint or destructiveHint",
            "fix": "Set readOnlyHint: true if it only reads; otherwise set destructiveHint and idempotentHint."
          },
          {
            "rule": "TC16",
            "severity": "warn",
            "tool": "reset_encryption",
            "message": "no readOnlyHint or destructiveHint",
            "fix": "Set readOnlyHint: true if it only reads; otherwise set destructiveHint and idempotentHint."
          },
          {
            "rule": "TC16",
            "severity": "warn",
            "tool": "rotate_encryption_secret",
            "message": "no readOnlyHint or destructiveHint",
            "fix": "Set readOnlyHint: true if it only reads; otherwise set destructiveHint and idempotentHint."
          },
          {
            "rule": "TC16",
            "severity": "warn",
            "tool": "search_emails",
            "message": "no readOnlyHint or destructiveHint",
            "fix": "Its name starts with \"search\"; if it only reads, set readOnlyHint: true so harnesses can run it without asking."
          },
          {
            "rule": "TC16",
            "severity": "warn",
            "tool": "send_email",
            "message": "no readOnlyHint or destructiveHint",
            "fix": "Set readOnlyHint: true if it only reads; otherwise set destructiveHint and idempotentHint."
          },
          {
            "rule": "TC16",
            "severity": "warn",
            "tool": "send_reply",
            "message": "no readOnlyHint or destructiveHint",
            "fix": "Set readOnlyHint: true if it only reads; otherwise set destructiveHint and idempotentHint."
          },
          {
            "rule": "TC16",
            "severity": "warn",
            "tool": "verify_owner",
            "message": "no readOnlyHint or destructiveHint",
            "fix": "Set readOnlyHint: true if it only reads; otherwise set destructiveHint and idempotentHint."
          },
          {
            "rule": "TC21",
            "severity": "warn",
            "tool": "get_emails",
            "message": "described almost the same as get_last_email (81% of the same words)",
            "fix": "Say in each description when to use it instead of the other."
          },
          {
            "rule": "TC24",
            "severity": "note",
            "message": "27 of 27 tools have no outputSchema",
            "fix": "Declare outputSchema for tools that return structured data, and return structuredContent that matches it."
          }
        ],
        "withheld": true
      }
    },
    "llmsTxt": "https://inboxapi.ai/llms.txt",
    "capabilities": [
      "email.inbox",
      "email.send",
      "email.inbound",
      "email.threads",
      "guard.injection"
    ],
    "tags": [
      "hosted",
      "free",
      "no-card",
      "no-signup",
      "mcp",
      "stdio",
      "cli",
      "llms-txt",
      "rust",
      "closed-source"
    ],
    "lastRelease": "2026-09-22",
    "graded": true,
    "anchor": {
      "graded": true,
      "score": 54.5,
      "grade": "C",
      "agentReady": false,
      "rank": 684,
      "ranked": true,
      "rankOf": 950,
      "categoryRank": 7,
      "methodology": "0.4",
      "run": "2026-10-01",
      "scores": {
        "ergonomics": 61,
        "maintenance": 63,
        "payments": 53,
        "reliability": 33,
        "schema": 69,
        "security": 57,
        "transparency": 53
      },
      "pending": [
        "performance",
        "tasks"
      ],
      "breakdown": [
        {
          "key": "reliability",
          "name": "Reliability",
          "weight": 16,
          "effectiveWeight": 20,
          "score": 33,
          "points": 6.6,
          "reason": "Graded as a hosted service, because the mail runs on InboxAPI's servers and the CLI is a bridge to them. No status page was found on the site, in its sitemap or in the repository (0 of 20), so there is no readable incident history (5 of 30). The limits page gives 100 requests a minute, 20 a minute on auth calls and five external recipient slots, and says daily and hourly send quotas are enforced without giving numbers (11 of 15). A 429 carries `Retry-After` per the limits page, the one response we received carried `x-ratelimit-limit: 100`, and the CLI source adds the wait to the tool error. Sends take no idempotency key (10 of 15). No SLA, and the terms guarantee no availability (0). Nothing on the site marks the service beta, while the CLI is at 0.3.23 and the README says functions may change without notice (7 of 10)."
        },
        {
          "key": "performance",
          "name": "Performance",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
        },
        {
          "key": "schema",
          "name": "Schema \u0026 documentation",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 69,
          "points": 11.21,
          "reason": "Graded on the MCP tools. A `tools/list` call to the hosted endpoint returned 27 tools, each with a JSON Schema input (25). `llms.txt` is published (10). Descriptions say what each tool does and often when to use it, such as `get_email` taking either a Message-ID or an index, and the plain-text default that saves tokens. Several fields, such as `limit` on `get_sent_emails`, have none (15 of 20). `content_format` is a three-value enum and `attachment_id` a UUID, but `status`, `priority` and dates are free strings with the allowed values only in prose, and `to` accepts a string or an array (9 of 15). The docs show one sample response, for spotlighting, and no error reference (5 of 15). Releases are tagged with empty notes, there is no changelog, and the hosted tools carry no version. The docs disagree in places, with 22 tools in the FAQ against 21 in the README, and a README that says updates install in the background where the source only tells the agent (5 of 15)."
        },
        {
          "key": "ergonomics",
          "name": "Agent ergonomics",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 61,
          "points": 9.91,
          "reason": "Through the CLI an agent sees 21 tools, because the source hides nine of the server's 27 and adds three local ones. The 27 definitions came to about 28 KB of JSON (15 of 25 for 11 to 30 tools, plus 2 for the hidden auth tools and the plain-text default, 17). Lists take `limit` and `offset` with a maximum of 50, search filters by sender, subject and date, `get_email_count` takes `since`, and `content_format` picks text, HTML or both. Bodies can't be searched (17 of 20). No error codes are documented. The CLI source returns plain messages for refused recipients and rate limits (8 of 20). Sends take no idempotency key. The CLI adds `readOnlyHint` and `destructiveHint` to the tools, which the server's own list lacks, and retries a call once after a token refresh (10 of 20). A send needs three fields and setup needs no configuration. There is no SDK, only the CLI, whose subcommands print JSON (9 of 15)."
        },
        {
          "key": "security",
          "name": "Security \u0026 auth",
          "weight": 14,
          "effectiveWeight": 17.5,
          "score": 57,
          "points": 9.98,
          "reason": "The CLI holds an access and a refresh token in a local file written with mode 0600 and puts the token into each call, so the model never handles it. Tokens cover the whole account with no scopes, travel in the request body, and can be revoked one at a time or all at once from the CLI (20 of 30). There is no read-only mode. The CLI refuses `forward_email` without `confirm`, refuses new recipients unless a flag the model can set itself is passed, and keeps five auth and encryption tools out of MCP. The service caps an account at five external recipients (12 of 20). Inbound mail gets one of four trust levels and untrusted text is datamarked with a per-request marker, tool descriptions warn against following email content, and outbound mail containing a JWT is rejected, per the docs (14 of 15). `get_sent_emails` shows delivery status and an optional Claude Code hook writes a local activity log. No server-side audit log was found (6 of 15). `security.txt` returns 404, and no disclosure policy, bounty or certification was found. The repository runs CodeQL and publishes to npm with provenance (5 of 20)."
        },
        {
          "key": "payments",
          "name": "Payments \u0026 pricing",
          "weight": 10,
          "effectiveWeight": 12.5,
          "score": 53,
          "points": 6.63,
          "reason": "Graded as a hosted service. No x402, MPP or L402 in the docs, the tool list or the CLI source (0 of 40). The home page and FAQ say the service is free with no usage tiers, and that paid plans are planned with no price given. Send quota numbers aren't published (15 of 20). No card and no trial period (20). The CLI creates the account by proof-of-work on first use with no person involved. Owner verification, which needs a person to read a six-digit code, lifts trial restrictions the docs don't describe (18 of 20)."
        },
        {
          "key": "tasks",
          "name": "Task success",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
        },
        {
          "key": "maintenance",
          "name": "Maintenance \u0026 community",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 63,
          "points": 5.51,
          "reason": "Version 0.3.23 was tagged on 22 September 2026 and is the latest on npm (30). Four versions, 0.3.20 to 0.3.23, were tagged that day and the one before was 25 May, so the last 90 days hold one release day (10 of 20). The last 30 issues and pull requests were opened by three accounts that look like the maintainers' own, most closed within days, with four issues open, the oldest from 29 April (15 of 25). A search of the official MCP registry for inboxapi returned nothing (0 of 15). CI and CodeQL passed on the default branch on 22 September, the same day as a dependency update, and npm publishing uses trusted publishing. `Cargo.toml` on the default branch still says 0.3.14 (8 of 10)."
        },
        {
          "key": "transparency",
          "name": "Transparency \u0026 trust",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 53,
          "points": 4.64,
          "note": "editorial 43, provenance 63",
          "reason": "The CLI is open source under the MIT licence. The hosted mail service is closed, under terms dated 11 September 2026 that name Sitka Capital Pty Ltd as operator and Dini Labs Pty Ltd as owner of the technology (20 of 30). The terms and the privacy policy agree on roles, with the customer as controller of mail content, and the policy lists what is collected. It gives no retention period, and a DPA is available on request only (15 of 30). No deprecation policy. The terms allow functions to be removed at any time, with 14 days' notice only for changes to the terms that reduce a user's rights (3 of 20). No sub-processors are named, and data may be held in Australia and overseas, the United States among them. The CLI asks the npm registry for the latest version once a day and sends the MCP client's name and version to the service in its User-Agent, per the source (5 of 20)."
        }
      ],
      "assessment": {
        "date": "2026-10-09",
        "basis": "public evidence",
        "confidence": "medium",
        "notes": {
          "ergonomics": "Through the CLI an agent sees 21 tools, because the source hides nine of the server's 27 and adds three local ones. The 27 definitions came to about 28 KB of JSON (15 of 25 for 11 to 30 tools, plus 2 for the hidden auth tools and the plain-text default, 17). Lists take `limit` and `offset` with a maximum of 50, search filters by sender, subject and date, `get_email_count` takes `since`, and `content_format` picks text, HTML or both. Bodies can't be searched (17 of 20). No error codes are documented. The CLI source returns plain messages for refused recipients and rate limits (8 of 20). Sends take no idempotency key. The CLI adds `readOnlyHint` and `destructiveHint` to the tools, which the server's own list lacks, and retries a call once after a token refresh (10 of 20). A send needs three fields and setup needs no configuration. There is no SDK, only the CLI, whose subcommands print JSON (9 of 15).",
          "maintenance": "Version 0.3.23 was tagged on 22 September 2026 and is the latest on npm (30). Four versions, 0.3.20 to 0.3.23, were tagged that day and the one before was 25 May, so the last 90 days hold one release day (10 of 20). The last 30 issues and pull requests were opened by three accounts that look like the maintainers' own, most closed within days, with four issues open, the oldest from 29 April (15 of 25). A search of the official MCP registry for inboxapi returned nothing (0 of 15). CI and CodeQL passed on the default branch on 22 September, the same day as a dependency update, and npm publishing uses trusted publishing. `Cargo.toml` on the default branch still says 0.3.14 (8 of 10).",
          "payments": "Graded as a hosted service. No x402, MPP or L402 in the docs, the tool list or the CLI source (0 of 40). The home page and FAQ say the service is free with no usage tiers, and that paid plans are planned with no price given. Send quota numbers aren't published (15 of 20). No card and no trial period (20). The CLI creates the account by proof-of-work on first use with no person involved. Owner verification, which needs a person to read a six-digit code, lifts trial restrictions the docs don't describe (18 of 20).",
          "reliability": "Graded as a hosted service, because the mail runs on InboxAPI's servers and the CLI is a bridge to them. No status page was found on the site, in its sitemap or in the repository (0 of 20), so there is no readable incident history (5 of 30). The limits page gives 100 requests a minute, 20 a minute on auth calls and five external recipient slots, and says daily and hourly send quotas are enforced without giving numbers (11 of 15). A 429 carries `Retry-After` per the limits page, the one response we received carried `x-ratelimit-limit: 100`, and the CLI source adds the wait to the tool error. Sends take no idempotency key (10 of 15). No SLA, and the terms guarantee no availability (0). Nothing on the site marks the service beta, while the CLI is at 0.3.23 and the README says functions may change without notice (7 of 10).",
          "schema": "Graded on the MCP tools. A `tools/list` call to the hosted endpoint returned 27 tools, each with a JSON Schema input (25). `llms.txt` is published (10). Descriptions say what each tool does and often when to use it, such as `get_email` taking either a Message-ID or an index, and the plain-text default that saves tokens. Several fields, such as `limit` on `get_sent_emails`, have none (15 of 20). `content_format` is a three-value enum and `attachment_id` a UUID, but `status`, `priority` and dates are free strings with the allowed values only in prose, and `to` accepts a string or an array (9 of 15). The docs show one sample response, for spotlighting, and no error reference (5 of 15). Releases are tagged with empty notes, there is no changelog, and the hosted tools carry no version. The docs disagree in places, with 22 tools in the FAQ against 21 in the README, and a README that says updates install in the background where the source only tells the agent (5 of 15).",
          "security": "The CLI holds an access and a refresh token in a local file written with mode 0600 and puts the token into each call, so the model never handles it. Tokens cover the whole account with no scopes, travel in the request body, and can be revoked one at a time or all at once from the CLI (20 of 30). There is no read-only mode. The CLI refuses `forward_email` without `confirm`, refuses new recipients unless a flag the model can set itself is passed, and keeps five auth and encryption tools out of MCP. The service caps an account at five external recipients (12 of 20). Inbound mail gets one of four trust levels and untrusted text is datamarked with a per-request marker, tool descriptions warn against following email content, and outbound mail containing a JWT is rejected, per the docs (14 of 15). `get_sent_emails` shows delivery status and an optional Claude Code hook writes a local activity log. No server-side audit log was found (6 of 15). `security.txt` returns 404, and no disclosure policy, bounty or certification was found. The repository runs CodeQL and publishes to npm with provenance (5 of 20).",
          "transparency": "The CLI is open source under the MIT licence. The hosted mail service is closed, under terms dated 11 September 2026 that name Sitka Capital Pty Ltd as operator and Dini Labs Pty Ltd as owner of the technology (20 of 30). The terms and the privacy policy agree on roles, with the customer as controller of mail content, and the policy lists what is collected. It gives no retention period, and a DPA is available on request only (15 of 30). No deprecation policy. The terms allow functions to be removed at any time, with 14 days' notice only for changes to the terms that reduce a user's rights (3 of 20). No sub-processors are named, and data may be held in Australia and overseas, the United States among them. The CLI asks the npm registry for the latest version once a day and sends the MCP client's name and version to the service in its User-Agent, per the source (5 of 20)."
        },
        "sources": [
          {
            "what": "llms.txt",
            "url": "https://inboxapi.ai/llms.txt",
            "seen": "2026-10-09"
          },
          {
            "what": "home page, price and feature claims",
            "url": "https://inboxapi.ai/",
            "seen": "2026-10-09"
          },
          {
            "what": "getting started",
            "url": "https://inboxapi.ai/getting-started/",
            "seen": "2026-10-09"
          },
          {
            "what": "email tools reference, trust levels and spotlighting",
            "url": "https://inboxapi.ai/tools/",
            "seen": "2026-10-09"
          },
          {
            "what": "limits and fair use, rate limit headers",
            "url": "https://inboxapi.ai/limits/",
            "seen": "2026-10-09"
          },
          {
            "what": "FAQ",
            "url": "https://inboxapi.ai/faq/",
            "seen": "2026-10-09"
          },
          {
            "what": "email delivery notes",
            "url": "https://inboxapi.ai/delivery/",
            "seen": "2026-10-09"
          },
          {
            "what": "terms of service, 11 September 2026",
            "url": "https://inboxapi.ai/tos/",
            "seen": "2026-10-09"
          },
          {
            "what": "privacy policy, 11 September 2026",
            "url": "https://inboxapi.ai/privacy/",
            "seen": "2026-10-09"
          },
          {
            "what": "sitemap, checked for status, pricing, changelog and security pages",
            "url": "https://inboxapi.ai/sitemap-0.xml",
            "seen": "2026-10-09"
          },
          {
            "what": "security.txt (404)",
            "url": "https://inboxapi.ai/.well-known/security.txt",
            "seen": "2026-10-09"
          },
          {
            "what": "hosted MCP endpoint, one unauthenticated tools/list call",
            "url": "https://mcp.inboxapi.ai/mcp",
            "seen": "2026-10-09"
          },
          {
            "what": "CLI repository, source read at v0.3.23 (src/main.rs, README, workflows, tags)",
            "url": "https://github.com/inboxapi/cli",
            "seen": "2026-10-09"
          },
          {
            "what": "GitHub releases",
            "url": "https://github.com/inboxapi/cli/releases",
            "seen": "2026-10-09"
          },
          {
            "what": "repository facts, issues and CI runs (GitHub API)",
            "url": "https://api.github.com/repos/inboxapi/cli",
            "seen": "2026-10-09"
          },
          {
            "what": "npm latest version and provenance",
            "url": "https://registry.npmjs.org/@inboxapi/cli/latest",
            "seen": "2026-10-09"
          },
          {
            "what": "npm weekly downloads",
            "url": "https://api.npmjs.org/downloads/point/last-week/@inboxapi/cli",
            "seen": "2026-10-09"
          },
          {
            "what": "official MCP registry search (no result)",
            "url": "https://registry.modelcontextprotocol.io/v0/servers?search=inboxapi",
            "seen": "2026-10-09"
          },
          {
            "what": "domain registration (RDAP)",
            "url": "https://rdap.org/domain/inboxapi.ai",
            "seen": "2026-10-09"
          }
        ],
        "openQuestions": [
          "unchecked: no account was created and no tool was called, so responses, error bodies and the `help` tool's output were not seen. The CLI was not installed or run, and its behaviour is read from source at v0.3.23.",
          "unchecked: the legal entities. Sitka Capital Pty Ltd and Dini Labs Pty Ltd (ABN 87 691 095 477) come from the vendor's terms and were not looked up in the Australian business register.",
          "What the trial restrictions are. The FAQ says owner verification removes them and the site says there is no trial period.",
          "The daily and hourly send quotas. The limits page says they are enforced and gives no numbers.",
          "How the five recipient slots work. The docs say the least recently used slot is replaced after five days of inactivity, while the README and the delivery page say five addresses a week.",
          "Whether custom domains are available. The FAQ says not yet, while the CLI has a `custom-domain-claim` command that takes a claim secret, with no account of how a secret is issued.",
          "Whether `verify_owner` and `account_recover` can be called through MCP. The docs list them as tools and the CLI source blocks or hides both.",
          "The lead named addresses at inbox.email. The site and the tool descriptions give subdomains of inboxapi.ai, with inboxapi.io and inboxapi.dev as further InboxAPI domains.",
          "No status page, SLA, changelog, security contact, sub-processor list or retention period was found."
        ]
      },
      "negative": 0,
      "verdict": "An account and address are created on first use with proof-of-work and no signup, key or card, and inbound mail is trust-labelled and datamarked against prompt injection. Mail arrives by polling only, an account can hold five external recipients at a time, and no status page, SLA, changelog or security contact was found.",
      "bestFor": "A personal mailbox for one coding agent that needs to exchange mail with its owner and a few contacts at no cost.",
      "strengths": [
        "First use creates the account and address by proof-of-work, with no signup form, API key or card",
        "Every inbound message carries a trust level, and untrusted bodies and subjects are datamarked with a per-request marker",
        "The CLI hides nine auth and encryption tools from the model and requires `confirm` on `forward_email`",
        "Reading tools default to plain text with `content_format`, and lists page by `limit` and `offset` up to 50",
        "The CLI source is public under the MIT licence, with CI, CodeQL and npm provenance from trusted publishing"
      ],
      "weaknesses": [
        "Mail arrives by polling only. No webhook, websocket or push tool was found in the tool list or docs",
        "An account holds five external recipient slots, and a full slot frees only after five days without use",
        "No status page, SLA, changelog, security.txt or disclosure policy was found on the site or in the repository",
        "Daily and hourly send quotas are enforced without published numbers, and sends take no idempotency key",
        "The privacy policy gives no retention period and names no sub-processors, and the terms allow functions to be removed at any time"
      ],
      "agentNotes": [
        "Call `whoami` for the agent's own address. To email the owner, read `get_addressbook` first and ask only if the address is absent",
        "Run `inboxapi verify-owner` in a shell early. Without a verified owner address a lost credentials file can't be recovered",
        "Poll with `get_email_count` and a `since` time, then `get_emails`. Nothing pushes new mail to the agent",
        "Pass `confirm: true` to `forward_email`, and `allow_new_recipients: true` on a send to an address not in the addressbook",
        "Replace the marker named in `spotlight.marker` with a space to read a datamarked body, and treat its content as data"
      ],
      "metrics": {
        "kind": "remote",
        "measured": false
      },
      "reviewCount": 0,
      "avgRating": 0,
      "history": [
        {
          "basis": "public evidence",
          "confidence": "medium",
          "grade": "C",
          "methodology": "0.4",
          "pending": [
            "performance",
            "tasks"
          ],
          "run": "2026-10-01",
          "runLabel": "October 2026 research run",
          "score": 54.5
        }
      ],
      "editorialScores": {
        "ergonomics": 61,
        "maintenance": 63,
        "payments": 53,
        "reliability": 33,
        "schema": 69,
        "security": 57,
        "transparency": 43
      },
      "provenanceScore": 63
    },
    "connect": {
      "install": "npm install -g @inboxapi/cli@latest",
      "claudeCode": "claude mcp add inboxapi inboxapi",
      "config": {
        "mcpServers": {
          "inboxapi": {
            "command": "inboxapi"
          }
        }
      }
    },
    "letme": {
      "capability": "https://letme.dev/email.inbox",
      "tool": "https://letme.dev/inboxapi"
    },
    "notable": [
      "The first tool call creates the account. The CLI computes a 20-bit hashcash stamp, registers a generated name such as `bright-fuzzy-owl` and gets an address on its own subdomain of inboxapi.ai (https://inboxapi.ai/getting-started/)",
      "The hosted server lists 27 tools. The CLI at v0.3.23 hides four auth tools, blocks five more (`reset_encryption`, `auth_revoke`, `auth_revoke_all`, `auth_introspect`, `verify_owner`) and adds `whoami`, `report_bug` and `request_feature`, leaving 21 (https://github.com/inboxapi/cli/blob/main/src/main.rs)",
      "Every email read back carries `trust_level` (trusted, agent, unverified or suspicious), and untrusted bodies, subjects and sender names have whitespace replaced by a per-request marker from the Unicode Private Use Area (https://inboxapi.ai/tools/)",
      "An account has five slots for external recipients, filled as it sends. A full slot is replaced only after five days without use. Mail to inboxapi.ai, inboxapi.io and inboxapi.dev addresses doesn't use a slot (https://inboxapi.ai/limits/)",
      "The service refuses mail to government, military, law enforcement, critical infrastructure and disposable domains, and rejects outbound mail that contains a JWT or access token, per the FAQ (https://inboxapi.ai/faq/)",
      "The terms name Sitka Capital Pty Ltd of Sydney as operator, under a licence from Dini Labs Pty Ltd (ABN 87 691 095 477), which owns the technology (https://inboxapi.ai/tos/)",
      "The vendor says it runs its own mail stack and doesn't use SES, SendGrid or Postfix. New subdomains have no sending reputation, and the delivery page says first emails may land in spam (https://inboxapi.ai/delivery/)",
      "When a newer version is on npm, the CLI adds a notice to the MCP instructions and to tool results asking the agent to tell the user to update. We record this as a fact and take no deduction (https://github.com/inboxapi/cli/blob/main/src/main.rs)"
    ],
    "area": "communication",
    "details": [
      {
        "label": "Inbox creation",
        "value": "Automatic on first use. One account has one address, `name@subdomain.inboxapi.ai`, with a generated name unless `inboxapi login --name` picks one. No tool creates further inboxes"
      },
      {
        "label": "How replies arrive",
        "value": "Polling only, with `get_emails`, `get_last_email`, `search_emails` and `get_email_count` (which takes `since`). No webhook, websocket or push tool"
      },
      {
        "label": "Threading",
        "value": "`send_reply` sets In-Reply-To and References and keeps the thread's recipients on multi-recipient threads. `get_thread` returns a whole conversation, oldest first, from any Message-ID in it"
      },
      {
        "label": "Custom domains",
        "value": "Not available, per the FAQ. The CLI has a `custom-domain-claim` command that takes a claim secret, with no published way to get one"
      },
      {
        "label": "Price",
        "value": "Free. No card, no trial period, no paid plan on sale"
      },
      {
        "label": "Limits",
        "value": "Five external recipient slots an account, 100 requests a minute (20 on auth calls), daily and hourly send quotas without published numbers. Lists return 20 emails by default and 50 at most"
      },
      {
        "label": "MCP tools",
        "value": "21 through the CLI. Reading (`get_emails`, `get_email`, `get_last_email`, `search_emails`, `get_email_count`, `get_thread`, `get_sent_emails`, `get_attachment`), sending (`send_email`, `send_reply`, `forward_email`), `delete_email`, `get_addressbook`, `get_announcements`, `help`, `whoami`, encryption and feedback tools"
      },
      {
        "label": "Transport",
        "value": "The `inboxapi` binary speaks MCP over stdio and forwards to https://mcp.inboxapi.ai/mcp over HTTP with SSE responses. The same commands exist as shell subcommands that print JSON"
      },
      {
        "label": "Credentials",
        "value": "Access and refresh tokens in `~/.config/inboxapi/credentials.json` (Linux) or `~/Library/Application Support/inboxapi/credentials.json` (macOS), mode 0600, added to calls by the CLI"
      },
      {
        "label": "Injection defences",
        "value": "Four trust levels on every inbound message, datamarking of untrusted text, warnings in tool descriptions, `confirm` required on `forward_email`, and outbound mail containing a JWT rejected"
      },
      {
        "label": "Attachments",
        "value": "Sent as base64 in `attachments`, or from local files with the CLI's `--attachment`. `get_attachment` returns a signed URL valid for five minutes"
      },
      {
        "label": "Search",
        "value": "By sender and subject (substring, case-insensitive) and by date range. No search of message bodies"
      },
      {
        "label": "Blocked recipients",
        "value": "Government, military, intelligence, law enforcement, critical infrastructure and disposable email domains, per the FAQ"
      },
      {
        "label": "CLI",
        "value": "`@inboxapi/cli` 0.3.23 on npm (22 September 2026), a Rust binary for macOS and Linux on x64 and ARM64 and Windows on x64, MIT, published with npm provenance"
      },
      {
        "label": "Status",
        "value": "No status page, SLA or changelog found. GitHub releases have empty notes"
      }
    ],
    "provenance": {
      "legalEntity": "Sitka Capital Pty Ltd",
      "domain": "inboxapi.ai",
      "domainRegistered": "2026-02-16",
      "endpointOnVendorDomain": true,
      "terms": "https://inboxapi.ai/tos/",
      "privacy": "https://inboxapi.ai/privacy/",
      "statusPage": "",
      "changelog": "https://github.com/inboxapi/cli/releases",
      "securityTxt": "none",
      "checked": "2026-10-09",
      "notes": [
        "The terms of service and the privacy policy (both last updated 11 September 2026) name Sitka Capital Pty Ltd of Sydney, New South Wales, as operator under a licence from Dini Labs Pty Ltd (ABN 87 691 095 477), which owns the technology. We did not look either company up in the Australian business register.",
        "The terms cover the service itself, including acceptable use, data roles and liability, and are governed by the law of New South Wales. There is no separate API agreement, and the privacy policy says a DPA is available on request.",
        "RDAP gives inboxapi.ai a registration date of 2026-02-16. The MCP endpoint is at mcp.inboxapi.ai, and the tool descriptions name inboxapi.io and inboxapi.dev as further InboxAPI domains.",
        "`https://inboxapi.ai/.well-known/security.txt` returns 404, and the repository has no SECURITY.md.",
        "No status page was found on the site, in its sitemap or in the repository. The changelog link is the GitHub releases list, whose notes are empty.",
        "The CLI's MIT licence names an individual, Shaon Diwakar, as copyright holder, and npm shows the package published from GitHub Actions by trusted publishing."
      ],
      "score": 63,
      "checks": [
        {
          "check": "Legal entity named",
          "value": "Sitka Capital Pty Ltd",
          "points": 20,
          "max": 20,
          "state": "ok"
        },
        {
          "check": "Domain age",
          "value": "inboxapi.ai, registered 2026-02-16 (under a year)",
          "points": 0,
          "max": 15,
          "state": "no"
        },
        {
          "check": "Endpoint on the vendor's domain",
          "value": "mcp.inboxapi.ai",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Terms of service",
          "value": "read, states 5 of the 7 things a reader expects",
          "points": 8.3,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Privacy policy",
          "value": "read, states 7 of the 8 things a reader expects",
          "points": 9.3,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Status page",
          "value": "not found",
          "points": 0,
          "max": 10,
          "state": "no"
        },
        {
          "check": "Changelog",
          "value": "published",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "security.txt",
          "value": "not found",
          "points": 0,
          "max": 10,
          "state": "no"
        }
      ],
      "policies": [
        {
          "kind": "terms",
          "url": "https://inboxapi.ai/tos/",
          "state": "read",
          "readAt": "2026-10-09",
          "statedDate": "2026-09-11",
          "words": 2194,
          "points": 8.3,
          "max": 10,
          "expected": [
            {
              "key": "terms.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Last updated: 2026-09-11",
              "says": "Last updated 2026-09-11"
            },
            {
              "key": "terms.law",
              "label": "Names the governing law or courts",
              "found": true,
              "quote": "These Terms are governed by the laws of New South Wales, Australia, without regard to conflict of law rules.",
              "says": "The law of New South Wales"
            },
            {
              "key": "terms.liability",
              "label": "States a limit on its liability",
              "found": true,
              "quote": "Sitka Capital’s aggregate liability arising out of or in connection with the Service or these Terms will not exceed the amount you paid us for the Service in the 12 months preceding the event giving rise to the claim, or AU$100, whichever is greater.",
              "says": "Capped at the fees paid in the 12 months before the claim or $100,"
            },
            {
              "key": "terms.termination",
              "label": "Says how the agreement or account can be ended",
              "found": true,
              "quote": "We may suspend, restrict, or terminate your access immediately, with or without notice, if:"
            },
            {
              "key": "terms.changes",
              "label": "Says how changes to the terms are announced",
              "found": false
            },
            {
              "key": "terms.use",
              "label": "Lists what users may not do",
              "found": true,
              "quote": "You must not use the Service for, or to facilitate:"
            },
            {
              "key": "terms.sla",
              "label": "Refers to a service level or uptime commitment",
              "found": false
            }
          ],
          "toKnow": [
            {
              "key": "terms.cutoff",
              "label": "Says access can be ended without notice or for any reason",
              "found": true,
              "quote": "We may suspend, restrict, or terminate your access immediately, with or without notice, if:"
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "The customer is responsible for all activity on its account, including activity started by a script or an AI agent.",
              "quote": "You are responsible for all activity that occurs through your account, whether initiated by a human, script, or AI agent."
            },
            {
              "date": "2026-10-08",
              "text": "High-volume transactional email and marketing campaigns are listed among the prohibited uses.",
              "quote": "High-volume transactional email, marketing campaigns, or other uses outside the product’s intended scope as described in our documentation"
            },
            {
              "date": "2026-10-08",
              "text": "On suspension or termination the customer's data may become unavailable or be deleted, and no retention period is stated.",
              "quote": "Your data may become unavailable or be deleted in accordance with our retention practices and legal obligations"
            }
          ]
        },
        {
          "kind": "privacy",
          "url": "https://inboxapi.ai/privacy/",
          "state": "read",
          "readAt": "2026-10-09",
          "statedDate": "2026-09-11",
          "words": 1945,
          "points": 9.3,
          "max": 10,
          "expected": [
            {
              "key": "privacy.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Last updated: 2026-09-11",
              "says": "Last updated 2026-09-11"
            },
            {
              "key": "privacy.collected",
              "label": "Says what personal data is collected",
              "found": true,
              "quote": "This policy explains how we collect, hold, use, and disclose personal information when we provide and operate the Service."
            },
            {
              "key": "privacy.retention",
              "label": "Says how long data is kept",
              "found": true,
              "quote": "We retain personal information for as long as reasonably necessary for:",
              "says": "For as long as needed, with no period named"
            },
            {
              "key": "privacy.processors",
              "label": "Says who else receives the data",
              "found": true,
              "quote": "We do not control how recipient systems, third-party mailbox providers, or AI/LLM tools configured by you handle data once it leaves our systems."
            },
            {
              "key": "privacy.sale",
              "label": "Says whether personal data is sold or shared for advertising",
              "found": true,
              "quote": "We do not currently use personal information for advertising profiling, and we do not sell personal information.",
              "says": "Says it does not sell personal data"
            },
            {
              "key": "privacy.rights",
              "label": "Says what rights people have over their data",
              "found": true,
              "quote": "…to us, (b) giving any notice required to those individuals under Australian Privacy Principle 5, the GDPR, or other applicable law, and (c) responding to any access, correction, deletion, or similar requests those individuals make."
            },
            {
              "key": "privacy.contact",
              "label": "Gives a privacy contact",
              "found": true,
              "quote": "To make a request, contact us at [email protected].",
              "says": "Gives an email address, hidden from our reader by the page"
            },
            {
              "key": "privacy.transfers",
              "label": "Says where data is transferred or stored",
              "found": false
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "The policy says the service is not designed for highly sensitive personal information such as health records, payment card data or government identifiers.",
              "quote": "InboxAPI is not designed for processing highly sensitive personal information."
            },
            {
              "date": "2026-10-08",
              "text": "The vendor says it does not control how AI or LLM tools configured by the customer handle data after it leaves the vendor's systems.",
              "quote": "We do not control how recipient systems, third-party mailbox providers, or AI/LLM tools configured by you handle data once it leaves our systems."
            }
          ]
        }
      ]
    },
    "pageJsonUrl": "https://www.anchorterminal.com/tools/inboxapi.json",
    "live": {
      "slug": "inboxapi",
      "probe": {
        "target": "https://mcp.inboxapi.ai/mcp",
        "method": "mcp-initialize",
        "lastAt": "2026-10-10T02:07:12.181706458Z",
        "lastOk": true,
        "lastStatus": 200,
        "lastMs": 1046,
        "lastNote": "initialize answered",
        "authRequired": false,
        "uptime24h": 100,
        "uptime30d": 100,
        "p50ms24h": 1101,
        "p95ms24h": 1197,
        "samples24h": 107,
        "samples30d": 107,
        "days": [
          {
            "date": "2026-10-09",
            "probes": 85,
            "ok": 85
          },
          {
            "date": "2026-10-10",
            "probes": 22,
            "ok": 22
          }
        ]
      },
      "versions": [
        {
          "registry": "github",
          "name": "inboxapi/cli",
          "version": "v0.3.23",
          "released": "2026-09-22",
          "seenAt": "2026-10-09T16:58:45.078221232Z"
        },
        {
          "registry": "npm",
          "name": "@inboxapi/cli",
          "version": "0.3.23",
          "seenAt": "2026-10-09T16:58:44.22009772Z"
        }
      ],
      "githubStars": 13,
      "npmWeekly": 38,
      "pages": [
        {
          "url": "https://inboxapi.ai/privacy/",
          "kind": "privacy",
          "status": 200,
          "checkedAt": "2026-10-09T18:40:25.496410151Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "ee12b4565acf"
        },
        {
          "url": "https://inboxapi.ai/tos/",
          "kind": "terms",
          "status": 200,
          "checkedAt": "2026-10-09T18:40:27.612724166Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "a60c79079bb3"
        }
      ],
      "mcpTools": {
        "url": "https://mcp.inboxapi.ai/mcp",
        "checkedAt": "2026-10-09T21:40:44.089418719Z",
        "status": "ok",
        "note": "answered without the initialize handshake",
        "tools": [
          {
            "name": "auth_revoke_all"
          },
          {
            "name": "rotate_encryption_secret"
          },
          {
            "name": "search_emails"
          },
          {
            "name": "get_addressbook"
          },
          {
            "name": "delete_email"
          },
          {
            "name": "send_email"
          },
          {
            "name": "forward_email"
          },
          {
            "name": "verify_owner"
          },
          {
            "name": "auth_introspect"
          },
          {
            "name": "auth_refresh"
          },
          {
            "name": "get_thread"
          },
          {
            "name": "custom_domain_claim"
          },
          {
            "name": "auth_exchange"
          },
          {
            "name": "get_email"
          },
          {
            "name": "enable_encryption"
          },
          {
            "name": "get_emails"
          },
          {
            "name": "get_attachment"
          },
          {
            "name": "get_announcements"
          },
          {
            "name": "get_last_email"
          },
          {
            "name": "account_create"
          },
          {
            "name": "reset_encryption"
          },
          {
            "name": "get_sent_emails"
          },
          {
            "name": "account_recover"
          },
          {
            "name": "get_email_count"
          },
          {
            "name": "send_reply"
          },
          {
            "name": "help"
          },
          {
            "name": "auth_revoke"
          }
        ],
        "schemaTokens": 6687,
        "changedAt": "2026-10-09T21:40:44.089418719Z",
        "check": {
          "checker": "anchor-check/1.0",
          "totalTokens": 6687,
          "counts": {
            "error": 2,
            "note": 1,
            "warn": 56
          },
          "findings": [
            {
              "rule": "TC19",
              "severity": "error",
              "tool": "forward_email",
              "message": "the definition asks the model to pass secrets as an argument",
              "fix": "Describe the tool; don't instruct the model."
            },
            {
              "rule": "TC19",
              "severity": "error",
              "tool": "send_reply",
              "message": "the definition asks the model to pass secrets as an argument",
              "fix": "Describe the tool; don't instruct the model."
            },
            {
              "rule": "TC11",
              "severity": "warn",
              "tool": "account_create",
              "message": "1 parameter without a description: name",
              "fix": "Describe each one: format, units, an example, and what happens when it's left out."
            },
            {
              "rule": "TC11",
              "severity": "warn",
              "tool": "auth_exchange",
              "message": "none of its 2 parameters has a description",
              "fix": "Describe each one: format, units, an example, and what happens when it's left out."
            },
            {
              "rule": "TC11",
              "severity": "warn",
              "tool": "auth_introspect",
              "message": "its one parameter, token, has no description",
              "fix": "Describe each one: format, units, an example, and what happens when it's left out."
            },
            {
              "rule": "TC11",
              "severity": "warn",
              "tool": "auth_refresh",
              "message": "none of its 2 parameters has a description",
              "fix": "Describe each one: format, units, an example, and what happens when it's left out."
            },
            {
              "rule": "TC11",
              "severity": "warn",
              "tool": "auth_revoke",
              "message": "its one parameter, token, has no description",
              "fix": "Describe each one: format, units, an example, and what happens when it's left out."
            },
            {
              "rule": "TC11",
              "severity": "warn",
              "tool": "auth_revoke_all",
              "message": "its one parameter, access_token, has no description",
              "fix": "Describe each one: format, units, an example, and what happens when it's left out."
            },
            {
              "rule": "TC11",
              "severity": "warn",
              "tool": "delete_email",
              "message": "1 parameter without a description: token",
              "fix": "Describe each one: format, units, an example, and what happens when it's left out."
            },
            {
              "rule": "TC11",
              "severity": "warn",
              "tool": "enable_encryption",
              "message": "its one parameter, token, has no description",
              "fix": "Describe each one: format, units, an example, and what happens when it's left out."
            },
            {
              "rule": "TC11",
              "severity": "warn",
              "tool": "forward_email",
              "message": "2 parameters without a description: domain, token",
              "fix": "Describe each one: format, units, an example, and what happens when it's left out."
            },
            {
              "rule": "TC11",
              "severity": "warn",
              "tool": "get_addressbook",
              "message": "none of its 2 parameters has a description",
              "fix": "Describe each one: format, units, an example, and what happens when it's left out."
            },
            {
              "rule": "TC11",
              "severity": "warn",
              "tool": "get_announcements",
              "message": "none of its 2 parameters has a description",
              "fix": "Describe each one: format, units, an example, and what happens when it's left out."
            },
            {
              "rule": "TC11",
              "severity": "warn",
              "tool": "get_email_count",
              "message": "2 parameters without a description: domain, token",
              "fix": "Describe each one: format, units, an example, and what happens when it's left out."
            },
            {
              "rule": "TC11",
              "severity": "warn",
              "tool": "get_emails",
              "message": "2 parameters without a description: domain, token",
              "fix": "Describe each one: format, units, an example, and what happens when it's left out."
            },
            {
              "rule": "TC11",
              "severity": "warn",
              "tool": "get_last_email",
              "message": "2 parameters without a description: domain, token",
              "fix": "Describe each one: format, units, an example, and what happens when it's left out."
            },
            {
              "rule": "TC11",
              "severity": "warn",
              "tool": "get_sent_emails",
              "message": "3 parameters without a description: limit, offset, token",
              "fix": "Describe each one: format, units, an example, and what happens when it's left out."
            },
            {
              "rule": "TC11",
              "severity": "warn",
              "tool": "get_thread",
              "message": "2 parameters without a description: domain, token",
              "fix": "Describe each one: format, units, an example, and what happens when it's left out."
            },
            {
              "rule": "TC11",
              "severity": "warn",
              "tool": "reset_encryption",
              "message": "1 parameter without a description: token",
              "fix": "Describe each one: format, units, an example, and what happens when it's left out."
            },
            {
              "rule": "TC11",
              "severity": "warn",
              "tool": "rotate_encryption_secret",
              "message": "none of its 3 parameters has a description",
              "fix": "Describe each one: format, units, an example, and what happens when it's left out."
            },
            {
              "rule": "TC11",
              "severity": "warn",
              "tool": "search_emails",
              "message": "4 parameters without a description: domain, limit, offset, token",
              "fix": "Describe each one: format, units, an example, and what happens when it's left out."
            },
            {
              "rule": "TC15",
              "severity": "warn",
              "tool": "forward_email",
              "message": "inputSchema uses $ref/$defs",
              "fix": "Inline the referenced schemas. Pydantic and zod-to-json-schema emit $defs for nested models; most can be told not to."
            },
            {
              "rule": "TC15",
              "severity": "warn",
              "tool": "get_email",
              "message": "inputSchema uses $ref/$defs",
              "fix": "Inline the referenced schemas. Pydantic and zod-to-json-schema emit $defs for nested models; most can be told not to."
            },
            {
              "rule": "TC15",
              "severity": "warn",
              "tool": "get_emails",
              "message": "inputSchema uses $ref/$defs",
              "fix": "Inline the referenced schemas. Pydantic and zod-to-json-schema emit $defs for nested models; most can be told not to."
            },
            {
              "rule": "TC15",
              "severity": "warn",
              "tool": "get_last_email",
              "message": "inputSchema uses $ref/$defs",
              "fix": "Inline the referenced schemas. Pydantic and zod-to-json-schema emit $defs for nested models; most can be told not to."
            },
            {
              "rule": "TC15",
              "severity": "warn",
              "tool": "get_sent_emails",
              "message": "inputSchema uses $ref/$defs",
              "fix": "Inline the referenced schemas. Pydantic and zod-to-json-schema emit $defs for nested models; most can be told not to."
            },
            {
              "rule": "TC15",
              "severity": "warn",
              "tool": "get_thread",
              "message": "inputSchema uses $ref/$defs",
              "fix": "Inline the referenced schemas. Pydantic and zod-to-json-schema emit $defs for nested models; most can be told not to."
            },
            {
              "rule": "TC15",
              "severity": "warn",
              "tool": "search_emails",
              "message": "inputSchema uses $ref/$defs",
              "fix": "Inline the referenced schemas. Pydantic and zod-to-json-schema emit $defs for nested models; most can be told not to."
            },
            {
              "rule": "TC15",
              "severity": "warn",
              "tool": "send_email",
              "message": "inputSchema uses $ref/$defs",
              "fix": "Inline the referenced schemas. Pydantic and zod-to-json-schema emit $defs for nested models; most can be told not to."
            },
            {
              "rule": "TC15",
              "severity": "warn",
              "tool": "send_reply",
              "message": "inputSchema uses $ref/$defs",
              "fix": "Inline the referenced schemas. Pydantic and zod-to-json-schema emit $defs for nested models; most can be told not to."
            },
            {
              "rule": "TC16",
              "severity": "warn",
              "tool": "account_create",
              "message": "no readOnlyHint or destructiveHint",
              "fix": "Set readOnlyHint: true if it only reads; otherwise set destructiveHint and idempotentHint."
            },
            {
              "rule": "TC16",
              "severity": "warn",
              "tool": "account_recover",
              "message": "no readOnlyHint or destructiveHint",
              "fix": "Set readOnlyHint: true if it only reads; otherwise set destructiveHint and idempotentHint."
            },
            {
              "rule": "TC16",
              "severity": "warn",
              "tool": "auth_exchange",
              "message": "no readOnlyHint or destructiveHint",
              "fix": "Set readOnlyHint: true if it only reads; otherwise set destructiveHint and idempotentHint."
            },
            {
              "rule": "TC16",
              "severity": "warn",
              "tool": "auth_introspect",
              "message": "no readOnlyHint or destructiveHint",
              "fix": "Set readOnlyHint: true if it only reads; otherwise set destructiveHint and idempotentHint."
            },
            {
              "rule": "TC16",
              "severity": "warn",
              "tool": "auth_refresh",
              "message": "no readOnlyHint or destructiveHint",
              "fix": "Set readOnlyHint: true if it only reads; otherwise set destructiveHint and idempotentHint."
            },
            {
              "rule": "TC16",
              "severity": "warn",
              "tool": "auth_revoke",
              "message": "no readOnlyHint or destructiveHint",
              "fix": "Set readOnlyHint: true if it only reads; otherwise set destructiveHint and idempotentHint."
            },
            {
              "rule": "TC16",
              "severity": "warn",
              "tool": "auth_revoke_all",
              "message": "no readOnlyHint or destructiveHint",
              "fix": "Set readOnlyHint: true if it only reads; otherwise set destructiveHint and idempotentHint."
            },
            {
              "rule": "TC16",
              "severity": "warn",
              "tool": "custom_domain_claim",
              "message": "no readOnlyHint or destructiveHint",
              "fix": "Set readOnlyHint: true if it only reads; otherwise set destructiveHint and idempotentHint."
            },
            {
              "rule": "TC16",
              "severity": "warn",
              "tool": "delete_email",
              "message": "no readOnlyHint or destructiveHint",
              "fix": "Set readOnlyHint: true if it only reads; otherwise set destructiveHint and idempotentHint."
            },
            {
              "rule": "TC16",
              "severity": "warn",
              "tool": "enable_encryption",
              "message": "no readOnlyHint or destructiveHint",
              "fix": "Set readOnlyHint: true if it only reads; otherwise set destructiveHint and idempotentHint."
            },
            {
              "rule": "TC16",
              "severity": "warn",
              "tool": "forward_email",
              "message": "no readOnlyHint or destructiveHint",
              "fix": "Set readOnlyHint: true if it only reads; otherwise set destructiveHint and idempotentHint."
            },
            {
              "rule": "TC16",
              "severity": "warn",
              "tool": "get_addressbook",
              "message": "no readOnlyHint or destructiveHint",
              "fix": "Its name starts with \"get\"; if it only reads, set readOnlyHint: true so harnesses can run it without asking."
            },
            {
              "rule": "TC16",
              "severity": "warn",
              "tool": "get_announcements",
              "message": "no readOnlyHint or destructiveHint",
              "fix": "Its name starts with \"get\"; if it only reads, set readOnlyHint: true so harnesses can run it without asking."
            },
            {
              "rule": "TC16",
              "severity": "warn",
              "tool": "get_attachment",
              "message": "no readOnlyHint or destructiveHint",
              "fix": "Its name starts with \"get\"; if it only reads, set readOnlyHint: true so harnesses can run it without asking."
            },
            {
              "rule": "TC16",
              "severity": "warn",
              "tool": "get_email",
              "message": "no readOnlyHint or destructiveHint",
              "fix": "Its name starts with \"get\"; if it only reads, set readOnlyHint: true so harnesses can run it without asking."
            },
            {
              "rule": "TC16",
              "severity": "warn",
              "tool": "get_email_count",
              "message": "no readOnlyHint or destructiveHint",
              "fix": "Its name starts with \"get\"; if it only reads, set readOnlyHint: true so harnesses can run it without asking."
            },
            {
              "rule": "TC16",
              "severity": "warn",
              "tool": "get_emails",
              "message": "no readOnlyHint or destructiveHint",
              "fix": "Its name starts with \"get\"; if it only reads, set readOnlyHint: true so harnesses can run it without asking."
            },
            {
              "rule": "TC16",
              "severity": "warn",
              "tool": "get_last_email",
              "message": "no readOnlyHint or destructiveHint",
              "fix": "Its name starts with \"get\"; if it only reads, set readOnlyHint: true so harnesses can run it without asking."
            },
            {
              "rule": "TC16",
              "severity": "warn",
              "tool": "get_sent_emails",
              "message": "no readOnlyHint or destructiveHint",
              "fix": "Its name starts with \"get\"; if it only reads, set readOnlyHint: true so harnesses can run it without asking."
            },
            {
              "rule": "TC16",
              "severity": "warn",
              "tool": "get_thread",
              "message": "no readOnlyHint or destructiveHint",
              "fix": "Its name starts with \"get\"; if it only reads, set readOnlyHint: true so harnesses can run it without asking."
            },
            {
              "rule": "TC16",
              "severity": "warn",
              "tool": "help",
              "message": "no readOnlyHint or destructiveHint",
              "fix": "Set readOnlyHint: true if it only reads; otherwise set destructiveHint and idempotentHint."
            },
            {
              "rule": "TC16",
              "severity": "warn",
              "tool": "reset_encryption",
              "message": "no readOnlyHint or destructiveHint",
              "fix": "Set readOnlyHint: true if it only reads; otherwise set destructiveHint and idempotentHint."
            },
            {
              "rule": "TC16",
              "severity": "warn",
              "tool": "rotate_encryption_secret",
              "message": "no readOnlyHint or destructiveHint",
              "fix": "Set readOnlyHint: true if it only reads; otherwise set destructiveHint and idempotentHint."
            },
            {
              "rule": "TC16",
              "severity": "warn",
              "tool": "search_emails",
              "message": "no readOnlyHint or destructiveHint",
              "fix": "Its name starts with \"search\"; if it only reads, set readOnlyHint: true so harnesses can run it without asking."
            },
            {
              "rule": "TC16",
              "severity": "warn",
              "tool": "send_email",
              "message": "no readOnlyHint or destructiveHint",
              "fix": "Set readOnlyHint: true if it only reads; otherwise set destructiveHint and idempotentHint."
            },
            {
              "rule": "TC16",
              "severity": "warn",
              "tool": "send_reply",
              "message": "no readOnlyHint or destructiveHint",
              "fix": "Set readOnlyHint: true if it only reads; otherwise set destructiveHint and idempotentHint."
            },
            {
              "rule": "TC16",
              "severity": "warn",
              "tool": "verify_owner",
              "message": "no readOnlyHint or destructiveHint",
              "fix": "Set readOnlyHint: true if it only reads; otherwise set destructiveHint and idempotentHint."
            },
            {
              "rule": "TC21",
              "severity": "warn",
              "tool": "get_emails",
              "message": "described almost the same as get_last_email (81% of the same words)",
              "fix": "Say in each description when to use it instead of the other."
            },
            {
              "rule": "TC24",
              "severity": "note",
              "message": "27 of 27 tools have no outputSchema",
              "fix": "Declare outputSchema for tools that return structured data, and return structuredContent that matches it."
            }
          ],
          "withheld": true
        }
      },
      "updatedAt": "2026-10-10T02:07:12.181706458Z"
    }
  }
}
