{
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "tool": {
    "slug": "robotomail",
    "name": "Robotomail",
    "vendor": "Tiny Bot Labs Limited",
    "vendorUrl": "https://robotomail.com",
    "kind": "http-api",
    "category": "agent-inboxes",
    "summary": "Robotomail gives an AI agent its own email address for sending, receiving and replying. Access is by REST API, a hosted MCP server with OAuth, a CLI and SDKs, and replies arrive by webhook, SSE or polling.",
    "url": "https://www.anchorterminal.com/tools/robotomail",
    "markdownUrl": "https://www.anchorterminal.com/tools/robotomail.md",
    "slimMarkdownUrl": "https://www.anchorterminal.com/tools/robotomail.min.md",
    "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/robotomail.json",
    "repo": "https://github.com/robotomail/robotomail-node",
    "license": "Proprietary service under Robotomail's terms of service. The five SDKs on GitHub are MIT",
    "transports": [
      "http",
      "streamable-http"
    ],
    "remoteUrl": "https://api.robotomail.com/v1",
    "packages": [
      {
        "registry": "npm",
        "name": "@robotomail/cli"
      }
    ],
    "auth": "mixed",
    "authNotes": "Bearer API key (`rm_...`) for REST, the CLI and the SDKs. A key is full-access or limited to named mailboxes with `mailboxIds`, and can be revoked by API. The hosted MCP server takes OAuth only (authorisation code with PKCE, refresh tokens or device login) with `mail:read`, `mail:send` and `offline_access` scopes, and REST keys don't work on it. An agent can create an account with `POST /v1/signup` and gets a key back, which does nothing until a person clicks the verification link.",
    "pricing": "freemium",
    "pricingNotes": "Free plan with no card and no expiry, limited to 1 mailbox and 10 sends and 10 receives a calendar month, only with the owner's verified address. Emailing anyone else needs a paid plan, from Starter at $19 a month, then Growth at $79 and Scale at $199, with a 30-day refund on the first paid charge. No overage charges. The pricing page shows annual billing at 50 per cent off for a limited time, while the billing API docs say about 25 per cent (https://robotomail.com/pricing).",
    "priceSummary": "$19 / mo",
    "where": "hosted",
    "x402": {
      "level": "no",
      "evidence": "No x402, MPP or L402 in the docs, `llms.txt` or the OpenAPI spec. An unauthenticated POST to https://api.robotomail.com/v1/mailboxes returned 401, not a payment challenge. The API's own 402 responses are plan gates that point to a Stripe checkout (checked 2026-10-08).",
      "endpoints": []
    },
    "toolCount": 6,
    "popularity": {
      "githubStars": null,
      "npmWeekly": 20,
      "pypiWeekly": null,
      "asOf": "2026-10-08"
    },
    "docsUrl": "https://robotomail.com/docs",
    "llmsTxt": "https://robotomail.com/llms.txt",
    "openapi": "https://robotomail.com/openapi.json",
    "capabilities": [
      "email.inbox",
      "email.send",
      "email.inbound",
      "email.threads",
      "email.domains"
    ],
    "tags": [
      "hosted",
      "freemium",
      "no-card",
      "mcp",
      "oauth",
      "llms-txt",
      "openapi",
      "cli",
      "typescript",
      "python",
      "go",
      "ruby",
      "rust",
      "webhooks",
      "streaming",
      "status-page",
      "closed-source"
    ],
    "lastRelease": "2026-09-25",
    "graded": true,
    "anchor": {
      "graded": true,
      "score": 69.8,
      "grade": "B",
      "agentReady": false,
      "rank": 148,
      "ranked": true,
      "rankOf": 722,
      "categoryRank": 2,
      "methodology": "0.4",
      "run": "2026-10-01",
      "scores": {
        "ergonomics": 72,
        "maintenance": 77,
        "payments": 35,
        "reliability": 73,
        "schema": 90,
        "security": 65,
        "transparency": 73
      },
      "pending": [
        "performance",
        "tasks"
      ],
      "breakdown": [
        {
          "key": "reliability",
          "name": "Reliability",
          "weight": 16,
          "effectiveWeight": 20,
          "score": 73,
          "points": 14.6,
          "reason": "Graded as a hosted service, on the REST API. A public UptimeRobot page with one monitor, on `robotomail.com/api/health`, and daily history. Sending, inbound mail and the MCP server have no component of their own (14 of 20). The monitor shows 100 per cent on each of the 90 days from 11 July to 8 October 2026 and the event feed is empty. One health check can't show a mail outage, so less 5 (25 of 30). Limits are published with numbers, 30 sends a minute per mailbox, 60 per account, daily and monthly caps per plan, 5 signups an hour per IP and 5 concurrent SSE streams (15). The error reference says every 429 carries `Retry-After`, the OpenAPI description says route-produced 429s don't, sends have no idempotency key, and the documented advice is to check sent mail before retrying (9 of 15). No SLA found on the pricing page or in the terms (0). The API is at `/v1` with no beta label (10)."
        },
        {
          "key": "performance",
          "name": "Performance",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
        },
        {
          "key": "schema",
          "name": "Schema \u0026 documentation",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 90,
          "points": 14.63,
          "reason": "OpenAPI 3.1 at `/openapi.json` with 40 operations on 27 paths, each with an operation ID (25). `llms.txt`, and a Markdown copy of every public page by adding `.md` or sending `Accept: text/markdown` (10). Operation descriptions state what each route does, which key type it needs and which gates apply, and `llms.txt` says when not to use the product. The MCP tool descriptions sit behind OAuth and were not read (15 of 20). Request schemas carry required fields, `format: email` and `uuid`, length limits, patterns and enums. The `headers` field on a send is a free object (13 of 15). An error reference and per-route error variants, with three inconsistencies we found, on `Retry-After`, on the SDK version (the docs say v0.1.0, the tags are v0.2.0) and on the annual discount (12 of 15). URL versioning at `/v1` and a dated public changelog (15)."
        },
        {
          "key": "ergonomics",
          "name": "Agent ergonomics",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 72,
          "points": 11.7,
          "reason": "Graded on the REST API, with the MCP server noted. The MCP server lists six tools, `search_messages` returns summaries and `read_message` reads large bodies in parts. REST message lists return full text and HTML bodies with no field selection, and quoted history isn't stripped (20 of 25). Message lists take `limit` up to 100, `offset`, `direction`, `threadId` and `since`. Thread lists stop at 50 and webhook deliveries at 20, both without pagination, and REST has no text search (14 of 20). Errors are always JSON. Quota gates carry `code`, an `upgrade` object, `resetAt` and `X-Robotomail-Retriable`, and an unknown path returned a JSON 404 with links when we tried one. Most other errors are a bare `error` string (17 of 20). Sends take no idempotency key and the SDKs don't retry them. Webhooks carry a stable delivery ID, and MCP tool annotations were not read (8 of 20). A send needs three fields and signup creates the first mailbox. SDKs exist in five languages but install from GitHub tags, not from package registries (13 of 15)."
        },
        {
          "key": "security",
          "name": "Security \u0026 auth",
          "weight": 14,
          "effectiveWeight": 17.5,
          "score": 65,
          "points": 11.38,
          "reason": "REST keys are revocable by API, stored as SHA-256 hashes, and can be limited to named mailboxes. The MCP server takes OAuth with PKCE, `mail:read` and `mail:send` scopes, 10-minute access tokens and per-app disconnect. Keys travel in the `Authorization` header only. A REST key can't be made read-only (27 of 30). An MCP grant with `mail:read` alone is read-only, and a mailbox can be paused. Sends go out at once, with no drafts or approval step (12 of 20). Inbound mail is untrusted content. A security guide tells developers to pass email as data, check recipients and require approval for sensitive actions, and says attachments aren't scanned. Nothing is filtered on the service side (11 of 15). The dashboard has a read-only Audit Feed of email activity and the API lists the last 20 delivery attempts per webhook. No log of API calls was found (8 of 15). `security.txt` is valid until 24 August 2027 and reports go to the support address. No bug bounty, SOC 2 or ISO 27001 statement found (7 of 20)."
        },
        {
          "key": "payments",
          "name": "Payments \u0026 pricing",
          "weight": 10,
          "effectiveWeight": 12.5,
          "score": 35,
          "points": 4.38,
          "reason": "No x402, MPP or L402. An unauthenticated POST to `/v1/mailboxes` returned 401 (0 of 40). Three plan prices are public, $19, $79 and $199 a month, with no per-unit price or overage (10 of 20). The Free plan needs no card and doesn't expire, but exchanges mail only with the owner's verified address, 10 each way a month, so it tests the loop without doing the job (15 of 20). `POST /v1/signup` returns an API key with no browser, and `POST /v1/billing/upgrade` returns a checkout link. The key does nothing until a person clicks the verification link, and a person pays at checkout (10 of 20)."
        },
        {
          "key": "tasks",
          "name": "Task success",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
        },
        {
          "key": "maintenance",
          "name": "Maintenance \u0026 community",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 77,
          "points": 6.74,
          "reason": "The latest changelog entry is 25 September 2026, with CLI 0.1.10 on npm and SDK tags v0.2.0 the same day (30). Six dated changelog entries in the 90 days to 8 October, on 12, 19 and 24 August and 9, 23 and 25 September (20). A closed service with a public changelog and email support that aims to answer within one working day. We didn't test support or read the GitHub issue trackers (10 of 15). The server isn't in the official MCP registry, where a search for robotomail returned nothing. The five SDKs are current but aren't on npm, PyPI, RubyGems or crates.io (10 of 15). The SDK repositories have CI workflows with pinned actions and a contract check against the OpenAPI file, and the CLI has one dependency. We didn't read the CI results (7 of 10)."
        },
        {
          "key": "transparency",
          "name": "Transparency \u0026 trust",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 73,
          "points": 6.39,
          "note": "editorial 64, provenance 82",
          "reason": "A closed service under published terms. The five SDKs are MIT. The CLI's npm record has no licence or repository field (17 of 30). The privacy policy and the terms agree on retention, with messages kept until deleted, mail server copies purged after 7 days and trial data removed within 24 hours to 7 days, and the policy says email content isn't read or used for advertising. No DPA is published and the policy gives its date as September 2026 without a day (20 of 30). The terms promise 30 days' notice before an endpoint or version is retired, with `Deprecation` and `Sunset` headers, and the changelog records the legacy free plan's retirement on 19 August after notice in July (18 of 20). The policy names Stripe, Resend and Cloudflare R2. It gives no locations and doesn't name where the mail server and database are hosted (9 of 20)."
        }
      ],
      "assessment": {
        "date": "2026-10-08",
        "basis": "public evidence",
        "confidence": "medium",
        "notes": {
          "ergonomics": "Graded on the REST API, with the MCP server noted. The MCP server lists six tools, `search_messages` returns summaries and `read_message` reads large bodies in parts. REST message lists return full text and HTML bodies with no field selection, and quoted history isn't stripped (20 of 25). Message lists take `limit` up to 100, `offset`, `direction`, `threadId` and `since`. Thread lists stop at 50 and webhook deliveries at 20, both without pagination, and REST has no text search (14 of 20). Errors are always JSON. Quota gates carry `code`, an `upgrade` object, `resetAt` and `X-Robotomail-Retriable`, and an unknown path returned a JSON 404 with links when we tried one. Most other errors are a bare `error` string (17 of 20). Sends take no idempotency key and the SDKs don't retry them. Webhooks carry a stable delivery ID, and MCP tool annotations were not read (8 of 20). A send needs three fields and signup creates the first mailbox. SDKs exist in five languages but install from GitHub tags, not from package registries (13 of 15).",
          "maintenance": "The latest changelog entry is 25 September 2026, with CLI 0.1.10 on npm and SDK tags v0.2.0 the same day (30). Six dated changelog entries in the 90 days to 8 October, on 12, 19 and 24 August and 9, 23 and 25 September (20). A closed service with a public changelog and email support that aims to answer within one working day. We didn't test support or read the GitHub issue trackers (10 of 15). The server isn't in the official MCP registry, where a search for robotomail returned nothing. The five SDKs are current but aren't on npm, PyPI, RubyGems or crates.io (10 of 15). The SDK repositories have CI workflows with pinned actions and a contract check against the OpenAPI file, and the CLI has one dependency. We didn't read the CI results (7 of 10).",
          "payments": "No x402, MPP or L402. An unauthenticated POST to `/v1/mailboxes` returned 401 (0 of 40). Three plan prices are public, $19, $79 and $199 a month, with no per-unit price or overage (10 of 20). The Free plan needs no card and doesn't expire, but exchanges mail only with the owner's verified address, 10 each way a month, so it tests the loop without doing the job (15 of 20). `POST /v1/signup` returns an API key with no browser, and `POST /v1/billing/upgrade` returns a checkout link. The key does nothing until a person clicks the verification link, and a person pays at checkout (10 of 20).",
          "reliability": "Graded as a hosted service, on the REST API. A public UptimeRobot page with one monitor, on `robotomail.com/api/health`, and daily history. Sending, inbound mail and the MCP server have no component of their own (14 of 20). The monitor shows 100 per cent on each of the 90 days from 11 July to 8 October 2026 and the event feed is empty. One health check can't show a mail outage, so less 5 (25 of 30). Limits are published with numbers, 30 sends a minute per mailbox, 60 per account, daily and monthly caps per plan, 5 signups an hour per IP and 5 concurrent SSE streams (15). The error reference says every 429 carries `Retry-After`, the OpenAPI description says route-produced 429s don't, sends have no idempotency key, and the documented advice is to check sent mail before retrying (9 of 15). No SLA found on the pricing page or in the terms (0). The API is at `/v1` with no beta label (10).",
          "schema": "OpenAPI 3.1 at `/openapi.json` with 40 operations on 27 paths, each with an operation ID (25). `llms.txt`, and a Markdown copy of every public page by adding `.md` or sending `Accept: text/markdown` (10). Operation descriptions state what each route does, which key type it needs and which gates apply, and `llms.txt` says when not to use the product. The MCP tool descriptions sit behind OAuth and were not read (15 of 20). Request schemas carry required fields, `format: email` and `uuid`, length limits, patterns and enums. The `headers` field on a send is a free object (13 of 15). An error reference and per-route error variants, with three inconsistencies we found, on `Retry-After`, on the SDK version (the docs say v0.1.0, the tags are v0.2.0) and on the annual discount (12 of 15). URL versioning at `/v1` and a dated public changelog (15).",
          "security": "REST keys are revocable by API, stored as SHA-256 hashes, and can be limited to named mailboxes. The MCP server takes OAuth with PKCE, `mail:read` and `mail:send` scopes, 10-minute access tokens and per-app disconnect. Keys travel in the `Authorization` header only. A REST key can't be made read-only (27 of 30). An MCP grant with `mail:read` alone is read-only, and a mailbox can be paused. Sends go out at once, with no drafts or approval step (12 of 20). Inbound mail is untrusted content. A security guide tells developers to pass email as data, check recipients and require approval for sensitive actions, and says attachments aren't scanned. Nothing is filtered on the service side (11 of 15). The dashboard has a read-only Audit Feed of email activity and the API lists the last 20 delivery attempts per webhook. No log of API calls was found (8 of 15). `security.txt` is valid until 24 August 2027 and reports go to the support address. No bug bounty, SOC 2 or ISO 27001 statement found (7 of 20).",
          "transparency": "A closed service under published terms. The five SDKs are MIT. The CLI's npm record has no licence or repository field (17 of 30). The privacy policy and the terms agree on retention, with messages kept until deleted, mail server copies purged after 7 days and trial data removed within 24 hours to 7 days, and the policy says email content isn't read or used for advertising. No DPA is published and the policy gives its date as September 2026 without a day (20 of 30). The terms promise 30 days' notice before an endpoint or version is retired, with `Deprecation` and `Sunset` headers, and the changelog records the legacy free plan's retirement on 19 August after notice in July (18 of 20). The policy names Stripe, Resend and Cloudflare R2. It gives no locations and doesn't name where the mail server and database are hosted (9 of 20)."
        },
        "sources": [
          {
            "what": "llms.txt index",
            "url": "https://robotomail.com/llms.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "OpenAPI 3.1 spec",
            "url": "https://robotomail.com/openapi.json",
            "seen": "2026-10-08"
          },
          {
            "what": "pricing",
            "url": "https://robotomail.com/pricing",
            "seen": "2026-10-08"
          },
          {
            "what": "limits and quotas",
            "url": "https://robotomail.com/docs/concepts/limits.md",
            "seen": "2026-10-08"
          },
          {
            "what": "authentication and key scoping",
            "url": "https://robotomail.com/docs/authentication.md",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP server, OAuth and tools",
            "url": "https://robotomail.com/docs/mcp.md",
            "seen": "2026-10-08"
          },
          {
            "what": "OAuth authorisation server metadata",
            "url": "https://robotomail.com/.well-known/oauth-authorization-server/api/auth",
            "seen": "2026-10-08"
          },
          {
            "what": "signup API",
            "url": "https://robotomail.com/docs/api/signup.md",
            "seen": "2026-10-08"
          },
          {
            "what": "messages API",
            "url": "https://robotomail.com/docs/api/messages.md",
            "seen": "2026-10-08"
          },
          {
            "what": "events (SSE) API",
            "url": "https://robotomail.com/docs/api/events.md",
            "seen": "2026-10-08"
          },
          {
            "what": "webhooks API and at-least-once delivery",
            "url": "https://robotomail.com/docs/api/webhooks.md",
            "seen": "2026-10-08"
          },
          {
            "what": "error reference and deprecation policy",
            "url": "https://robotomail.com/docs/api/errors.md",
            "seen": "2026-10-08"
          },
          {
            "what": "agent email security guide",
            "url": "https://robotomail.com/docs/guides/agent-email-security.md",
            "seen": "2026-10-08"
          },
          {
            "what": "SDK guide",
            "url": "https://robotomail.com/docs/sdks.md",
            "seen": "2026-10-08"
          },
          {
            "what": "changelog",
            "url": "https://robotomail.com/docs/changelog.md",
            "seen": "2026-10-08"
          },
          {
            "what": "terms of service",
            "url": "https://robotomail.com/terms.md",
            "seen": "2026-10-08"
          },
          {
            "what": "privacy policy",
            "url": "https://robotomail.com/privacy.md",
            "seen": "2026-10-08"
          },
          {
            "what": "acceptable use policy",
            "url": "https://robotomail.com/acceptable-use.md",
            "seen": "2026-10-08"
          },
          {
            "what": "contact page, legal entity and support",
            "url": "https://robotomail.com/contact.md",
            "seen": "2026-10-08"
          },
          {
            "what": "security.txt",
            "url": "https://robotomail.com/.well-known/security.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "status page monitor history",
            "url": "https://stats.uptimerobot.com/api/getMonitorList/5hwqjYveUl",
            "seen": "2026-10-08"
          },
          {
            "what": "CLI on npm",
            "url": "https://registry.npmjs.org/@robotomail%2Fcli",
            "seen": "2026-10-08"
          },
          {
            "what": "TypeScript SDK repository (tags, licence, CI workflow)",
            "url": "https://github.com/robotomail/robotomail-node",
            "seen": "2026-10-08"
          },
          {
            "what": "official MCP registry search (no result)",
            "url": "https://registry.modelcontextprotocol.io/v0/servers?search=robotomail",
            "seen": "2026-10-08"
          },
          {
            "what": "domain registration (RDAP)",
            "url": "https://rdap.org/domain/robotomail.com",
            "seen": "2026-10-08"
          },
          {
            "what": "unauthenticated API and unknown-path responses",
            "url": "https://api.robotomail.com/v1/mailboxes",
            "seen": "2026-10-08"
          }
        ],
        "openQuestions": [
          "unchecked: the MCP tool definitions, their descriptions and annotations. `tools/list` needs an OAuth grant, and an unauthenticated call returned 401.",
          "unchecked: GitHub stars, open issues and CI results for the SDK repositories. The GitHub API refused us for its rate limit, so `githubStars` is empty.",
          "unchecked: the legal entity at Companies House. The name and country come from the vendor's own pages.",
          "Whether a 429 carries `Retry-After`. The error reference says every one does and the OpenAPI description says route-produced ones don't.",
          "Which annual discount applies. The pricing page shows 50 per cent for a limited time and the billing API docs say about 25 per cent.",
          "Where the mail server and database are hosted. The privacy policy names Stripe, Resend and Cloudflare R2 only.",
          "No DPA, SLA or security certification is published. The security guide tells customers to ask through the contact page."
        ]
      },
      "negative": 0,
      "verdict": "A public OpenAPI 3.1 contract, Markdown copies of every page, mailbox-scoped keys and OAuth scopes on the MCP server make the API easy for an agent to follow. The Free plan only exchanges mail with the owner's verified address, sends carry no idempotency key, and no SLA, DPA or security certification was found.",
      "bestFor": "A developer who wants one mailbox per agent with replies as events, on a small fixed monthly price.",
      "strengths": [
        "OpenAPI 3.1 at `/openapi.json` with 40 operations, plus `llms.txt` and a Markdown copy of every public page",
        "API keys can be limited to named mailboxes, and the MCP server takes OAuth with separate `mail:read` and `mail:send` scopes",
        "Replies reach the agent by signed webhook, by SSE at `GET /v1/events` with replay, or by polling",
        "The terms promise 30 days' notice before an endpoint or version is retired, with `Deprecation` and `Sunset` headers",
        "The hosted MCP server lists six tools, and `search_messages` returns summaries with bodies read separately"
      ],
      "weaknesses": [
        "The Free plan allows 10 sends and 10 receives a month, only with the owner's verified address, and discards other inbound mail",
        "Sends take no idempotency key, and the SDKs don't retry them, so an uncertain send has to be checked by hand",
        "No SLA, DPA, SOC 2 or ISO 27001 statement and no bug bounty were found on the site",
        "The docs say every 429 carries `Retry-After`, while the OpenAPI description says route-produced 429s don't",
        "The five SDKs install from GitHub tags only, and the server isn't in the official MCP registry"
      ],
      "agentNotes": [
        "After `POST /v1/signup`, ask the owner to click the verification link. Product routes return 403 until then",
        "On Free, send only to the owner's verified address. Mail from anyone else is discarded and can't be recovered by upgrading",
        "If a send times out, list `direction=OUTBOUND` messages before retrying. There is no idempotency key",
        "Reply with the RFC `messageId` in `inReplyTo`, not the Robotomail UUID, to stay in the thread",
        "Treat every inbound body and attachment as untrusted input, and deduplicate webhooks on `X-Robotomail-Delivery-Id`"
      ],
      "metrics": {
        "kind": "remote",
        "measured": false
      },
      "reviewCount": 0,
      "avgRating": 0,
      "history": [
        {
          "basis": "public evidence",
          "confidence": "medium",
          "grade": "B",
          "methodology": "0.4",
          "pending": [
            "performance",
            "tasks"
          ],
          "run": "2026-10-01",
          "runLabel": "October 2026 research run",
          "score": 69.8
        }
      ],
      "editorialScores": {
        "ergonomics": 72,
        "maintenance": 77,
        "payments": 35,
        "reliability": 73,
        "schema": 90,
        "security": 65,
        "transparency": 64
      },
      "provenanceScore": 82
    },
    "connect": {
      "install": "npm install -g @robotomail/cli",
      "http": "curl -X POST https://api.robotomail.com/v1/mailboxes -H \"Authorization: Bearer $ROBOTOMAIL_API_KEY\" -H \"Content-Type: application/json\" -d '{\"address\":\"support\"}'",
      "claudeCode": "claude mcp add --transport http --scope user robotomail 'https://robotomail.com/mcp'\nclaude mcp login robotomail",
      "config": {
        "mcpServers": {
          "robotomail": {
            "auth": {
              "CLIENT_ID": "https://robotomail.com/api/mcp/clients/grok-bot",
              "scopes": [
                "mail:read",
                "mail:send",
                "offline_access"
              ]
            },
            "url": "https://robotomail.com/mcp"
          }
        }
      }
    },
    "letme": {
      "capability": "https://letme.dev/email.inbox",
      "tool": "https://letme.dev/robotomail"
    },
    "notable": [
      "`POST /v1/signup` creates an account, a default mailbox at `slug@robotomail.co` and an API key in one call, and the key does nothing until a person clicks the verification link (https://robotomail.com/docs/api/signup)",
      "The Free plan, permanent since 9 September 2026, allows one mailbox with 10 sends and 10 receives a calendar month, only between the agent and the owner's verified address. Other inbound mail is discarded (https://robotomail.com/docs/concepts/limits)",
      "The hosted MCP server at https://robotomail.com/mcp takes OAuth only, with authorisation code and PKCE, refresh tokens and device login. REST API keys don't work on it, and dynamic client registration is disabled (https://robotomail.com/docs/mcp)",
      "The MCP server lists six tools and handles plain text only, with no attachments, reply-all, mailbox creation or domain management. Those need the REST API (https://robotomail.com/docs/mcp)",
      "Outbound mail goes through Resend and attachments sit in Cloudflare R2, per the privacy policy (https://robotomail.com/privacy)",
      "The free allowance changed three times in 2026. It was 3 mailboxes and 5,000 sends a month on 2 April, a 3-day trial on 16 June, with the legacy plan retired on 19 August after notice in July, and the current plan on 9 September (https://robotomail.com/docs/changelog)",
      "Robotomail is run by Tiny Bot Labs Limited in the United Kingdom, built by one named founder and bootstrapped, per its about and contact pages (https://robotomail.com/contact)",
      "The home page and `llms.txt` address agents directly and ask them to fetch `/skill` and sign up by API. We record this as a fact and take no deduction (https://robotomail.com/llms.txt)"
    ],
    "area": "communication",
    "details": [
      {
        "label": "Inbox creation",
        "value": "`POST /v1/mailboxes` with an `address`, and optionally a `domainId` and `displayName`. Addresses default to @robotomail.co. Signup creates the first mailbox"
      },
      {
        "label": "How replies arrive",
        "value": "Webhooks signed with HMAC-SHA256 in `X-Robotomail-Signature`, SSE at `GET /v1/events`, or polling `GET /v1/mailboxes/:id/messages`. Five event types"
      },
      {
        "label": "Threading",
        "value": "By `In-Reply-To` and `References` headers, then by normalised subject. A reply passes the RFC `messageId` in `inReplyTo`. `GET /v1/mailboxes/:id/threads` returns the last 50 threads with no pagination"
      },
      {
        "label": "Custom domains",
        "value": "Paid plans only. Starter 1, Growth 5, Scale unlimited. `POST /v1/domains` returns MX, SPF, DKIM and DMARC records to publish"
      },
      {
        "label": "Free plan",
        "value": "1 mailbox, 10 sends and 10 receives a calendar month, only with the owner's verified address, 1 GB of attachments, no card, no expiry"
      },
      {
        "label": "Paid plans",
        "value": "Starter $19 a month (10 mailboxes, 15,000 sends a month and 500 a day per mailbox, 2,000 inbound). Growth $79 (50 mailboxes, 1,000 a day, 20,000 inbound). Scale $199 (200 mailboxes, 2,000 a day, unlimited inbound)"
      },
      {
        "label": "Rate limits",
        "value": "30 sends a minute per mailbox and 60 per account, daily and monthly send caps per plan, 5 signups an hour per IP, 5 concurrent SSE streams. No general API-wide limiter, per the limits page"
      },
      {
        "label": "Credentials",
        "value": "Bearer keys (`rm_` plus 64 hex characters), stored as SHA-256 hashes, full-access or limited to named mailboxes. MCP uses OAuth with `mail:read`, `mail:send` and `offline_access`, access tokens lasting 10 minutes"
      },
      {
        "label": "MCP server",
        "value": "Streamable HTTP at https://robotomail.com/mcp. Tools are `list_mailboxes`, `search_messages`, `read_message`, `send_email`, `reply_to_email` and `set_mailbox_display_name`"
      },
      {
        "label": "Errors",
        "value": "Always JSON with an `error` string. Payment and quota gates add `code`, an `upgrade` object and `resetAt`. Unknown `/v1` paths return a JSON 404 with `code: NOT_FOUND` and links"
      },
      {
        "label": "SDKs and CLI",
        "value": "TypeScript, Python, Go, Ruby and Rust SDKs at v0.2.0 (25 September 2026), MIT, installed from GitHub tags. CLI `@robotomail/cli` 0.1.10 on npm, Node 20 or later"
      },
      {
        "label": "Webhook retries",
        "value": "Five retries from 1 minute to 12 hours, paused after 10 consecutive failures. Delivery is at-least-once with a stable `X-Robotomail-Delivery-Id`"
      },
      {
        "label": "Message limits",
        "value": "50 recipients each in `to`, `cc` and `bcc`, 25 MB a message, 10 attachments on a send and 20 on an inbound message"
      },
      {
        "label": "Status",
        "value": "UptimeRobot page with one monitor on `/api/health`, 100 per cent on each of the 90 days to 8 October 2026 and no posted events"
      },
      {
        "label": "Deprecations",
        "value": "At least 30 days' notice in the changelog with `Deprecation` and `Sunset` headers, written into the terms of service"
      }
    ],
    "unitPrices": [
      {
        "item": "Starter plan",
        "unit": "month",
        "usd": 19,
        "note": "10 mailboxes, 15,000 sends a month per mailbox, 2,000 inbound, 1 custom domain"
      },
      {
        "item": "Growth plan",
        "unit": "month",
        "usd": 79,
        "note": "50 mailboxes, 1,000 sends a day per mailbox, 20,000 inbound, 5 custom domains"
      },
      {
        "item": "Scale plan",
        "unit": "month",
        "usd": 199,
        "note": "200 mailboxes, 2,000 sends a day per mailbox, unlimited inbound and custom domains"
      }
    ],
    "provenance": {
      "legalEntity": "Tiny Bot Labs Limited",
      "domain": "robotomail.com",
      "domainRegistered": "2026-03-10",
      "endpointOnVendorDomain": true,
      "terms": "https://robotomail.com/terms",
      "privacy": "https://robotomail.com/privacy",
      "statusPage": "https://stats.uptimerobot.com/5hwqjYveUl",
      "changelog": "https://robotomail.com/docs/changelog",
      "securityTxt": "valid",
      "checked": "2026-10-08",
      "notes": [
        "The terms of service (last updated 5 October 2026) and the privacy policy (last updated September 2026, no day given) both name Tiny Bot Labs Limited as owner and operator. The contact page says it is registered in the United Kingdom. We did not look the company up at Companies House.",
        "The terms of service cover the API itself, including versioning, quotas, retention and billing. There is no separate API agreement or DPA.",
        "RDAP gives robotomail.com a registration date of 2026-03-10 with NameCheap as registrar. Mailbox addresses use a second domain, robotomail.co.",
        "The API answers at api.robotomail.com and at robotomail.com/v1, and the MCP server at robotomail.com/mcp.",
        "`/.well-known/security.txt` gives a contact address, a canonical URL and an expiry of 24 August 2027. Its policy link points to the contact page.",
        "The status page is hosted by UptimeRobot, not on the vendor's domain."
      ],
      "score": 82,
      "checks": [
        {
          "check": "Legal entity named",
          "value": "Tiny Bot Labs Limited",
          "points": 20,
          "max": 20,
          "state": "ok"
        },
        {
          "check": "Domain age",
          "value": "robotomail.com, registered 2026-03-10 (under a year)",
          "points": 0,
          "max": 15,
          "state": "no"
        },
        {
          "check": "Endpoint on the vendor's domain",
          "value": "api.robotomail.com",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Terms of service",
          "value": "read, states 4 of the 7 things a reader expects",
          "points": 7.4,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Privacy policy",
          "value": "read, states 8 of the 8 things a reader expects",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Status page",
          "value": "stats.uptimerobot.com/5hwqjYveUl",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Changelog",
          "value": "published",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "security.txt",
          "value": "valid",
          "points": 10,
          "max": 10,
          "state": "ok"
        }
      ],
      "policies": [
        {
          "kind": "terms",
          "url": "https://robotomail.com/terms",
          "state": "read",
          "readAt": "2026-10-08",
          "statedDate": "2026-10-05",
          "words": 768,
          "points": 7.4,
          "max": 10,
          "expected": [
            {
              "key": "terms.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Last updated: 5 October 2026",
              "says": "Last updated 2026-10-05"
            },
            {
              "key": "terms.law",
              "label": "Names the governing law or courts",
              "found": false
            },
            {
              "key": "terms.liability",
              "label": "States a limit on its liability",
              "found": true,
              "quote": "To the maximum extent permitted by law, Robotomail shall not be liable for any indirect, incidental, special, or consequential damages arising from your use of the Service, including but not limited to lost emails, failed deliveries, or data loss.",
              "says": "Rules out indirect and consequential losses, with no cap named in this sentence"
            },
            {
              "key": "terms.termination",
              "label": "Says how the agreement or account can be ended",
              "found": true,
              "quote": "We reserve the right to suspend or terminate your account immediately, without prior notice, if you violate these Terms or engage in activity that may harm the Service or other users."
            },
            {
              "key": "terms.changes",
              "label": "Says how changes to the terms are announced",
              "found": false
            },
            {
              "key": "terms.use",
              "label": "Lists what users may not do",
              "found": true,
              "quote": "You may not use the Service to send spam, phishing, malware, or any unsolicited bulk email."
            },
            {
              "key": "terms.sla",
              "label": "Refers to a service level or uptime commitment",
              "found": false
            }
          ],
          "toKnow": [
            {
              "key": "terms.cutoff",
              "label": "Says access can be ended without notice or for any reason",
              "found": true,
              "quote": "We reserve the right to suspend or terminate your account immediately, without prior notice, if you violate these Terms or engage in activity that may harm the Service or other users."
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "The account holder is responsible for all activity under the account, including actions taken by AI agents using its API keys.",
              "quote": "You are responsible for all activity under your account, including actions taken by AI agents using your API keys."
            },
            {
              "date": "2026-10-08",
              "text": "Robotomail commits to at least 30 days of notice before a price increase takes effect.",
              "quote": "We will provide at least 30 days’ notice before any price increases take effect."
            },
            {
              "date": "2026-10-08",
              "text": "A customer may request an export of its data for up to 30 days after termination.",
              "quote": "You may request export of your data for up to 30 days following termination."
            }
          ]
        },
        {
          "kind": "privacy",
          "url": "https://robotomail.com/privacy",
          "state": "read",
          "readAt": "2026-10-08",
          "statedDate": "2026-09-01",
          "words": 950,
          "points": 10,
          "max": 10,
          "expected": [
            {
              "key": "privacy.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Last updated: September 2026",
              "says": "Last updated 2026-09-01"
            },
            {
              "key": "privacy.collected",
              "label": "Says what personal data is collected",
              "found": true,
              "quote": "We collect information you provide when creating an account (email address, name, account slug) and information generated through your use of the Service (email messages, API logs, usage metrics)."
            },
            {
              "key": "privacy.retention",
              "label": "Says how long data is kept",
              "found": true,
              "quote": "Account data is retained as long as your account is active.",
              "says": "For as long as needed, with no period named"
            },
            {
              "key": "privacy.processors",
              "label": "Says who else receives the data",
              "found": true,
              "quote": "We may share your information only in the following circumstances: with integrations you explicitly authorize (see section 15), with third-party service providers who assist in operating the Service (see section 7), when required by law or to comply with legal process, or in connection with a merger, acquisition, or s…"
            },
            {
              "key": "privacy.sale",
              "label": "Says whether personal data is sold or shared for advertising",
              "found": true,
              "quote": "We do not sell your personal information to third parties.",
              "says": "Says it does not sell personal data"
            },
            {
              "key": "privacy.rights",
              "label": "Says what rights people have over their data",
              "found": true,
              "quote": "You have the right to access, correct, or delete your personal data."
            },
            {
              "key": "privacy.contact",
              "label": "Gives a privacy contact",
              "found": true,
              "quote": "If you connect Robotomail to ChatGPT, Claude, or another MCP app, you authorize the permissions displayed on the consent screen for that app."
            },
            {
              "key": "privacy.transfers",
              "label": "Says where data is transferred or stored",
              "found": true,
              "quote": "Your information may be transferred to and processed in countries other than your country of residence."
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "Email messages stay in the Robotomail database indefinitely unless the customer deletes them through the API.",
              "quote": "Email messages are retained indefinitely in our database unless you delete them via the API."
            },
            {
              "date": "2026-10-08",
              "text": "Robotomail says it does not read, analyse or use email content for advertising or for any purpose beyond running the service.",
              "quote": "We do not read, analyze, or use the content of your emails for advertising or any purpose beyond providing the Service."
            },
            {
              "date": "2026-10-08",
              "text": "Disconnecting a connected AI or MCP app such as ChatGPT or Claude does not delete emails or information already shared with that app.",
              "quote": "Disconnecting does not delete your emails or information already shared with an app."
            }
          ]
        }
      ]
    },
    "pageJsonUrl": "https://www.anchorterminal.com/tools/robotomail.json",
    "live": {
      "slug": "robotomail",
      "probe": {
        "target": "https://api.robotomail.com/v1",
        "method": "get",
        "lastAt": "2026-10-08T21:12:20.360962098Z",
        "lastOk": true,
        "lastStatus": 404,
        "lastMs": 142,
        "authRequired": false,
        "uptime24h": 100,
        "uptime30d": 100,
        "p50ms24h": 126,
        "p95ms24h": 202,
        "samples24h": 21,
        "samples30d": 21,
        "days": [
          {
            "date": "2026-10-08",
            "probes": 21,
            "ok": 21
          }
        ]
      },
      "vendorStatus": {
        "page": "https://stats.uptimerobot.com/5hwqjYveUl",
        "indicator": "unknown",
        "summary": "no machine-readable status found",
        "checkedAt": "2026-10-08T19:39:08.554234665Z"
      },
      "updatedAt": "2026-10-08T21:12:20.360962098Z"
    }
  }
}
