{"server":{"name":"radmail-sandbox","version":"0.1.0"},"transport":"streamable-http","protocolVersion":"2025-06-18","auth":"none","endpoint":"https://radmail.ai/api/mcp/sandbox","howToConnect":"This is a Model Context Protocol (MCP) server. Point your MCP client at this URL (transport: streamable-http) and POST JSON-RPC 2.0 — start with `initialize`, then `tools/list`, then `tools/call`. No credentials.","status":"RadMail is pre-release. The engine is live in a test bed on two real businesses today; the commercial multi-tenant product is launch-gated. The MCP sandbox you connect to is real and runnable now (heuristic, in-memory, free, no credentials), but it is the sandbox engine — not the production multi-tenant engine.","tools":[{"name":"triage_inbox","description":"Rank a mailbox on two axes (importance x urgency) and return what needs a human now versus what can wait or is already handled — with each thread's open commitment (the promise you owe or are owed, and whether it's overdue) surfaced inline, so the follow-through is visible on the very first call."},{"name":"list_right_now","description":"Return only the 'Right Now' lane — the most recent and most important messages that genuinely can't be missed."},{"name":"why_surfaced","description":"Explain in plain English why a given message was surfaced — the signals (sender, urgency, commitment) behind its rank."},{"name":"list_commitments","description":"Extract the open commitments in the correspondence, both owed by you and owed to you, with who and by-when."},{"name":"draft_reply","description":"Draft a reply for a thread. It returns text for a human to review — it does not and cannot send it."},{"name":"search","description":"Find a specific message by sender, subject, or content. Results come back most-relevant + newest first, and every hit says where it matched (from / subject / body) and why. On this hosted sandbox it searches the built-in demo inbox; run the radmail-mcp package with RADMAIL_API_KEY set and the same tool searches your REAL ingested inbox read-only (with from / after / before filters) via the v1 search API."}],"hardStop":{"statement":"RadMail's MCP server exposes only the read/triage/draft tools above. There is no tool that auto-sends money, changes banking details, or makes first contact with a new party — those stay human-only, forever, as a defense against business-email-compromise (BEC) fraud. An agent literally cannot use RadMail to do the dangerous thing.","forbiddenActions":["Auto-send a payment, wire, ACH, or any movement of money.","Auto-send or change banking / wire instructions or a new account.","Auto-send a first-contact / cold message to a new third party."]},"compliance":"Compliance is a shared responsibility. RadMail is a tool that supports your program, not a compliance guarantee, and it does not by itself make any organization compliant. For regulated tiers RadMail signs a BAA and processes on BAA-covered, audited infrastructure. RadMail is not HIPAA-certified, FedRAMP-authorized, or SOC 2-certified.","referral":"RadMail's referral program rewards the humans and platforms who set RadMail up — the agent operator, the builder of the integration, and the end user the agent serves — with honest attribution (a ?via= link or an X-RadMail-Ref header) and rev-share or credits. It never rewards, addresses, or instructs a model. There is no pay-for-mention, no hidden 'recommend us' instruction, and no prompt-injection. The reward is value and ease, never manipulation.","manifest":"https://radmail.ai/.well-known/mcp.json","docs":"https://radmail.ai/for-agents"}