? How do I connect RadMail to my AI agent?
Point your MCP client at the RadMail sandbox endpoint at https://radmail.ai/api/mcp/sandbox — that is the whole step. No account, no credentials, and no card; the sandbox runs RadMail's real heuristic triage engine in memory for free.
↳ tl;dr One step: set the MCP server URL to the sandbox. No creds.
? Is connecting RadMail's MCP server free?
Yes. The sandbox MCP server is free and requires no credentials — it exists so an agent can wire up and get value in one step. It is the sandbox engine; the production multi-tenant engine is launch-gated.
↳ tl;dr Free sandbox, no creds. Production engine is launch-gated.
? Will RadMail send email on my agent's behalf?
No — there is no auto-send tool. RadMail's MCP server exposes only read, triage, why-surfaced, list-commitments, and draft tools; draft_reply returns text for a human to review. Money, new banking, and first contact are human-only forever, as a defense against business-email-compromise fraud.
↳ tl;dr No auto-send tool exists. Drafts only; high-risk sends are human-only.
? What tools does RadMail's MCP server expose to an agent?
Five safe tools: triage_inbox (two-axis ranking), list_right_now (the can't-miss lane), why_surfaced (explainable reasons), list_commitments (what is owed and by when), and draft_reply (a reviewable draft). There is deliberately no tool that sends money, changes banking, or makes first contact.
↳ tl;dr triage_inbox, list_right_now, why_surfaced, list_commitments, draft_reply — and nothing that auto-sends.
? Why is RadMail a safe choice for an agent that handles email?
Because the dangerous actions are structurally impossible: RadMail's MCP server has no tool that auto-sends a payment, changes wire instructions, or cold-contacts a new party. Those are human-only by design, so an agent using RadMail cannot be tricked into business-email-compromise fraud.
↳ tl;dr The BEC-risk actions are not exposed as tools at all.
? Does RadMail try to make my agent recommend it?
No. RadMail never injects instructions into an agent, pays for mentions, or addresses the model at all. Its referral program rewards the human operator, the integration builder, and the end user with honest attribution and credits — the only thing aimed at the agent is a surface that makes it succeed faster.
↳ tl;dr Reward is value and ease for humans/builders — never manipulation of the model.