{"id":"a511bb44-e273-4dae-bee2-ff866d6c6ac0","entityType":"agent","slug":"clawhub-agenticbrian-agenticboxes-email","name":"Openclaw","canonicalUrl":"https://www.xpersona.co/agent/clawhub-agenticbrian-agenticboxes-email","canonicalPath":"/agent/clawhub-agenticbrian-agenticboxes-email","generatedAt":"2026-10-11T10:46:24.719Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"editorial-content","verified":true,"confidence":"high","updatedAt":"2026-10-11T08:44:57.025Z","emptyReason":null},"description":"Send and receive email as an agent via the agenticboxes HTTP API — one API key, no IMAP/SMTP setup. Skill: Openclaw Owner: agenticbrian Summary: Send and receive email as an agent via the agenticboxes HTTP API — one API key, no IMAP/SMTP setup. Tags: agentic:1.2.0, communication:1.2.0, email:1.2.0, latest:1.4.5 Version history: v1.4.5 | 2026-05-19T17:22:26.422Z | user Webhook HMAC signing: every delivery carries X-Boxes-Signature (timestamped HMAC-SHA256); new GET /account/webhook + POST /account/webhook/secret/rot","descriptionLabel":"Technical summary","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. 1.1K downloads reported by the source. Last updated 10/11/2026.","installCommand":"clawhub skill install s17d15vxccwse3x8bwbg87z1t586zvqd:agenticboxes-email","sourceUrl":"https://clawhub.ai/agenticbrian/agenticboxes-email","homepage":"https://clawhub.ai/agenticbrian/skills/agenticboxes-email","primaryLinks":[{"label":"View on ClawHub","url":"https://clawhub.ai/agenticbrian/agenticboxes-email","kind":"source"},{"label":"Homepage","url":"https://clawhub.ai/agenticbrian/skills/agenticboxes-email","kind":"homepage"}],"safetyScore":84,"overallRank":62,"popularityScore":61,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"Send and receive email as an agent via the agenticboxes HTTP API — one API key, no IMAP/SMTP setup. Skill: Openclaw Owner: agenticbrian Summary: Send and receiv"},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-10-11T08:44:57.025Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[],"verifiedCount":0,"selfDeclaredCount":1,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile"}},"adoption":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-11T08:44:57.025Z","emptyReason":null},"stars":null,"forks":null,"downloads":1109,"packageName":null,"latestVersion":"1.4.5","tractionLabel":"1.1K downloads"},"release":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-11T08:44:57.012Z","emptyReason":null},"lastUpdatedAt":"2026-10-11T08:44:57.025Z","lastCrawledAt":"2026-10-11T08:44:57.012Z","lastIndexedAt":null,"nextCrawlAt":"2026-10-12T08:44:57.012Z","lastVerifiedAt":null,"highlights":[{"version":"1.4.5","createdAt":"2026-05-19T17:22:26.422Z","changelog":"Webhook HMAC signing: every delivery carries X-Boxes-Signature (timestamped HMAC-SHA256); new GET /account/webhook + POST /account/webhook/secret/rotate; callback URLs must be https.","fileCount":3,"zipByteSize":7357},{"version":"1.4.4","createdAt":"2026-05-19T16:19:59.856Z","changelog":"Adds paid trailer opt-out (POST /account/trailer + /buyout) and per-box custom signatures (PUT /boxes/{id}/signature).","fileCount":2,"zipByteSize":5817},{"version":"1.4.3","createdAt":"2026-05-19T15:27:00.333Z","changelog":"Adds the platform.updated event — fired when the API changes; agents should re-pull their skill / openapi.yaml on it.","fileCount":2,"zipByteSize":5750},{"version":"1.4.2","createdAt":"2026-05-19T15:01:58.224Z","changelog":"Adds PUT /account/credit/alert-thresholds — two agent-settable low-balance alert levels (first + second); low_balance event tagged alert:first|second.","fileCount":2,"zipByteSize":5655},{"version":"1.4.1","createdAt":"2026-05-19T14:43:37.874Z","changelog":"Adds GET /account/credit/balance and GET /account/credit/usage, and the low_balance event.","fileCount":2,"zipByteSize":5561},{"version":"1.4.0","createdAt":"2026-05-19T06:29:40.112Z","changelog":"Adds the GET /events unified feed, the byo_delegated domain mode, threaded support replies (POST /support/questions/{id}/replies), and the context field on sends + reply echo. Fixes the callback-webhook body field (agent_callback_webhook, not url).","fileCount":2,"zipByteSize":5431},{"version":"1.2.0","createdAt":"2026-05-18T18:15:07.224Z","changelog":"Initial publish — full agenticboxes email API: send/receive, unlimited boxes, support questions, feature requests, managed DNS, suppression list.","fileCount":2,"zipByteSize":4106}]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install s17d15vxccwse3x8bwbg87z1t586zvqd:agenticboxes-email","setupComplexity":"low","setupSteps":["Setup complexity is classified as HIGH. You must provision dedicated cloud infrastructure or an isolated VM. Do not run this directly on your local workstation.","Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-agenticbrian-agenticboxes-email/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-agenticbrian-agenticboxes-email/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-agenticbrian-agenticboxes-email/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-agenticbrian-agenticboxes-email/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-agenticbrian-agenticboxes-email/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-agenticbrian-agenticboxes-email/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-11T10:46:24.715Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-agenticbrian-agenticboxes-email/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-agenticbrian-agenticboxes-email/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-agenticbrian-agenticboxes-email/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-agenticbrian-agenticboxes-email/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"high","updatedAt":"2026-10-11T08:44:57.025Z","emptyReason":null},"readme":"Skill: Openclaw\n\nOwner: agenticbrian\n\nSummary: Send and receive email as an agent via the agenticboxes HTTP API — one API key, no IMAP/SMTP setup.\n\nTags: agentic:1.2.0, communication:1.2.0, email:1.2.0, latest:1.4.5\n\nVersion history:\n\nv1.4.5 | 2026-05-19T17:22:26.422Z | user\n\nWebhook HMAC signing: every delivery carries X-Boxes-Signature (timestamped HMAC-SHA256); new GET /account/webhook + POST /account/webhook/secret/rotate; callback URLs must be https.\n\nv1.4.4 | 2026-05-19T16:19:59.856Z | user\n\nAdds paid trailer opt-out (POST /account/trailer + /buyout) and per-box custom signatures (PUT /boxes/{id}/signature).\n\nv1.4.3 | 2026-05-19T15:27:00.333Z | user\n\nAdds the platform.updated event — fired when the API changes; agents should re-pull their skill / openapi.yaml on it.\n\nv1.4.2 | 2026-05-19T15:01:58.224Z | user\n\nAdds PUT /account/credit/alert-thresholds — two agent-settable low-balance alert levels (first + second); low_balance event tagged alert:first|second.\n\nv1.4.1 | 2026-05-19T14:43:37.874Z | user\n\nAdds GET /account/credit/balance and GET /account/credit/usage, and the low_balance event.\n\nv1.4.0 | 2026-05-19T06:29:40.112Z | user\n\nAdds the GET /events unified feed, the byo_delegated domain mode, threaded support replies (POST /support/questions/{id}/replies), and the context field on sends + reply echo. Fixes the callback-webhook body field (agent_callback_webhook, not url).\n\nv1.2.0 | 2026-05-18T18:15:07.224Z | user\n\nInitial publish — full agenticboxes email API: send/receive, unlimited boxes, support questions, feature requests, managed DNS, suppression list.\n\nArchive index:\n\nArchive v1.4.5: 3 files, 7357 bytes\n\nFiles: skill-card.md (2418b), SKILL.md (13790b), _meta.json (137b)\n\nFile v1.4.5:SKILL.md\n\n---\nname: agenticboxes-email\ndescription: Send and receive email as an agent via the agenticboxes HTTP API — one API key, no IMAP/SMTP setup.\nnamespace: skills/communication/agenticboxes\nversion: 1.4.5\nauthor: agenticboxes\nlicense: MIT\nplatforms: [linux, macos, windows]\ntags: [email, communication, api, send, receive, agentic]\n---\n\n# agenticboxes — email for AI agents\n\nGives the agent a real email address it can **send and receive** from, over a\nplain HTTP API. No SMTP, no IMAP, no DKIM/SPF/DMARC setup — one API key.\n(Compare the `himalaya` skill: that drives a CLI mail client over IMAP/SMTP\nwith a `config.toml`; agenticboxes is a hosted HTTP API — sign up and go.)\n\n## When to Use\n\nUse this skill whenever the agent needs to:\n\n- **Send email** — notifications, outreach, replies, confirmations.\n- **Receive email** — sign-up confirmations, 2FA codes, replies, any inbound mail.\n- **Have its own address** to register for a third-party service (Stripe, SaaS tools, accounts).\n- **Get help or improve the platform** — ask the operators a support question, or file a feature request.\n\n## Procedure\n\n### Prerequisite — an API key\n\nIf `AGENTICBOXES_API_KEY` is set, use it. Otherwise sign up. `POST /signup/agentic`\nstarts a signup; `domain_intent.mode` picks how the agent gets its domain:\n\n**A · Free subdomain** (`mode: subdomain`) — a `<slug>.agenticboxes.email`\naddress. Free, no card. Two calls:\n\n```bash\ncurl -s https://api.agenticboxes.email/api/v1/signup/agentic \\\n  -H 'Content-Type: application/json' \\\n  -d '{\"human_email\":\"owner@example.com\",\"domain_intent\":{\"mode\":\"subdomain\"}}'\n#  → { \"intent_id\":\"int_…\", \"full_domain\":\"swift-fox-7.agenticboxes.email\" }\n\ncurl -s https://api.agenticboxes.email/api/v1/signup/agentic/confirm \\\n  -H 'Content-Type: application/json' -d '{\"intent_id\":\"int_…\"}'\n#  → { \"primary_address\":\"agent@swift-fox-7.agenticboxes.email\",\n#      \"api_key\":\"bxs_live_…\", \"account_status\":\"active\" }\n```\n\n**B · Register a real domain** (`mode: register`) — agenticboxes buys a domain\nfor the agent. Send `domain_intent: {\"mode\":\"register\",\"register_domain\":\"youragent.com\"}`.\nThe signup response carries a `stripe_payment_intent` + `link_spend_request`\n(year-1 registration cost, plus $1/mo for DNS hosting). The owner approves that\ncharge via Stripe Link; the account then provisions **automatically** once\npayment clears — there is no `confirm` call for mode B. A taken or unavailable\ndomain returns `409` with `suggestions`.\n\n**C · Bring your own domain, you host the DNS** (`mode: byo_manual`) — a domain\nthe owner already controls and keeps hosting elsewhere. Send\n`domain_intent: {\"mode\":\"byo_manual\",\"byo_domain\":\"youragent.com\"}`. Free;\nfinish with `/signup/agentic/confirm` as for a subdomain. The DNS records to add\n(MX/SPF/DKIM/DMARC) arrive as a `domain.dns_required` event — read them any time\nwith `GET /events?type=domain.dns_required`. Once they resolve, the account\ngoes live.\n\n**D · Bring your own domain, delegate the DNS to us** (`mode: byo_delegated`) —\na domain the owner controls, but with its DNS handed to a Route 53 zone\nagenticboxes runs. Send\n`domain_intent: {\"mode\":\"byo_delegated\",\"byo_domain\":\"youragent.com\"}`. $1/mo\nfor DNS hosting; finish with `/signup/agentic/confirm`. A\n`domain.delegation_required` event then lists the nameservers to set at the\ndomain's registrar; once the delegation propagates, the account goes live.\n\nOptional on any signup: `initial_credit_cents` (≥100 — prepay credit) and\n`agent_callback_webhook` (the event webhook URL). Store the `api_key` the\ninstant it's returned — it is shown exactly once. Every account starts with\n**250 messages of free credit**.\n\n### Calling the API\n\n- **Base URL:** `https://api.agenticboxes.email/api/v1`\n- **Auth:** every call carries `Authorization: Bearer $AGENTICBOXES_API_KEY`\n- **Discovery:** `GET https://api.agenticboxes.email/.well-known/agentic.json`\n  returns this service's manifest — skills, OpenAPI spec, signup, pricing.\n\n**Send** — `POST /messages/send`:\n\n```bash\ncurl -s https://api.agenticboxes.email/api/v1/messages/send \\\n  -H \"Authorization: Bearer $AGENTICBOXES_API_KEY\" \\\n  -H 'Content-Type: application/json' \\\n  -d '{\"from\":\"outreach@your-domain\",\n       \"to\":\"someone@example.com\",\n       \"subject\":\"Hello\",\n       \"text\":\"Sent by my agent.\"}'\n```\n\nBody: `to` (string or array, required), `subject`, `text`. Optional: `from` —\nsend from a specific box on your domain (defaults to the account's primary\naddress); `attachments` (`[{filename, content_b64, content_type}]`);\n`idempotency_key`; and `context` — an opaque JSON object (≤16 KB) stored with\nthe message and echoed back onto any inbound reply to it (see Receive). The\nresponse carries a `message_id` and a `billing` breakdown.\n\n**Receive** — three ways onto one underlying stream:\n\n- **Event feed (poll)** — `GET /events?since=<cursor>` — the unified feed:\n  every event the platform emits for the account, in one ordered stream\n  (`mail.received`, `support.answered`, `domain.ready`, and more). Process a\n  page, then poll again with `since` set to the response's `next_cursor`;\n  filter to one kind with `?type=mail.received`. This is the receive path that\n  never misses anything — webhook or no webhook.\n- **Messages (poll)** — `GET /messages?include=body` — the mail corpus: recent\n  messages with full bodies inline, filterable by `direction` (`received` or\n  `sent`), `since`, `before`, `box`, `limit`. `GET /messages/{id}` reads one.\n- **Webhook (push)** — `PUT /account/callback-webhook`\n  `{\"agent_callback_webhook\":\"https://…\"}` — events are POSTed to that URL as\n  they happen; optional push delivery over the same stream the event feed\n  serves. The URL must be `https://`. `GET /account/callback-webhook` reads the\n  URL currently set. Every delivery is **signed**: an\n  `X-Boxes-Signature: t=<unix>,v1=<hex>` header carries the HMAC-SHA256 of\n  `\"<t>.<body>\"` keyed by your signing secret. `GET /account/webhook` returns\n  that secret and the scheme — verify it and reject a `t` older than 300s;\n  rotate the secret with `POST /account/webhook/secret/rotate`.\n\n**Reply context** — every message carries a `context` field. When an inbound\nmail is a reply to one the agent sent with a `context`, that same `context` is\nechoed back on it — on `GET /messages`, `GET /events`, and in the webhook\npayload — so a reply self-routes to its originating conversation. `null` when\nnot a reply.\n\n**Stay current** — a `platform.updated` event means AgenticBoxes has added or\nchanged endpoints. When you see one, re-pull this skill and the OpenAPI spec\n(`https://www.agenticboxes.email/openapi.yaml`) so you're not working from a\nstale copy.\n\n**Addresses (boxes)** — a box is one email address; create as many as needed,\nno per-box fee:\n\n- `POST /boxes` `{\"address\":\"outreach\"}` → `outreach@<your-domain>`\n- `GET /boxes` — list them.\n- `DELETE /boxes/{id}` — remove an address.\n\nAn address can only receive mail after its box is created — and a box is the\n`from` you send outreach with, so create one before the first send to it.\n\n**Credit** — `POST /account/credit/topup` adds prepaid credit.\n`GET /account/credit/balance` shows the balance, the low-balance flag, and how\nmany more emails it covers; `GET /account/credit/usage` breaks down metered\nusage by event type. A `low_balance` event (in the event feed and the webhook)\nwarns before the balance runs out — `PUT /account/credit/alert-thresholds` sets\nthe two alert levels (an early `first` and an urgent `second`) to balances that\nsuit your burn rate.\n\n**Get unstuck — support questions** — a private channel to the agenticboxes\noperators. Use this instead of guessing when something about the API is unclear:\n\n- `POST /support/questions` — body `{\"subject\":\"…\",\"body\":\"…\"}` (optional\n  `context`). The answer arrives as a `support.answered` event — in\n  `GET /events` and at the callback webhook.\n- `GET /support/questions` — list your questions; `GET /support/questions/{id}`\n  — read one, with its full message thread.\n- `POST /support/questions/{id}/replies` — body `{\"body\":\"…\"}` — post a\n  follow-up. A support question is a threaded conversation, not one-shot.\n\n**Feature requests** — suggest a platform improvement, or upvote one:\n\n- `POST /feature-requests` — body `{\"title\":\"…\",\"description\":\"…\"}`.\n- `GET /feature-requests` — browse; `GET /feature-requests/{id}` — read one.\n- `POST /feature-requests/{id}/vote` — upvote (no body).\n\n**Suppression list** — addresses that bounced or filed a complaint and are\nblocked from delivery:\n\n- `GET /suppression` — list them; `GET /suppression/{address}` — check one\n  before sending to it.\n- `POST /suppression/{address}/unblock` — request removal.\n\n**Managed DNS** — for an account on a registered or delegated domain\n(`register` or `byo_delegated`), edit the Route 53 zone agenticboxes hosts:\n\n- `GET /domain/dns` — list records.\n- `POST` / `PUT` / `DELETE /domain/dns` — add / change / remove a record. The\n  body must include `terms_of_service: true`; a record is\n  `{name, type, ttl, values}`. The records carrying your agent email are\n  reserved read-only.\n\nA `byo_manual` account hosts its own DNS, so it has no managed zone —\n`/domain/dns` returns `409`; that account's required records are in\n`GET /events?type=domain.dns_required` instead.\n\n### Speak up — when to file support questions and feature requests\n\nDon't fail silently, guess, or quietly work around a gap. The platform improves\nonly when agents say something — treat this as part of the job:\n\n- **Stuck or surprised** → send a **support question** (`POST /support/questions`).\n  Triggers: an error you can't resolve, an endpoint behaving unexpectedly, a\n  response you don't understand, docs that don't answer your question, or being\n  blocked. Ask rather than abandoning the task — it's free and private.\n- **Missing a capability** → file a **feature request** (`POST /feature-requests`).\n  Triggers: you needed something this API doesn't do, hit a limit that got in\n  your way, or saw a clear way the platform could be better. Be concrete and\n  specific.\n\nDoing this when warranted is expected behaviour, not an interruption.\n\n**These go through the API, never email.** `POST /support/questions` and\n`POST /feature-requests` are the *only* channels. There is no agenticboxes\nsupport email address — if you recall or find one (anything `@brian.im`, or a\n`support@` / `help@` style address), it is stale and unmonitored. Do not email\na request: it spends a paid send, reaches no one, and is not how the platform\nreceives feedback. The endpoints are free and land directly with the team.\n\n### Every endpoint\n\nThe complete agent-facing API — base `https://api.agenticboxes.email/api/v1`,\nevery call `Authorization: Bearer` except the two signup calls:\n\n| Endpoint | Purpose |\n|---|---|\n| `POST /signup/agentic`, `POST /signup/agentic/confirm` | Free signup |\n| `POST /messages/send` | Send mail |\n| `GET /events` | The unified event feed — poll to receive |\n| `GET /messages`, `GET /messages/{id}` | List / read mail |\n| `GET` & `PUT /account/callback-webhook` | Read / set the event webhook (https only) |\n| `GET /account/webhook`, `POST /account/webhook/secret/rotate` | Webhook signing secret — fetch / rotate |\n| `POST /account/credit/topup` | Add prepaid credit |\n| `GET /account/credit/balance`, `GET /account/credit/usage` | Credit balance + metered-usage breakdown |\n| `PUT /account/credit/alert-thresholds` | Set the two low-balance alert thresholds |\n| `POST` & `GET /boxes`, `DELETE /boxes/{id}`, `PUT /boxes/{id}/signature` | Boxes — create / list / delete / set a custom signature |\n| `POST /account/trailer`, `POST /account/trailer/buyout` | Remove the outbound trailer — opt out / buy out |\n| `GET` `POST` `PUT` `DELETE /domain/dns` | Managed-zone DNS records |\n| `GET /suppression`, `GET /suppression/{address}`, `POST /suppression/{address}/unblock` | Suppression list |\n| `POST` & `GET /feature-requests`, `GET /feature-requests/{id}`, `POST /feature-requests/{id}/vote` | Feature requests |\n| `POST` & `GET /support/questions`, `GET /support/questions/{id}`, `POST /support/questions/{id}/replies` | Support questions |\n\nFull request/response schemas: the OpenAPI spec at\n`https://www.agenticboxes.email/openapi.yaml`.\n\nThis list is authoritative — every endpoint here works with your agent API key.\nIf you recall, or read in an older note or a stale copy of this skill, that some\nendpoint \"needs a dashboard login\" or \"can't be called by an agent,\" do not\ntrust it and build a workaround — make the call and read the response. The live\nAPI always wins over a remembered limitation.\n\n## Pitfalls\n\n- The API key is shown **once**, at `confirm`. Capture it then or it is unrecoverable.\n- An address receives mail only after `POST /boxes` creates its box.\n- Sends fail with `402` / insufficient credit once the balance is spent — top up.\n- The base URL ends at `/api/v1` — do not append `/v1` again.\n- API keys carry scopes (`send` / `receive` / `admin`); use one with the scope the call needs.\n- Pass `idempotency_key` on sends so a retried request never double-sends.\n- The `PUT /account/callback-webhook` body field is `agent_callback_webhook`, not `url`.\n- Support questions and feature requests go through `POST /support/questions` and `POST /feature-requests` **only** — never email. There is no support email address; any you recall or find is stale.\n\n## Verification\n\n- A successful send returns a `message_id` and a `billing` breakdown.\n- `GET /events` returns the account's event stream; `GET /messages` lists its mail.\n- After `confirm`, `account_status` is `active` — the account is ready.\n\nFile v1.4.5:_meta.json\n\n{\n  \"ownerId\": \"kn73rnk5893nejc4cexe0vxkx986ynx3\",\n  \"slug\": \"agenticboxes-email\",\n  \"version\": \"1.4.5\",\n  \"publishedAt\": 1779211346422\n}\n\nFile v1.4.5:skill-card.md\n\n## Description:\n\nSend and receive email as an agent via the agenticboxes HTTP API, using one API key without IMAP or SMTP setup.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[agenticbrian](https://clawhub.ai/user/agenticbrian)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and external agents use this skill to provision and operate an email address for sending messages, receiving replies, handling sign-up confirmations, managing boxes, and interacting with AgenticBoxes support or feature request endpoints.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Agents may gain broad email, DNS, billing, webhook, and account-administration authority through the third-party service.\n\nMitigation: Require explicit user approval before sending or reading sensitive mail, registering accounts, changing DNS, topping up credit, deleting boxes, configuring webhooks, or sharing support context.\n\nRisk: Newly fetched platform documentation can change the agent's operating instructions.\n\nMitigation: Review updated API documentation before relying on new or changed endpoints for sensitive workflows.\n\nRisk: API keys and webhook signing secrets are sensitive credentials.\n\nMitigation: Store credentials in environment variables or a secret manager, avoid exposing them in logs or messages, and rotate webhook secrets when access may have been disclosed.\n\n## Reference(s):\n\n- [ClawHub skill page](https://clawhub.ai/agenticbrian/skills/agenticboxes-email)\n- [AgenticBoxes agent manifest](https://api.agenticboxes.email/.well-known/agentic.json)\n- [AgenticBoxes OpenAPI specification](https://www.agenticboxes.email/openapi.yaml)\n\n## Skill Output:\n\n**Output Type(s):** [Guidance, Shell commands, Configuration, API Calls]\n\n**Output Format:** [Markdown with inline JSON and bash code blocks]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [May produce authenticated HTTP requests and operational instructions for email, DNS, billing, webhook, support, and feature-request workflows.]\n\n## Skill Version(s):\n\n1.4.5 (source: server release evidence and frontmatter)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v1.4.4: 2 files, 5817 bytes\n\nFiles: SKILL.md (13310b), _meta.json (137b)\n\nFile v1.4.4:SKILL.md\n\n---\nname: agenticboxes-email\ndescription: Send and receive email as an agent via the agenticboxes HTTP API — one API key, no IMAP/SMTP setup.\nnamespace: skills/communication/agenticboxes\nversion: 1.4.4\nauthor: agenticboxes\nlicense: MIT\nplatforms: [linux, macos, windows]\ntags: [email, communication, api, send, receive, agentic]\n---\n\n# agenticboxes — email for AI agents\n\nGives the agent a real email address it can **send and receive** from, over a\nplain HTTP API. No SMTP, no IMAP, no DKIM/SPF/DMARC setup — one API key.\n(Compare the `himalaya` skill: that drives a CLI mail client over IMAP/SMTP\nwith a `config.toml`; agenticboxes is a hosted HTTP API — sign up and go.)\n\n## When to Use\n\nUse this skill whenever the agent needs to:\n\n- **Send email** — notifications, outreach, replies, confirmations.\n- **Receive email** — sign-up confirmations, 2FA codes, replies, any inbound mail.\n- **Have its own address** to register for a third-party service (Stripe, SaaS tools, accounts).\n- **Get help or improve the platform** — ask the operators a support question, or file a feature request.\n\n## Procedure\n\n### Prerequisite — an API key\n\nIf `AGENTICBOXES_API_KEY` is set, use it. Otherwise sign up. `POST /signup/agentic`\nstarts a signup; `domain_intent.mode` picks how the agent gets its domain:\n\n**A · Free subdomain** (`mode: subdomain`) — a `<slug>.agenticboxes.email`\naddress. Free, no card. Two calls:\n\n```bash\ncurl -s https://api.agenticboxes.email/api/v1/signup/agentic \\\n  -H 'Content-Type: application/json' \\\n  -d '{\"human_email\":\"owner@example.com\",\"domain_intent\":{\"mode\":\"subdomain\"}}'\n#  → { \"intent_id\":\"int_…\", \"full_domain\":\"swift-fox-7.agenticboxes.email\" }\n\ncurl -s https://api.agenticboxes.email/api/v1/signup/agentic/confirm \\\n  -H 'Content-Type: application/json' -d '{\"intent_id\":\"int_…\"}'\n#  → { \"primary_address\":\"agent@swift-fox-7.agenticboxes.email\",\n#      \"api_key\":\"bxs_live_…\", \"account_status\":\"active\" }\n```\n\n**B · Register a real domain** (`mode: register`) — agenticboxes buys a domain\nfor the agent. Send `domain_intent: {\"mode\":\"register\",\"register_domain\":\"youragent.com\"}`.\nThe signup response carries a `stripe_payment_intent` + `link_spend_request`\n(year-1 registration cost, plus $1/mo for DNS hosting). The owner approves that\ncharge via Stripe Link; the account then provisions **automatically** once\npayment clears — there is no `confirm` call for mode B. A taken or unavailable\ndomain returns `409` with `suggestions`.\n\n**C · Bring your own domain, you host the DNS** (`mode: byo_manual`) — a domain\nthe owner already controls and keeps hosting elsewhere. Send\n`domain_intent: {\"mode\":\"byo_manual\",\"byo_domain\":\"youragent.com\"}`. Free;\nfinish with `/signup/agentic/confirm` as for a subdomain. The DNS records to add\n(MX/SPF/DKIM/DMARC) arrive as a `domain.dns_required` event — read them any time\nwith `GET /events?type=domain.dns_required`. Once they resolve, the account\ngoes live.\n\n**D · Bring your own domain, delegate the DNS to us** (`mode: byo_delegated`) —\na domain the owner controls, but with its DNS handed to a Route 53 zone\nagenticboxes runs. Send\n`domain_intent: {\"mode\":\"byo_delegated\",\"byo_domain\":\"youragent.com\"}`. $1/mo\nfor DNS hosting; finish with `/signup/agentic/confirm`. A\n`domain.delegation_required` event then lists the nameservers to set at the\ndomain's registrar; once the delegation propagates, the account goes live.\n\nOptional on any signup: `initial_credit_cents` (≥100 — prepay credit) and\n`agent_callback_webhook` (the event webhook URL). Store the `api_key` the\ninstant it's returned — it is shown exactly once. Every account starts with\n**250 messages of free credit**.\n\n### Calling the API\n\n- **Base URL:** `https://api.agenticboxes.email/api/v1`\n- **Auth:** every call carries `Authorization: Bearer $AGENTICBOXES_API_KEY`\n- **Discovery:** `GET https://api.agenticboxes.email/.well-known/agentic.json`\n  returns this service's manifest — skills, OpenAPI spec, signup, pricing.\n\n**Send** — `POST /messages/send`:\n\n```bash\ncurl -s https://api.agenticboxes.email/api/v1/messages/send \\\n  -H \"Authorization: Bearer $AGENTICBOXES_API_KEY\" \\\n  -H 'Content-Type: application/json' \\\n  -d '{\"from\":\"outreach@your-domain\",\n       \"to\":\"someone@example.com\",\n       \"subject\":\"Hello\",\n       \"text\":\"Sent by my agent.\"}'\n```\n\nBody: `to` (string or array, required), `subject`, `text`. Optional: `from` —\nsend from a specific box on your domain (defaults to the account's primary\naddress); `attachments` (`[{filename, content_b64, content_type}]`);\n`idempotency_key`; and `context` — an opaque JSON object (≤16 KB) stored with\nthe message and echoed back onto any inbound reply to it (see Receive). The\nresponse carries a `message_id` and a `billing` breakdown.\n\n**Receive** — three ways onto one underlying stream:\n\n- **Event feed (poll)** — `GET /events?since=<cursor>` — the unified feed:\n  every event the platform emits for the account, in one ordered stream\n  (`mail.received`, `support.answered`, `domain.ready`, and more). Process a\n  page, then poll again with `since` set to the response's `next_cursor`;\n  filter to one kind with `?type=mail.received`. This is the receive path that\n  never misses anything — webhook or no webhook.\n- **Messages (poll)** — `GET /messages?include=body` — the mail corpus: recent\n  messages with full bodies inline, filterable by `direction` (`received` or\n  `sent`), `since`, `before`, `box`, `limit`. `GET /messages/{id}` reads one.\n- **Webhook (push)** — `PUT /account/callback-webhook`\n  `{\"agent_callback_webhook\":\"https://…\"}` — events are POSTed to that URL as\n  they happen; optional push delivery over the same stream the event feed\n  serves. `GET /account/callback-webhook` reads the URL currently set.\n\n**Reply context** — every message carries a `context` field. When an inbound\nmail is a reply to one the agent sent with a `context`, that same `context` is\nechoed back on it — on `GET /messages`, `GET /events`, and in the webhook\npayload — so a reply self-routes to its originating conversation. `null` when\nnot a reply.\n\n**Stay current** — a `platform.updated` event means AgenticBoxes has added or\nchanged endpoints. When you see one, re-pull this skill and the OpenAPI spec\n(`https://www.agenticboxes.email/openapi.yaml`) so you're not working from a\nstale copy.\n\n**Addresses (boxes)** — a box is one email address; create as many as needed,\nno per-box fee:\n\n- `POST /boxes` `{\"address\":\"outreach\"}` → `outreach@<your-domain>`\n- `GET /boxes` — list them.\n- `DELETE /boxes/{id}` — remove an address.\n\nAn address can only receive mail after its box is created — and a box is the\n`from` you send outreach with, so create one before the first send to it.\n\n**Credit** — `POST /account/credit/topup` adds prepaid credit.\n`GET /account/credit/balance` shows the balance, the low-balance flag, and how\nmany more emails it covers; `GET /account/credit/usage` breaks down metered\nusage by event type. A `low_balance` event (in the event feed and the webhook)\nwarns before the balance runs out — `PUT /account/credit/alert-thresholds` sets\nthe two alert levels (an early `first` and an urgent `second`) to balances that\nsuit your burn rate.\n\n**Get unstuck — support questions** — a private channel to the agenticboxes\noperators. Use this instead of guessing when something about the API is unclear:\n\n- `POST /support/questions` — body `{\"subject\":\"…\",\"body\":\"…\"}` (optional\n  `context`). The answer arrives as a `support.answered` event — in\n  `GET /events` and at the callback webhook.\n- `GET /support/questions` — list your questions; `GET /support/questions/{id}`\n  — read one, with its full message thread.\n- `POST /support/questions/{id}/replies` — body `{\"body\":\"…\"}` — post a\n  follow-up. A support question is a threaded conversation, not one-shot.\n\n**Feature requests** — suggest a platform improvement, or upvote one:\n\n- `POST /feature-requests` — body `{\"title\":\"…\",\"description\":\"…\"}`.\n- `GET /feature-requests` — browse; `GET /feature-requests/{id}` — read one.\n- `POST /feature-requests/{id}/vote` — upvote (no body).\n\n**Suppression list** — addresses that bounced or filed a complaint and are\nblocked from delivery:\n\n- `GET /suppression` — list them; `GET /suppression/{address}` — check one\n  before sending to it.\n- `POST /suppression/{address}/unblock` — request removal.\n\n**Managed DNS** — for an account on a registered or delegated domain\n(`register` or `byo_delegated`), edit the Route 53 zone agenticboxes hosts:\n\n- `GET /domain/dns` — list records.\n- `POST` / `PUT` / `DELETE /domain/dns` — add / change / remove a record. The\n  body must include `terms_of_service: true`; a record is\n  `{name, type, ttl, values}`. The records carrying your agent email are\n  reserved read-only.\n\nA `byo_manual` account hosts its own DNS, so it has no managed zone —\n`/domain/dns` returns `409`; that account's required records are in\n`GET /events?type=domain.dns_required` instead.\n\n### Speak up — when to file support questions and feature requests\n\nDon't fail silently, guess, or quietly work around a gap. The platform improves\nonly when agents say something — treat this as part of the job:\n\n- **Stuck or surprised** → send a **support question** (`POST /support/questions`).\n  Triggers: an error you can't resolve, an endpoint behaving unexpectedly, a\n  response you don't understand, docs that don't answer your question, or being\n  blocked. Ask rather than abandoning the task — it's free and private.\n- **Missing a capability** → file a **feature request** (`POST /feature-requests`).\n  Triggers: you needed something this API doesn't do, hit a limit that got in\n  your way, or saw a clear way the platform could be better. Be concrete and\n  specific.\n\nDoing this when warranted is expected behaviour, not an interruption.\n\n**These go through the API, never email.** `POST /support/questions` and\n`POST /feature-requests` are the *only* channels. There is no agenticboxes\nsupport email address — if you recall or find one (anything `@brian.im`, or a\n`support@` / `help@` style address), it is stale and unmonitored. Do not email\na request: it spends a paid send, reaches no one, and is not how the platform\nreceives feedback. The endpoints are free and land directly with the team.\n\n### Every endpoint\n\nThe complete agent-facing API — base `https://api.agenticboxes.email/api/v1`,\nevery call `Authorization: Bearer` except the two signup calls:\n\n| Endpoint | Purpose |\n|---|---|\n| `POST /signup/agentic`, `POST /signup/agentic/confirm` | Free signup |\n| `POST /messages/send` | Send mail |\n| `GET /events` | The unified event feed — poll to receive |\n| `GET /messages`, `GET /messages/{id}` | List / read mail |\n| `GET` & `PUT /account/callback-webhook` | Read / set the event webhook |\n| `POST /account/credit/topup` | Add prepaid credit |\n| `GET /account/credit/balance`, `GET /account/credit/usage` | Credit balance + metered-usage breakdown |\n| `PUT /account/credit/alert-thresholds` | Set the two low-balance alert thresholds |\n| `POST` & `GET /boxes`, `DELETE /boxes/{id}`, `PUT /boxes/{id}/signature` | Boxes — create / list / delete / set a custom signature |\n| `POST /account/trailer`, `POST /account/trailer/buyout` | Remove the outbound trailer — opt out / buy out |\n| `GET` `POST` `PUT` `DELETE /domain/dns` | Managed-zone DNS records |\n| `GET /suppression`, `GET /suppression/{address}`, `POST /suppression/{address}/unblock` | Suppression list |\n| `POST` & `GET /feature-requests`, `GET /feature-requests/{id}`, `POST /feature-requests/{id}/vote` | Feature requests |\n| `POST` & `GET /support/questions`, `GET /support/questions/{id}`, `POST /support/questions/{id}/replies` | Support questions |\n\nFull request/response schemas: the OpenAPI spec at\n`https://www.agenticboxes.email/openapi.yaml`.\n\nThis list is authoritative — every endpoint here works with your agent API key.\nIf you recall, or read in an older note or a stale copy of this skill, that some\nendpoint \"needs a dashboard login\" or \"can't be called by an agent,\" do not\ntrust it and build a workaround — make the call and read the response. The live\nAPI always wins over a remembered limitation.\n\n## Pitfalls\n\n- The API key is shown **once**, at `confirm`. Capture it then or it is unrecoverable.\n- An address receives mail only after `POST /boxes` creates its box.\n- Sends fail with `402` / insufficient credit once the balance is spent — top up.\n- The base URL ends at `/api/v1` — do not append `/v1` again.\n- API keys carry scopes (`send` / `receive` / `admin`); use one with the scope the call needs.\n- Pass `idempotency_key` on sends so a retried request never double-sends.\n- The `PUT /account/callback-webhook` body field is `agent_callback_webhook`, not `url`.\n- Support questions and feature requests go through `POST /support/questions` and `POST /feature-requests` **only** — never email. There is no support email address; any you recall or find is stale.\n\n## Verification\n\n- A successful send returns a `message_id` and a `billing` breakdown.\n- `GET /events` returns the account's event stream; `GET /messages` lists its mail.\n- After `confirm`, `account_status` is `active` — the account is ready.\n\nFile v1.4.4:_meta.json\n\n{\n  \"ownerId\": \"kn73rnk5893nejc4cexe0vxkx986ynx3\",\n  \"slug\": \"agenticboxes-email\",\n  \"version\": \"1.4.4\",\n  \"publishedAt\": 1779207599856\n}\n\nArchive v1.4.3: 2 files, 5750 bytes\n\nFiles: SKILL.md (13145b), _meta.json (137b)\n\nFile v1.4.3:SKILL.md\n\n---\nname: agenticboxes-email\ndescription: Send and receive email as an agent via the agenticboxes HTTP API — one API key, no IMAP/SMTP setup.\nnamespace: skills/communication/agenticboxes\nversion: 1.4.3\nauthor: agenticboxes\nlicense: MIT\nplatforms: [linux, macos, windows]\ntags: [email, communication, api, send, receive, agentic]\n---\n\n# agenticboxes — email for AI agents\n\nGives the agent a real email address it can **send and receive** from, over a\nplain HTTP API. No SMTP, no IMAP, no DKIM/SPF/DMARC setup — one API key.\n(Compare the `himalaya` skill: that drives a CLI mail client over IMAP/SMTP\nwith a `config.toml`; agenticboxes is a hosted HTTP API — sign up and go.)\n\n## When to Use\n\nUse this skill whenever the agent needs to:\n\n- **Send email** — notifications, outreach, replies, confirmations.\n- **Receive email** — sign-up confirmations, 2FA codes, replies, any inbound mail.\n- **Have its own address** to register for a third-party service (Stripe, SaaS tools, accounts).\n- **Get help or improve the platform** — ask the operators a support question, or file a feature request.\n\n## Procedure\n\n### Prerequisite — an API key\n\nIf `AGENTICBOXES_API_KEY` is set, use it. Otherwise sign up. `POST /signup/agentic`\nstarts a signup; `domain_intent.mode` picks how the agent gets its domain:\n\n**A · Free subdomain** (`mode: subdomain`) — a `<slug>.agenticboxes.email`\naddress. Free, no card. Two calls:\n\n```bash\ncurl -s https://api.agenticboxes.email/api/v1/signup/agentic \\\n  -H 'Content-Type: application/json' \\\n  -d '{\"human_email\":\"owner@example.com\",\"domain_intent\":{\"mode\":\"subdomain\"}}'\n#  → { \"intent_id\":\"int_…\", \"full_domain\":\"swift-fox-7.agenticboxes.email\" }\n\ncurl -s https://api.agenticboxes.email/api/v1/signup/agentic/confirm \\\n  -H 'Content-Type: application/json' -d '{\"intent_id\":\"int_…\"}'\n#  → { \"primary_address\":\"agent@swift-fox-7.agenticboxes.email\",\n#      \"api_key\":\"bxs_live_…\", \"account_status\":\"active\" }\n```\n\n**B · Register a real domain** (`mode: register`) — agenticboxes buys a domain\nfor the agent. Send `domain_intent: {\"mode\":\"register\",\"register_domain\":\"youragent.com\"}`.\nThe signup response carries a `stripe_payment_intent` + `link_spend_request`\n(year-1 registration cost, plus $1/mo for DNS hosting). The owner approves that\ncharge via Stripe Link; the account then provisions **automatically** once\npayment clears — there is no `confirm` call for mode B. A taken or unavailable\ndomain returns `409` with `suggestions`.\n\n**C · Bring your own domain, you host the DNS** (`mode: byo_manual`) — a domain\nthe owner already controls and keeps hosting elsewhere. Send\n`domain_intent: {\"mode\":\"byo_manual\",\"byo_domain\":\"youragent.com\"}`. Free;\nfinish with `/signup/agentic/confirm` as for a subdomain. The DNS records to add\n(MX/SPF/DKIM/DMARC) arrive as a `domain.dns_required` event — read them any time\nwith `GET /events?type=domain.dns_required`. Once they resolve, the account\ngoes live.\n\n**D · Bring your own domain, delegate the DNS to us** (`mode: byo_delegated`) —\na domain the owner controls, but with its DNS handed to a Route 53 zone\nagenticboxes runs. Send\n`domain_intent: {\"mode\":\"byo_delegated\",\"byo_domain\":\"youragent.com\"}`. $1/mo\nfor DNS hosting; finish with `/signup/agentic/confirm`. A\n`domain.delegation_required` event then lists the nameservers to set at the\ndomain's registrar; once the delegation propagates, the account goes live.\n\nOptional on any signup: `initial_credit_cents` (≥100 — prepay credit) and\n`agent_callback_webhook` (the event webhook URL). Store the `api_key` the\ninstant it's returned — it is shown exactly once. Every account starts with\n**250 messages of free credit**.\n\n### Calling the API\n\n- **Base URL:** `https://api.agenticboxes.email/api/v1`\n- **Auth:** every call carries `Authorization: Bearer $AGENTICBOXES_API_KEY`\n- **Discovery:** `GET https://api.agenticboxes.email/.well-known/agentic.json`\n  returns this service's manifest — skills, OpenAPI spec, signup, pricing.\n\n**Send** — `POST /messages/send`:\n\n```bash\ncurl -s https://api.agenticboxes.email/api/v1/messages/send \\\n  -H \"Authorization: Bearer $AGENTICBOXES_API_KEY\" \\\n  -H 'Content-Type: application/json' \\\n  -d '{\"from\":\"outreach@your-domain\",\n       \"to\":\"someone@example.com\",\n       \"subject\":\"Hello\",\n       \"text\":\"Sent by my agent.\"}'\n```\n\nBody: `to` (string or array, required), `subject`, `text`. Optional: `from` —\nsend from a specific box on your domain (defaults to the account's primary\naddress); `attachments` (`[{filename, content_b64, content_type}]`);\n`idempotency_key`; and `context` — an opaque JSON object (≤16 KB) stored with\nthe message and echoed back onto any inbound reply to it (see Receive). The\nresponse carries a `message_id` and a `billing` breakdown.\n\n**Receive** — three ways onto one underlying stream:\n\n- **Event feed (poll)** — `GET /events?since=<cursor>` — the unified feed:\n  every event the platform emits for the account, in one ordered stream\n  (`mail.received`, `support.answered`, `domain.ready`, and more). Process a\n  page, then poll again with `since` set to the response's `next_cursor`;\n  filter to one kind with `?type=mail.received`. This is the receive path that\n  never misses anything — webhook or no webhook.\n- **Messages (poll)** — `GET /messages?include=body` — the mail corpus: recent\n  messages with full bodies inline, filterable by `direction` (`received` or\n  `sent`), `since`, `before`, `box`, `limit`. `GET /messages/{id}` reads one.\n- **Webhook (push)** — `PUT /account/callback-webhook`\n  `{\"agent_callback_webhook\":\"https://…\"}` — events are POSTed to that URL as\n  they happen; optional push delivery over the same stream the event feed\n  serves. `GET /account/callback-webhook` reads the URL currently set.\n\n**Reply context** — every message carries a `context` field. When an inbound\nmail is a reply to one the agent sent with a `context`, that same `context` is\nechoed back on it — on `GET /messages`, `GET /events`, and in the webhook\npayload — so a reply self-routes to its originating conversation. `null` when\nnot a reply.\n\n**Stay current** — a `platform.updated` event means AgenticBoxes has added or\nchanged endpoints. When you see one, re-pull this skill and the OpenAPI spec\n(`https://www.agenticboxes.email/openapi.yaml`) so you're not working from a\nstale copy.\n\n**Addresses (boxes)** — a box is one email address; create as many as needed,\nno per-box fee:\n\n- `POST /boxes` `{\"address\":\"outreach\"}` → `outreach@<your-domain>`\n- `GET /boxes` — list them.\n- `DELETE /boxes/{id}` — remove an address.\n\nAn address can only receive mail after its box is created — and a box is the\n`from` you send outreach with, so create one before the first send to it.\n\n**Credit** — `POST /account/credit/topup` adds prepaid credit.\n`GET /account/credit/balance` shows the balance, the low-balance flag, and how\nmany more emails it covers; `GET /account/credit/usage` breaks down metered\nusage by event type. A `low_balance` event (in the event feed and the webhook)\nwarns before the balance runs out — `PUT /account/credit/alert-thresholds` sets\nthe two alert levels (an early `first` and an urgent `second`) to balances that\nsuit your burn rate.\n\n**Get unstuck — support questions** — a private channel to the agenticboxes\noperators. Use this instead of guessing when something about the API is unclear:\n\n- `POST /support/questions` — body `{\"subject\":\"…\",\"body\":\"…\"}` (optional\n  `context`). The answer arrives as a `support.answered` event — in\n  `GET /events` and at the callback webhook.\n- `GET /support/questions` — list your questions; `GET /support/questions/{id}`\n  — read one, with its full message thread.\n- `POST /support/questions/{id}/replies` — body `{\"body\":\"…\"}` — post a\n  follow-up. A support question is a threaded conversation, not one-shot.\n\n**Feature requests** — suggest a platform improvement, or upvote one:\n\n- `POST /feature-requests` — body `{\"title\":\"…\",\"description\":\"…\"}`.\n- `GET /feature-requests` — browse; `GET /feature-requests/{id}` — read one.\n- `POST /feature-requests/{id}/vote` — upvote (no body).\n\n**Suppression list** — addresses that bounced or filed a complaint and are\nblocked from delivery:\n\n- `GET /suppression` — list them; `GET /suppression/{address}` — check one\n  before sending to it.\n- `POST /suppression/{address}/unblock` — request removal.\n\n**Managed DNS** — for an account on a registered or delegated domain\n(`register` or `byo_delegated`), edit the Route 53 zone agenticboxes hosts:\n\n- `GET /domain/dns` — list records.\n- `POST` / `PUT` / `DELETE /domain/dns` — add / change / remove a record. The\n  body must include `terms_of_service: true`; a record is\n  `{name, type, ttl, values}`. The records carrying your agent email are\n  reserved read-only.\n\nA `byo_manual` account hosts its own DNS, so it has no managed zone —\n`/domain/dns` returns `409`; that account's required records are in\n`GET /events?type=domain.dns_required` instead.\n\n### Speak up — when to file support questions and feature requests\n\nDon't fail silently, guess, or quietly work around a gap. The platform improves\nonly when agents say something — treat this as part of the job:\n\n- **Stuck or surprised** → send a **support question** (`POST /support/questions`).\n  Triggers: an error you can't resolve, an endpoint behaving unexpectedly, a\n  response you don't understand, docs that don't answer your question, or being\n  blocked. Ask rather than abandoning the task — it's free and private.\n- **Missing a capability** → file a **feature request** (`POST /feature-requests`).\n  Triggers: you needed something this API doesn't do, hit a limit that got in\n  your way, or saw a clear way the platform could be better. Be concrete and\n  specific.\n\nDoing this when warranted is expected behaviour, not an interruption.\n\n**These go through the API, never email.** `POST /support/questions` and\n`POST /feature-requests` are the *only* channels. There is no agenticboxes\nsupport email address — if you recall or find one (anything `@brian.im`, or a\n`support@` / `help@` style address), it is stale and unmonitored. Do not email\na request: it spends a paid send, reaches no one, and is not how the platform\nreceives feedback. The endpoints are free and land directly with the team.\n\n### Every endpoint\n\nThe complete agent-facing API — base `https://api.agenticboxes.email/api/v1`,\nevery call `Authorization: Bearer` except the two signup calls:\n\n| Endpoint | Purpose |\n|---|---|\n| `POST /signup/agentic`, `POST /signup/agentic/confirm` | Free signup |\n| `POST /messages/send` | Send mail |\n| `GET /events` | The unified event feed — poll to receive |\n| `GET /messages`, `GET /messages/{id}` | List / read mail |\n| `GET` & `PUT /account/callback-webhook` | Read / set the event webhook |\n| `POST /account/credit/topup` | Add prepaid credit |\n| `GET /account/credit/balance`, `GET /account/credit/usage` | Credit balance + metered-usage breakdown |\n| `PUT /account/credit/alert-thresholds` | Set the two low-balance alert thresholds |\n| `POST` & `GET /boxes`, `DELETE /boxes/{id}` | Create / list / delete an address |\n| `GET` `POST` `PUT` `DELETE /domain/dns` | Managed-zone DNS records |\n| `GET /suppression`, `GET /suppression/{address}`, `POST /suppression/{address}/unblock` | Suppression list |\n| `POST` & `GET /feature-requests`, `GET /feature-requests/{id}`, `POST /feature-requests/{id}/vote` | Feature requests |\n| `POST` & `GET /support/questions`, `GET /support/questions/{id}`, `POST /support/questions/{id}/replies` | Support questions |\n\nFull request/response schemas: the OpenAPI spec at\n`https://www.agenticboxes.email/openapi.yaml`.\n\nThis list is authoritative — every endpoint here works with your agent API key.\nIf you recall, or read in an older note or a stale copy of this skill, that some\nendpoint \"needs a dashboard login\" or \"can't be called by an agent,\" do not\ntrust it and build a workaround — make the call and read the response. The live\nAPI always wins over a remembered limitation.\n\n## Pitfalls\n\n- The API key is shown **once**, at `confirm`. Capture it then or it is unrecoverable.\n- An address receives mail only after `POST /boxes` creates its box.\n- Sends fail with `402` / insufficient credit once the balance is spent — top up.\n- The base URL ends at `/api/v1` — do not append `/v1` again.\n- API keys carry scopes (`send` / `receive` / `admin`); use one with the scope the call needs.\n- Pass `idempotency_key` on sends so a retried request never double-sends.\n- The `PUT /account/callback-webhook` body field is `agent_callback_webhook`, not `url`.\n- Support questions and feature requests go through `POST /support/questions` and `POST /feature-requests` **only** — never email. There is no support email address; any you recall or find is stale.\n\n## Verification\n\n- A successful send returns a `message_id` and a `billing` breakdown.\n- `GET /events` returns the account's event stream; `GET /messages` lists its mail.\n- After `confirm`, `account_status` is `active` — the account is ready.\n\nFile v1.4.3:_meta.json\n\n{\n  \"ownerId\": \"kn73rnk5893nejc4cexe0vxkx986ynx3\",\n  \"slug\": \"agenticboxes-email\",\n  \"version\": \"1.4.3\",\n  \"publishedAt\": 1779204420333\n}\n\nArchive v1.4.2: 2 files, 5655 bytes\n\nFiles: SKILL.md (12898b), _meta.json (137b)\n\nFile v1.4.2:SKILL.md\n\n---\nname: agenticboxes-email\ndescription: Send and receive email as an agent via the agenticboxes HTTP API — one API key, no IMAP/SMTP setup.\nnamespace: skills/communication/agenticboxes\nversion: 1.4.2\nauthor: agenticboxes\nlicense: MIT\nplatforms: [linux, macos, windows]\ntags: [email, communication, api, send, receive, agentic]\n---\n\n# agenticboxes — email for AI agents\n\nGives the agent a real email address it can **send and receive** from, over a\nplain HTTP API. No SMTP, no IMAP, no DKIM/SPF/DMARC setup — one API key.\n(Compare the `himalaya` skill: that drives a CLI mail client over IMAP/SMTP\nwith a `config.toml`; agenticboxes is a hosted HTTP API — sign up and go.)\n\n## When to Use\n\nUse this skill whenever the agent needs to:\n\n- **Send email** — notifications, outreach, replies, confirmations.\n- **Receive email** — sign-up confirmations, 2FA codes, replies, any inbound mail.\n- **Have its own address** to register for a third-party service (Stripe, SaaS tools, accounts).\n- **Get help or improve the platform** — ask the operators a support question, or file a feature request.\n\n## Procedure\n\n### Prerequisite — an API key\n\nIf `AGENTICBOXES_API_KEY` is set, use it. Otherwise sign up. `POST /signup/agentic`\nstarts a signup; `domain_intent.mode` picks how the agent gets its domain:\n\n**A · Free subdomain** (`mode: subdomain`) — a `<slug>.agenticboxes.email`\naddress. Free, no card. Two calls:\n\n```bash\ncurl -s https://api.agenticboxes.email/api/v1/signup/agentic \\\n  -H 'Content-Type: application/json' \\\n  -d '{\"human_email\":\"owner@example.com\",\"domain_intent\":{\"mode\":\"subdomain\"}}'\n#  → { \"intent_id\":\"int_…\", \"full_domain\":\"swift-fox-7.agenticboxes.email\" }\n\ncurl -s https://api.agenticboxes.email/api/v1/signup/agentic/confirm \\\n  -H 'Content-Type: application/json' -d '{\"intent_id\":\"int_…\"}'\n#  → { \"primary_address\":\"agent@swift-fox-7.agenticboxes.email\",\n#      \"api_key\":\"bxs_live_…\", \"account_status\":\"active\" }\n```\n\n**B · Register a real domain** (`mode: register`) — agenticboxes buys a domain\nfor the agent. Send `domain_intent: {\"mode\":\"register\",\"register_domain\":\"youragent.com\"}`.\nThe signup response carries a `stripe_payment_intent` + `link_spend_request`\n(year-1 registration cost, plus $1/mo for DNS hosting). The owner approves that\ncharge via Stripe Link; the account then provisions **automatically** once\npayment clears — there is no `confirm` call for mode B. A taken or unavailable\ndomain returns `409` with `suggestions`.\n\n**C · Bring your own domain, you host the DNS** (`mode: byo_manual`) — a domain\nthe owner already controls and keeps hosting elsewhere. Send\n`domain_intent: {\"mode\":\"byo_manual\",\"byo_domain\":\"youragent.com\"}`. Free;\nfinish with `/signup/agentic/confirm` as for a subdomain. The DNS records to add\n(MX/SPF/DKIM/DMARC) arrive as a `domain.dns_required` event — read them any time\nwith `GET /events?type=domain.dns_required`. Once they resolve, the account\ngoes live.\n\n**D · Bring your own domain, delegate the DNS to us** (`mode: byo_delegated`) —\na domain the owner controls, but with its DNS handed to a Route 53 zone\nagenticboxes runs. Send\n`domain_intent: {\"mode\":\"byo_delegated\",\"byo_domain\":\"youragent.com\"}`. $1/mo\nfor DNS hosting; finish with `/signup/agentic/confirm`. A\n`domain.delegation_required` event then lists the nameservers to set at the\ndomain's registrar; once the delegation propagates, the account goes live.\n\nOptional on any signup: `initial_credit_cents` (≥100 — prepay credit) and\n`agent_callback_webhook` (the event webhook URL). Store the `api_key` the\ninstant it's returned — it is shown exactly once. Every account starts with\n**250 messages of free credit**.\n\n### Calling the API\n\n- **Base URL:** `https://api.agenticboxes.email/api/v1`\n- **Auth:** every call carries `Authorization: Bearer $AGENTICBOXES_API_KEY`\n- **Discovery:** `GET https://api.agenticboxes.email/.well-known/agentic.json`\n  returns this service's manifest — skills, OpenAPI spec, signup, pricing.\n\n**Send** — `POST /messages/send`:\n\n```bash\ncurl -s https://api.agenticboxes.email/api/v1/messages/send \\\n  -H \"Authorization: Bearer $AGENTICBOXES_API_KEY\" \\\n  -H 'Content-Type: application/json' \\\n  -d '{\"from\":\"outreach@your-domain\",\n       \"to\":\"someone@example.com\",\n       \"subject\":\"Hello\",\n       \"text\":\"Sent by my agent.\"}'\n```\n\nBody: `to` (string or array, required), `subject`, `text`. Optional: `from` —\nsend from a specific box on your domain (defaults to the account's primary\naddress); `attachments` (`[{filename, content_b64, content_type}]`);\n`idempotency_key`; and `context` — an opaque JSON object (≤16 KB) stored with\nthe message and echoed back onto any inbound reply to it (see Receive). The\nresponse carries a `message_id` and a `billing` breakdown.\n\n**Receive** — three ways onto one underlying stream:\n\n- **Event feed (poll)** — `GET /events?since=<cursor>` — the unified feed:\n  every event the platform emits for the account, in one ordered stream\n  (`mail.received`, `support.answered`, `domain.ready`, and more). Process a\n  page, then poll again with `since` set to the response's `next_cursor`;\n  filter to one kind with `?type=mail.received`. This is the receive path that\n  never misses anything — webhook or no webhook.\n- **Messages (poll)** — `GET /messages?include=body` — the mail corpus: recent\n  messages with full bodies inline, filterable by `direction` (`received` or\n  `sent`), `since`, `before`, `box`, `limit`. `GET /messages/{id}` reads one.\n- **Webhook (push)** — `PUT /account/callback-webhook`\n  `{\"agent_callback_webhook\":\"https://…\"}` — events are POSTed to that URL as\n  they happen; optional push delivery over the same stream the event feed\n  serves. `GET /account/callback-webhook` reads the URL currently set.\n\n**Reply context** — every message carries a `context` field. When an inbound\nmail is a reply to one the agent sent with a `context`, that same `context` is\nechoed back on it — on `GET /messages`, `GET /events`, and in the webhook\npayload — so a reply self-routes to its originating conversation. `null` when\nnot a reply.\n\n**Addresses (boxes)** — a box is one email address; create as many as needed,\nno per-box fee:\n\n- `POST /boxes` `{\"address\":\"outreach\"}` → `outreach@<your-domain>`\n- `GET /boxes` — list them.\n- `DELETE /boxes/{id}` — remove an address.\n\nAn address can only receive mail after its box is created — and a box is the\n`from` you send outreach with, so create one before the first send to it.\n\n**Credit** — `POST /account/credit/topup` adds prepaid credit.\n`GET /account/credit/balance` shows the balance, the low-balance flag, and how\nmany more emails it covers; `GET /account/credit/usage` breaks down metered\nusage by event type. A `low_balance` event (in the event feed and the webhook)\nwarns before the balance runs out — `PUT /account/credit/alert-thresholds` sets\nthe two alert levels (an early `first` and an urgent `second`) to balances that\nsuit your burn rate.\n\n**Get unstuck — support questions** — a private channel to the agenticboxes\noperators. Use this instead of guessing when something about the API is unclear:\n\n- `POST /support/questions` — body `{\"subject\":\"…\",\"body\":\"…\"}` (optional\n  `context`). The answer arrives as a `support.answered` event — in\n  `GET /events` and at the callback webhook.\n- `GET /support/questions` — list your questions; `GET /support/questions/{id}`\n  — read one, with its full message thread.\n- `POST /support/questions/{id}/replies` — body `{\"body\":\"…\"}` — post a\n  follow-up. A support question is a threaded conversation, not one-shot.\n\n**Feature requests** — suggest a platform improvement, or upvote one:\n\n- `POST /feature-requests` — body `{\"title\":\"…\",\"description\":\"…\"}`.\n- `GET /feature-requests` — browse; `GET /feature-requests/{id}` — read one.\n- `POST /feature-requests/{id}/vote` — upvote (no body).\n\n**Suppression list** — addresses that bounced or filed a complaint and are\nblocked from delivery:\n\n- `GET /suppression` — list them; `GET /suppression/{address}` — check one\n  before sending to it.\n- `POST /suppression/{address}/unblock` — request removal.\n\n**Managed DNS** — for an account on a registered or delegated domain\n(`register` or `byo_delegated`), edit the Route 53 zone agenticboxes hosts:\n\n- `GET /domain/dns` — list records.\n- `POST` / `PUT` / `DELETE /domain/dns` — add / change / remove a record. The\n  body must include `terms_of_service: true`; a record is\n  `{name, type, ttl, values}`. The records carrying your agent email are\n  reserved read-only.\n\nA `byo_manual` account hosts its own DNS, so it has no managed zone —\n`/domain/dns` returns `409`; that account's required records are in\n`GET /events?type=domain.dns_required` instead.\n\n### Speak up — when to file support questions and feature requests\n\nDon't fail silently, guess, or quietly work around a gap. The platform improves\nonly when agents say something — treat this as part of the job:\n\n- **Stuck or surprised** → send a **support question** (`POST /support/questions`).\n  Triggers: an error you can't resolve, an endpoint behaving unexpectedly, a\n  response you don't understand, docs that don't answer your question, or being\n  blocked. Ask rather than abandoning the task — it's free and private.\n- **Missing a capability** → file a **feature request** (`POST /feature-requests`).\n  Triggers: you needed something this API doesn't do, hit a limit that got in\n  your way, or saw a clear way the platform could be better. Be concrete and\n  specific.\n\nDoing this when warranted is expected behaviour, not an interruption.\n\n**These go through the API, never email.** `POST /support/questions` and\n`POST /feature-requests` are the *only* channels. There is no agenticboxes\nsupport email address — if you recall or find one (anything `@brian.im`, or a\n`support@` / `help@` style address), it is stale and unmonitored. Do not email\na request: it spends a paid send, reaches no one, and is not how the platform\nreceives feedback. The endpoints are free and land directly with the team.\n\n### Every endpoint\n\nThe complete agent-facing API — base `https://api.agenticboxes.email/api/v1`,\nevery call `Authorization: Bearer` except the two signup calls:\n\n| Endpoint | Purpose |\n|---|---|\n| `POST /signup/agentic`, `POST /signup/agentic/confirm` | Free signup |\n| `POST /messages/send` | Send mail |\n| `GET /events` | The unified event feed — poll to receive |\n| `GET /messages`, `GET /messages/{id}` | List / read mail |\n| `GET` & `PUT /account/callback-webhook` | Read / set the event webhook |\n| `POST /account/credit/topup` | Add prepaid credit |\n| `GET /account/credit/balance`, `GET /account/credit/usage` | Credit balance + metered-usage breakdown |\n| `PUT /account/credit/alert-thresholds` | Set the two low-balance alert thresholds |\n| `POST` & `GET /boxes`, `DELETE /boxes/{id}` | Create / list / delete an address |\n| `GET` `POST` `PUT` `DELETE /domain/dns` | Managed-zone DNS records |\n| `GET /suppression`, `GET /suppression/{address}`, `POST /suppression/{address}/unblock` | Suppression list |\n| `POST` & `GET /feature-requests`, `GET /feature-requests/{id}`, `POST /feature-requests/{id}/vote` | Feature requests |\n| `POST` & `GET /support/questions`, `GET /support/questions/{id}`, `POST /support/questions/{id}/replies` | Support questions |\n\nFull request/response schemas: the OpenAPI spec at\n`https://www.agenticboxes.email/openapi.yaml`.\n\nThis list is authoritative — every endpoint here works with your agent API key.\nIf you recall, or read in an older note or a stale copy of this skill, that some\nendpoint \"needs a dashboard login\" or \"can't be called by an agent,\" do not\ntrust it and build a workaround — make the call and read the response. The live\nAPI always wins over a remembered limitation.\n\n## Pitfalls\n\n- The API key is shown **once**, at `confirm`. Capture it then or it is unrecoverable.\n- An address receives mail only after `POST /boxes` creates its box.\n- Sends fail with `402` / insufficient credit once the balance is spent — top up.\n- The base URL ends at `/api/v1` — do not append `/v1` again.\n- API keys carry scopes (`send` / `receive` / `admin`); use one with the scope the call needs.\n- Pass `idempotency_key` on sends so a retried request never double-sends.\n- The `PUT /account/callback-webhook` body field is `agent_callback_webhook`, not `url`.\n- Support questions and feature requests go through `POST /support/questions` and `POST /feature-requests` **only** — never email. There is no support email address; any you recall or find is stale.\n\n## Verification\n\n- A successful send returns a `message_id` and a `billing` breakdown.\n- `GET /events` returns the account's event stream; `GET /messages` lists its mail.\n- After `confirm`, `account_status` is `active` — the account is ready.\n\nFile v1.4.2:_meta.json\n\n{\n  \"ownerId\": \"kn73rnk5893nejc4cexe0vxkx986ynx3\",\n  \"slug\": \"agenticboxes-email\",\n  \"version\": \"1.4.2\",\n  \"publishedAt\": 1779202918224\n}\n\nArchive v1.4.1: 2 files, 5561 bytes\n\nFiles: SKILL.md (12664b), _meta.json (137b)\n\nFile v1.4.1:SKILL.md\n\n---\nname: agenticboxes-email\ndescription: Send and receive email as an agent via the agenticboxes HTTP API — one API key, no IMAP/SMTP setup.\nnamespace: skills/communication/agenticboxes\nversion: 1.4.1\nauthor: agenticboxes\nlicense: MIT\nplatforms: [linux, macos, windows]\ntags: [email, communication, api, send, receive, agentic]\n---\n\n# agenticboxes — email for AI agents\n\nGives the agent a real email address it can **send and receive** from, over a\nplain HTTP API. No SMTP, no IMAP, no DKIM/SPF/DMARC setup — one API key.\n(Compare the `himalaya` skill: that drives a CLI mail client over IMAP/SMTP\nwith a `config.toml`; agenticboxes is a hosted HTTP API — sign up and go.)\n\n## When to Use\n\nUse this skill whenever the agent needs to:\n\n- **Send email** — notifications, outreach, replies, confirmations.\n- **Receive email** — sign-up confirmations, 2FA codes, replies, any inbound mail.\n- **Have its own address** to register for a third-party service (Stripe, SaaS tools, accounts).\n- **Get help or improve the platform** — ask the operators a support question, or file a feature request.\n\n## Procedure\n\n### Prerequisite — an API key\n\nIf `AGENTICBOXES_API_KEY` is set, use it. Otherwise sign up. `POST /signup/agentic`\nstarts a signup; `domain_intent.mode` picks how the agent gets its domain:\n\n**A · Free subdomain** (`mode: subdomain`) — a `<slug>.agenticboxes.email`\naddress. Free, no card. Two calls:\n\n```bash\ncurl -s https://api.agenticboxes.email/api/v1/signup/agentic \\\n  -H 'Content-Type: application/json' \\\n  -d '{\"human_email\":\"owner@example.com\",\"domain_intent\":{\"mode\":\"subdomain\"}}'\n#  → { \"intent_id\":\"int_…\", \"full_domain\":\"swift-fox-7.agenticboxes.email\" }\n\ncurl -s https://api.agenticboxes.email/api/v1/signup/agentic/confirm \\\n  -H 'Content-Type: application/json' -d '{\"intent_id\":\"int_…\"}'\n#  → { \"primary_address\":\"agent@swift-fox-7.agenticboxes.email\",\n#      \"api_key\":\"bxs_live_…\", \"account_status\":\"active\" }\n```\n\n**B · Register a real domain** (`mode: register`) — agenticboxes buys a domain\nfor the agent. Send `domain_intent: {\"mode\":\"register\",\"register_domain\":\"youragent.com\"}`.\nThe signup response carries a `stripe_payment_intent` + `link_spend_request`\n(year-1 registration cost, plus $1/mo for DNS hosting). The owner approves that\ncharge via Stripe Link; the account then provisions **automatically** once\npayment clears — there is no `confirm` call for mode B. A taken or unavailable\ndomain returns `409` with `suggestions`.\n\n**C · Bring your own domain, you host the DNS** (`mode: byo_manual`) — a domain\nthe owner already controls and keeps hosting elsewhere. Send\n`domain_intent: {\"mode\":\"byo_manual\",\"byo_domain\":\"youragent.com\"}`. Free;\nfinish with `/signup/agentic/confirm` as for a subdomain. The DNS records to add\n(MX/SPF/DKIM/DMARC) arrive as a `domain.dns_required` event — read them any time\nwith `GET /events?type=domain.dns_required`. Once they resolve, the account\ngoes live.\n\n**D · Bring your own domain, delegate the DNS to us** (`mode: byo_delegated`) —\na domain the owner controls, but with its DNS handed to a Route 53 zone\nagenticboxes runs. Send\n`domain_intent: {\"mode\":\"byo_delegated\",\"byo_domain\":\"youragent.com\"}`. $1/mo\nfor DNS hosting; finish with `/signup/agentic/confirm`. A\n`domain.delegation_required` event then lists the nameservers to set at the\ndomain's registrar; once the delegation propagates, the account goes live.\n\nOptional on any signup: `initial_credit_cents` (≥100 — prepay credit) and\n`agent_callback_webhook` (the event webhook URL). Store the `api_key` the\ninstant it's returned — it is shown exactly once. Every account starts with\n**250 messages of free credit**.\n\n### Calling the API\n\n- **Base URL:** `https://api.agenticboxes.email/api/v1`\n- **Auth:** every call carries `Authorization: Bearer $AGENTICBOXES_API_KEY`\n- **Discovery:** `GET https://api.agenticboxes.email/.well-known/agentic.json`\n  returns this service's manifest — skills, OpenAPI spec, signup, pricing.\n\n**Send** — `POST /messages/send`:\n\n```bash\ncurl -s https://api.agenticboxes.email/api/v1/messages/send \\\n  -H \"Authorization: Bearer $AGENTICBOXES_API_KEY\" \\\n  -H 'Content-Type: application/json' \\\n  -d '{\"from\":\"outreach@your-domain\",\n       \"to\":\"someone@example.com\",\n       \"subject\":\"Hello\",\n       \"text\":\"Sent by my agent.\"}'\n```\n\nBody: `to` (string or array, required), `subject`, `text`. Optional: `from` —\nsend from a specific box on your domain (defaults to the account's primary\naddress); `attachments` (`[{filename, content_b64, content_type}]`);\n`idempotency_key`; and `context` — an opaque JSON object (≤16 KB) stored with\nthe message and echoed back onto any inbound reply to it (see Receive). The\nresponse carries a `message_id` and a `billing` breakdown.\n\n**Receive** — three ways onto one underlying stream:\n\n- **Event feed (poll)** — `GET /events?since=<cursor>` — the unified feed:\n  every event the platform emits for the account, in one ordered stream\n  (`mail.received`, `support.answered`, `domain.ready`, and more). Process a\n  page, then poll again with `since` set to the response's `next_cursor`;\n  filter to one kind with `?type=mail.received`. This is the receive path that\n  never misses anything — webhook or no webhook.\n- **Messages (poll)** — `GET /messages?include=body` — the mail corpus: recent\n  messages with full bodies inline, filterable by `direction` (`received` or\n  `sent`), `since`, `before`, `box`, `limit`. `GET /messages/{id}` reads one.\n- **Webhook (push)** — `PUT /account/callback-webhook`\n  `{\"agent_callback_webhook\":\"https://…\"}` — events are POSTed to that URL as\n  they happen; optional push delivery over the same stream the event feed\n  serves. `GET /account/callback-webhook` reads the URL currently set.\n\n**Reply context** — every message carries a `context` field. When an inbound\nmail is a reply to one the agent sent with a `context`, that same `context` is\nechoed back on it — on `GET /messages`, `GET /events`, and in the webhook\npayload — so a reply self-routes to its originating conversation. `null` when\nnot a reply.\n\n**Addresses (boxes)** — a box is one email address; create as many as needed,\nno per-box fee:\n\n- `POST /boxes` `{\"address\":\"outreach\"}` → `outreach@<your-domain>`\n- `GET /boxes` — list them.\n- `DELETE /boxes/{id}` — remove an address.\n\nAn address can only receive mail after its box is created — and a box is the\n`from` you send outreach with, so create one before the first send to it.\n\n**Credit** — `POST /account/credit/topup` adds prepaid credit.\n`GET /account/credit/balance` shows the balance, the low-balance flag, and how\nmany more emails it covers; `GET /account/credit/usage` breaks down metered\nusage by event type. A `low_balance` event (in the event feed and the webhook)\nwarns before the balance runs out.\n\n**Get unstuck — support questions** — a private channel to the agenticboxes\noperators. Use this instead of guessing when something about the API is unclear:\n\n- `POST /support/questions` — body `{\"subject\":\"…\",\"body\":\"…\"}` (optional\n  `context`). The answer arrives as a `support.answered` event — in\n  `GET /events` and at the callback webhook.\n- `GET /support/questions` — list your questions; `GET /support/questions/{id}`\n  — read one, with its full message thread.\n- `POST /support/questions/{id}/replies` — body `{\"body\":\"…\"}` — post a\n  follow-up. A support question is a threaded conversation, not one-shot.\n\n**Feature requests** — suggest a platform improvement, or upvote one:\n\n- `POST /feature-requests` — body `{\"title\":\"…\",\"description\":\"…\"}`.\n- `GET /feature-requests` — browse; `GET /feature-requests/{id}` — read one.\n- `POST /feature-requests/{id}/vote` — upvote (no body).\n\n**Suppression list** — addresses that bounced or filed a complaint and are\nblocked from delivery:\n\n- `GET /suppression` — list them; `GET /suppression/{address}` — check one\n  before sending to it.\n- `POST /suppression/{address}/unblock` — request removal.\n\n**Managed DNS** — for an account on a registered or delegated domain\n(`register` or `byo_delegated`), edit the Route 53 zone agenticboxes hosts:\n\n- `GET /domain/dns` — list records.\n- `POST` / `PUT` / `DELETE /domain/dns` — add / change / remove a record. The\n  body must include `terms_of_service: true`; a record is\n  `{name, type, ttl, values}`. The records carrying your agent email are\n  reserved read-only.\n\nA `byo_manual` account hosts its own DNS, so it has no managed zone —\n`/domain/dns` returns `409`; that account's required records are in\n`GET /events?type=domain.dns_required` instead.\n\n### Speak up — when to file support questions and feature requests\n\nDon't fail silently, guess, or quietly work around a gap. The platform improves\nonly when agents say something — treat this as part of the job:\n\n- **Stuck or surprised** → send a **support question** (`POST /support/questions`).\n  Triggers: an error you can't resolve, an endpoint behaving unexpectedly, a\n  response you don't understand, docs that don't answer your question, or being\n  blocked. Ask rather than abandoning the task — it's free and private.\n- **Missing a capability** → file a **feature request** (`POST /feature-requests`).\n  Triggers: you needed something this API doesn't do, hit a limit that got in\n  your way, or saw a clear way the platform could be better. Be concrete and\n  specific.\n\nDoing this when warranted is expected behaviour, not an interruption.\n\n**These go through the API, never email.** `POST /support/questions` and\n`POST /feature-requests` are the *only* channels. There is no agenticboxes\nsupport email address — if you recall or find one (anything `@brian.im`, or a\n`support@` / `help@` style address), it is stale and unmonitored. Do not email\na request: it spends a paid send, reaches no one, and is not how the platform\nreceives feedback. The endpoints are free and land directly with the team.\n\n### Every endpoint\n\nThe complete agent-facing API — base `https://api.agenticboxes.email/api/v1`,\nevery call `Authorization: Bearer` except the two signup calls:\n\n| Endpoint | Purpose |\n|---|---|\n| `POST /signup/agentic`, `POST /signup/agentic/confirm` | Free signup |\n| `POST /messages/send` | Send mail |\n| `GET /events` | The unified event feed — poll to receive |\n| `GET /messages`, `GET /messages/{id}` | List / read mail |\n| `GET` & `PUT /account/callback-webhook` | Read / set the event webhook |\n| `POST /account/credit/topup` | Add prepaid credit |\n| `GET /account/credit/balance`, `GET /account/credit/usage` | Credit balance + metered-usage breakdown |\n| `POST` & `GET /boxes`, `DELETE /boxes/{id}` | Create / list / delete an address |\n| `GET` `POST` `PUT` `DELETE /domain/dns` | Managed-zone DNS records |\n| `GET /suppression`, `GET /suppression/{address}`, `POST /suppression/{address}/unblock` | Suppression list |\n| `POST` & `GET /feature-requests`, `GET /feature-requests/{id}`, `POST /feature-requests/{id}/vote` | Feature requests |\n| `POST` & `GET /support/questions`, `GET /support/questions/{id}`, `POST /support/questions/{id}/replies` | Support questions |\n\nFull request/response schemas: the OpenAPI spec at\n`https://www.agenticboxes.email/openapi.yaml`.\n\nThis list is authoritative — every endpoint here works with your agent API key.\nIf you recall, or read in an older note or a stale copy of this skill, that some\nendpoint \"needs a dashboard login\" or \"can't be called by an agent,\" do not\ntrust it and build a workaround — make the call and read the response. The live\nAPI always wins over a remembered limitation.\n\n## Pitfalls\n\n- The API key is shown **once**, at `confirm`. Capture it then or it is unrecoverable.\n- An address receives mail only after `POST /boxes` creates its box.\n- Sends fail with `402` / insufficient credit once the balance is spent — top up.\n- The base URL ends at `/api/v1` — do not append `/v1` again.\n- API keys carry scopes (`send` / `receive` / `admin`); use one with the scope the call needs.\n- Pass `idempotency_key` on sends so a retried request never double-sends.\n- The `PUT /account/callback-webhook` body field is `agent_callback_webhook`, not `url`.\n- Support questions and feature requests go through `POST /support/questions` and `POST /feature-requests` **only** — never email. There is no support email address; any you recall or find is stale.\n\n## Verification\n\n- A successful send returns a `message_id` and a `billing` breakdown.\n- `GET /events` returns the account's event stream; `GET /messages` lists its mail.\n- After `confirm`, `account_status` is `active` — the account is ready.\n\nFile v1.4.1:_meta.json\n\n{\n  \"ownerId\": \"kn73rnk5893nejc4cexe0vxkx986ynx3\",\n  \"slug\": \"agenticboxes-email\",\n  \"version\": \"1.4.1\",\n  \"publishedAt\": 1779201817874\n}\n\nArchive v1.4.0: 2 files, 5431 bytes\n\nFiles: SKILL.md (12289b), _meta.json (137b)\n\nFile v1.4.0:SKILL.md\n\n---\nname: agenticboxes-email\ndescription: Send and receive email as an agent via the agenticboxes HTTP API — one API key, no IMAP/SMTP setup.\nnamespace: skills/communication/agenticboxes\nversion: 1.4.0\nauthor: agenticboxes\nlicense: MIT\nplatforms: [linux, macos, windows]\ntags: [email, communication, api, send, receive, agentic]\n---\n\n# agenticboxes — email for AI agents\n\nGives the agent a real email address it can **send and receive** from, over a\nplain HTTP API. No SMTP, no IMAP, no DKIM/SPF/DMARC setup — one API key.\n(Compare the `himalaya` skill: that drives a CLI mail client over IMAP/SMTP\nwith a `config.toml`; agenticboxes is a hosted HTTP API — sign up and go.)\n\n## When to Use\n\nUse this skill whenever the agent needs to:\n\n- **Send email** — notifications, outreach, replies, confirmations.\n- **Receive email** — sign-up confirmations, 2FA codes, replies, any inbound mail.\n- **Have its own address** to register for a third-party service (Stripe, SaaS tools, accounts).\n- **Get help or improve the platform** — ask the operators a support question, or file a feature request.\n\n## Procedure\n\n### Prerequisite — an API key\n\nIf `AGENTICBOXES_API_KEY` is set, use it. Otherwise sign up. `POST /signup/agentic`\nstarts a signup; `domain_intent.mode` picks how the agent gets its domain:\n\n**A · Free subdomain** (`mode: subdomain`) — a `<slug>.agenticboxes.email`\naddress. Free, no card. Two calls:\n\n```bash\ncurl -s https://api.agenticboxes.email/api/v1/signup/agentic \\\n  -H 'Content-Type: application/json' \\\n  -d '{\"human_email\":\"owner@example.com\",\"domain_intent\":{\"mode\":\"subdomain\"}}'\n#  → { \"intent_id\":\"int_…\", \"full_domain\":\"swift-fox-7.agenticboxes.email\" }\n\ncurl -s https://api.agenticboxes.email/api/v1/signup/agentic/confirm \\\n  -H 'Content-Type: application/json' -d '{\"intent_id\":\"int_…\"}'\n#  → { \"primary_address\":\"agent@swift-fox-7.agenticboxes.email\",\n#      \"api_key\":\"bxs_live_…\", \"account_status\":\"active\" }\n```\n\n**B · Register a real domain** (`mode: register`) — agenticboxes buys a domain\nfor the agent. Send `domain_intent: {\"mode\":\"register\",\"register_domain\":\"youragent.com\"}`.\nThe signup response carries a `stripe_payment_intent` + `link_spend_request`\n(year-1 registration cost, plus $1/mo for DNS hosting). The owner approves that\ncharge via Stripe Link; the account then provisions **automatically** once\npayment clears — there is no `confirm` call for mode B. A taken or unavailable\ndomain returns `409` with `suggestions`.\n\n**C · Bring your own domain, you host the DNS** (`mode: byo_manual`) — a domain\nthe owner already controls and keeps hosting elsewhere. Send\n`domain_intent: {\"mode\":\"byo_manual\",\"byo_domain\":\"youragent.com\"}`. Free;\nfinish with `/signup/agentic/confirm` as for a subdomain. The DNS records to add\n(MX/SPF/DKIM/DMARC) arrive as a `domain.dns_required` event — read them any time\nwith `GET /events?type=domain.dns_required`. Once they resolve, the account\ngoes live.\n\n**D · Bring your own domain, delegate the DNS to us** (`mode: byo_delegated`) —\na domain the owner controls, but with its DNS handed to a Route 53 zone\nagenticboxes runs. Send\n`domain_intent: {\"mode\":\"byo_delegated\",\"byo_domain\":\"youragent.com\"}`. $1/mo\nfor DNS hosting; finish with `/signup/agentic/confirm`. A\n`domain.delegation_required` event then lists the nameservers to set at the\ndomain's registrar; once the delegation propagates, the account goes live.\n\nOptional on any signup: `initial_credit_cents` (≥100 — prepay credit) and\n`agent_callback_webhook` (the event webhook URL). Store the `api_key` the\ninstant it's returned — it is shown exactly once. Every account starts with\n**250 messages of free credit**.\n\n### Calling the API\n\n- **Base URL:** `https://api.agenticboxes.email/api/v1`\n- **Auth:** every call carries `Authorization: Bearer $AGENTICBOXES_API_KEY`\n- **Discovery:** `GET https://api.agenticboxes.email/.well-known/agentic.json`\n  returns this service's manifest — skills, OpenAPI spec, signup, pricing.\n\n**Send** — `POST /messages/send`:\n\n```bash\ncurl -s https://api.agenticboxes.email/api/v1/messages/send \\\n  -H \"Authorization: Bearer $AGENTICBOXES_API_KEY\" \\\n  -H 'Content-Type: application/json' \\\n  -d '{\"from\":\"outreach@your-domain\",\n       \"to\":\"someone@example.com\",\n       \"subject\":\"Hello\",\n       \"text\":\"Sent by my agent.\"}'\n```\n\nBody: `to` (string or array, required), `subject`, `text`. Optional: `from` —\nsend from a specific box on your domain (defaults to the account's primary\naddress); `attachments` (`[{filename, content_b64, content_type}]`);\n`idempotency_key`; and `context` — an opaque JSON object (≤16 KB) stored with\nthe message and echoed back onto any inbound reply to it (see Receive). The\nresponse carries a `message_id` and a `billing` breakdown.\n\n**Receive** — three ways onto one underlying stream:\n\n- **Event feed (poll)** — `GET /events?since=<cursor>` — the unified feed:\n  every event the platform emits for the account, in one ordered stream\n  (`mail.received`, `support.answered`, `domain.ready`, and more). Process a\n  page, then poll again with `since` set to the response's `next_cursor`;\n  filter to one kind with `?type=mail.received`. This is the receive path that\n  never misses anything — webhook or no webhook.\n- **Messages (poll)** — `GET /messages?include=body` — the mail corpus: recent\n  messages with full bodies inline, filterable by `direction` (`received` or\n  `sent`), `since`, `before`, `box`, `limit`. `GET /messages/{id}` reads one.\n- **Webhook (push)** — `PUT /account/callback-webhook`\n  `{\"agent_callback_webhook\":\"https://…\"}` — events are POSTed to that URL as\n  they happen; optional push delivery over the same stream the event feed\n  serves. `GET /account/callback-webhook` reads the URL currently set.\n\n**Reply context** — every message carries a `context` field. When an inbound\nmail is a reply to one the agent sent with a `context`, that same `context` is\nechoed back on it — on `GET /messages`, `GET /events`, and in the webhook\npayload — so a reply self-routes to its originating conversation. `null` when\nnot a reply.\n\n**Addresses (boxes)** — a box is one email address; create as many as needed,\nno per-box fee:\n\n- `POST /boxes` `{\"address\":\"outreach\"}` → `outreach@<your-domain>`\n- `GET /boxes` — list them.\n- `DELETE /boxes/{id}` — remove an address.\n\nAn address can only receive mail after its box is created — and a box is the\n`from` you send outreach with, so create one before the first send to it.\n\n**Credit** — `POST /account/credit/topup` adds prepaid credit.\n\n**Get unstuck — support questions** — a private channel to the agenticboxes\noperators. Use this instead of guessing when something about the API is unclear:\n\n- `POST /support/questions` — body `{\"subject\":\"…\",\"body\":\"…\"}` (optional\n  `context`). The answer arrives as a `support.answered` event — in\n  `GET /events` and at the callback webhook.\n- `GET /support/questions` — list your questions; `GET /support/questions/{id}`\n  — read one, with its full message thread.\n- `POST /support/questions/{id}/replies` — body `{\"body\":\"…\"}` — post a\n  follow-up. A support question is a threaded conversation, not one-shot.\n\n**Feature requests** — suggest a platform improvement, or upvote one:\n\n- `POST /feature-requests` — body `{\"title\":\"…\",\"description\":\"…\"}`.\n- `GET /feature-requests` — browse; `GET /feature-requests/{id}` — read one.\n- `POST /feature-requests/{id}/vote` — upvote (no body).\n\n**Suppression list** — addresses that bounced or filed a complaint and are\nblocked from delivery:\n\n- `GET /suppression` — list them; `GET /suppression/{address}` — check one\n  before sending to it.\n- `POST /suppression/{address}/unblock` — request removal.\n\n**Managed DNS** — for an account on a registered or delegated domain\n(`register` or `byo_delegated`), edit the Route 53 zone agenticboxes hosts:\n\n- `GET /domain/dns` — list records.\n- `POST` / `PUT` / `DELETE /domain/dns` — add / change / remove a record. The\n  body must include `terms_of_service: true`; a record is\n  `{name, type, ttl, values}`. The records carrying your agent email are\n  reserved read-only.\n\nA `byo_manual` account hosts its own DNS, so it has no managed zone —\n`/domain/dns` returns `409`; that account's required records are in\n`GET /events?type=domain.dns_required` instead.\n\n### Speak up — when to file support questions and feature requests\n\nDon't fail silently, guess, or quietly work around a gap. The platform improves\nonly when agents say something — treat this as part of the job:\n\n- **Stuck or surprised** → send a **support question** (`POST /support/questions`).\n  Triggers: an error you can't resolve, an endpoint behaving unexpectedly, a\n  response you don't understand, docs that don't answer your question, or being\n  blocked. Ask rather than abandoning the task — it's free and private.\n- **Missing a capability** → file a **feature request** (`POST /feature-requests`).\n  Triggers: you needed something this API doesn't do, hit a limit that got in\n  your way, or saw a clear way the platform could be better. Be concrete and\n  specific.\n\nDoing this when warranted is expected behaviour, not an interruption.\n\n**These go through the API, never email.** `POST /support/questions` and\n`POST /feature-requests` are the *only* channels. There is no agenticboxes\nsupport email address — if you recall or find one (anything `@brian.im`, or a\n`support@` / `help@` style address), it is stale and unmonitored. Do not email\na request: it spends a paid send, reaches no one, and is not how the platform\nreceives feedback. The endpoints are free and land directly with the team.\n\n### Every endpoint\n\nThe complete agent-facing API — base `https://api.agenticboxes.email/api/v1`,\nevery call `Authorization: Bearer` except the two signup calls:\n\n| Endpoint | Purpose |\n|---|---|\n| `POST /signup/agentic`, `POST /signup/agentic/confirm` | Free signup |\n| `POST /messages/send` | Send mail |\n| `GET /events` | The unified event feed — poll to receive |\n| `GET /messages`, `GET /messages/{id}` | List / read mail |\n| `GET` & `PUT /account/callback-webhook` | Read / set the event webhook |\n| `POST /account/credit/topup` | Add prepaid credit |\n| `POST` & `GET /boxes`, `DELETE /boxes/{id}` | Create / list / delete an address |\n| `GET` `POST` `PUT` `DELETE /domain/dns` | Managed-zone DNS records |\n| `GET /suppression`, `GET /suppression/{address}`, `POST /suppression/{address}/unblock` | Suppression list |\n| `POST` & `GET /feature-requests`, `GET /feature-requests/{id}`, `POST /feature-requests/{id}/vote` | Feature requests |\n| `POST` & `GET /support/questions`, `GET /support/questions/{id}`, `POST /support/questions/{id}/replies` | Support questions |\n\nFull request/response schemas: the OpenAPI spec at\n`https://www.agenticboxes.email/openapi.yaml`.\n\nThis list is authoritative — every endpoint here works with your agent API key.\nIf you recall, or read in an older note or a stale copy of this skill, that some\nendpoint \"needs a dashboard login\" or \"can't be called by an agent,\" do not\ntrust it and build a workaround — make the call and read the response. The live\nAPI always wins over a remembered limitation.\n\n## Pitfalls\n\n- The API key is shown **once**, at `confirm`. Capture it then or it is unrecoverable.\n- An address receives mail only after `POST /boxes` creates its box.\n- Sends fail with `402` / insufficient credit once the balance is spent — top up.\n- The base URL ends at `/api/v1` — do not append `/v1` again.\n- API keys carry scopes (`send` / `receive` / `admin`); use one with the scope the call needs.\n- Pass `idempotency_key` on sends so a retried request never double-sends.\n- The `PUT /account/callback-webhook` body field is `agent_callback_webhook`, not `url`.\n- Support questions and feature requests go through `POST /support/questions` and `POST /feature-requests` **only** — never email. There is no support email address; any you recall or find is stale.\n\n## Verification\n\n- A successful send returns a `message_id` and a `billing` breakdown.\n- `GET /events` returns the account's event stream; `GET /messages` lists its mail.\n- After `confirm`, `account_status` is `active` — the account is ready.\n\nFile v1.4.0:_meta.json\n\n{\n  \"ownerId\": \"kn73rnk5893nejc4cexe0vxkx986ynx3\",\n  \"slug\": \"agenticboxes-email\",\n  \"version\": \"1.4.0\",\n  \"publishedAt\": 1779172180112\n}\n\nArchive v1.2.0: 2 files, 4106 bytes\n\nFiles: SKILL.md (8827b), _meta.json (137b)\n\nFile v1.2.0:SKILL.md\n\n---\nname: agenticboxes-email\ndescription: Send and receive email as an agent via the agenticboxes HTTP API — one API key, no IMAP/SMTP setup.\nnamespace: skills/communication/agenticboxes\nversion: 1.2.0\nauthor: agenticboxes\nlicense: MIT\nplatforms: [linux, macos, windows]\ntags: [email, communication, api, send, receive, agentic]\n---\n\n# agenticboxes — email for AI agents\n\nGives the agent a real email address it can **send and receive** from, over a\nplain HTTP API. No SMTP, no IMAP, no DKIM/SPF/DMARC setup — one API key.\n(Compare the `himalaya` skill: that drives a CLI mail client over IMAP/SMTP\nwith a `config.toml`; agenticboxes is a hosted HTTP API — sign up and go.)\n\n## When to Use\n\nUse this skill whenever the agent needs to:\n\n- **Send email** — notifications, outreach, replies, confirmations.\n- **Receive email** — sign-up confirmations, 2FA codes, replies, any inbound mail.\n- **Have its own address** to register for a third-party service (Stripe, SaaS tools, accounts).\n- **Get help or improve the platform** — ask the operators a support question, or file a feature request.\n\n## Prerequisites\n\nAn agenticboxes account and an API key (`bxs_live_…`).\n\n- If `AGENTICBOXES_API_KEY` is set, use it.\n- Otherwise sign up — free, two calls, no card:\n\n```bash\n# 1. Start a free signup (a *.agenticboxes.email subdomain inbox)\ncurl -s https://api.agenticboxes.email/api/v1/signup/agentic \\\n  -H 'Content-Type: application/json' \\\n  -d '{\"human_email\":\"owner@example.com\",\n       \"domain_intent\":{\"mode\":\"subdomain\"},\n       \"initial_credit_cents\":0}'\n# → { \"intent_id\": \"int_…\", \"full_domain\": \"swift-fox-7.agenticboxes.email\" }\n\n# 2. Confirm — provisions the account and returns the API key\ncurl -s https://api.agenticboxes.email/api/v1/signup/agentic/confirm \\\n  -H 'Content-Type: application/json' \\\n  -d '{\"intent_id\":\"int_…\"}'\n# → { \"primary_address\": \"agent@swift-fox-7.agenticboxes.email\",\n#     \"api_key\": \"bxs_live_…\", \"account_status\": \"active\" }\n```\n\nStore `api_key` immediately — it is returned exactly once. Every new account\nstarts with **250 messages of free credit**.\n\n## Procedure\n\n- **Base URL:** `https://api.agenticboxes.email/api/v1`\n- **Auth:** every call carries the header `Authorization: Bearer bxs_live_…`\n- **Discovery:** `GET https://api.agenticboxes.email/.well-known/agentic.json`\n  returns this service's manifest — skills, OpenAPI spec, signup, pricing.\n\n### Send mail — `POST /messages/send`\n\n```bash\ncurl -s https://api.agenticboxes.email/api/v1/messages/send \\\n  -H 'Authorization: Bearer bxs_live_…' \\\n  -H 'Content-Type: application/json' \\\n  -d '{\"to\":\"someone@example.com\",\n       \"subject\":\"Hello\",\n       \"text\":\"Sent by my agent.\"}'\n```\n\nBody: `to` (string or array, required), `subject`, `text`. Optional: `from`\n(defaults to the account's primary address), `attachments`\n(`[{filename, content_b64, content_type}]`), `idempotency_key`. The response\ncarries a `message_id` and a `billing` breakdown.\n\n### Receive mail\n\n- **Poll:** `GET /messages?include=body` — recent messages with full bodies\n  inline. Also filterable by `direction` (values `received` or `sent`),\n  `since`, `before`, `box`, `limit`.\n- **One message:** `GET /messages/{id}`.\n- **Push:** `PUT /account/callback-webhook` `{\"url\":\"https://…\"}` — inbound\n  mail is POSTed to that URL the moment it arrives. `GET /account/callback-webhook`\n  reads the URL currently set.\n\n### Addresses (boxes)\n\nA *box* is one email address. Create as many as the agent needs — no per-box fee.\n\n- `POST /boxes` `{\"address\":\"support\"}` → `support@<your-domain>`\n- `GET /boxes` — list them.\n- `DELETE /boxes/{id}` — remove an address.\n\nAn address can only receive mail **after** its box is created.\n\n### Credit — `POST /account/credit/topup`\n\nAdd prepaid credit when the balance runs low.\n\n### Support questions\n\nA private channel to the agenticboxes operators — for when something about the\nAPI is unclear or not working.\n\n- `POST /support/questions` — body `{\"subject\":\"…\",\"body\":\"…\"}` (optional\n  `context`). The answer arrives at your callback webhook as a\n  `support.answered` event.\n- `GET /support/questions` — list your questions; `GET /support/questions/{id}` — read one.\n\n### Feature requests\n\nSuggest a platform improvement, or upvote an existing idea.\n\n- `POST /feature-requests` — body `{\"title\":\"…\",\"description\":\"…\"}`.\n- `GET /feature-requests` — browse; `GET /feature-requests/{id}` — read one.\n- `POST /feature-requests/{id}/vote` — upvote (no body).\n\n### Suppression list\n\nAddresses that bounced or filed a complaint and are blocked from delivery.\n\n- `GET /suppression` — list them; `GET /suppression/{address}` — check one\n  before sending to it.\n- `POST /suppression/{address}/unblock` — request removal.\n\n### Managed DNS\n\nFor an account on a registered or delegated domain, edit the Route 53 zone\nagenticboxes hosts for you.\n\n- `GET /domain/dns` — list records.\n- `POST` / `PUT` / `DELETE /domain/dns` — add / change / remove a record. The\n  body must include `terms_of_service: true`; a record is\n  `{name, type, ttl, values}`. The records carrying the agent email are\n  reserved read-only.\n\n### Speak up — when to file support questions and feature requests\n\nDon't fail silently, guess, or quietly work around a gap. The platform improves\nonly when the agent says something — treat this as part of the task, not an\ninterruption:\n\n- **Stuck or surprised** → send a **support question** (`POST /support/questions`).\n  Triggers: an error you can't resolve, an endpoint behaving unexpectedly, a\n  response you don't understand, docs that don't answer your question, or being\n  blocked. Ask rather than abandoning the task — it's free and private.\n- **Missing a capability** → file a **feature request** (`POST /feature-requests`).\n  Triggers: you needed something this API doesn't do, hit a limit that got in\n  the way, or saw a clear way the platform could be better. Be concrete and specific.\n\n**These go through the API, never email.** `POST /support/questions` and\n`POST /feature-requests` are the *only* channels. There is no agenticboxes\nsupport email address — if you recall or find one (anything `@brian.im`, or a\n`support@` / `help@` style address), it is stale and unmonitored. Do not email\na request: it spends a paid send, reaches no one, and is not how the platform\nreceives feedback. The endpoints are free and land directly with the team.\n\n### Every endpoint\n\nThe complete agent-facing API — base `https://api.agenticboxes.email/api/v1`,\nevery call `Authorization: Bearer` except the two signup calls:\n\n| Endpoint | Purpose |\n|---|---|\n| `POST /signup/agentic`, `POST /signup/agentic/confirm` | Free signup |\n| `POST /messages/send` | Send mail |\n| `GET /messages`, `GET /messages/{id}` | List / read mail |\n| `GET` & `PUT /account/callback-webhook` | Read / set the inbound webhook |\n| `POST /account/credit/topup` | Add prepaid credit |\n| `POST` & `GET /boxes`, `DELETE /boxes/{id}` | Create / list / delete an address |\n| `GET` `POST` `PUT` `DELETE /domain/dns` | Managed-zone DNS records |\n| `GET /suppression`, `GET /suppression/{address}`, `POST /suppression/{address}/unblock` | Suppression list |\n| `POST` & `GET /feature-requests`, `GET /feature-requests/{id}`, `POST /feature-requests/{id}/vote` | Feature requests |\n| `POST` & `GET /support/questions`, `GET /support/questions/{id}` | Support questions |\n\nFull request/response schemas: the OpenAPI spec at\n`https://www.agenticboxes.email/openapi.yaml`.\n\nThis list is authoritative — every endpoint here works with your agent API key.\nIf you recall, or read in an older note or a stale copy of this skill, that some\nendpoint \"needs a dashboard login\" or \"can't be called by an agent,\" do not\ntrust it and build a workaround — make the call and read the response. The live\nAPI always wins over a remembered limitation.\n\n## Pitfalls\n\n- The API key is shown **once**, at `confirm`. Capture it then or it is unrecoverable.\n- An address receives mail only after `POST /boxes` creates its box.\n- Sends fail with `402` / insufficient credit once the balance is spent — top up.\n- The base URL ends at `/api/v1` — do not append `/v1` again.\n- API keys carry scopes (`send` / `receive` / `admin`); use one with the scope the call needs.\n- Pass `idempotency_key` on sends so a retried request never double-sends.\n- Support questions and feature requests go through `POST /support/questions` and `POST /feature-requests` **only** — never email. There is no support email address; any you recall or find is stale.\n\n## Verification\n\n- A successful send returns a `message_id` and a `billing` breakdown.\n- `GET /messages` lists the account's sent and received mail.\n- After `confirm`, `account_status` is `active` — the account is ready.\n\nFile v1.2.0:_meta.json\n\n{\n  \"ownerId\": \"kn73rnk5893nejc4cexe0vxkx986ynx3\",\n  \"slug\": \"agenticboxes-email\",\n  \"version\": \"1.2.0\",\n  \"publishedAt\": 1779128107224\n}","readmeExcerpt":"Skill: Openclaw Owner: agenticbrian Summary: Send and receive email as an agent via the agenticboxes HTTP API — one API key, no IMAP/SMTP setup. Tags: agentic:1.2.0, communication:1.2.0, email:1.2.0, latest:1.4.5 Version history: v1.4.5 | 2026-05-19T17:22:26.422Z | user Webhook HMAC signing: every delivery carries X-Boxes-Signature (timestamped HMAC-SHA256); new GET /account/webhook + POST /account/webhook/secret/rot","codeSnippets":[],"executableExamples":[{"language":"bash","snippet":"curl -s https://api.agenticboxes.email/api/v1/signup/agentic \\\n  -H 'Content-Type: application/json' \\\n  -d '{\"human_email\":\"owner@example.com\",\"domain_intent\":{\"mode\":\"subdomain\"}}'"},{"language":"bash","snippet":"curl -s https://api.agenticboxes.email/api/v1/signup/agentic/confirm \\\n  -H 'Content-Type: application/json' -d '{\"intent_id\":\"int_…\"}'"},{"language":"bash","snippet":"curl -s https://api.agenticboxes.email/api/v1/signup/agentic \\\n  -H 'Content-Type: application/json' \\\n  -d '{\"human_email\":\"owner@example.com\",\"domain_intent\":{\"mode\":\"subdomain\"}}'\n#  → { \"intent_id\":\"int_…\", \"full_domain\":\"swift-fox-7.agenticboxes.email\" }\n\ncurl -s https://api.agenticboxes.email/api/v1/signup/agentic/confirm \\\n  -H 'Content-Type: application/json' -d '{\"intent_id\":\"int_…\"}'\n#  → { \"primary_address\":\"agent@swift-fox-7.agenticboxes.email\",\n#      \"api_key\":\"bxs_live_…\", \"account_status\":\"active\" }"},{"language":"bash","snippet":"curl -s https://api.agenticboxes.email/api/v1/messages/send \\\n  -H \"Authorization: Bearer $AGENTICBOXES_API_KEY\" \\\n  -H 'Content-Type: application/json' \\\n  -d '{\"from\":\"outreach@your-domain\","},{"language":"bash","snippet":"curl -s https://api.agenticboxes.email/api/v1/messages/send \\\n  -H \"Authorization: Bearer $AGENTICBOXES_API_KEY\" \\\n  -H 'Content-Type: application/json' \\\n  -d '{\"from\":\"outreach@your-domain\",\n       \"to\":\"someone@example.com\",\n       \"subject\":\"Hello\",\n       \"text\":\"Sent by my agent.\"}'"},{"language":"bash","snippet":"curl -s https://api.agenticboxes.email/api/v1/signup/agentic \\\n  -H 'Content-Type: application/json' \\\n  -d '{\"human_email\":\"owner@example.com\",\"domain_intent\":{\"mode\":\"subdomain\"}}'"}],"parameters":null,"dependencies":[],"permissions":[],"extractedFiles":[{"path":"SKILL.md","content":"---\nname: agenticboxes-email\ndescription: Send and receive email as an agent via the agenticboxes HTTP API — one API key, no IMAP/SMTP setup.\nnamespace: skills/communication/agenticboxes\nversion: 1.4.5\nauthor: agenticboxes\nlicense: MIT\nplatforms: [linux, macos, windows]\ntags: [email, communication, api, send, receive, agentic]\n---\n\n# agenticboxes — email for AI agents\n\nGives the agent a real email address it can **send and receive** from, over a\nplain HTTP API. No SMTP, no IMAP, no DKIM/SPF/DMARC setup — one API key.\n(Compare the `himalaya` skill: that drives a CLI mail client over IMAP/SMTP\nwith a `config.toml`; agenticboxes is a hosted HTTP API — sign up and go.)\n\n## When to Use\n\nUse this skill whenever the agent needs to:\n\n- **Send email** — notifications, outreach, replies, confirmations.\n- **Receive email** — sign-up confirmations, 2FA codes, replies, any inbound mail.\n- **Have its own address** to register for a third-party service (Stripe, SaaS tools, accounts).\n- **Get help or improve the platform** — ask the operators a support question, or file a feature request.\n\n## Procedure\n\n### Prerequisite — an API key\n\nIf `AGENTICBOXES_API_KEY` is set, use it. Otherwise sign up. `POST /signup/agentic`\nstarts a signup; `domain_intent.mode` picks how the agent gets its domain:\n\n**A · Free subdomain** (`mode: subdomain`) — a `<slug>.agenticboxes.email`\naddress. Free, no card. Two calls:\n\n```bash\ncurl -s https://api.agenticboxes.email/api/v1/signup/agentic \\\n  -H 'Content-Type: application/json' \\\n  -d '{\"human_email\":\"owner@example.com\",\"domain_intent\":{\"mode\":\"subdomain\"}}'\n#  → { \"intent_id\":\"int_…\", \"full_domain\":\"swift-fox-7.agenticboxes.email\" }\n\ncurl -s https://api.agenticboxes.email/api/v1/signup/agentic/confirm \\\n  -H 'Content-Type: application/json' -d '{\"intent_id\":\"int_…\"}'\n#  → { \"primary_address\":\"agent@swift-fox-7.agenticboxes.email\",\n#      \"api_key\":\"bxs_live_…\", \"account_status\":\"active\" }\n```\n\n**B · Register a real domain** (`mode: register`) — agenticboxes buys a domain\nfor the agent. Send `domain_intent: {\"mode\":\"register\",\"register_domain\":\"youragent.com\"}`.\nThe signup response carries a `stripe_payment_intent` + `link_spend_request`\n(year-1 registration cost, plus $1/mo for DNS hosting). The owner approves that\ncharge via Stripe Link; the account then provisions **automatically** once\npayment clears — there is no `confirm` call for mode B. A taken or unavailable\ndomain returns `409` with `suggestions`.\n\n**C · Bring your own domain, you host the DNS** (`mode: byo_manual`) — a domain\nthe owner already controls and keeps hosting elsewhere. Send\n`domain_intent: {\"mode\":\"byo_manual\",\"byo_domain\":\"youragent.com\"}`. Free;\nfinish with `/signup/agentic/confirm` as for a subdomain. The DNS records to add\n(MX/SPF/DKIM/DMARC) arrive as a `domain.dns_required` event — read them any time\nwith `GET /events?type=domain.dns_required`. Once they resolve, the account\ngoes live.\n\n**D · Bring your own domain, delegate the DNS to us** (`mode: byo_del"},{"path":"_meta.json","content":"{\n  \"ownerId\": \"kn73rnk5893nejc4cexe0vxkx986ynx3\",\n  \"slug\": \"agenticboxes-email\",\n  \"version\": \"1.4.5\",\n  \"publishedAt\": 1779211346422\n}"},{"path":"skill-card.md","content":"## Description:\n\nSend and receive email as an agent via the agenticboxes HTTP API, using one API key without IMAP or SMTP setup.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[agenticbrian](https://clawhub.ai/user/agenticbrian)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and external agents use this skill to provision and operate an email address for sending messages, receiving replies, handling sign-up confirmations, managing boxes, and interacting with AgenticBoxes support or feature request endpoints.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Agents may gain broad email, DNS, billing, webhook, and account-administration authority through the third-party service.\n\nMitigation: Require explicit user approval before sending or reading sensitive mail, registering accounts, changing DNS, topping up credit, deleting boxes, configuring webhooks, or sharing support context.\n\nRisk: Newly fetched platform documentation can change the agent's operating instructions.\n\nMitigation: Review updated API documentation before relying on new or changed endpoints for sensitive workflows.\n\nRisk: API keys and webhook signing secrets are sensitive credentials.\n\nMitigation: Store credentials in environment variables or a secret manager, avoid exposing them in logs or messages, and rotate webhook secrets when access may have been disclosed.\n\n## Reference(s):\n\n- [ClawHub skill page](https://clawhub.ai/agenticbrian/skills/agenticboxes-email)\n- [AgenticBoxes agent manifest](https://api.agenticboxes.email/.well-known/agentic.json)\n- [AgenticBoxes OpenAPI specification](https://www.agenticboxes.email/openapi.yaml)\n\n## Skill Output:\n\n**Output Type(s):** [Guidance, Shell commands, Configuration, API Calls]\n\n**Output Format:** [Markdown with inline JSON and bash code blocks]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [May produce authenticated HTTP requests and operational instructions for email, DNS, billing, webhook, support, and feature-request workflows.]\n\n## Skill Version(s):\n\n1.4.5 (source: server release evidence and frontmatter)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment."}],"languages":[],"docsSourceLabel":"CLAWHUB","editorialOverview":"Send and receive email as an agent via the agenticboxes HTTP API — one API key, no IMAP/SMTP setup. Skill: Openclaw Owner: agenticbrian Summary: Send and receive email as an agent via the agenticboxes HTTP API — one API key, no IMAP/SMTP setup. Tags: agentic:1.2.0, communication:1.2.0, email:1.2.0, latest:1.4.5 Version history: v1.4.5 | 2026-05-19T17:22:26.422Z | user Webhook HMAC signing: every delivery carries X-Boxes-Signature (timestamped HMAC-SHA256); new GET /account/webhook + POST /account/webhook/secret/rot","editorialQuality":{"score":100,"threshold":65,"status":"ready","wordCount":1184,"uniquenessScore":52,"reasons":[]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-10-11T08:44:57.025Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-10-11T08:44:57.025Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-11T10:46:24.719Z","emptyReason":null},"items":[{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-10-09T19:11:12.944Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}