{"id":"2c803128-33d9-414d-86c9-83dee0c5786b","entityType":"agent","slug":"clawhub-sendmux-ai-sendmux-cli","name":"sendmux-cli","canonicalUrl":"https://www.xpersona.co/agent/clawhub-sendmux-ai-sendmux-cli","canonicalPath":"/agent/clawhub-sendmux-ai-sendmux-cli","generatedAt":"2026-10-10T08:44:04.251Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-10T04:19:04.198Z","emptyReason":null},"description":"Use the Sendmux CLI for durable agent inbox registration, owner invites, profiles, and terminal-driven Management, Mailbox, and Sending workflows.","descriptionLabel":"Source description","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. 1.7K downloads reported by the source. Last updated 10/10/2026.","installCommand":"clawhub skill install s175c163jct9mhsx0mrfbz64j989s00r:sendmux-cli","sourceUrl":"https://clawhub.ai/sendmux.ai/sendmux-cli","homepage":"https://clawhub.ai/sendmux.ai/skills/sendmux-cli","primaryLinks":[{"label":"View on ClawHub","url":"https://clawhub.ai/sendmux.ai/sendmux-cli","kind":"source"},{"label":"Homepage","url":"https://clawhub.ai/sendmux.ai/skills/sendmux-cli","kind":"homepage"}],"safetyScore":84,"overallRank":62,"popularityScore":65,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"sendmux-cli technical dossier on Xpersona with agent coverage, OPENCLEW support, and live trust metadata."},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-10-10T04:19:04.198Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[],"verifiedCount":0,"selfDeclaredCount":1,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile"}},"adoption":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-10T04:19:04.198Z","emptyReason":null},"stars":null,"forks":null,"downloads":1693,"packageName":null,"latestVersion":"1.0.12","tractionLabel":"1.7K downloads"},"release":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-10T04:19:04.153Z","emptyReason":null},"lastUpdatedAt":"2026-10-10T04:19:04.198Z","lastCrawledAt":"2026-10-10T04:19:04.153Z","lastIndexedAt":null,"nextCrawlAt":"2026-10-11T04:19:04.153Z","lastVerifiedAt":null,"highlights":[{"version":"1.0.12","createdAt":"2026-10-07T07:19:18.856Z","changelog":"sendmux-cli 1.0.12 - Documentation updated: SKILL.md modified. - Obsolete or redundant file removed: skill-card.md. - No functional changes to the skill logic or interface.","fileCount":3,"zipByteSize":6745},{"version":"1.0.11","createdAt":"2026-10-02T04:22:31.924Z","changelog":"- Version bumped from 1.7.0 to 1.7.1 in SKILL.md. - Minor documentation or metadata update in SKILL.md. - Removed file: skill-card.md.","fileCount":3,"zipByteSize":6659},{"version":"1.0.10","createdAt":"2026-09-30T12:02:12.099Z","changelog":"sendmux-cli 1.7.0 - Updated SKILL.md with latest documentation and metadata. - Removed deprecated skill-card.md file.","fileCount":3,"zipByteSize":6624},{"version":"1.0.9","createdAt":"2026-09-18T05:51:39.774Z","changelog":"sendmux-cli 1.0.9 - Updated `SKILL.md` with detailed instructions and clarifications on OAuth flow, agent onboarding storage lifecycle, and safer key management practices. - Profile setup examples now recommend using environment variables over command-line flags for secrets, improving security guidance. - Expanded documentation on OAuth login/logout behavior and recovery, including profile naming and locked/reserved profiles. - Clarified inbox storage transition: 500 MiB cap increases to at least 5 GiB after owner-approved sending. - Removed `skill-card.md`.","fileCount":3,"zipByteSize":6578},{"version":"1.0.8","createdAt":"2026-09-11T03:59:17.296Z","changelog":"**OAuth authentication and profile support added.** - Added OAuth login and connection checks, including support for named OAuth profiles and browser-based consent flows. - New environment variable: `SENDMUX_ACCESS_TOKEN` for externally managed OAuth tokens; documented precedence over API keys. - Clarified boundaries: OAuth profiles now supported for REST APIs (HTTP only), not SMTP/IMAP. - Expanded documentation for authentication resolution and error cases with mixed credential types. - Removed legacy `skill-card.md` file.","fileCount":3,"zipByteSize":6228},{"version":"1.0.7","createdAt":"2026-09-01T10:36:39.024Z","changelog":"sendmux-cli 1.0.7 - Updated SKILL.md to clarify that revoking owner-approved sending does not change the current inbox storage allocation. - Version bumped from 1.4.1 to 1.4.2 in documentation. - No functional or code changes; documentation only.","fileCount":3,"zipByteSize":5466},{"version":"1.0.6","createdAt":"2026-09-01T10:27:40.458Z","changelog":"- Version bump from 1.4.0 to 1.4.1 in SKILL.md. - Updated inbox storage documentation: owner-approved sending now increases inbox quota to at least 5 GiB. - Removed outdated skill-card.md file.","fileCount":3,"zipByteSize":5468},{"version":"1.0.5","createdAt":"2026-09-01T06:04:52.326Z","changelog":"sendmux-cli 1.4.0 adds durable agent inbox registration, owner invite commands, and improves agent profile behavior. - Added agent onboarding: register durable inboxes and invite inbox owners directly from the CLI. - Agent profiles can now receive mail without an existing Sendmux account; sending is enabled after owner approval. - Sending with agent profiles automatically exchanges and caches delegated tokens after approval. - Updated boundary guidance and profile documentation. - Removed obsolete skill-card.md.","fileCount":3,"zipByteSize":5442}]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install s175c163jct9mhsx0mrfbz64j989s00r:sendmux-cli","setupComplexity":"low","setupSteps":["Install using `clawhub skill install s175c163jct9mhsx0mrfbz64j989s00r:sendmux-cli` in an isolated environment before connecting it to live workloads.","No published capability contract is available yet, so validate auth and request/response behavior manually.","Review the upstream CLAWHUB listing at https://clawhub.ai/sendmux.ai/sendmux-cli before using production credentials."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-sendmux-ai-sendmux-cli/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-sendmux-ai-sendmux-cli/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-sendmux-ai-sendmux-cli/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-sendmux-ai-sendmux-cli/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-sendmux-ai-sendmux-cli/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-sendmux-ai-sendmux-cli/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-10T08:44:04.249Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-sendmux-ai-sendmux-cli/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-sendmux-ai-sendmux-cli/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-sendmux-ai-sendmux-cli/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-sendmux-ai-sendmux-cli/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-10T04:19:04.198Z","emptyReason":null},"readme":"Skill: sendmux-cli\n\nOwner: sendmux.ai\n\nSummary: Use the Sendmux CLI for durable agent inbox registration, owner invites, profiles, and terminal-driven Management, Mailbox, and Sending workflows.\n\nTags: latest:1.0.12\n\nVersion history:\n\nv1.0.12 | 2026-10-07T07:19:18.856Z | auto\n\nsendmux-cli 1.0.12\n\n- Documentation updated: SKILL.md modified.\n- Obsolete or redundant file removed: skill-card.md.\n- No functional changes to the skill logic or interface.\n\nv1.0.11 | 2026-10-02T04:22:31.924Z | auto\n\n- Version bumped from 1.7.0 to 1.7.1 in SKILL.md.\n- Minor documentation or metadata update in SKILL.md.\n- Removed file: skill-card.md.\n\nv1.0.10 | 2026-09-30T12:02:12.099Z | auto\n\nsendmux-cli 1.7.0\n\n- Updated SKILL.md with latest documentation and metadata.\n- Removed deprecated skill-card.md file.\n\nv1.0.9 | 2026-09-18T05:51:39.774Z | auto\n\nsendmux-cli 1.0.9\n\n- Updated `SKILL.md` with detailed instructions and clarifications on OAuth flow, agent onboarding storage lifecycle, and safer key management practices.\n- Profile setup examples now recommend using environment variables over command-line flags for secrets, improving security guidance.\n- Expanded documentation on OAuth login/logout behavior and recovery, including profile naming and locked/reserved profiles.\n- Clarified inbox storage transition: 500 MiB cap increases to at least 5 GiB after owner-approved sending.\n- Removed `skill-card.md`.\n\nv1.0.8 | 2026-09-11T03:59:17.296Z | auto\n\n**OAuth authentication and profile support added.**\n\n- Added OAuth login and connection checks, including support for named OAuth profiles and browser-based consent flows.\n- New environment variable: `SENDMUX_ACCESS_TOKEN` for externally managed OAuth tokens; documented precedence over API keys.\n- Clarified boundaries: OAuth profiles now supported for REST APIs (HTTP only), not SMTP/IMAP.\n- Expanded documentation for authentication resolution and error cases with mixed credential types.\n- Removed legacy `skill-card.md` file.\n\nv1.0.7 | 2026-09-01T10:36:39.024Z | auto\n\nsendmux-cli 1.0.7\n\n- Updated SKILL.md to clarify that revoking owner-approved sending does not change the current inbox storage allocation.\n- Version bumped from 1.4.1 to 1.4.2 in documentation. \n- No functional or code changes; documentation only.\n\nv1.0.6 | 2026-09-01T10:27:40.458Z | auto\n\n- Version bump from 1.4.0 to 1.4.1 in SKILL.md.\n- Updated inbox storage documentation: owner-approved sending now increases inbox quota to at least 5 GiB.\n- Removed outdated skill-card.md file.\n\nv1.0.5 | 2026-09-01T06:04:52.326Z | auto\n\nsendmux-cli 1.4.0 adds durable agent inbox registration, owner invite commands, and improves agent profile behavior.\n\n- Added agent onboarding: register durable inboxes and invite inbox owners directly from the CLI.\n- Agent profiles can now receive mail without an existing Sendmux account; sending is enabled after owner approval.\n- Sending with agent profiles automatically exchanges and caches delegated tokens after approval.\n- Updated boundary guidance and profile documentation.\n- Removed obsolete skill-card.md.\n\nv1.0.4 | 2026-07-09T03:58:13.641Z | auto\n\nVersion 1.3.0\n\n- Updated skill version from 1.2.0 to 1.3.0 in SKILL.md.\n\nv1.0.3 | 2026-07-09T01:45:57.612Z | auto\n\nVersion 1.2.0\n\n- Updated documentation in SKILL.md.\n- Bumped skill version from 1.1.0 to 1.2.0 in metadata.\n- No changes to functionality or CLI commands; documentation only.\n\nv1.0.2 | 2026-07-08T04:07:48.045Z | auto\n\nsendmux-cli 1.0.2\n\n- Updated documentation to reflect expanded support for sending commands.\n- Sending surface now lists 7 commands (was 3), including new attachment upload and management commands.\n- Operation flag descriptions for `--file` and `--via-presigned` clarify mailbox vs sending behavior.\n- Additional documentation on new `sending:*` commands: `upload-attachment`, `create-attachment-upload`, `complete-attachment-upload`, and `get-attachment`.\n- No functional or code changes; SKILL.md documentation only.\n\nv1.0.1 | 2026-07-06T01:36:34.965Z | auto\n\nVersion 1.1.0\n\n- Updated SKILL.md to reflect the new version number.\n- No functional or interface changes; documentation only.\n\nv1.0.0 | 2026-07-03T08:05:36.227Z | auto\n\nInitial release of sendmux-cli.\n\n- Provides terminal-driven workflows for Management, Mailbox, and Sending using the Sendmux CLI.\n- Supports JSON output for agent-readability and automation.\n- Allows credential scoping and management through profiles and environment variables.\n- Performs command preflight checks to validate key types before network calls.\n- Bundles over 90 generated operation commands with shared flags and detailed help.\n- Includes usage examples and guidance on secure credential handling.\n\nArchive index:\n\nArchive v1.0.12: 3 files, 6745 bytes\n\nFiles: skill-card.md (2061b), SKILL.md (15560b), _meta.json (131b)\n\nFile v1.0.12:SKILL.md\n\n---\nname: \"sendmux-cli\"\ndescription: \"Use the Sendmux CLI for durable agent inbox registration, owner invites, profiles, and terminal-driven Management, Mailbox, and Sending workflows.\"\nversion: \"1.7.1\"\nmetadata:\n  openclaw:\n    skillKey: \"sendmux-cli\"\n    homepage: \"https://github.com/Sendmux/skills\"\n    primaryEnv: \"SENDMUX_API_KEY\"\n    envVars:\n      - name: \"SENDMUX_ACCESS_TOKEN\"\n        required: false\n        description: \"Optional externally managed OAuth access token for CLI HTTP requests; the CLI does not refresh it.\"\n      - name: \"SENDMUX_API_KEY\"\n        required: false\n        description: \"Optional Sendmux API key or scoped agent token used by CLI, SDK, HTTP, or MCP examples.\"\n      - name: \"SENDMUX_BASE_URL\"\n        required: false\n        description: \"Optional Sendmux API base URL override for CLI examples.\"\n      - name: \"SENDMUX_MBX_KEY\"\n        required: false\n        description: \"Optional Sendmux mailbox key for Mailbox and send-capable mailbox workflows.\"\n      - name: \"SENDMUX_PROFILE\"\n        required: false\n        description: \"Optional Sendmux CLI profile name.\"\n      - name: \"SENDMUX_ROOT_KEY\"\n        required: false\n        description: \"Optional Sendmux root key for account-level Management API setup.\"\n    install:\n      - kind: \"node\"\n        package: \"@sendmux/cli\"\n        bins:\n          - \"sendmux\"\n---\n\n# Sendmux CLI\n\n## ClawHub account note\n\nThis ClawHub skill connects OpenClaw agents to Sendmux. Some workflows require a Sendmux account and an appropriate Sendmux API key or agent token. Sendmux account usage is external to ClawHub; do not ask users to paste secrets into chat.\n\nUse this skill when the terminal is the right Sendmux surface.\n\n## Boundaries\n\n- Do not ask the user to paste API keys.\n- For API-key profiles, use `smx_root_` for `management:*` and `smx_mbx_` or scoped `smx_agent_` for `mailbox:*`.\n- OAuth profiles require the operation's approved surface, scopes and mailbox access. REST OAuth tokens authenticate HTTP, not SMTP or IMAP.\n- Durable agent profiles can read and receive mail while active, but cannot send until an invited owner accepts and approves sending.\n- After owner approval, `sending:*` commands with an agent profile automatically exchange and cache a one-hour delegated token.\n- Do not run destructive commands without explicit confirmation.\n- Use `--json` for agent-readable output.\n- Prefer task-specific Sendmux skills when the user needs strategy; use this skill for exact CLI mechanics.\n\n## Install\n\n```bash\nnpm install -g @sendmux/cli\nsendmux --help\n```\n\nThe package exposes the `sendmux` binary.\n\n## OAuth login and connection checks\n\nFor an existing user's account, create a new named OAuth profile with the required scopes:\n\n```bash\nsendmux auth:login work --scope mailbox.read --scope email.send\nsendmux mailbox:get-connection --profile work --json\n```\n\nThe CLI opens browser consent and receives the callback on the same computer. `--no-browser` only suppresses automatic browser launch and prints the authorisation URL; the OAuth callback still requires the browser flow on the CLI host, so the flag alone is not a remote-machine authentication transport. The CLI preserves existing profiles.\n\nWhen explaining the OAuth lifecycle, include all three storage and recovery facts: the CLI stores tokens locally with restricted file permissions; expiring tokens refresh automatically with concurrent refreshes serialised; and an uncertain refresh outcome requires authentication under a new profile name because `auth:login` preserves an occupied profile. To reuse the same name, first complete `sendmux auth:logout work`, then log in again.\n\nUse `sending:get-connection`, `mailbox:get-connection`, or `management:get-connection` for the selected surface. These checks require no mailbox selector and send no email. Use `data.label` for the connection name and `data.team.id` for its stable team identifier.\n\nRun `sendmux auth:logout work` to revoke the connection and remove its profile. A failed revocation keeps the profile for retry; logout also clears an interrupted login reservation.\n\nFor externally managed tokens, inject `SENDMUX_ACCESS_TOKEN` through the environment. The CLI does not refresh that token. Supplying it alongside an API key is an error. See [OAuth for REST APIs](https://sendmux.ai/docs/developer-tools/oauth) for grant scopes and refresh rules.\n\n## Agent inbox onboarding\n\nNo existing Sendmux account or API key is required:\n\n```bash\nsendmux agent:register my-agent \\\n  --mailbox-local-part my-agent \\\n  --client-name \"My agent\" \\\n  --default \\\n  --json\n```\n\nAdd `--owner-email owner@example.com` to invite the owner during registration. Otherwise invite later:\n\n```bash\nsendmux agent:invite-owner owner@example.com --profile my-agent --json\n```\n\nThe CLI persists registration idempotency before the network request, stores the durable credential in the local profile with restricted permissions, never prints it, reloads it from disk, and waits up to 10 minutes for readiness. Rerun registration with the same profile and options to resume safely. Include this storage transition when explaining the onboarding lifecycle: the inbox is capped at 500 MiB before owner approval, and enabling owner-approved sending raises it to at least 5 GiB.\n\nUse the profile for later reads:\n\n```bash\nsendmux mailbox:messages:list --profile my-agent --query limit=25 --json\n```\n\nRead/receive access has no expiry date while the registration remains active. Sending remains blocked until the owner accepts and approves it. After approval, a command such as `sending:send --profile my-agent` automatically exchanges the durable credential for a one-hour `email.send` token and caches it until near expiry. Full registration revocation removes read access and every delegated token.\n\nRevoking sending does not itself change the current inbox storage allocation.\n\n## Profiles\n\nCreate separate profiles for root and mailbox keys.\n\n```bash\nSENDMUX_API_KEY=\"$SENDMUX_ROOT_KEY\" sendmux profiles:set default --default --json\nSENDMUX_API_KEY=\"$SENDMUX_MBX_KEY\" sendmux profiles:set mailbox --json\nSENDMUX_API_KEY=\"$SENDMUX_MBX_KEY\" sendmux profiles:set sending --json\nsendmux profiles:list --json\nsendmux profiles:show default --json\n```\n\n`profiles:set` reads the key from `SENDMUX_API_KEY`; populate the source variables through the user's secret store. The direct `--api-key` flag remains supported and takes precedence over `SENDMUX_API_KEY`, but do not expand a secret into that flag because the resulting value is visible in process arguments.\n\nProfile reads mask stored API keys and never reveal agent credentials. `profiles:set` reports `key_kind` as `root` or `mailbox`; `agent:register` creates a discriminated agent profile.\n\nAuthentication resolution: `SENDMUX_ACCESS_TOKEN` takes precedence and rejects a simultaneous API key. Otherwise:\n\n1. `--api-key`, then `SENDMUX_API_KEY`.\n2. If no direct key is present, `--profile` / `-p`, then `SENDMUX_PROFILE`, then the configured default profile.\n3. Base URL comes from `--base-url`, then `SENDMUX_BASE_URL`, then the selected profile.\n\n## Preflight\n\nFor API-key authentication, the CLI infers key kind from the prefix before sending a request. OAuth profiles use their approved grants instead of API-key prefix checks.\n\n| Command surface | Required key                                                                      |\n| --------------- | --------------------------------------------------------------------------------- |\n| `management:*`  | `smx_root_`                                                                       |\n| `mailbox:*`     | `smx_mbx_` or scoped `smx_agent_`                                                 |\n| `sending:*`     | Send-capable `smx_mbx_` key or owner-approved Sending-resource `smx_agent_` token |\n\nFor an agent profile, `mailbox:*` uses the durable read credential. `sending:*` obtains a delegated token only after owner approval. `management:*` rejects agent profiles before the request.\n\nWrong-key examples fail before network:\n\n```text\nCommand requires a root API key, but --api-key contains a mailbox API key.\nCommand requires a send-capable `smx_mbx_` key or owner-approved Sending-resource `smx_agent_` token, but --api-key contains a root API key.\n```\n\n## Command catalogue\n\nThe unpublished candidate CLI source exposes these generated operation commands. Verify its published version before relying on the new commands:\n\n| Surface    | Count | Examples                                                                                                                                                   |\n| ---------- | ----: | ---------------------------------------------------------------------------------------------------------------------------------------------------------- |\n| Management |    57 | `management:domains:list`, `management:create-domain`, `management:create-mailbox`, `management:get-spend-summary`, `management:create-webhook`            |\n| Mailbox    |    52 | `mailbox:search-message-snippets`, `mailbox:batch-get-messages`, `mailbox:query-message-changes`, `mailbox:send-message`, `mailbox:list-granted-mailboxes` |\n| Sending    |     8 | `sending:get-open-api-spec`, `sending:send`, `sending:send:batch`, `sending:upload-attachment`, `sending:create-attachment-upload`, `sending:complete-attachment-upload`, `sending:get-attachment` |\n| OAuth      |     2 | `auth:login`, `auth:logout` |\n| Profiles   |     3 | `profiles:list`, `profiles:set`, `profiles:show`                                                                                                           |\n| Agent      |     2 | `agent:register`, `agent:invite-owner`                                                                                                                      |\n\nUse command-level help to discover accepted path, query, header, and body fields:\n\n```bash\nsendmux management:create-domain --help\nsendmux mailbox:search-message-snippets --help\nsendmux sending:send:batch --help\nsendmux sending:upload-attachment --help\n```\n\n## Operation flags\n\nOperation commands share these flags:\n\n| Flag                  | Use                                                                        |\n| --------------------- | -------------------------------------------------------------------------- |\n| `--api-key`           | Direct key; overrides profile/env profile lookup.                          |\n| `--base-url`          | Override API base URL.                                                     |\n| `--profile`, `-p`     | Select a local profile.                                                    |\n| `--body`              | Inline JSON request body, or text bytes for byte-oriented operations.      |\n| `--body-file`         | Read a JSON request body or byte payload from a file.                      |\n| `--attach`            | Attach a local file to supported send commands. Repeat for multiple files. |\n| `--file`              | Read a local file for mailbox attachment upload convenience commands.       |\n| `--via-presigned`     | Upload a mailbox `--file` through a short-lived signed URL instead of API bytes. |\n| `--content-type`      | Override inferred MIME type for `--attach` or `--file`.                    |\n| `--path name=value`   | Path parameters. Repeat for multiple path params.                          |\n| `--query name=value`  | Query parameters. Repeat for filters and pagination.                       |\n| `--header name=value` | Headers accepted by the operation. Repeat for multiple headers.            |\n| `--idempotency-key`   | Shortcut for `Idempotency-Key`. Works only when the operation supports it. |\n| `--if-match`          | Shortcut for `If-Match`. Works only when the operation supports it.        |\n| `--if-none-match`     | Shortcut for `If-None-Match`. Works only when the operation supports it.   |\n| `--json`              | Machine-readable output.                                                   |\n\n`--path`, `--query`, and `--header` require `name=value`. Booleans use `true` or `false`. Repeat an array-valued parameter rather than comma-joining it.\n\nPass either `--body` or `--body-file`, not both.\n\nUse `sendmux-attachments` for attachment-heavy flows and size/token trade-offs.\n\n## Examples\n\nFor workflows spanning Sending, Mailbox, and Management, state the classification explicitly: they are three command surfaces and may use three profiles, but the CLI has only `root` and `mailbox` API-key kinds. A send-capable mailbox key may populate both the mailbox and sending profiles; do not call those profiles different key kinds.\n\nCreate a domain:\n\n```bash\nsendmux management:create-domain \\\n  --profile default \\\n  --idempotency-key \"$IDEMPOTENCY_KEY\" \\\n  --body '{\"domain\":\"example.com\",\"mode\":\"send_receive\"}' \\\n  --json\n```\n\nGet domain DNS records:\n\n```bash\nsendmux management:get-domain-zone-file \\\n  --profile default \\\n  --path public_id=mdom_abc \\\n  --json\n```\n\nSearch a mailbox without reading full messages:\n\n```bash\nsendmux mailbox:search-message-snippets \\\n  --profile mailbox \\\n  --query q=invoice \\\n  --query is_unread=true \\\n  --query limit=10 \\\n  --json\n```\n\nBatch-read selected mailbox messages:\n\n```bash\nsendmux mailbox:batch-get-messages \\\n  --profile mailbox \\\n  --body '{\n    \"ids\": [\"eml_abc\", \"eml_def\"],\n    \"body_mode\": \"clean_json\",\n    \"max_body_chars\": 4000\n  }' \\\n  --json\n```\n\nSend a batch:\n\n```bash\nsendmux sending:send:batch \\\n  --profile sending \\\n  --idempotency-key \"$IDEMPOTENCY_KEY\" \\\n  --body-file ./messages.json \\\n  --json\n```\n\nSend through the Sending API with a local attachment:\n\n```bash\nsendmux sending:send \\\n  --profile sending \\\n  --idempotency-key \"$IDEMPOTENCY_KEY\" \\\n  --attach ./report.pdf \\\n  --body '{\"from\":{\"email\":\"sender@example.com\"},\"to\":{\"email\":\"user@example.com\"},\"subject\":\"Report\",\"html_body\":\"<p>Attached.</p>\"}' \\\n  --json\n```\n\n`sending:send --attach` uploads the file first and injects an `attachment_id` reference; it does not place base64 in the send body.\n\nUpload a Sending attachment separately:\n\n```bash\nSIZE_BYTES=\"$(wc -c < ./report.pdf | tr -d '[:space:]')\"\n\nsendmux sending:upload-attachment \\\n  --profile sending \\\n  --body-file ./report.pdf \\\n  --header Content-Length=\"$SIZE_BYTES\" \\\n  --query filename=report.pdf \\\n  --query content_type=application/pdf \\\n  --json\n```\n\nSend a mailbox message with a local attachment:\n\n```bash\nsendmux mailbox:send-message \\\n  --profile mailbox \\\n  --idempotency-key \"$IDEMPOTENCY_KEY\" \\\n  --attach ./report.pdf \\\n  --body '{\"to\":[{\"email\":\"user@example.com\",\"name\":null}],\"subject\":\"Report\",\"text_body\":\"Attached.\"}' \\\n  --json\n```\n\nMailbox attachment upload commands share the 7,500,000 byte per-attachment cap. For larger files, split the file or host it externally and send a link.\n\nUpload a mailbox attachment by presigned URL:\n\n```bash\nsendmux mailbox:upload-attachment \\\n  --profile mailbox \\\n  --file ./report.pdf \\\n  --via-presigned \\\n  --json\n```\n\nPoll one unchanged-safe delivery log:\n\n```bash\nsendmux management:get-email-log \\\n  --profile default \\\n  --path public_id=dlog_abc \\\n  --if-none-match \"$ETAG\" \\\n  --json\n```\n\n## Routing\n\n- First setup/auth check: `sendmux-getting-started`.\n- Sending strategy and body shape: `sendmux-send-email`.\n- Attachment file paths and presigned upload/download: `sendmux-attachments`.\n- Mailbox read, search, sync, triage, or reply: `sendmux-mailbox-agent`.\n- Account-level management strategy: `sendmux-management`.\n- MCP connection setup: `sendmux-mcp-setup`.\n- Cheapest-call doctrine: `sendmux-token-efficient-usage`.\n\nFile v1.0.12:_meta.json\n\n{\n  \"ownerId\": \"kn77z51yqhw8mt9vjfkpt8w74989rfb3\",\n  \"slug\": \"sendmux-cli\",\n  \"version\": \"1.0.12\",\n  \"publishedAt\": 1791357558856\n}\n\nFile v1.0.12:skill-card.md\n\n## Description:\n\nUse the Sendmux CLI for durable agent inbox registration, owner invites, profiles, and terminal-driven Management, Mailbox, and Sending workflows.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[sendmux.ai](https://clawhub.ai/user/sendmux.ai)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and agent operators use this skill to set up Sendmux inboxes and profiles, check access, and carry out email, mailbox, and account-management tasks from a terminal.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Credentials for mailbox, sending, or account management could be exposed or granted excessive access.\n\nMitigation: Keep keys in a secret store or environment and use scoped profiles or OAuth where possible; do not paste secrets into chat or command arguments.\n\nRisk: Sending mail or changing account settings can have unintended effects.\n\nMitigation: Review send and account-management commands before execution and confirm destructive actions explicitly.\n\nRisk: Saved profiles can retain access after the task ends.\n\nMitigation: Log out or revoke profiles when access is no longer needed.\n\n## Reference(s):\n\n- [Sendmux CLI skill on ClawHub](https://clawhub.ai/sendmux.ai/skills/sendmux-cli)\n- [Sendmux skills homepage](https://github.com/Sendmux/skills)\n- [Sendmux OAuth for REST APIs](https://sendmux.ai/docs/developer-tools/oauth)\n\n## Skill Output:\n\n**Output Type(s):** [Guidance, Shell commands, Configuration instructions]\n\n**Output Format:** [Markdown with bash and JSON examples]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [CLI responses can be requested as machine-readable JSON.]\n\n## Skill Version(s):\n\n1.0.12 (source: ClawHub release; artifact frontmatter: 1.7.1)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v1.0.11: 3 files, 6659 bytes\n\nFiles: skill-card.md (2013b), SKILL.md (15460b), _meta.json (131b)\n\nFile v1.0.11:SKILL.md\n\n---\nname: \"sendmux-cli\"\ndescription: \"Use the Sendmux CLI for durable agent inbox registration, owner invites, profiles, and terminal-driven Management, Mailbox, and Sending workflows.\"\nversion: \"1.7.1\"\nmetadata:\n  openclaw:\n    skillKey: \"sendmux-cli\"\n    homepage: \"https://github.com/Sendmux/skills\"\n    primaryEnv: \"SENDMUX_API_KEY\"\n    envVars:\n      - name: \"SENDMUX_ACCESS_TOKEN\"\n        required: false\n        description: \"Optional externally managed OAuth access token for CLI HTTP requests; the CLI does not refresh it.\"\n      - name: \"SENDMUX_API_KEY\"\n        required: false\n        description: \"Optional Sendmux API key or scoped agent token used by CLI, SDK, HTTP, or MCP examples.\"\n      - name: \"SENDMUX_BASE_URL\"\n        required: false\n        description: \"Optional Sendmux API base URL override for CLI examples.\"\n      - name: \"SENDMUX_MBX_KEY\"\n        required: false\n        description: \"Optional Sendmux mailbox key for Mailbox and send-capable mailbox workflows.\"\n      - name: \"SENDMUX_PROFILE\"\n        required: false\n        description: \"Optional Sendmux CLI profile name.\"\n      - name: \"SENDMUX_ROOT_KEY\"\n        required: false\n        description: \"Optional Sendmux root key for account-level Management API setup.\"\n    install:\n      - kind: \"node\"\n        package: \"@sendmux/cli\"\n        bins:\n          - \"sendmux\"\n---\n\n# Sendmux CLI\n\n## ClawHub account note\n\nThis ClawHub skill connects OpenClaw agents to Sendmux. Some workflows require a Sendmux account and an appropriate Sendmux API key or agent token. Sendmux account usage is external to ClawHub; do not ask users to paste secrets into chat.\n\nUse this skill when the terminal is the right Sendmux surface.\n\n## Boundaries\n\n- Do not ask the user to paste API keys.\n- For API-key profiles, use `smx_root_` for `management:*` and `smx_mbx_` or scoped `smx_agent_` for `mailbox:*`.\n- OAuth profiles require the operation's approved surface, scopes and mailbox access. REST OAuth tokens authenticate HTTP, not SMTP or IMAP.\n- Durable agent profiles can read and receive mail while active, but cannot send until an invited owner accepts and approves sending.\n- After owner approval, `sending:*` commands with an agent profile automatically exchange and cache a one-hour delegated token.\n- Do not run destructive commands without explicit confirmation.\n- Use `--json` for agent-readable output.\n- Prefer task-specific Sendmux skills when the user needs strategy; use this skill for exact CLI mechanics.\n\n## Install\n\n```bash\nnpm install -g @sendmux/cli\nsendmux --help\n```\n\nThe package exposes the `sendmux` binary.\n\n## OAuth login and connection checks\n\nFor an existing user's account, create a new named OAuth profile with the required scopes:\n\n```bash\nsendmux auth:login work --scope mailbox.read --scope email.send\nsendmux mailbox:get-connection --profile work --json\n```\n\nThe CLI opens browser consent and receives the callback on the same computer. `--no-browser` only suppresses automatic browser launch and prints the authorisation URL; the OAuth callback still requires the browser flow on the CLI host, so the flag alone is not a remote-machine authentication transport. The CLI preserves existing profiles.\n\nWhen explaining the OAuth lifecycle, include all three storage and recovery facts: the CLI stores tokens locally with restricted file permissions; expiring tokens refresh automatically with concurrent refreshes serialised; and an uncertain refresh outcome requires authentication under a new profile name because `auth:login` preserves an occupied profile. To reuse the same name, first complete `sendmux auth:logout work`, then log in again.\n\nUse `sending:get-connection`, `mailbox:get-connection`, or `management:get-connection` for the selected surface. These checks require no mailbox selector and send no email. Use `data.label` for the connection name and `data.team.id` for its stable team identifier.\n\nRun `sendmux auth:logout work` to revoke the connection and remove its profile. A failed revocation keeps the profile for retry; logout also clears an interrupted login reservation.\n\nFor externally managed tokens, inject `SENDMUX_ACCESS_TOKEN` through the environment. The CLI does not refresh that token. Supplying it alongside an API key is an error. See [OAuth for REST APIs](https://sendmux.ai/docs/developer-tools/oauth) for grant scopes and refresh rules.\n\n## Agent inbox onboarding\n\nNo existing Sendmux account or API key is required:\n\n```bash\nsendmux agent:register my-agent \\\n  --mailbox-local-part my-agent \\\n  --client-name \"My agent\" \\\n  --default \\\n  --json\n```\n\nAdd `--owner-email owner@example.com` to invite the owner during registration. Otherwise invite later:\n\n```bash\nsendmux agent:invite-owner owner@example.com --profile my-agent --json\n```\n\nThe CLI persists registration idempotency before the network request, stores the durable credential in the local profile with restricted permissions, never prints it, reloads it from disk, and waits up to 10 minutes for readiness. Rerun registration with the same profile and options to resume safely. Include this storage transition when explaining the onboarding lifecycle: the inbox is capped at 500 MiB before owner approval, and enabling owner-approved sending raises it to at least 5 GiB.\n\nUse the profile for later reads:\n\n```bash\nsendmux mailbox:messages:list --profile my-agent --query limit=25 --json\n```\n\nRead/receive access has no expiry date while the registration remains active. Sending remains blocked until the owner accepts and approves it. After approval, a command such as `sending:send --profile my-agent` automatically exchanges the durable credential for a one-hour `email.send` token and caches it until near expiry. Full registration revocation removes read access and every delegated token.\n\nRevoking sending does not itself change the current inbox storage allocation.\n\n## Profiles\n\nCreate separate profiles for root and mailbox keys.\n\n```bash\nSENDMUX_API_KEY=\"$SENDMUX_ROOT_KEY\" sendmux profiles:set default --default --json\nSENDMUX_API_KEY=\"$SENDMUX_MBX_KEY\" sendmux profiles:set mailbox --json\nSENDMUX_API_KEY=\"$SENDMUX_MBX_KEY\" sendmux profiles:set sending --json\nsendmux profiles:list --json\nsendmux profiles:show default --json\n```\n\n`profiles:set` reads the key from `SENDMUX_API_KEY`; populate the source variables through the user's secret store. The direct `--api-key` flag remains supported and takes precedence over `SENDMUX_API_KEY`, but do not expand a secret into that flag because the resulting value is visible in process arguments.\n\nProfile reads mask stored API keys and never reveal agent credentials. `profiles:set` reports `key_kind` as `root` or `mailbox`; `agent:register` creates a discriminated agent profile.\n\nAuthentication resolution: `SENDMUX_ACCESS_TOKEN` takes precedence and rejects a simultaneous API key. Otherwise:\n\n1. `--api-key`, then `SENDMUX_API_KEY`.\n2. If no direct key is present, `--profile` / `-p`, then `SENDMUX_PROFILE`, then the configured default profile.\n3. Base URL comes from `--base-url`, then `SENDMUX_BASE_URL`, then the selected profile.\n\n## Preflight\n\nFor API-key authentication, the CLI infers key kind from the prefix before sending a request. OAuth profiles use their approved grants instead of API-key prefix checks.\n\n| Command surface | Required key                                                                      |\n| --------------- | --------------------------------------------------------------------------------- |\n| `management:*`  | `smx_root_`                                                                       |\n| `mailbox:*`     | `smx_mbx_` or scoped `smx_agent_`                                                 |\n| `sending:*`     | Send-capable `smx_mbx_` key or owner-approved Sending-resource `smx_agent_` token |\n\nFor an agent profile, `mailbox:*` uses the durable read credential. `sending:*` obtains a delegated token only after owner approval. `management:*` rejects agent profiles before the request.\n\nWrong-key examples fail before network:\n\n```text\nCommand requires a root API key, but --api-key contains a mailbox API key.\nCommand requires a send-capable `smx_mbx_` key or owner-approved Sending-resource `smx_agent_` token, but --api-key contains a root API key.\n```\n\n## Command catalogue\n\nThe CLI exposes generated operation commands:\n\n| Surface    | Count | Examples                                                                                                                                                   |\n| ---------- | ----: | ---------------------------------------------------------------------------------------------------------------------------------------------------------- |\n| Management |    54 | `management:domains:list`, `management:create-domain`, `management:create-mailbox`, `management:get-spend-summary`, `management:create-webhook`            |\n| Mailbox    |    42 | `mailbox:search-message-snippets`, `mailbox:batch-get-messages`, `mailbox:query-message-changes`, `mailbox:send-message`, `mailbox:list-granted-mailboxes` |\n| Sending    |     8 | `sending:get-open-api-spec`, `sending:send`, `sending:send:batch`, `sending:upload-attachment`, `sending:create-attachment-upload`, `sending:complete-attachment-upload`, `sending:get-attachment` |\n| OAuth      |     2 | `auth:login`, `auth:logout` |\n| Profiles   |     3 | `profiles:list`, `profiles:set`, `profiles:show`                                                                                                           |\n| Agent      |     2 | `agent:register`, `agent:invite-owner`                                                                                                                      |\n\nUse command-level help to discover accepted path, query, header, and body fields:\n\n```bash\nsendmux management:create-domain --help\nsendmux mailbox:search-message-snippets --help\nsendmux sending:send:batch --help\nsendmux sending:upload-attachment --help\n```\n\n## Operation flags\n\nOperation commands share these flags:\n\n| Flag                  | Use                                                                        |\n| --------------------- | -------------------------------------------------------------------------- |\n| `--api-key`           | Direct key; overrides profile/env profile lookup.                          |\n| `--base-url`          | Override API base URL.                                                     |\n| `--profile`, `-p`     | Select a local profile.                                                    |\n| `--body`              | Inline JSON request body, or text bytes for byte-oriented operations.      |\n| `--body-file`         | Read a JSON request body or byte payload from a file.                      |\n| `--attach`            | Attach a local file to supported send commands. Repeat for multiple files. |\n| `--file`              | Read a local file for mailbox attachment upload convenience commands.       |\n| `--via-presigned`     | Upload a mailbox `--file` through a short-lived signed URL instead of API bytes. |\n| `--content-type`      | Override inferred MIME type for `--attach` or `--file`.                    |\n| `--path name=value`   | Path parameters. Repeat for multiple path params.                          |\n| `--query name=value`  | Query parameters. Repeat for filters and pagination.                       |\n| `--header name=value` | Headers accepted by the operation. Repeat for multiple headers.            |\n| `--idempotency-key`   | Shortcut for `Idempotency-Key`. Works only when the operation supports it. |\n| `--if-match`          | Shortcut for `If-Match`. Works only when the operation supports it.        |\n| `--if-none-match`     | Shortcut for `If-None-Match`. Works only when the operation supports it.   |\n| `--json`              | Machine-readable output.                                                   |\n\n`--path`, `--query`, and `--header` require `name=value`. Booleans use `true` or `false`. Repeat an array-valued parameter rather than comma-joining it.\n\nPass either `--body` or `--body-file`, not both.\n\nUse `sendmux-attachments` for attachment-heavy flows and size/token trade-offs.\n\n## Examples\n\nFor workflows spanning Sending, Mailbox, and Management, state the classification explicitly: they are three command surfaces and may use three profiles, but the CLI has only `root` and `mailbox` API-key kinds. A send-capable mailbox key may populate both the mailbox and sending profiles; do not call those profiles different key kinds.\n\nCreate a domain:\n\n```bash\nsendmux management:create-domain \\\n  --profile default \\\n  --idempotency-key \"$IDEMPOTENCY_KEY\" \\\n  --body '{\"domain\":\"example.com\",\"mode\":\"send_receive\"}' \\\n  --json\n```\n\nGet domain DNS records:\n\n```bash\nsendmux management:get-domain-zone-file \\\n  --profile default \\\n  --path public_id=mdom_abc \\\n  --json\n```\n\nSearch a mailbox without reading full messages:\n\n```bash\nsendmux mailbox:search-message-snippets \\\n  --profile mailbox \\\n  --query q=invoice \\\n  --query is_unread=true \\\n  --query limit=10 \\\n  --json\n```\n\nBatch-read selected mailbox messages:\n\n```bash\nsendmux mailbox:batch-get-messages \\\n  --profile mailbox \\\n  --body '{\n    \"ids\": [\"eml_abc\", \"eml_def\"],\n    \"body_mode\": \"clean_json\",\n    \"max_body_chars\": 4000\n  }' \\\n  --json\n```\n\nSend a batch:\n\n```bash\nsendmux sending:send:batch \\\n  --profile sending \\\n  --idempotency-key \"$IDEMPOTENCY_KEY\" \\\n  --body-file ./messages.json \\\n  --json\n```\n\nSend through the Sending API with a local attachment:\n\n```bash\nsendmux sending:send \\\n  --profile sending \\\n  --idempotency-key \"$IDEMPOTENCY_KEY\" \\\n  --attach ./report.pdf \\\n  --body '{\"from\":{\"email\":\"sender@example.com\"},\"to\":{\"email\":\"user@example.com\"},\"subject\":\"Report\",\"html_body\":\"<p>Attached.</p>\"}' \\\n  --json\n```\n\n`sending:send --attach` uploads the file first and injects an `attachment_id` reference; it does not place base64 in the send body.\n\nUpload a Sending attachment separately:\n\n```bash\nSIZE_BYTES=\"$(wc -c < ./report.pdf | tr -d '[:space:]')\"\n\nsendmux sending:upload-attachment \\\n  --profile sending \\\n  --body-file ./report.pdf \\\n  --header Content-Length=\"$SIZE_BYTES\" \\\n  --query filename=report.pdf \\\n  --query content_type=application/pdf \\\n  --json\n```\n\nSend a mailbox message with a local attachment:\n\n```bash\nsendmux mailbox:send-message \\\n  --profile mailbox \\\n  --idempotency-key \"$IDEMPOTENCY_KEY\" \\\n  --attach ./report.pdf \\\n  --body '{\"to\":[{\"email\":\"user@example.com\",\"name\":null}],\"subject\":\"Report\",\"text_body\":\"Attached.\"}' \\\n  --json\n```\n\nMailbox attachment upload commands share the 7,500,000 byte per-attachment cap. For larger files, split the file or host it externally and send a link.\n\nUpload a mailbox attachment by presigned URL:\n\n```bash\nsendmux mailbox:upload-attachment \\\n  --profile mailbox \\\n  --file ./report.pdf \\\n  --via-presigned \\\n  --json\n```\n\nPoll one unchanged-safe delivery log:\n\n```bash\nsendmux management:get-email-log \\\n  --profile default \\\n  --path public_id=dlog_abc \\\n  --if-none-match \"$ETAG\" \\\n  --json\n```\n\n## Routing\n\n- First setup/auth check: `sendmux-getting-started`.\n- Sending strategy and body shape: `sendmux-send-email`.\n- Attachment file paths and presigned upload/download: `sendmux-attachments`.\n- Mailbox read, search, sync, triage, or reply: `sendmux-mailbox-agent`.\n- Account-level management strategy: `sendmux-management`.\n- MCP connection setup: `sendmux-mcp-setup`.\n- Cheapest-call doctrine: `sendmux-token-efficient-usage`.\n\nFile v1.0.11:_meta.json\n\n{\n  \"ownerId\": \"kn77z51yqhw8mt9vjfkpt8w74989rfb3\",\n  \"slug\": \"sendmux-cli\",\n  \"version\": \"1.0.11\",\n  \"publishedAt\": 1790914951924\n}\n\nFile v1.0.11:skill-card.md\n\n## Description:\n\nUse the Sendmux CLI for durable agent inbox registration, owner invites, profiles, and terminal-driven Management, Mailbox, and Sending workflows.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[sendmux.ai](https://clawhub.ai/user/sendmux.ai)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and agents use the Sendmux CLI to register agent inboxes, manage profiles and account resources, read mailboxes, and send email from a terminal.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Mailbox reads, sends, attachments, and account-management commands can access private data or change external resources.\n\nMitigation: Review each mailbox-read, send, attachment-upload, and account-management command before execution; confirm destructive operations explicitly.\n\nRisk: Credentials and persistent profiles can retain access beyond the immediate task.\n\nMitigation: Use scoped profiles or tokens, keep secrets in a secret store rather than chat or command arguments, and revoke or log out profiles when no longer needed.\n\n## Reference(s):\n\n- [Sendmux CLI on ClawHub](https://clawhub.ai/sendmux.ai/skills/sendmux-cli)\n- [Sendmux skills homepage (listed in skill metadata)](https://github.com/Sendmux/skills)\n- [Sendmux OAuth for REST APIs](https://sendmux.ai/docs/developer-tools/oauth)\n\n## Skill Output:\n\n**Output Type(s):** [Shell commands, Configuration instructions, Guidance]\n\n**Output Format:** [Markdown with inline shell commands and JSON examples]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Commands can request JSON-formatted CLI responses.]\n\n## Skill Version(s):\n\n1.0.11 (source: ClawHub release; skill frontmatter: 1.7.1)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v1.0.10: 3 files, 6624 bytes\n\nFiles: skill-card.md (1909b), SKILL.md (15460b), _meta.json (131b)\n\nFile v1.0.10:SKILL.md\n\n---\nname: \"sendmux-cli\"\ndescription: \"Use the Sendmux CLI for durable agent inbox registration, owner invites, profiles, and terminal-driven Management, Mailbox, and Sending workflows.\"\nversion: \"1.7.0\"\nmetadata:\n  openclaw:\n    skillKey: \"sendmux-cli\"\n    homepage: \"https://github.com/Sendmux/skills\"\n    primaryEnv: \"SENDMUX_API_KEY\"\n    envVars:\n      - name: \"SENDMUX_ACCESS_TOKEN\"\n        required: false\n        description: \"Optional externally managed OAuth access token for CLI HTTP requests; the CLI does not refresh it.\"\n      - name: \"SENDMUX_API_KEY\"\n        required: false\n        description: \"Optional Sendmux API key or scoped agent token used by CLI, SDK, HTTP, or MCP examples.\"\n      - name: \"SENDMUX_BASE_URL\"\n        required: false\n        description: \"Optional Sendmux API base URL override for CLI examples.\"\n      - name: \"SENDMUX_MBX_KEY\"\n        required: false\n        description: \"Optional Sendmux mailbox key for Mailbox and send-capable mailbox workflows.\"\n      - name: \"SENDMUX_PROFILE\"\n        required: false\n        description: \"Optional Sendmux CLI profile name.\"\n      - name: \"SENDMUX_ROOT_KEY\"\n        required: false\n        description: \"Optional Sendmux root key for account-level Management API setup.\"\n    install:\n      - kind: \"node\"\n        package: \"@sendmux/cli\"\n        bins:\n          - \"sendmux\"\n---\n\n# Sendmux CLI\n\n## ClawHub account note\n\nThis ClawHub skill connects OpenClaw agents to Sendmux. Some workflows require a Sendmux account and an appropriate Sendmux API key or agent token. Sendmux account usage is external to ClawHub; do not ask users to paste secrets into chat.\n\nUse this skill when the terminal is the right Sendmux surface.\n\n## Boundaries\n\n- Do not ask the user to paste API keys.\n- For API-key profiles, use `smx_root_` for `management:*` and `smx_mbx_` or scoped `smx_agent_` for `mailbox:*`.\n- OAuth profiles require the operation's approved surface, scopes and mailbox access. REST OAuth tokens authenticate HTTP, not SMTP or IMAP.\n- Durable agent profiles can read and receive mail while active, but cannot send until an invited owner accepts and approves sending.\n- After owner approval, `sending:*` commands with an agent profile automatically exchange and cache a one-hour delegated token.\n- Do not run destructive commands without explicit confirmation.\n- Use `--json` for agent-readable output.\n- Prefer task-specific Sendmux skills when the user needs strategy; use this skill for exact CLI mechanics.\n\n## Install\n\n```bash\nnpm install -g @sendmux/cli\nsendmux --help\n```\n\nThe package exposes the `sendmux` binary.\n\n## OAuth login and connection checks\n\nFor an existing user's account, create a new named OAuth profile with the required scopes:\n\n```bash\nsendmux auth:login work --scope mailbox.read --scope email.send\nsendmux mailbox:get-connection --profile work --json\n```\n\nThe CLI opens browser consent and receives the callback on the same computer. `--no-browser` only suppresses automatic browser launch and prints the authorisation URL; the OAuth callback still requires the browser flow on the CLI host, so the flag alone is not a remote-machine authentication transport. The CLI preserves existing profiles.\n\nWhen explaining the OAuth lifecycle, include all three storage and recovery facts: the CLI stores tokens locally with restricted file permissions; expiring tokens refresh automatically with concurrent refreshes serialised; and an uncertain refresh outcome requires authentication under a new profile name because `auth:login` preserves an occupied profile. To reuse the same name, first complete `sendmux auth:logout work`, then log in again.\n\nUse `sending:get-connection`, `mailbox:get-connection`, or `management:get-connection` for the selected surface. These checks require no mailbox selector and send no email. Use `data.label` for the connection name and `data.team.id` for its stable team identifier.\n\nRun `sendmux auth:logout work` to revoke the connection and remove its profile. A failed revocation keeps the profile for retry; logout also clears an interrupted login reservation.\n\nFor externally managed tokens, inject `SENDMUX_ACCESS_TOKEN` through the environment. The CLI does not refresh that token. Supplying it alongside an API key is an error. See [OAuth for REST APIs](https://sendmux.ai/docs/developer-tools/oauth) for grant scopes and refresh rules.\n\n## Agent inbox onboarding\n\nNo existing Sendmux account or API key is required:\n\n```bash\nsendmux agent:register my-agent \\\n  --mailbox-local-part my-agent \\\n  --client-name \"My agent\" \\\n  --default \\\n  --json\n```\n\nAdd `--owner-email owner@example.com` to invite the owner during registration. Otherwise invite later:\n\n```bash\nsendmux agent:invite-owner owner@example.com --profile my-agent --json\n```\n\nThe CLI persists registration idempotency before the network request, stores the durable credential in the local profile with restricted permissions, never prints it, reloads it from disk, and waits up to 10 minutes for readiness. Rerun registration with the same profile and options to resume safely. Include this storage transition when explaining the onboarding lifecycle: the inbox is capped at 500 MiB before owner approval, and enabling owner-approved sending raises it to at least 5 GiB.\n\nUse the profile for later reads:\n\n```bash\nsendmux mailbox:messages:list --profile my-agent --query limit=25 --json\n```\n\nRead/receive access has no expiry date while the registration remains active. Sending remains blocked until the owner accepts and approves it. After approval, a command such as `sending:send --profile my-agent` automatically exchanges the durable credential for a one-hour `email.send` token and caches it until near expiry. Full registration revocation removes read access and every delegated token.\n\nRevoking sending does not itself change the current inbox storage allocation.\n\n## Profiles\n\nCreate separate profiles for root and mailbox keys.\n\n```bash\nSENDMUX_API_KEY=\"$SENDMUX_ROOT_KEY\" sendmux profiles:set default --default --json\nSENDMUX_API_KEY=\"$SENDMUX_MBX_KEY\" sendmux profiles:set mailbox --json\nSENDMUX_API_KEY=\"$SENDMUX_MBX_KEY\" sendmux profiles:set sending --json\nsendmux profiles:list --json\nsendmux profiles:show default --json\n```\n\n`profiles:set` reads the key from `SENDMUX_API_KEY`; populate the source variables through the user's secret store. The direct `--api-key` flag remains supported and takes precedence over `SENDMUX_API_KEY`, but do not expand a secret into that flag because the resulting value is visible in process arguments.\n\nProfile reads mask stored API keys and never reveal agent credentials. `profiles:set` reports `key_kind` as `root` or `mailbox`; `agent:register` creates a discriminated agent profile.\n\nAuthentication resolution: `SENDMUX_ACCESS_TOKEN` takes precedence and rejects a simultaneous API key. Otherwise:\n\n1. `--api-key`, then `SENDMUX_API_KEY`.\n2. If no direct key is present, `--profile` / `-p`, then `SENDMUX_PROFILE`, then the configured default profile.\n3. Base URL comes from `--base-url`, then `SENDMUX_BASE_URL`, then the selected profile.\n\n## Preflight\n\nFor API-key authentication, the CLI infers key kind from the prefix before sending a request. OAuth profiles use their approved grants instead of API-key prefix checks.\n\n| Command surface | Required key                                                                      |\n| --------------- | --------------------------------------------------------------------------------- |\n| `management:*`  | `smx_root_`                                                                       |\n| `mailbox:*`     | `smx_mbx_` or scoped `smx_agent_`                                                 |\n| `sending:*`     | Send-capable `smx_mbx_` key or owner-approved Sending-resource `smx_agent_` token |\n\nFor an agent profile, `mailbox:*` uses the durable read credential. `sending:*` obtains a delegated token only after owner approval. `management:*` rejects agent profiles before the request.\n\nWrong-key examples fail before network:\n\n```text\nCommand requires a root API key, but --api-key contains a mailbox API key.\nCommand requires a send-capable `smx_mbx_` key or owner-approved Sending-resource `smx_agent_` token, but --api-key contains a root API key.\n```\n\n## Command catalogue\n\nThe CLI exposes generated operation commands:\n\n| Surface    | Count | Examples                                                                                                                                                   |\n| ---------- | ----: | ---------------------------------------------------------------------------------------------------------------------------------------------------------- |\n| Management |    54 | `management:domains:list`, `management:create-domain`, `management:create-mailbox`, `management:get-spend-summary`, `management:create-webhook`            |\n| Mailbox    |    42 | `mailbox:search-message-snippets`, `mailbox:batch-get-messages`, `mailbox:query-message-changes`, `mailbox:send-message`, `mailbox:list-granted-mailboxes` |\n| Sending    |     8 | `sending:get-open-api-spec`, `sending:send`, `sending:send:batch`, `sending:upload-attachment`, `sending:create-attachment-upload`, `sending:complete-attachment-upload`, `sending:get-attachment` |\n| OAuth      |     2 | `auth:login`, `auth:logout` |\n| Profiles   |     3 | `profiles:list`, `profiles:set`, `profiles:show`                                                                                                           |\n| Agent      |     2 | `agent:register`, `agent:invite-owner`                                                                                                                      |\n\nUse command-level help to discover accepted path, query, header, and body fields:\n\n```bash\nsendmux management:create-domain --help\nsendmux mailbox:search-message-snippets --help\nsendmux sending:send:batch --help\nsendmux sending:upload-attachment --help\n```\n\n## Operation flags\n\nOperation commands share these flags:\n\n| Flag                  | Use                                                                        |\n| --------------------- | -------------------------------------------------------------------------- |\n| `--api-key`           | Direct key; overrides profile/env profile lookup.                          |\n| `--base-url`          | Override API base URL.                                                     |\n| `--profile`, `-p`     | Select a local profile.                                                    |\n| `--body`              | Inline JSON request body, or text bytes for byte-oriented operations.      |\n| `--body-file`         | Read a JSON request body or byte payload from a file.                      |\n| `--attach`            | Attach a local file to supported send commands. Repeat for multiple files. |\n| `--file`              | Read a local file for mailbox attachment upload convenience commands.       |\n| `--via-presigned`     | Upload a mailbox `--file` through a short-lived signed URL instead of API bytes. |\n| `--content-type`      | Override inferred MIME type for `--attach` or `--file`.                    |\n| `--path name=value`   | Path parameters. Repeat for multiple path params.                          |\n| `--query name=value`  | Query parameters. Repeat for filters and pagination.                       |\n| `--header name=value` | Headers accepted by the operation. Repeat for multiple headers.            |\n| `--idempotency-key`   | Shortcut for `Idempotency-Key`. Works only when the operation supports it. |\n| `--if-match`          | Shortcut for `If-Match`. Works only when the operation supports it.        |\n| `--if-none-match`     | Shortcut for `If-None-Match`. Works only when the operation supports it.   |\n| `--json`              | Machine-readable output.                                                   |\n\n`--path`, `--query`, and `--header` require `name=value`. Booleans use `true` or `false`. Repeat an array-valued parameter rather than comma-joining it.\n\nPass either `--body` or `--body-file`, not both.\n\nUse `sendmux-attachments` for attachment-heavy flows and size/token trade-offs.\n\n## Examples\n\nFor workflows spanning Sending, Mailbox, and Management, state the classification explicitly: they are three command surfaces and may use three profiles, but the CLI has only `root` and `mailbox` API-key kinds. A send-capable mailbox key may populate both the mailbox and sending profiles; do not call those profiles different key kinds.\n\nCreate a domain:\n\n```bash\nsendmux management:create-domain \\\n  --profile default \\\n  --idempotency-key \"$IDEMPOTENCY_KEY\" \\\n  --body '{\"domain\":\"example.com\",\"mode\":\"send_receive\"}' \\\n  --json\n```\n\nGet domain DNS records:\n\n```bash\nsendmux management:get-domain-zone-file \\\n  --profile default \\\n  --path public_id=mdom_abc \\\n  --json\n```\n\nSearch a mailbox without reading full messages:\n\n```bash\nsendmux mailbox:search-message-snippets \\\n  --profile mailbox \\\n  --query q=invoice \\\n  --query is_unread=true \\\n  --query limit=10 \\\n  --json\n```\n\nBatch-read selected mailbox messages:\n\n```bash\nsendmux mailbox:batch-get-messages \\\n  --profile mailbox \\\n  --body '{\n    \"ids\": [\"eml_abc\", \"eml_def\"],\n    \"body_mode\": \"clean_json\",\n    \"max_body_chars\": 4000\n  }' \\\n  --json\n```\n\nSend a batch:\n\n```bash\nsendmux sending:send:batch \\\n  --profile sending \\\n  --idempotency-key \"$IDEMPOTENCY_KEY\" \\\n  --body-file ./messages.json \\\n  --json\n```\n\nSend through the Sending API with a local attachment:\n\n```bash\nsendmux sending:send \\\n  --profile sending \\\n  --idempotency-key \"$IDEMPOTENCY_KEY\" \\\n  --attach ./report.pdf \\\n  --body '{\"from\":{\"email\":\"sender@example.com\"},\"to\":{\"email\":\"user@example.com\"},\"subject\":\"Report\",\"html_body\":\"<p>Attached.</p>\"}' \\\n  --json\n```\n\n`sending:send --attach` uploads the file first and injects an `attachment_id` reference; it does not place base64 in the send body.\n\nUpload a Sending attachment separately:\n\n```bash\nSIZE_BYTES=\"$(wc -c < ./report.pdf | tr -d '[:space:]')\"\n\nsendmux sending:upload-attachment \\\n  --profile sending \\\n  --body-file ./report.pdf \\\n  --header Content-Length=\"$SIZE_BYTES\" \\\n  --query filename=report.pdf \\\n  --query content_type=application/pdf \\\n  --json\n```\n\nSend a mailbox message with a local attachment:\n\n```bash\nsendmux mailbox:send-message \\\n  --profile mailbox \\\n  --idempotency-key \"$IDEMPOTENCY_KEY\" \\\n  --attach ./report.pdf \\\n  --body '{\"to\":[{\"email\":\"user@example.com\",\"name\":null}],\"subject\":\"Report\",\"text_body\":\"Attached.\"}' \\\n  --json\n```\n\nMailbox attachment upload commands share the 7,500,000 byte per-attachment cap. For larger files, split the file or host it externally and send a link.\n\nUpload a mailbox attachment by presigned URL:\n\n```bash\nsendmux mailbox:upload-attachment \\\n  --profile mailbox \\\n  --file ./report.pdf \\\n  --via-presigned \\\n  --json\n```\n\nPoll one unchanged-safe delivery log:\n\n```bash\nsendmux management:get-email-log \\\n  --profile default \\\n  --path public_id=dlog_abc \\\n  --if-none-match \"$ETAG\" \\\n  --json\n```\n\n## Routing\n\n- First setup/auth check: `sendmux-getting-started`.\n- Sending strategy and body shape: `sendmux-send-email`.\n- Attachment file paths and presigned upload/download: `sendmux-attachments`.\n- Mailbox read, search, sync, triage, or reply: `sendmux-mailbox-agent`.\n- Account-level management strategy: `sendmux-management`.\n- MCP connection setup: `sendmux-mcp-setup`.\n- Cheapest-call doctrine: `sendmux-token-efficient-usage`.\n\nFile v1.0.10:_meta.json\n\n{\n  \"ownerId\": \"kn77z51yqhw8mt9vjfkpt8w74989rfb3\",\n  \"slug\": \"sendmux-cli\",\n  \"version\": \"1.0.10\",\n  \"publishedAt\": 1790769732099\n}\n\nFile v1.0.10:skill-card.md\n\n## Description:\n\nUse the Sendmux CLI for durable agent inbox registration, owner invites, profiles, and terminal-driven Management, Mailbox, and Sending workflows.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[sendmux.ai](https://clawhub.ai/user/sendmux.ai)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and agent operators use this skill to register agent inboxes, manage Sendmux profiles and accounts, read mail, and send email through the terminal.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: API keys, OAuth tokens, stored profiles, and mailbox contents may expose sensitive information.\n\nMitigation: Use scoped credentials and protected local profiles; do not paste secrets into chat or expose them in command arguments.\n\nRisk: Sending email or changing account settings may have unintended consequences.\n\nMitigation: Confirm email-sending and account-changing actions before running them, and require explicit confirmation for destructive commands.\n\n## Reference(s):\n\n- [Sendmux CLI skill on ClawHub](https://clawhub.ai/sendmux.ai/skills/sendmux-cli)\n- [Sendmux skills homepage](https://github.com/Sendmux/skills)\n- [Sendmux OAuth for REST APIs](https://sendmux.ai/docs/developer-tools/oauth)\n\n## Skill Output:\n\n**Output Type(s):** [Shell commands, Configuration instructions, Guidance]\n\n**Output Format:** [Markdown with bash examples]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Examples can request JSON-formatted CLI responses.]\n\n## Skill Version(s):\n\n1.0.10 (source: ClawHub release metadata; skill frontmatter lists 1.7.0)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v1.0.9: 3 files, 6578 bytes\n\nFiles: skill-card.md (2002b), SKILL.md (15360b), _meta.json (130b)\n\nFile v1.0.9:SKILL.md\n\n---\nname: \"sendmux-cli\"\ndescription: \"Use the Sendmux CLI for durable agent inbox registration, owner invites, profiles, and terminal-driven Management, Mailbox, and Sending workflows.\"\nversion: \"1.6.0\"\nmetadata:\n  openclaw:\n    skillKey: \"sendmux-cli\"\n    homepage: \"https://github.com/Sendmux/skills\"\n    primaryEnv: \"SENDMUX_API_KEY\"\n    envVars:\n      - name: \"SENDMUX_ACCESS_TOKEN\"\n        required: false\n        description: \"Optional externally managed OAuth access token for CLI HTTP requests; the CLI does not refresh it.\"\n      - name: \"SENDMUX_API_KEY\"\n        required: false\n        description: \"Optional Sendmux API key or scoped agent token used by CLI, SDK, HTTP, or MCP examples.\"\n      - name: \"SENDMUX_BASE_URL\"\n        required: false\n        description: \"Optional Sendmux API base URL override for CLI examples.\"\n      - name: \"SENDMUX_MBX_KEY\"\n        required: false\n        description: \"Optional Sendmux mailbox key for Mailbox and send-capable mailbox workflows.\"\n      - name: \"SENDMUX_PROFILE\"\n        required: false\n        description: \"Optional Sendmux CLI profile name.\"\n      - name: \"SENDMUX_ROOT_KEY\"\n        required: false\n        description: \"Optional Sendmux root key for account-level Management API setup.\"\n    install:\n      - kind: \"node\"\n        package: \"@sendmux/cli\"\n        bins:\n          - \"sendmux\"\n---\n\n# Sendmux CLI\n\n## ClawHub account note\n\nThis ClawHub skill connects OpenClaw agents to Sendmux. Some workflows require a Sendmux account and an appropriate Sendmux API key or agent token. Sendmux account usage is external to ClawHub; do not ask users to paste secrets into chat.\n\nUse this skill when the terminal is the right Sendmux surface.\n\n## Boundaries\n\n- Do not ask the user to paste API keys.\n- For API-key profiles, use `smx_root_` for `management:*` and `smx_mbx_` or scoped `smx_agent_` for `mailbox:*`.\n- OAuth profiles require the operation's approved surface, scopes and mailbox access. REST OAuth tokens authenticate HTTP, not SMTP or IMAP.\n- Durable agent profiles can read and receive mail while active, but cannot send until an invited owner accepts and approves sending.\n- After owner approval, `sending:*` commands with an agent profile automatically exchange and cache a one-hour delegated token.\n- Do not run destructive commands without explicit confirmation.\n- Use `--json` for agent-readable output.\n- Prefer task-specific Sendmux skills when the user needs strategy; use this skill for exact CLI mechanics.\n\n## Install\n\n```bash\nnpm install -g @sendmux/cli\nsendmux --help\n```\n\nThe package exposes the `sendmux` binary.\n\n## OAuth login and connection checks\n\nFor an existing user's account, create a new named OAuth profile with the required scopes:\n\n```bash\nsendmux auth:login work --scope mailbox.read --scope email.send\nsendmux mailbox:get-connection --profile work --json\n```\n\nThe CLI opens browser consent and receives the callback on the same computer. `--no-browser` only suppresses automatic browser launch and prints the authorisation URL; the OAuth callback still requires the browser flow on the CLI host, so the flag alone is not a remote-machine authentication transport. The CLI preserves existing profiles.\n\nWhen explaining the OAuth lifecycle, include all three storage and recovery facts: the CLI stores tokens locally with restricted file permissions; expiring tokens refresh automatically with concurrent refreshes serialised; and an uncertain refresh outcome requires authentication under a new profile name because `auth:login` preserves an occupied profile. To reuse the same name, first complete `sendmux auth:logout work`, then log in again.\n\nUse `sending:get-connection`, `mailbox:get-connection`, or `management:get-connection` for the selected surface. These checks require no mailbox selector and send no email. Use `data.label` for the connection name and `data.team.id` for its stable team identifier.\n\nRun `sendmux auth:logout work` to revoke the connection and remove its profile. A failed revocation keeps the profile for retry; logout also clears an interrupted login reservation.\n\nFor externally managed tokens, inject `SENDMUX_ACCESS_TOKEN` through the environment. The CLI does not refresh that token. Supplying it alongside an API key is an error. See [OAuth for REST APIs](https://sendmux.ai/docs/developer-tools/oauth) for grant scopes and refresh rules.\n\n## Agent inbox onboarding\n\nNo existing Sendmux account or API key is required:\n\n```bash\nsendmux agent:register my-agent \\\n  --mailbox-local-part my-agent \\\n  --client-name \"My agent\" \\\n  --default \\\n  --json\n```\n\nAdd `--owner-email owner@example.com` to invite the owner during registration. Otherwise invite later:\n\n```bash\nsendmux agent:invite-owner owner@example.com --profile my-agent --json\n```\n\nThe CLI persists registration idempotency before the network request, stores the durable credential in the local profile with restricted permissions, never prints it, reloads it from disk, and waits up to 10 minutes for readiness. Rerun registration with the same profile and options to resume safely. Include this storage transition when explaining the onboarding lifecycle: the inbox is capped at 500 MiB before owner approval, and enabling owner-approved sending raises it to at least 5 GiB.\n\nUse the profile for later reads:\n\n```bash\nsendmux mailbox:messages:list --profile my-agent --query limit=25 --json\n```\n\nRead/receive access has no expiry date while the registration remains active. Sending remains blocked until the owner accepts and approves it. After approval, a command such as `sending:send --profile my-agent` automatically exchanges the durable credential for a one-hour `email.send` token and caches it until near expiry. Full registration revocation removes read access and every delegated token.\n\nRevoking sending does not itself change the current inbox storage allocation.\n\n## Profiles\n\nCreate separate profiles for root and mailbox keys.\n\n```bash\nSENDMUX_API_KEY=\"$SENDMUX_ROOT_KEY\" sendmux profiles:set default --default --json\nSENDMUX_API_KEY=\"$SENDMUX_MBX_KEY\" sendmux profiles:set mailbox --json\nSENDMUX_API_KEY=\"$SENDMUX_MBX_KEY\" sendmux profiles:set sending --json\nsendmux profiles:list --json\nsendmux profiles:show default --json\n```\n\n`profiles:set` reads the key from `SENDMUX_API_KEY`; populate the source variables through the user's secret store. The direct `--api-key` flag remains supported and takes precedence over `SENDMUX_API_KEY`, but do not expand a secret into that flag because the resulting value is visible in process arguments.\n\nProfile reads mask stored API keys and never reveal agent credentials. `profiles:set` reports `key_kind` as `root` or `mailbox`; `agent:register` creates a discriminated agent profile.\n\nAuthentication resolution: `SENDMUX_ACCESS_TOKEN` takes precedence and rejects a simultaneous API key. Otherwise:\n\n1. `--api-key`, then `SENDMUX_API_KEY`.\n2. If no direct key is present, `--profile` / `-p`, then `SENDMUX_PROFILE`, then the configured default profile.\n3. Base URL comes from `--base-url`, then `SENDMUX_BASE_URL`, then the selected profile.\n\n## Preflight\n\nFor API-key authentication, the CLI infers key kind from the prefix before sending a request. OAuth profiles use their approved grants instead of API-key prefix checks.\n\n| Command surface | Required key                                                                      |\n| --------------- | --------------------------------------------------------------------------------- |\n| `management:*`  | `smx_root_`                                                                       |\n| `mailbox:*`     | `smx_mbx_` or scoped `smx_agent_`                                                 |\n| `sending:*`     | Send-capable `smx_mbx_` key or owner-approved Sending-resource `smx_agent_` token |\n\nFor an agent profile, `mailbox:*` uses the durable read credential. `sending:*` obtains a delegated token only after owner approval. `management:*` rejects agent profiles before the request.\n\nWrong-key examples fail before network:\n\n```text\nCommand requires a root API key, but --api-key contains a mailbox API key.\nCommand requires a send-capable `smx_mbx_` key or owner-approved Sending-resource `smx_agent_` token, but --api-key contains a root API key.\n```\n\n## Command catalogue\n\nThe CLI exposes generated operation commands:\n\n| Surface    | Count | Examples                                                                                                                                                   |\n| ---------- | ----: | ---------------------------------------------------------------------------------------------------------------------------------------------------------- |\n| Management |    54 | `management:domains:list`, `management:create-domain`, `management:create-mailbox`, `management:get-spend-summary`, `management:create-webhook`            |\n| Mailbox    |    42 | `mailbox:search-message-snippets`, `mailbox:batch-get-messages`, `mailbox:query-message-changes`, `mailbox:send-message`, `mailbox:list-granted-mailboxes` |\n| Sending    |     8 | `sending:get-open-api-spec`, `sending:send`, `sending:send:batch`, `sending:upload-attachment`, `sending:create-attachment-upload`, `sending:complete-attachment-upload`, `sending:get-attachment` |\n| OAuth      |     2 | `auth:login`, `auth:logout` |\n| Profiles   |     3 | `profiles:list`, `profiles:set`, `profiles:show`                                                                                                           |\n| Agent      |     2 | `agent:register`, `agent:invite-owner`                                                                                                                      |\n\nUse command-level help to discover accepted path, query, header, and body fields:\n\n```bash\nsendmux management:create-domain --help\nsendmux mailbox:search-message-snippets --help\nsendmux sending:send:batch --help\nsendmux sending:upload-attachment --help\n```\n\n## Operation flags\n\nOperation commands share these flags:\n\n| Flag                  | Use                                                                        |\n| --------------------- | -------------------------------------------------------------------------- |\n| `--api-key`           | Direct key; overrides profile/env profile lookup.                          |\n| `--base-url`          | Override API base URL.                                                     |\n| `--profile`, `-p`     | Select a local profile.                                                    |\n| `--body`              | Inline JSON request body, or text bytes for byte-oriented operations.      |\n| `--body-file`         | Read a JSON request body or byte payload from a file.                      |\n| `--attach`            | Attach a local file to supported send commands. Repeat for multiple files. |\n| `--file`              | Read a local file for mailbox attachment upload convenience commands.       |\n| `--via-presigned`     | Upload a mailbox `--file` through a short-lived signed URL instead of API bytes. |\n| `--content-type`      | Override inferred MIME type for `--attach` or `--file`.                    |\n| `--path name=value`   | Path parameters. Repeat for multiple path params.                          |\n| `--query name=value`  | Query parameters. Repeat for filters and pagination.                       |\n| `--header name=value` | Headers accepted by the operation. Repeat for multiple headers.            |\n| `--idempotency-key`   | Shortcut for `Idempotency-Key`. Works only when the operation supports it. |\n| `--if-match`          | Shortcut for `If-Match`. Works only when the operation supports it.        |\n| `--if-none-match`     | Shortcut for `If-None-Match`. Works only when the operation supports it.   |\n| `--json`              | Machine-readable output.                                                   |\n\n`--path`, `--query`, and `--header` require `name=value`. Booleans use `true` or `false`. Repeat an array-valued parameter rather than comma-joining it.\n\nPass either `--body` or `--body-file`, not both.\n\nUse `sendmux-attachments` for attachment-heavy flows and size/token trade-offs.\n\n## Examples\n\nFor workflows spanning Sending, Mailbox, and Management, state the classification explicitly: they are three command surfaces and may use three profiles, but the CLI has only `root` and `mailbox` API-key kinds. A send-capable mailbox key may populate both the mailbox and sending profiles; do not call those profiles different key kinds.\n\nCreate a domain:\n\n```bash\nsendmux management:create-domain \\\n  --profile default \\\n  --idempotency-key \"$IDEMPOTENCY_KEY\" \\\n  --body '{\"domain\":\"example.com\",\"mode\":\"send_receive\"}' \\\n  --json\n```\n\nGet domain DNS records:\n\n```bash\nsendmux management:get-domain-zone-file \\\n  --profile default \\\n  --path public_id=mdom_abc \\\n  --json\n```\n\nSearch a mailbox without reading full messages:\n\n```bash\nsendmux mailbox:search-message-snippets \\\n  --profile mailbox \\\n  --query q=invoice \\\n  --query is_unread=true \\\n  --query limit=10 \\\n  --json\n```\n\nBatch-read selected mailbox messages:\n\n```bash\nsendmux mailbox:batch-get-messages \\\n  --profile mailbox \\\n  --body '{\n    \"ids\": [\"eml_abc\", \"eml_def\"],\n    \"body_mode\": \"clean_json\",\n    \"max_body_chars\": 4000\n  }' \\\n  --json\n```\n\nSend a batch:\n\n```bash\nsendmux sending:send:batch \\\n  --profile sending \\\n  --idempotency-key \"$IDEMPOTENCY_KEY\" \\\n  --body-file ./messages.json \\\n  --json\n```\n\nSend through the Sending API with a local attachment:\n\n```bash\nsendmux sending:send \\\n  --profile sending \\\n  --idempotency-key \"$IDEMPOTENCY_KEY\" \\\n  --attach ./report.pdf \\\n  --body '{\"from\":{\"email\":\"sender@example.com\"},\"to\":{\"email\":\"user@example.com\"},\"subject\":\"Report\",\"html_body\":\"<p>Attached.</p>\"}' \\\n  --json\n```\n\n`sending:send --attach` uploads the file first and injects an `attachment_id` reference; it does not place base64 in the send body.\n\nUpload a Sending attachment separately:\n\n```bash\nsendmux sending:upload-attachment \\\n  --profile sending \\\n  --body-file ./report.pdf \\\n  --query filename=report.pdf \\\n  --query content_type=application/pdf \\\n  --json\n```\n\nSend a mailbox message with a local attachment:\n\n```bash\nsendmux mailbox:send-message \\\n  --profile mailbox \\\n  --idempotency-key \"$IDEMPOTENCY_KEY\" \\\n  --attach ./report.pdf \\\n  --body '{\"to\":[{\"email\":\"user@example.com\",\"name\":null}],\"subject\":\"Report\",\"text_body\":\"Attached.\"}' \\\n  --json\n```\n\nMailbox attachment upload commands share the 7,500,000 byte per-attachment cap. For larger files, split the file or host it externally and send a link.\n\nUpload a mailbox attachment by presigned URL:\n\n```bash\nsendmux mailbox:upload-attachment \\\n  --profile mailbox \\\n  --file ./report.pdf \\\n  --via-presigned \\\n  --json\n```\n\nPoll one unchanged-safe delivery log:\n\n```bash\nsendmux management:get-email-log \\\n  --profile default \\\n  --path public_id=dlog_abc \\\n  --if-none-match \"$ETAG\" \\\n  --json\n```\n\n## Routing\n\n- First setup/auth check: `sendmux-getting-started`.\n- Sending strategy and body shape: `sendmux-send-email`.\n- Attachment file paths and presigned upload/download: `sendmux-attachments`.\n- Mailbox read, search, sync, triage, or reply: `sendmux-mailbox-agent`.\n- Account-level management strategy: `sendmux-management`.\n- MCP connection setup: `sendmux-mcp-setup`.\n- Cheapest-call doctrine: `sendmux-token-efficient-usage`.\n\nFile v1.0.9:_meta.json\n\n{\n  \"ownerId\": \"kn77z51yqhw8mt9vjfkpt8w74989rfb3\",\n  \"slug\": \"sendmux-cli\",\n  \"version\": \"1.0.9\",\n  \"publishedAt\": 1789710699774\n}\n\nFile v1.0.9:skill-card.md\n\n## Description:\n\nUse the Sendmux CLI for durable agent inbox registration, owner invites, profiles, and terminal-driven Management, Mailbox, and Sending workflows.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[sendmux.ai](https://clawhub.ai/user/sendmux.ai)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and agent operators use this skill to install and operate the Sendmux CLI for profile setup, OAuth checks, durable agent inbox registration, owner invitations, mailbox workflows, and sending workflows.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: The skill can guide agents through mailbox access, email sending, and management actions using Sendmux credentials.\n\nMitigation: Use scoped mailbox or agent tokens where possible, keep root keys limited to management setup, and review email sends and management changes before execution.\n\nRisk: Local profiles may persist credentials until logout or revocation.\n\nMitigation: Use named profiles deliberately, run logout or revoke credentials when access is no longer needed, and avoid exposing secrets in chat or command arguments.\n\n## Reference(s):\n\n- [Sendmux skills repository](https://github.com/Sendmux/skills)\n- [OAuth for REST APIs](https://sendmux.ai/docs/developer-tools/oauth)\n\n## Skill Output:\n\n**Output Type(s):** [guidance, shell commands, configuration, markdown]\n\n**Output Format:** [Markdown guidance with inline shell commands and JSON-oriented CLI examples]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Recommends --json for agent-readable command output and environment variables for credentials.]\n\n## Skill Version(s):\n\n1.0.9 (source: server release metadata)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v1.0.8: 3 files, 6228 bytes\n\nFiles: skill-card.md (2273b), SKILL.md (14173b), _meta.json (130b)\n\nFile v1.0.8:SKILL.md\n\n---\nname: \"sendmux-cli\"\ndescription: \"Use the Sendmux CLI for durable agent inbox registration, owner invites, profiles, and terminal-driven Management, Mailbox, and Sending workflows.\"\nversion: \"1.5.0\"\nmetadata:\n  openclaw:\n    skillKey: \"sendmux-cli\"\n    homepage: \"https://github.com/Sendmux/skills\"\n    primaryEnv: \"SENDMUX_API_KEY\"\n    envVars:\n      - name: \"SENDMUX_ACCESS_TOKEN\"\n        required: false\n        description: \"Optional externally managed OAuth access token for CLI HTTP requests; the CLI does not refresh it.\"\n      - name: \"SENDMUX_API_KEY\"\n        required: false\n        description: \"Optional Sendmux API key or scoped agent token used by CLI, SDK, HTTP, or MCP examples.\"\n      - name: \"SENDMUX_BASE_URL\"\n        required: false\n        description: \"Optional Sendmux API base URL override for CLI examples.\"\n      - name: \"SENDMUX_MBX_KEY\"\n        required: false\n        description: \"Optional Sendmux mailbox key for Mailbox and send-capable mailbox workflows.\"\n      - name: \"SENDMUX_PROFILE\"\n        required: false\n        description: \"Optional Sendmux CLI profile name.\"\n      - name: \"SENDMUX_ROOT_KEY\"\n        required: false\n        description: \"Optional Sendmux root key for account-level Management API setup.\"\n    install:\n      - kind: \"node\"\n        package: \"@sendmux/cli\"\n        bins:\n          - \"sendmux\"\n---\n\n# Sendmux CLI\n\n## ClawHub account note\n\nThis ClawHub skill connects OpenClaw agents to Sendmux. Some workflows require a Sendmux account and an appropriate Sendmux API key or agent token. Sendmux account usage is external to ClawHub; do not ask users to paste secrets into chat.\n\nUse this skill when the terminal is the right Sendmux surface.\n\n## Boundaries\n\n- Do not ask the user to paste API keys.\n- For API-key profiles, use `smx_root_` for `management:*` and `smx_mbx_` or scoped `smx_agent_` for `mailbox:*`.\n- OAuth profiles require the operation's approved surface, scopes and mailbox access. REST OAuth tokens authenticate HTTP, not SMTP or IMAP.\n- Durable agent profiles can read and receive mail while active, but cannot send until an invited owner accepts and approves sending.\n- After owner approval, `sending:*` commands with an agent profile automatically exchange and cache a one-hour delegated token.\n- Do not run destructive commands without explicit confirmation.\n- Use `--json` for agent-readable output.\n- Prefer task-specific Sendmux skills when the user needs strategy; use this skill for exact CLI mechanics.\n\n## Install\n\n```bash\nnpm install -g @sendmux/cli\nsendmux --help\n```\n\nThe package exposes the `sendmux` binary.\n\n## OAuth login and connection checks\n\nFor an existing user's account, create a new named OAuth profile with the required scopes:\n\n```bash\nsendmux auth:login work --scope mailbox.read --scope email.send\nsendmux mailbox:get-connection --profile work --json\n```\n\nThe CLI opens browser consent and receives the callback on the same computer. `--no-browser` prints the authorisation URL for manual opening. It preserves existing profiles and stores tokens with restricted file permissions. Expiring tokens refresh automatically with concurrent refreshes serialised; an uncertain refresh requires a new login.\n\nUse `sending:get-connection`, `mailbox:get-connection`, or `management:get-connection` for the selected surface. These checks require no mailbox selector and send no email. Use `data.label` for the connection name and `data.team.id` for its stable team identifier.\n\nRun `sendmux auth:logout work` to revoke the connection and remove its profile. A failed revocation keeps the profile for retry; logout also clears an interrupted login reservation.\n\nFor externally managed tokens, inject `SENDMUX_ACCESS_TOKEN` through the environment. The CLI does not refresh that token. Supplying it alongside an API key is an error. See [OAuth for REST APIs](https://sendmux.ai/docs/developer-tools/oauth) for grant scopes and refresh rules.\n\n## Agent inbox onboarding\n\nNo existing Sendmux account or API key is required:\n\n```bash\nsendmux agent:register my-agent \\\n  --mailbox-local-part my-agent \\\n  --client-name \"My agent\" \\\n  --default \\\n  --json\n```\n\nAdd `--owner-email owner@example.com` to invite the owner during registration. Otherwise invite later:\n\n```bash\nsendmux agent:invite-owner owner@example.com --profile my-agent --json\n```\n\nThe CLI persists registration idempotency before the network request, stores the durable credential in the local profile with restricted permissions, never prints it, reloads it from disk, and waits up to 10 minutes for readiness. Rerun registration with the same profile and options to resume safely.\n\nUse the profile for later reads:\n\n```bash\nsendmux mailbox:messages:list --profile my-agent --query limit=25 --json\n```\n\nRead/receive access has no expiry date while the registration remains active. Sending remains blocked until the owner accepts and approves it. After approval, a command such as `sending:send --profile my-agent` automatically exchanges the durable credential for a one-hour `email.send` token and caches it until near expiry. Full registration revocation removes read access and every delegated token.\n\nThe inbox is capped at 500 MiB before approval. Enabling owner-approved sending first raises it to at least 5 GiB. Revoking sending does not itself change the current inbox storage allocation.\n\n## Profiles\n\nCreate separate profiles for root and mailbox keys.\n\n```bash\nsendmux profiles:set default --api-key \"$SENDMUX_ROOT_KEY\" --default --json\nsendmux profiles:set mailbox --api-key \"$SENDMUX_MBX_KEY\" --json\nsendmux profiles:set sending --api-key \"$SENDMUX_MBX_KEY\" --json\nsendmux profiles:list --json\nsendmux profiles:show default --json\n```\n\nProfile reads mask stored API keys and never reveal agent credentials. `profiles:set` reports `key_kind` as `root` or `mailbox`; `agent:register` creates a discriminated agent profile.\n\nAuthentication resolution: `SENDMUX_ACCESS_TOKEN` takes precedence and rejects a simultaneous API key. Otherwise:\n\n1. `--api-key`, then `SENDMUX_API_KEY`.\n2. If no direct key is present, `--profile` / `-p`, then `SENDMUX_PROFILE`, then the configured default profile.\n3. Base URL comes from `--base-url`, then `SENDMUX_BASE_URL`, then the selected profile.\n\n## Preflight\n\nFor API-key authentication, the CLI infers key kind from the prefix before sending a request. OAuth profiles use their approved grants instead of API-key prefix checks.\n\n| Command surface | Required key                                                                      |\n| --------------- | --------------------------------------------------------------------------------- |\n| `management:*`  | `smx_root_`                                                                       |\n| `mailbox:*`     | `smx_mbx_` or scoped `smx_agent_`                                                 |\n| `sending:*`     | Send-capable `smx_mbx_` key or owner-approved Sending-resource `smx_agent_` token |\n\nFor an agent profile, `mailbox:*` uses the durable read credential. `sending:*` obtains a delegated token only after owner approval. `management:*` rejects agent profiles before the request.\n\nWrong-key examples fail before network:\n\n```text\nCommand requires a root API key, but --api-key contains a mailbox API key.\nCommand requires a send-capable `smx_mbx_` key or owner-approved Sending-resource `smx_agent_` token, but --api-key contains a root API key.\n```\n\n## Command catalogue\n\nThe CLI exposes generated operation commands:\n\n| Surface    | Count | Examples                                                                                                                                                   |\n| ---------- | ----: | ---------------------------------------------------------------------------------------------------------------------------------------------------------- |\n| Management |    54 | `management:domains:list`, `management:create-domain`, `management:create-mailbox`, `management:get-spend-summary`, `management:create-webhook`            |\n| Mailbox    |    42 | `mailbox:search-message-snippets`, `mailbox:batch-get-messages`, `mailbox:query-message-changes`, `mailbox:send-message`, `mailbox:list-granted-mailboxes` |\n| Sending    |     8 | `sending:get-open-api-spec`, `sending:send`, `sending:send:batch`, `sending:upload-attachment`, `sending:create-attachment-upload`, `sending:complete-attachment-upload`, `sending:get-attachment` |\n| OAuth      |     2 | `auth:login`, `auth:logout` |\n| Profiles   |     3 | `profiles:list`, `profiles:set`, `profiles:show`                                                                                                           |\n| Agent      |     2 | `agent:register`, `agent:invite-owner`                                                                                                                      |\n\nUse command-level help to discover accepted path, query, header, and body fields:\n\n```bash\nsendmux management:create-domain --help\nsendmux mailbox:search-message-snippets --help\nsendmux sending:send:batch --help\nsendmux sending:upload-attachment --help\n```\n\n## Operation flags\n\nOperation commands share these flags:\n\n| Flag                  | Use                                                                        |\n| --------------------- | -------------------------------------------------------------------------- |\n| `--api-key`           | Direct key; overrides profile/env profile lookup.                          |\n| `--base-url`          | Override API base URL.                                                     |\n| `--profile`, `-p`     | Select a local profile.                                                    |\n| `--body`              | Inline JSON request body, or text bytes for byte-oriented operations.      |\n| `--body-file`         | Read a JSON request body or byte payload from a file.                      |\n| `--attach`            | Attach a local file to supported send commands. Repeat for multiple files. |\n| `--file`              | Read a local file for mailbox attachment upload convenience commands.       |\n| `--via-presigned`     | Upload a mailbox `--file` through a short-lived signed URL instead of API bytes. |\n| `--content-type`      | Override inferred MIME type for `--attach` or `--file`.                    |\n| `--path name=value`   | Path parameters. Repeat for multiple path params.                          |\n| `--query name=value`  | Query parameters. Repeat for filters and pagination.                       |\n| `--header name=value` | Headers accepted by the operation. Repeat for multiple headers.            |\n| `--idempotency-key`   | Shortcut for `Idempotency-Key`. Works only when the operation supports it. |\n| `--if-match`          | Shortcut for `If-Match`. Works only when the operation supports it.        |\n| `--if-none-match`     | Shortcut for `If-None-Match`. Works only when the operation supports it.   |\n| `--json`              | Machine-readable output.                                                   |\n\n`--path`, `--query`, and `--header` require `name=value`. Booleans use `true` or `false`. Repeat an array-valued parameter rather than comma-joining it.\n\nPass either `--body` or `--body-file`, not both.\n\nUse `sendmux-attachments` for attachment-heavy flows and size/token trade-offs.\n\n## Examples\n\nCreate a domain:\n\n```bash\nsendmux management:create-domain \\\n  --profile default \\\n  --idempotency-key \"$IDEMPOTENCY_KEY\" \\\n  --body '{\"domain\":\"example.com\",\"mode\":\"send_receive\"}' \\\n  --json\n```\n\nGet domain DNS records:\n\n```bash\nsendmux management:get-domain-zone-file \\\n  --profile default \\\n  --path public_id=mdom_abc \\\n  --json\n```\n\nSearch a mailbox without reading full messages:\n\n```bash\nsendmux mailbox:search-message-snippets \\\n  --profile mailbox \\\n  --query q=invoice \\\n  --query is_unread=true \\\n  --query limit=10 \\\n  --json\n```\n\nBatch-read selected mailbox messages:\n\n```bash\nsendmux mailbox:batch-get-messages \\\n  --profile mailbox \\\n  --body '{\n    \"ids\": [\"eml_abc\", \"eml_def\"],\n    \"body_mode\": \"clean_json\",\n    \"max_body_chars\": 4000\n  }' \\\n  --json\n```\n\nSend a batch:\n\n```bash\nsendmux sending:send:batch \\\n  --profile sending \\\n  --idempotency-key \"$IDEMPOTENCY_KEY\" \\\n  --body-file ./messages.json \\\n  --json\n```\n\nSend through the Sending API with a local attachment:\n\n```bash\nsendmux sending:send \\\n  --profile sending \\\n  --idempotency-key \"$IDEMPOTENCY_KEY\" \\\n  --attach ./report.pdf \\\n  --body '{\"from\":{\"email\":\"sender@example.com\"},\"to\":{\"email\":\"user@example.com\"},\"subject\":\"Report\",\"html_body\":\"<p>Attached.</p>\"}' \\\n  --json\n```\n\n`sending:send --attach` uploads the file first and injects an `attachment_id` reference; it does not place base64 in the send body.\n\nUpload a Sending attachment separately:\n\n```bash\nsendmux sending:upload-attachment \\\n  --profile sending \\\n  --body-file ./report.pdf \\\n  --query filename=report.pdf \\\n  --query content_type=application/pdf \\\n  --json\n```\n\nSend a mailbox message with a local attachment:\n\n```bash\nsendmux mailbox:send-message \\\n  --profile mailbox \\\n  --idempotency-key \"$IDEMPOTENCY_KEY\" \\\n  --attach ./report.pdf \\\n  --body '{\"to\":[{\"email\":\"user@example.com\",\"name\":null}],\"subject\":\"Report\",\"text_body\":\"Attached.\"}' \\\n  --json\n```\n\nMailbox attachment upload commands share the 7,500,000 byte per-attachment cap. For larger files, split the file or host it externally and send a link.\n\nUpload a mailbox attachment by presigned URL:\n\n```bash\nsendmux mailbox:upload-attachment \\\n  --profile mailbox \\\n  --file ./report.pdf \\\n  --via-presigned \\\n  --json\n```\n\nPoll one unchanged-safe delivery log:\n\n```bash\nsendmux management:get-email-log \\\n  --profile default \\\n  --path public_id=dlog_abc \\\n  --if-none-match \"$ETAG\" \\\n  --json\n```\n\n## Routing\n\n- First setup/auth check: `sendmux-getting-started`.\n- Sending strategy and body shape: `sendmux-send-email`.\n- Attachment file paths and presigned upload/download: `sendmux-attachments`.\n- Mailbox read, search, sync, triage, or reply: `sendmux-mailbox-agent`.\n- Account-level management strategy: `sendmux-management`.\n- MCP connection setup: `sendmux-mcp-setup`.\n- Cheapest-call doctrine: `sendmux-token-efficient-usage`.\n\nFile v1.0.8:_meta.json\n\n{\n  \"ownerId\": \"kn77z51yqhw8mt9vjfkpt8w74989rfb3\",\n  \"slug\": \"sendmux-cli\",\n  \"version\": \"1.0.8\",\n  \"publishedAt\": 1789099157296\n}\n\nFile v1.0.8:skill-card.md\n\n## Description:\n\nUse the Sendmux CLI for durable agent inbox registration, owner invites, profiles, and terminal-driven Management, Mailbox, and Sending workflows.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[sendmux.ai](https://clawhub.ai/user/sendmux.ai)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and agents use this skill to install and operate the Sendmux CLI for inbox registration, OAuth or API-key profiles, and terminal-driven Management, Mailbox, and Sending workflows.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: The skill handles Sendmux credentials, including root, mailbox, scoped agent, and OAuth tokens.\n\nMitigation: Use least-privilege mailbox or scoped agent tokens where possible, avoid pasting secrets into chat, and keep credentials in environment variables or CLI profiles.\n\nRisk: The skill can guide agents through email sending, attachment upload, and account-management commands.\n\nMitigation: Review sending, attachment, destructive, and account-management commands before execution and require explicit confirmation for destructive operations.\n\nRisk: Installing the CLI executes an npm package from the local terminal environment.\n\nMitigation: Install without elevated privileges where possible and verify the @sendmux/cli package source and provenance before use.\n\n## Reference(s):\n\n- [Sendmux skills repository](https://github.com/Sendmux/skills)\n- [OAuth for REST APIs](https://sendmux.ai/docs/developer-tools/oauth)\n- [ClawHub skill page](https://clawhub.ai/sendmux.ai/skills/sendmux-cli)\n\n## Skill Output:\n\n**Output Type(s):** [text, markdown, shell commands, configuration, guidance]\n\n**Output Format:** [Markdown with inline shell commands and JSON-oriented examples]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Agent-readable command examples favor --json output.]\n\n## Skill Version(s):\n\n1.0.8 (source: server release metadata; artifact frontmatter says 1.5.0)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v1.0.7: 3 files, 5466 bytes\n\nFiles: skill-card.md (2144b), SKILL.md (12293b), _meta.json (130b)\n\nFile v1.0.7:SKILL.md\n\n---\nname: \"sendmux-cli\"\ndescription: \"Use the Sendmux CLI for durable agent inbox registration, owner invites, profiles, and terminal-driven Management, Mailbox, and Sending workflows.\"\nversion: \"1.4.2\"\nmetadata:\n  openclaw:\n    skillKey: \"sendmux-cli\"\n    homepage: \"https://github.com/Sendmux/skills\"\n    primaryEnv: \"SENDMUX_API_KEY\"\n    envVars:\n      - name: \"SENDMUX_API_KEY\"\n        required: false\n        description: \"Optional Sendmux API key or scoped agent token used by CLI, SDK, HTTP, or MCP examples.\"\n      - name: \"SENDMUX_BASE_URL\"\n        required: false\n        description: \"Optional Sendmux API base URL override for CLI examples.\"\n      - name: \"SENDMUX_MBX_KEY\"\n        required: false\n        description: \"Optional Sendmux mailbox key for Mailbox and send-capable mailbox workflows.\"\n      - name: \"SENDMUX_PROFILE\"\n        required: false\n        description: \"Optional Sendmux CLI profile name.\"\n      - name: \"SENDMUX_ROOT_KEY\"\n        required: false\n        description: \"Optional Sendmux root key for account-level Management API setup.\"\n    install:\n      - kind: \"node\"\n        package: \"@sendmux/cli\"\n        bins:\n          - \"sendmux\"\n---\n\n# Sendmux CLI\n\n## ClawHub account note\n\nThis ClawHub skill connects OpenClaw agents to Sendmux. Some workflows require a Sendmux account and an appropriate Sendmux API key or agent token. Sendmux account usage is external to ClawHub; do not ask users to paste secrets into chat.\n\nUse this skill when the terminal is the right Sendmux surface.\n\n## Boundaries\n\n- Do not ask the user to paste API keys.\n- Use `smx_root_` keys only for `management:*` commands.\n- Use `smx_mbx_` keys or scoped `smx_agent_` tokens for `mailbox:*` commands.\n- Durable agent profiles can read and receive mail while active, but cannot send until an invited owner accepts and approves sending.\n- After owner approval, `sending:*` commands with an agent profile automatically exchange and cache a one-hour delegated token.\n- Do not run destructive commands without explicit confirmation.\n- Use `--json` for agent-readable output.\n- Prefer task-specific Sendmux skills when the user needs strategy; use this skill for exact CLI mechanics.\n\n## Install\n\n```bash\nnpm install -g @sendmux/cli\nsendmux --help\n```\n\nThe package exposes the `sendmux` binary.\n\n## Agent inbox onboarding\n\nNo existing Sendmux account or API key is required:\n\n```bash\nsendmux agent:register my-agent \\\n  --mailbox-local-part my-agent \\\n  --client-name \"My agent\" \\\n  --default \\\n  --json\n```\n\nAdd `--owner-email owner@example.com` to invite the owner during registration. Otherwise invite later:\n\n```bash\nsendmux agent:invite-owner owner@example.com --profile my-agent --json\n```\n\nThe CLI persists registration idempotency before the network request, stores the durable credential in the local profile with restricted permissions, never prints it, reloads it from disk, and waits up to 10 minutes for readiness. Rerun registration with the same profile and options to resume safely.\n\nUse the profile for later reads:\n\n```bash\nsendmux mailbox:messages:list --profile my-agent --query limit=25 --json\n```\n\nRead/receive access has no expiry date while the registration remains active. Sending remains blocked until the owner accepts and approves it. After approval, a command such as `sending:send --profile my-agent` automatically exchanges the durable credential for a one-hour `email.send` token and caches it until near expiry. Full registration revocation removes read access and every delegated token.\n\nThe inbox is capped at 500 MiB before approval. Enabling owner-approved sending first raises it to at least 5 GiB. Revoking sending does not itself change the current inbox storage allocation.\n\n## Profiles\n\nCreate separate profiles for root and mailbox keys.\n\n```bash\nsendmux profiles:set default --api-key \"$SENDMUX_ROOT_KEY\" --default --json\nsendmux profiles:set mailbox --api-key \"$SENDMUX_MBX_KEY\" --json\nsendmux profiles:set sending --api-key \"$SENDMUX_MBX_KEY\" --json\nsendmux profiles:list --json\nsendmux profiles:show default --json\n```\n\nProfile reads mask stored API keys and never reveal agent credentials. `profiles:set` reports `key_kind` as `root` or `mailbox`; `agent:register` creates a discriminated agent profile.\n\nAuthentication resolution:\n\n1. `--api-key`, then `SENDMUX_API_KEY`.\n2. If no direct key is present, `--profile` / `-p`, then `SENDMUX_PROFILE`, then the configured default profile.\n3. Base URL comes from `--base-url`, then `SENDMUX_BASE_URL`, then the selected profile.\n\n## Preflight\n\nThe CLI infers key kind from the prefix before sending a request.\n\n| Command surface | Required key                                                                      |\n| --------------- | --------------------------------------------------------------------------------- |\n| `management:*`  | `smx_root_`                                                                       |\n| `mailbox:*`     | `smx_mbx_` or scoped `smx_agent_`                                                 |\n| `sending:*`     | Send-capable `smx_mbx_` key or owner-approved Sending-resource `smx_agent_` token |\n\nFor an agent profile, `mailbox:*` uses the durable read credential. `sending:*` obtains a delegated token only after owner approval. `management:*` rejects agent profiles before the request.\n\nWrong-key examples fail before network:\n\n```text\nCommand requires a root API key, but --api-key contains a mailbox API key.\nCommand requires a send-capable `smx_mbx_` key or owner-approved Sending-resource `smx_agent_` token, but --api-key contains a root API key.\n```\n\n## Command catalogue\n\nThe CLI exposes generated operation commands:\n\n| Surface    | Count | Examples                                                                                                                                                   |\n| ---------- | ----: | ---------------------------------------------------------------------------------------------------------------------------------------------------------- |\n| Management |    53 | `management:domains:list`, `management:create-domain`, `management:create-mailbox`, `management:get-spend-summary`, `management:create-webhook`            |\n| Mailbox    |    41 | `mailbox:search-message-snippets`, `mailbox:batch-get-messages`, `mailbox:query-message-changes`, `mailbox:send-message`, `mailbox:list-granted-mailboxes` |\n| Sending    |     7 | `sending:get-open-api-spec`, `sending:send`, `sending:send:batch`, `sending:upload-attachment`, `sending:create-attachment-upload`, `sending:complete-attachment-upload`, `sending:get-attachment` |\n| Profiles   |     3 | `profiles:list`, `profiles:set`, `profiles:show`                                                                                                           |\n| Agent      |     2 | `agent:register`, `agent:invite-owner`                                                                                                                      |\n\nUse command-level help to discover accepted path, query, header, and body fields:\n\n```bash\nsendmux management:create-domain --help\nsendmux mailbox:search-message-snippets --help\nsendmux sending:send:batch --help\nsendmux sending:upload-attachment --help\n```\n\n## Operation flags\n\nOperation commands share these flags:\n\n| Flag                  | Use                                                                        |\n| --------------------- | -------------------------------------------------------------------------- |\n| `--api-key`           | Direct key; overrides profile/env profile lookup.                          |\n| `--base-url`          | Override API base URL.                                                     |\n| `--profile`, `-p`     | Select a local profile.                                                    |\n| `--body`              | Inline JSON request body, or text bytes for byte-oriented operations.      |\n| `--body-file`         | Read a JSON request body or byte payload from a file.                      |\n| `--attach`            | Attach a local file to supported send commands. Repeat for multiple files. |\n| `--file`              | Read a local file for mailbox attachment upload convenience commands.       |\n| `--via-presigned`     | Upload a mailbox `--file` through a short-lived signed URL instead of API bytes. |\n| `--content-type`      | Override inferred MIME type for `--attach` or `--file`.                    |\n| `--path name=value`   | Path parameters. Repeat for multiple path params.                          |\n| `--query name=value`  | Query parameters. Repeat for filters and pagination.                       |\n| `--header name=value` | Headers accepted by the operation. Repeat for multiple headers.            |\n| `--idempotency-key`   | Shortcut for `Idempotency-Key`. Works only when the operation supports it. |\n| `--if-match`          | Shortcut for `If-Match`. Works only when the operation supports it.        |\n| `--if-none-match`     | Shortcut for `If-None-Match`. Works only when the operation supports it.   |\n| `--json`              | Machine-readable output.                                                   |\n\n`--path`, `--query`, and `--header` require `name=value`. Booleans use `true` or `false`. Repeat an array-valued parameter rather than comma-joining it.\n\nPass either `--body` or `--body-file`, not both.\n\nUse `sendmux-attachments` for attachment-heavy flows and size/token trade-offs.\n\n## Examples\n\nCreate a domain:\n\n```bash\nsendmux management:create-domain \\\n  --profile default \\\n  --idempotency-key \"$IDEMPOTENCY_KEY\" \\\n  --body '{\"domain\":\"example.com\",\"mode\":\"send_receive\"}' \\\n  --json\n```\n\nGet domain DNS records:\n\n```bash\nsendmux management:get-domain-zone-file \\\n  --profile default \\\n  --path public_id=mdom_abc \\\n  --json\n```\n\nSearch a mailbox without reading full messages:\n\n```bash\nsendmux mailbox:search-message-snippets \\\n  --profile mailbox \\\n  --query q=invoice \\\n  --query is_unread=true \\\n  --query limit=10 \\\n  --json\n```\n\nBatch-read selected mailbox messages:\n\n```bash\nsendmux mailbox:batch-get-messages \\\n  --profile mailbox \\\n  --body '{\n    \"ids\": [\"eml_abc\", \"eml_def\"],\n    \"body_mode\": \"clean_json\",\n    \"max_body_chars\": 4000\n  }' \\\n  --json\n```\n\nSend a batch:\n\n```bash\nsendmux sending:send:batch \\\n  --profile sending \\\n  --idempotency-key \"$IDEMPOTENCY_KEY\" \\\n  --body-file ./messages.json \\\n  --json\n```\n\nSend through the Sending API with a local attachment:\n\n```bash\nsendmux sending:send \\\n  --profile sending \\\n  --idempotency-key \"$IDEMPOTENCY_KEY\" \\\n  --attach ./report.pdf \\\n  --body '{\"from\":{\"email\":\"sender@example.com\"},\"to\":{\"email\":\"user@example.com\"},\"subject\":\"Report\",\"html_body\":\"<p>Attached.</p>\"}' \\\n  --json\n```\n\n`sending:send --attach` uploads the file first and injects an `attachment_id` reference; it does not place base64 in the send body.\n\nUpload a Sending attachment separately:\n\n```bash\nsendmux sending:upload-attachment \\\n  --profile sending \\\n  --body-file ./report.pdf \\\n  --query filename=report.pdf \\\n  --query content_type=application/pdf \\\n  --json\n```\n\nSend a mailbox message with a local attachment:\n\n```bash\nsendmux mailbox:send-message \\\n  --profile mailbox \\\n  --idempotency-key \"$IDEMPOTENCY_KEY\" \\\n  --attach ./report.pdf \\\n  --body '{\"to\":[{\"email\":\"user@example.com\",\"name\":null}],\"subject\":\"Report\",\"text_body\":\"Attached.\"}' \\\n  --json\n```\n\nMailbox attachment upload commands share the 7,500,000 byte per-attachment cap. For larger files, split the file or host it externally and send a link.\n\nUpload a mailbox attachment by presigned URL:\n\n```bash\nsendmux mailbox:upload-attachment \\\n  --profile mailbox \\\n  --file ./report.pdf \\\n  --via-presigned \\\n  --json\n```\n\nPoll one unchanged-safe delivery log:\n\n```bash\nsendmux management:get-email-log \\\n  --profile default \\\n  --path public_id=dlog_abc \\\n  --if-none-match \"$ETAG\" \\\n  --json\n```\n\n## Routing\n\n- First setup/auth check: `sendmux-getting-started`.\n- Sending strategy and body shape: `sendmux-send-email`.\n- Attachment file paths and presigned upload/download: `sendmux-attachments`.\n- Mailbox read, search, sync, triage, or reply: `sendmux-mailbox-agent`.\n- Account-level management strategy: `sendmux-management`.\n- MCP connection setup: `sendmux-mcp-setup`.\n- Cheapest-call doctrine: `sendmux-token-efficient-usage`.\n\nFile v1.0.7:_meta.json\n\n{\n  \"ownerId\": \"kn77z51yqhw8mt9vjfkpt8w74989rfb3\",\n  \"slug\": \"sendmux-cli\",\n  \"version\": \"1.0.7\",\n  \"publishedAt\": 1788258999024\n}\n\nFile v1.0.7:skill-card.md\n\n## Description:\n\nUse the Sendmux CLI for durable agent inbox registration, owner invites, profiles, and terminal-driven Management, Mailbox, and Sending workflows.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[sendmux.ai](https://clawhub.ai/user/sendmux.ai)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and operators use this skill to configure Sendmux CLI profiles, register durable agent inboxes, and run Management, Mailbox, and Sending workflows from a terminal.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: API keys and mailbox credentials may grant access to account, mailbox, or sending workflows.\n\nMitigation: Use scoped mailbox or agent tokens where possible, avoid pasting secrets into chat, and reserve root keys for management commands.\n\nRisk: The skill can guide actions that send mail or change account resources.\n\nMitigation: Require explicit confirmation for destructive or externally visible actions, and prefer idempotency keys and --json output for auditable CLI runs.\n\nRisk: Durable agent inbox profiles can retain mailbox read access while the registration remains active.\n\nMitigation: Review profile storage and revocation behavior before registering a durable agent inbox; use full registration revocation when read access and delegated tokens must be removed.\n\n## Reference(s):\n\n- [ClawHub skill page](https://clawhub.ai/sendmux.ai/skills/sendmux-cli)\n- [Sendmux skills homepage](https://github.com/Sendmux/skills)\n\n## Skill Output:\n\n**Output Type(s):** [guidance, shell commands, configuration]\n\n**Output Format:** [Markdown with inline shell commands and JSON-oriented CLI examples]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [CLI examples favor --json for agent-readable output.]\n\n## Skill Version(s):\n\n1.0.7 (source: server release metadata)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v1.0.6: 3 files, 5468 bytes\n\nFiles: skill-card.md (2083b), SKILL.md (12279b), _meta.json (130b)\n\nFile v1.0.6:SKILL.md\n\n---\nname: \"sendmux-cli\"\ndescription: \"Use the Sendmux CLI for durable agent inbox registration, owner invites, profiles, and terminal-driven Management, Mailbox, and Sending workflows.\"\nversion: \"1.4.1\"\nmetadata:\n  openclaw:\n    skillKey: \"sendmux-cli\"\n    homepage: \"https://github.com/Sendmux/skills\"\n    primaryEnv: \"SENDMUX_API_KEY\"\n    envVars:\n      - name: \"SENDMUX_API_KEY\"\n        required: false\n        description: \"Optional Sendmux API key or scoped agent token used by CLI, SDK, HTTP, or MCP examples.\"\n      - name: \"SENDMUX_BASE_URL\"\n        required: false\n        description: \"Optional Sendmux API base URL override for CLI examples.\"\n      - name: \"SENDMUX_MBX_KEY\"\n        required: false\n        description: \"Optional Sendmux mailbox key for Mailbox and send-capable mailbox workflows.\"\n      - name: \"SENDMUX_PROFILE\"\n        required: false\n        description: \"Optional Sendmux CLI profile name.\"\n      - name: \"SENDMUX_ROOT_KEY\"\n        required: false\n        description: \"Optional Sendmux root key for account-level Management API setup.\"\n    install:\n      - kind: \"node\"\n        package: \"@sendmux/cli\"\n        bins:\n          - \"sendmux\"\n---\n\n# Sendmux CLI\n\n## ClawHub account note\n\nThis ClawHub skill connects OpenClaw agents to Sendmux. Some workflows require a Sendmux account and an appropriate Sendmux API key or agent token. Sendmux account usage is external to ClawHub; do not ask users to paste secrets into chat.\n\nUse this skill when the terminal is the right Sendmux surface.\n\n## Boundaries\n\n- Do not ask the user to paste API keys.\n- Use `smx_root_` keys only for `management:*` commands.\n- Use `smx_mbx_` keys or scoped `smx_agent_` tokens for `mailbox:*` commands.\n- Durable agent profiles can read and receive mail while active, but cannot send until an invited owner accepts and approves sending.\n- After owner approval, `sending:*` commands with an agent profile automatically exchange and cache a one-hour delegated token.\n- Do not run destructive commands without explicit confirmation.\n- Use `--json` for agent-readable output.\n- Prefer task-specific Sendmux skills when the user needs strategy; use this skill for exact CLI mechanics.\n\n## Install\n\n```bash\nnpm install -g @sendmux/cli\nsendmux --help\n```\n\nThe package exposes the `sendmux` binary.\n\n## Agent inbox onboarding\n\nNo existing Sendmux account or API key is required:\n\n```bash\nsendmux agent:register my-agent \\\n  --mailbox-local-part my-agent \\\n  --client-name \"My agent\" \\\n  --default \\\n  --json\n```\n\nAdd `--owner-email owner@example.com` to invite the owner during registration. Otherwise invite later:\n\n```bash\nsendmux agent:invite-owner owner@example.com --profile my-agent --json\n```\n\nThe CLI persists registration idempotency before the network request, stores the durable credential in the local profile with restricted permissions, never prints it, reloads it from disk, and waits up to 10 minutes for readiness. Rerun registration with the same profile and options to resume safely.\n\nUse the profile for later reads:\n\n```bash\nsendmux mailbox:messages:list --profile my-agent --query limit=25 --json\n```\n\nRead/receive access has no expiry date while the registration remains active. Sending remains blocked until the owner accepts and approves it. After approval, a command such as `sending:send --profile my-agent` automatically exchanges the durable credential for a one-hour `email.send` token and caches it until near expiry. Full registration revocation removes read access and every delegated token.\n\nThe inbox is capped at 500 MiB before approval. Enabling owner-approved sending first raises it to at least 5 GiB. Later send revocation leaves that storage allocation unchanged.\n\n## Profiles\n\nCreate separate profiles for root and mailbox keys.\n\n```bash\nsendmux profiles:set default --api-key \"$SENDMUX_ROOT_KEY\" --default --json\nsendmux profiles:set mailbox --api-key \"$SENDMUX_MBX_KEY\" --json\nsendmux profiles:set sending --api-key \"$SENDMUX_MBX_KEY\" --json\nsendmux profiles:list --json\nsendmux profiles:show default --json\n```\n\nProfile reads mask stored API keys and never reveal agent credentials. `profiles:set` reports `key_kind` as `root` or `mailbox`; `agent:register` creates a discriminated agent profile.\n\nAuthentication resolution:\n\n1. `--api-key`, then `SENDMUX_API_KEY`.\n2. If no direct key is present, `--profile` / `-p`, then `SENDMUX_PROFILE`, then the configured default profile.\n3. Base URL comes from `--base-url`, then `SENDMUX_BASE_URL`, then the selected profile.\n\n## Preflight\n\nThe CLI infers key kind from the prefix before sending a request.\n\n| Command surface | Required key                                                                      |\n| --------------- | --------------------------------------------------------------------------------- |\n| `management:*`  | `smx_root_`                                                                       |\n| `mailbox:*`     | `smx_mbx_` or scoped `smx_agent_`                                                 |\n| `sending:*`     | Send-capable `smx_mbx_` key or owner-approved Sending-resource `smx_agent_` token |\n\nFor an agent profile, `mailbox:*` uses the durable read credential. `sending:*` obtains a delegated token only after owner approval. `management:*` rejects agent profiles before the request.\n\nWrong-key examples fail before network:\n\n```text\nCommand requires a root API key, but --api-key contains a mailbox API key.\nCommand requires a send-capable `smx_mbx_` key or owner-approved Sending-resource `smx_agent_` token, but --api-key contains a root API key.\n```\n\n## Command catalogue\n\nThe CLI exposes generated operation commands:\n\n| Surface    | Count | Examples                                                                                                                                                   |\n| ---------- | ----: | ---------------------------------------------------------------------------------------------------------------------------------------------------------- |\n| Management |    53 | `management:domains:list`, `management:create-domain`, `management:create-mailbox`, `management:get-spend-summary`, `management:create-webhook`            |\n| Mailbox    |    41 | `mailbox:search-message-snippets`, `mailbox:batch-get-messages`, `mailbox:query-message-changes`, `mailbox:send-message`, `mailbox:list-granted-mailboxes` |\n| Sending    |     7 | `sending:get-open-api-spec`, `sending:send`, `sending:send:batch`, `sending:upload-attachment`, `sending:create-attachment-upload`, `sending:complete-attachment-upload`, `sending:get-attachment` |\n| Profiles   |     3 | `profiles:list`, `profiles:set`, `profiles:show`                                                                                                           |\n| Agent      |     2 | `agent:register`, `agent:invite-owner`                                                                                                                      |\n\nUse command-level help to discover accepted path, query, header, and body fields:\n\n```bash\nsendmux management:create-domain --help\nsendmux mailbox:search-message-snippets --help\nsendmux sending:send:batch --help\nsendmux sending:upload-attachment --help\n```\n\n## Operation flags\n\nOperation commands share these flags:\n\n| Flag                  | Use                                                                        |\n| --------------------- | -------------------------------------------------------------------------- |\n| `--api-key`           | Direct key; overrides profile/env profile lookup.                          |\n| `--base-url`          | Override API base URL.                                                     |\n| `--profile`, `-p`     | Select a local profile.                                                    |\n| `--body`              | Inline JSON request body, or text bytes for byte-oriented operations.      |\n| `--body-file`         | Read a JSON request body or byte payload from a file.                      |\n| `--attach`            | Attach a local file to supported send commands. Repeat for multiple files. |\n| `--file`              | Read a local file for mailbox attachment upload convenience commands.       |\n| `--via-presigned`     | Upload a mailbox `--file` through a short-lived signed URL instead of API bytes. |\n| `--content-type`      | Override inferred MIME type for `--attach` or `--file`.                    |\n| `--path name=value`   | Path parameters. Repeat for multiple path params.                          |\n| `--query name=value`  | Query parameters. Repeat for filters and pagination.                       |\n| `--header name=value` | Headers accepted by the operation. Repeat for multiple headers.            |\n| `--idempotency-key`   | Shortcut for `Idempotency-Key`. Works only when the operation supports it. |\n| `--if-match`          | Shortcut for `If-Match`. Works only when the operation supports it.        |\n| `--if-none-match`     | Shortcut for `If-None-Match`. Works only when the operation supports it.   |\n| `--json`              | Machine-readable output.                                                   |\n\n`--path`, `--query`, and `--header` require `name=value`. Booleans use `true` or `false`. Repeat an array-valued parameter rather than comma-joining it.\n\nPass either `--body` or `--body-file`, not both.\n\nUse `sendmux-attachments` for attachment-heavy flows and size/token trade-offs.\n\n## Examples\n\nCreate a domain:\n\n```bash\nsendmux management:create-domain \\\n  --profile default \\\n  --idempotency-key \"$IDEMPOTENCY_KEY\" \\\n  --body '{\"domain\":\"example.com\",\"mode\":\"send_receive\"}' \\\n  --json\n```\n\nGet domain DNS records:\n\n```bash\nsendmux management:get-domain-zone-file \\\n  --profile default \\\n  --path public_id=mdom_abc \\\n  --json\n```\n\nSearch a mailbox without reading full messages:\n\n```bash\nsendmux mailbox:search-message-snippets \\\n  --profile mailbox \\\n  --query q=invoice \\\n  --query is_unread=true \\\n  --query limit=10 \\\n  --json\n```\n\nBatch-read selected mailbox messages:\n\n```bash\nsendmux mailbox:batch-get-messages \\\n  --profile mailbox \\\n  --body '{\n    \"ids\": [\"eml_abc\", \"eml_def\"],\n    \"body_mode\": \"clean_json\",\n    \"max_body_chars\": 4000\n  }' \\\n  --json\n```\n\nSend a batch:\n\n```bash\nsendmux sending:send:batch \\\n  --profile sending \\\n  --idempotency-key \"$IDEMPOTENCY_KEY\" \\\n  --body-file ./messages.json \\\n  --json\n```\n\nSend through the Sending API with a local attachment:\n\n```bash\nsendmux sending:send \\\n  --profile sending \\\n  --idempotency-key \"$IDEMPOTENCY_KEY\" \\\n  --attach ./report.pdf \\\n  --body '{\"from\":{\"email\":\"sender@example.com\"},\"to\":{\"email\":\"user@example.com\"},\"subject\":\"Report\",\"html_body\":\"<p>Attached.</p>\"}' \\\n  --json\n```\n\n`sending:send --attach` uploads the file first and injects an `attachment_id` reference; it does not place base64 in the send body.\n\nUpload a Sending attachment separately:\n\n```bash\nsendmux sending:upload-attachment \\\n  --profile sending \\\n  --body-file ./report.pdf \\\n  --query filename=report.pdf \\\n  --query content_type=application/pdf \\\n  --json\n```\n\nSend a mailbox message with a local attachment:\n\n```bash\nsendmux mailbox:send-message \\\n  --profile mailbox \\\n  --idempotency-key \"$IDEMPOTENCY_KEY\" \\\n  --attach ./report.pdf \\\n  --body '{\"to\":[{\"email\":\"user@example.com\",\"name\":null}],\"subject\":\"Report\",\"text_body\":\"Attached.\"}' \\\n  --json\n```\n\nMailbox attachment upload commands share the 7,500,000 byte per-attachment cap. For larger files, split the file or host it externally and send a link.\n\nUpload a mailbox attachment by presigned URL:\n\n```bash\nsendmux mailbox:upload-attachment \\\n  --profile mailbox \\\n  --file ./report.pdf \\\n  --via-presigned \\\n  --json\n```\n\nPoll one unchanged-safe delivery log:\n\n```bash\nsendmux management:get-email-log \\\n  --profile default \\\n  --path public_id=dlog_abc \\\n  --if-none-match \"$ETAG\" \\\n  --json\n```\n\n## Routing\n\n- First setup/auth check: `sendmux-getting-started`.\n- Sending strategy and body shape: `sendmux-send-email`.\n- Attachment file paths and presigned upload/download: `sendmux-attachments`.\n- Mailbox read, search, sync, triage, or reply: `sendmux-mailbox-agent`.\n- Account-level management strategy: `sendmux-management`.\n- MCP connection setup: `sendmux-mcp-setup`.\n- Cheapest-call doctrine: `sendmux-token-efficient-usage`.\n\nFile v1.0.6:_meta.json\n\n{\n  \"ownerId\": \"kn77z51yqhw8mt9vjfkpt8w74989rfb3\",\n  \"slug\": \"sendmux-cli\",\n  \"version\": \"1.0.6\",\n  \"publishedAt\": 1788258460458\n}\n\nFile v1.0.6:skill-card.md\n\n## Description:\n\nUse the Sendmux CLI for durable agent inbox registration, owner invites, profiles, and terminal-driven Management, Mailbox, and Sending workflows.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[sendmux.ai](https://clawhub.ai/user/sendmux.ai)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and external agent operators use this skill to install and operate the Sendmux CLI for mailbox registration, local profiles, account management, mailbox access, and sending workflows from a terminal.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: An agent may use credentials with broader access than needed for the requested Sendmux workflow.\n\nMitigation: Use scoped mailbox or agent tokens where possible and reserve root keys for account-level management tasks.\n\nRisk: Email sending or account-resource commands can create external side effects.\n\nMitigation: Review commands that send email or change account resources before execution, and require explicit confirmation for destructive actions.\n\nRisk: Secrets may be exposed if copied into chat or logs.\n\nMitigation: Do not ask users to paste API keys; rely on environment variables or local Sendmux profiles.\n\n## Reference(s):\n\n- [ClawHub sendmux-cli skill page](https://clawhub.ai/sendmux.ai/skills/sendmux-cli)\n- [Sendmux skills repository](https://github.com/Sendmux/skills)\n\n## Skill Output:\n\n**Output Type(s):** [Shell commands, Configuration, Guidance, JSON]\n\n**Output Format:** [Markdown with inline bash commands and JSON-oriented CLI examples]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Examples prefer --json for agent-readable terminal output.]\n\n## Skill Version(s):\n\n1.0.6 (source: server release metadata; artifact frontmatter says 1.4.1)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v1.0.5: 3 files, 5442 bytes\n\nFiles: skill-card.md (2109b), SKILL.md (12270b), _meta.json (130b)\n\nFile v1.0.5:SKILL.md\n\n---\nname: \"sendmux-cli\"\ndescription: \"Use the Sendmux CLI for durable agent inbox registration, owner invites, profiles, and terminal-driven Management, Mailbox, and Sending workflows.\"\nversion: \"1.4.0\"\nmetadata:\n  openclaw:\n    skillKey: \"sendmux-cli\"\n    homepage: \"https://github.com/Sendmux/skills\"\n    primaryEnv: \"SENDMUX_API_KEY\"\n    envVars:\n      - name: \"SENDMUX_API_KEY\"\n        required: false\n        description: \"Optional Sendmux API key or scoped agent token used by CLI, SDK, HTTP, or MCP examples.\"\n      - name: \"SENDMUX_BASE_URL\"\n        required: false\n        description: \"Optional Sendmux API base URL override for CLI examples.\"\n      - name: \"SENDMUX_MBX_KEY\"\n        required: false\n        description: \"Optional Sendmux mailbox key for Mailbox and send-capable mailbox workflows.\"\n      - name: \"SENDMUX_PROFILE\"\n        required: false\n        description: \"Optional Sendmux CLI profile name.\"\n      - name: \"SENDMUX_ROOT_KEY\"\n        required: false\n        description: \"Optional Sendmux root key for account-level Management API setup.\"\n    install:\n      - kind: \"node\"\n        package: \"@sendmux/cli\"\n        bins:\n          - \"sendmux\"\n---\n\n# Sendmux CLI\n\n## ClawHub account note\n\nThis ClawHub skill connects OpenClaw agents to Sendmux. Some workflows require a Sendmux account and an appropriate Sendmux API key or agent token. Sendmux account usage is external to ClawHub; do not ask users to paste secrets into chat.\n\nUse this skill when the terminal is the right Sendmux surface.\n\n## Boundaries\n\n- Do not ask the user to paste API keys.\n- Use `smx_root_` keys only for `management:*` commands.\n- Use `smx_mbx_` keys or scoped `smx_agent_` tokens for `mailbox:*` commands.\n- Durable agent profiles can read and receive mail while active, but cannot send until an invited owner accepts and approves sending.\n- After owner approval, `sending:*` commands with an agent profile automatically exchange and cache a one-hour delegated token.\n- Do not run destructive commands without explicit confirmation.\n- Use `--json` for agent-readable output.\n- Prefer task-specific Sendmux skills when the user needs strategy; use this skill for exact CLI mechanics.\n\n## Install\n\n```bash\nnpm install -g @sendmux/cli\nsendmux --help\n```\n\nThe package exposes the `sendmux` binary.\n\n## Agent inbox onboarding\n\nNo existing Sendmux account or API key is required:\n\n```bash\nsendmux agent:register my-agent \\\n  --mailbox-local-part my-agent \\\n  --client-name \"My agent\" \\\n  --default \\\n  --json\n```\n\nAdd `--owner-email owner@example.com` to invite the owner during registration. Otherwise invite later:\n\n```bash\nsendmux agent:invite-owner owner@example.com --profile my-agent --json\n```\n\nThe CLI persists registration idempotency before the network request, stores the durable credential in the local profile with restricted permissions, never prints it, reloads it from disk, and waits up to 10 minutes for readiness. Rerun registration with the same profile and options to resume safely.\n\nUse the profile for later reads:\n\n```bash\nsendmux mailbox:messages:list --profile my-agent --query limit=25 --json\n```\n\nRead/receive access has no expiry date while the registration remains active. Sending remains blocked until the owner accepts and approves it. After approval, a command such as `sending:send --profile my-agent` automatically exchanges the durable credential for a one-hour `email.send` token and caches it until near expiry. Full registration revocation removes read access and every delegated token.\n\nThe inbox is capped at 500 MiB before approval. Enabling owner-approved sending first raises it to 5 GiB. Later send revocation leaves that storage allocation unchanged.\n\n## Profiles\n\nCreate separate profiles for root and mailbox keys.\n\n```bash\nsendmux profiles:set default --api-key \"$SENDMUX_ROOT_KEY\" --default --json\nsendmux profiles:set mailbox --api-key \"$SENDMUX_MBX_KEY\" --json\nsendmux profiles:set sending --api-key \"$SENDMUX_MBX_KEY\" --json\nsendmux profiles:list --json\nsendmux profiles:show default --json\n```\n\nProfile reads mask stored API keys and never reveal agent credentials. `profiles:set` reports `key_kind` as `root` or `mailbox`; `agent:register` creates a discriminated agent profile.\n\nAuthentication resolution:\n\n1. `--api-key`, then `SENDMUX_API_KEY`.\n2. If no direct key is present, `--profile` / `-p`, then `SENDMUX_PROFILE`, then the configured default profile.\n3. Base URL comes from `--base-url`, then `SENDMUX_BASE_URL`, then the selected profile.\n\n## Preflight\n\nThe CLI infers key kind from the prefix before sending a request.\n\n| Command surface | Required key                                                                      |\n| --------------- | --------------------------------------------------------------------------------- |\n| `management:*`  | `smx_root_`                                                                       |\n| `mailbox:*`     | `smx_mbx_` or scoped `smx_agent_`                                                 |\n| `sending:*`     | Send-capable `smx_mbx_` key or owner-approved Sending-resource `smx_agent_` token |\n\nFor an agent profile, `mailbox:*` uses the durable read credential. `sending:*` obtains a delegated token only after owner approval. `management:*` rejects agent profiles before the request.\n\nWrong-key examples fail before network:\n\n```text\nCommand requires a root API key, but --api-key contains a mailbox API key.\nCommand requires a send-capable `smx_mbx_` key or owner-approved Sending-resource `smx_agent_` token, but --api-key contains a root API key.\n```\n\n## Command catalogue\n\nThe CLI exposes generated operation commands:\n\n| Surface    | Count | Examples                                                                                                                                                   |\n| ---------- | ----: | ---------------------------------------------------------------------------------------------------------------------------------------------------------- |\n| Management |    53 | `management:domains:list`, `management:create-domain`, `management:create-mailbox`, `management:get-spend-summary`, `management:create-webhook`            |\n| Mailbox    |    41 | `mailbox:search-message-snippets`, `mailbox:batch-get-messages`, `mailbox:query-message-changes`, `mailbox:send-message`, `mailbox:list-granted-mailboxes` |\n| Sending    |     7 | `sending:get-open-api-spec`, `sending:send`, `sending:send:batch`, `sending:upload-attachment`, `sending:create-attachment-upload`, `sending:complete-attachment-upload`, `sending:get-attachment` |\n| Profiles   |     3 | `profiles:list`, `profiles:set`, `profiles:show`                                                                                                           |\n| Agent      |     2 | `agent:register`, `agent:invite-owner`                                                                                                                      |\n\nUse command-level help to discover accepted path, query, header, and body fields:\n\n```bash\nsendmux management:create-domain --help\nsendmux mailbox:search-message-snippets --help\nsendmux sending:send:batch --help\nsendmux sending:upload-attachment --help\n```\n\n## Operation flags\n\nOperation commands share these flags:\n\n| Flag                  | Use                                                                        |\n| --------------------- | -------------------------------------------------------------------------- |\n| `--api-key`           | Direct key; overrides profile/env profile lookup.                          |\n| `--base-url`          | Override API base URL.                                                     |\n| `--profile`, `-p`     | Select a local profile.                                                    |\n| `--body`              | Inline JSON request body, or text bytes for byte-oriented operations.      |\n| `--body-file`         | Read a JSON request body or byte payload from a file.                      |\n| `--attach`            | Attach a local file to supported send commands. Repeat for multiple files. |\n| `--file`              | Read a local file for mailbox attachment upload convenience commands.       |\n| `--via-presigned`     | Upload a mailbox `--file` through a short-lived signed URL instead of API bytes. |\n| `--content-type`      | Override inferred MIME type for `--attach` or `--file`.                    |\n| `--path name=value`   | Path parameters. Repeat for multiple path params.                          |\n| `--query name=value`  | Query parameters. Repeat for filters and pagination.                       |\n| `--header name=value` | Headers accepted by the operation. Repeat for multiple headers.            |\n| `--idempotency-key`   | Shortcut for `Idempotency-Key`. Works only when the operation supports it. |\n| `--if-match`          | Shortcut for `If-Match`. Works only when the operation supports it.        |\n| `--if-none-match`     | Shortcut for `If-None-Match`. Works only when the operation supports it.   |\n| `--json`              | Machine-readable output.                                                   |\n\n`--path`, `--query`, and `--header` require `name=value`. Booleans use `true` or `false`. Repeat an array-valued parameter rather than comma-joining it.\n\nPass either `--body` or `--body-file`, not both.\n\nUse `sendmux-attachments` for attachment-heavy flows and size/token trade-offs.\n\n## Examples\n\nCreate a domain:\n\n```bash\nsendmux management:create-domain \\\n  --profile default \\\n  --idempotency-key \"$IDEMPOTENCY_KEY\" \\\n  --body '{\"domain\":\"example.com\",\"mode\":\"send_receive\"}' \\\n  --json\n```\n\nGet domain DNS records:\n\n```bash\nsendmux management:get-domain-zone-file \\\n  --profile default \\\n  --path public_id=mdom_abc \\\n  --json\n```\n\nSearch a mailbox without reading full messages:\n\n```bash\nsendmux mailbox:search-message-snippets \\\n  --profile mailbox \\\n  --query q=invoice \\\n  --query is_unread=true \\\n  --query limit=10 \\\n  --json\n```\n\nBatch-read selected mailbox messages:\n\n```bash\nsendmux mailbox:batch-get-messages \\\n  --profile mailbox \\\n  --body '{\n    \"ids\": [\"eml_abc\", \"eml_def\"],\n    \"body_mode\": \"clean_json\",\n    \"max_body_chars\": 4000\n  }' \\\n  --json\n```\n\nSend a batch:\n\n```bash\nsendmux sending:send:batch \\\n  --profile sending \\\n  --idempotency-key \"$IDEMPOTENCY_KEY\" \\\n  --body-file ./messages.json \\\n  --json\n```\n\nSend through the Sending API with a local attachment:\n\n```bash\nsendmux sending:send \\\n  --profile sending \\\n  --idempotency-key \"$IDEMPOTENCY_KEY\" \\\n  --attach ./report.pdf \\\n  --body '{\"from\":{\"email\":\"sender@example.com\"},\"to\":{\"email\":\"user@example.com\"},\"subject\":\"Report\",\"html_body\":\"<p>Attached.</p>\"}' \\\n  --json\n```\n\n`sending:send --attach` uploads the file first and injects an `attachment_id` reference; it does not place base64 in the send body.\n\nUpload a Sending attachment separately:\n\n```bash\nsendmux sending:upload-attachment \\\n  --profile sending \\\n  --body-file ./report.pdf \\\n  --query filename=report.pdf \\\n  --query content_type=application/pdf \\\n  --json\n```\n\nSend a mailbox message with a local attachment:\n\n```bash\nsendmux mailbox:send-message \\\n  --profile mailbox \\\n  --idempotency-key \"$IDEMPOTENCY_KEY\" \\\n  --attach ./report.pdf \\\n  --body '{\"to\":[{\"email\":\"user@example.com\",\"name\":null}],\"subject\":\"Report\",\"text_body\":\"Attached.\"}' \\\n  --json\n```\n\nMailbox attachment upload commands share the 7,500,000 byte per-attachment cap. For larger files, split the file or host it externally and send a link.\n\nUpload a mailbox attachment by presigned URL:\n\n```bash\nsendmux mailbox:upload-attachment \\\n  --profile mailbox \\\n  --file ./report.pdf \\\n  --via-presigned \\\n  --json\n```\n\nPoll one unchanged-safe delivery log:\n\n```bash\nsendmux management:get-email-log \\\n  --profile default \\\n  --path public_id=dlog_abc \\\n  --if-none-match \"$ETAG\" \\\n  --json\n```\n\n## Routing\n\n- First setup/auth check: `sendmux-getting-started`.\n- Sending strategy and body shape: `sendmux-send-email`.\n- Attachment file paths and presigned upload/download: `sendmux-attachments`.\n- Mailbox read, search, sync, triage, or reply: `sendmux-mailbox-agent`.\n- Account-level management strategy: `sendmux-management`.\n- MCP connection setup: `sendmux-mcp-setup`.\n- Cheapest-call doctrine: `sendmux-token-efficient-usage`.\n\nFile v1.0.5:_meta.json\n\n{\n  \"ownerId\": \"kn77z51yqhw8mt9vjfkpt8w74989rfb3\",\n  \"slug\": \"sendmux-cli\",\n  \"version\": \"1.0.5\",\n  \"publishedAt\": 1788242692326\n}\n\nFile v1.0.5:skill-card.md\n\n## Description:\n\nUse the Sendmux CLI for durable agent inbox registration, owner invites, profiles, and terminal-driven Management, Mailbox, and Sending workflows.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[sendmux.ai](https://clawhub.ai/user/sendmux.ai)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nExternal developers and agent operators use this skill to let an agent operate Sendmux from the terminal for inbox registration, owner invites, profile setup, mailbox access, sending, attachments, and account-management workflows.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: The skill can guide an agent through Sendmux email, mailbox, profile, sending, attachment, and account-management operations that may affect external systems.\n\nMitigation: Install only when the agent is intended to operate Sendmux from the terminal, and review send, upload, profile, and destructive operations before execution.\n\nRisk: Sendmux credentials and local profiles can grant sensitive access, and profiles may persist credentials for later use.\n\nMitigation: Use scoped mailbox or agent tokens where possible, reserve root keys for account-management tasks, and do not ask users to paste secrets into chat.\n\n## Reference(s):\n\n- [Sendmux skills homepage](https://github.com/Sendmux/skills)\n- [ClawHub skill page](https://clawhub.ai/sendmux.ai/skills/sendmux-cli)\n\n## Skill Output:\n\n**Output Type(s):** [Text, Markdown, Shell commands, Configuration instructions, Guidance]\n\n**Output Format:** [Markdown with bash, text, and JSON command examples]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Uses --json for agent-readable Sendmux CLI output when appropriate.]\n\n## Skill Version(s):\n\n1.0.5 (source: server release metadata; artifact frontmatter reports 1.4.0)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v1.0.4: 3 files, 4702 bytes\n\nFiles: skill-card.md (1989b), SKILL.md (10396b), _meta.json (130b)\n\nFile v1.0.4:SKILL.md\n\n---\nname: \"sendmux-cli\"\ndescription: \"Use the Sendmux CLI for terminal-driven Management, Mailbox, and Sending workflows with JSON output and scoped credentials.\"\nversion: \"1.3.0\"\nmetadata:\n  openclaw:\n    skillKey: \"sendmux-cli\"\n    homepage: \"https://github.com/Sendmux/skills\"\n    primaryEnv: \"SENDMUX_API_KEY\"\n    envVars:\n      - name: \"SENDMUX_API_KEY\"\n        required: false\n        description: \"Optional Sendmux API key or scoped agent token used by CLI, SDK, HTTP, or MCP examples.\"\n      - name: \"SENDMUX_BASE_URL\"\n        required: false\n        description: \"Optional Sendmux API base URL override for CLI examples.\"\n      - name: \"SENDMUX_MBX_KEY\"\n        required: false\n        description: \"Optional Sendmux mailbox key for Mailbox and send-capable mailbox workflows.\"\n      - name: \"SENDMUX_PROFILE\"\n        required: false\n        description: \"Optional Sendmux CLI profile name.\"\n      - name: \"SENDMUX_ROOT_KEY\"\n        required: false\n        description: \"Optional Sendmux root key for account-level Management API setup.\"\n    install:\n      - kind: \"node\"\n        package: \"@sendmux/cli\"\n        bins:\n          - \"sendmux\"\n---\n\n# Sendmux CLI\n\n## ClawHub account note\n\nThis ClawHub skill connects OpenClaw agents to Sendmux. Some workflows require a Sendmux account and an appropriate Sendmux API key or agent token. Sendmux account usage is external to ClawHub; do not ask users to paste secrets into chat.\n\nUse this skill when the terminal is the right Sendmux surface.\n\n## Boundaries\n\n- Do not ask the user to paste API keys.\n- Use `smx_root_` keys only for `management:*` commands.\n- Use `smx_mbx_` keys or scoped `smx_agent_` tokens for `mailbox:*` commands.\n- Use a send-capable `smx_mbx_` key or owner-approved Sending-resource `smx_agent_` token for `sending:*` commands. Pre-claim `smx_agent_` tokens cannot send.\n- Do not run destructive commands without explicit confirmation.\n- Use `--json` for agent-readable output.\n- Prefer task-specific Sendmux skills when the user needs strategy; use this skill for exact CLI mechanics.\n\n## Install\n\n```bash\nnpm install -g @sendmux/cli\nsendmux --help\n```\n\nThe package exposes the `sendmux` binary.\nUse the latest CLI before using `smx_agent_` tokens; older installs may reject that prefix before sending a request.\n\n## Profiles\n\nCreate separate profiles for root and mailbox keys.\n\n```bash\nsendmux profiles:set default --api-key \"$SENDMUX_ROOT_KEY\" --default --json\nsendmux profiles:set mailbox --api-key \"$SENDMUX_MBX_KEY\" --json\nsendmux profiles:set sending --api-key \"$SENDMUX_MBX_KEY\" --json\nsendmux profiles:list --json\nsendmux profiles:show default --json\n```\n\nProfile reads mask stored keys. `profiles:set` reports `key_kind` as `root` or `mailbox`.\n\nAuthentication resolution:\n\n1. `--api-key`, then `SENDMUX_API_KEY`.\n2. If no direct key is present, `--profile` / `-p`, then `SENDMUX_PROFILE`, then the configured default profile.\n3. Base URL comes from `--base-url`, then `SENDMUX_BASE_URL`, then the selected profile.\n\n## Preflight\n\nThe CLI infers key kind from the prefix before sending a request.\n\n| Command surface | Required key                                                                      |\n| --------------- | --------------------------------------------------------------------------------- |\n| `management:*`  | `smx_root_`                                                                       |\n| `mailbox:*`     | `smx_mbx_` or scoped `smx_agent_`                                                 |\n| `sending:*`     | Send-capable `smx_mbx_` key or owner-approved Sending-resource `smx_agent_` token |\n\nWrong-key examples fail before network:\n\n```text\nCommand requires a root API key, but --api-key contains a mailbox API key.\nCommand requires a send-capable `smx_mbx_` key or owner-approved Sending-resource `smx_agent_` token, but --api-key contains a root API key.\n```\n\n## Command catalogue\n\nThe CLI exposes generated operation commands:\n\n| Surface    | Count | Examples                                                                                                                                                   |\n| ---------- | ----: | ---------------------------------------------------------------------------------------------------------------------------------------------------------- |\n| Management |    53 | `management:domains:list`, `management:create-domain`, `management:create-mailbox`, `management:get-spend-summary`, `management:create-webhook`            |\n| Mailbox    |    41 | `mailbox:search-message-snippets`, `mailbox:batch-get-messages`, `mailbox:query-message-changes`, `mailbox:send-message`, `mailbox:list-granted-mailboxes` |\n| Sending    |     7 | `sending:get-open-api-spec`, `sending:send`, `sending:send:batch`, `sending:upload-attachment`, `sending:create-attachment-upload`, `sending:complete-attachment-upload`, `sending:get-attachment` |\n| Profiles   |     3 | `profiles:list`, `profiles:set`, `profiles:show`                                                                                                           |\n\nUse command-level help to discover accepted path, query, header, and body fields:\n\n```bash\nsendmux management:create-domain --help\nsendmux mailbox:search-message-snippets --help\nsendmux sending:send:batch --help\nsendmux sending:upload-attachment --help\n```\n\n## Operation flags\n\nOperation commands share these flags:\n\n| Flag                  | Use                                                                        |\n| --------------------- | -------------------------------------------------------------------------- |\n| `--api-key`           | Direct key; overrides profile/env profile lookup.                          |\n| `--base-url`          | Override API base URL.                                                     |\n| `--profile`, `-p`     | Select a local profile.                                                    |\n| `--body`              | Inline JSON request body, or text bytes for byte-oriented operations.      |\n| `--body-file`         | Read a JSON request body or byte payload from a file.                      |\n| `--attach`            | Attach a local file to supported send commands. Repeat for multiple files. |\n| `--file`              | Read a local file for mailbox attachment upload convenience commands.       |\n| `--via-presigned`     | Upload a mailbox `--file` through a short-lived signed URL instead of API bytes. |\n| `--content-type`      | Override inferred MIME type for `--attach` or `--file`.                    |\n| `--path name=value`   | Path parameters. Repeat for multiple path params.                          |\n| `--query name=value`  | Query parameters. Repeat for filters and pagination.                       |\n| `--header name=value` | Headers accepted by the operation. Repeat for multiple headers.            |\n| `--idempotency-key`   | Shortcut for `Idempotency-Key`. Works only when the operation supports it. |\n| `--if-match`          | Shortcut for `If-Match`. Works only when the operation supports it.        |\n| `--if-none-match`     | Shortcut for `If-None-Match`. Works only when the operation supports it.   |\n| `--json`              | Machine-readable output.                                                   |\n\n`--path`, `--query`, and `--header` require `name=value`. Booleans use `true` or `false`. Repeat an array-valued parameter rather than comma-joining it.\n\nPass either `--body` or `--body-file`, not both.\n\nUse `sendmux-attachments` for attachment-heavy flows and size/token trade-offs.\n\n## Examples\n\nCreate a domain:\n\n```bash\nsendmux management:create-domain \\\n  --profile default \\\n  --idempotency-key \"$IDEMPOTENCY_KEY\" \\\n  --body '{\"domain\":\"example.com\",\"mode\":\"send_receive\"}' \\\n  --json\n```\n\nGet domain DNS records:\n\n```bash\nsendmux management:get-domain-zone-file \\\n  --profile default \\\n  --path public_id=mdom_abc \\\n  --json\n```\n\nSearch a mailbox without reading full messages:\n\n```bash\nsendmux mailbox:search-message-snippets \\\n  --profile mailbox \\\n  --query q=invoice \\\n  --query is_unread=true \\\n  --query limit=10 \\\n  --json\n```\n\nBatch-read selected mailbox messages:\n\n```bash\nsendmux mailbox:batch-get-messages \\\n  --profile mailbox \\\n  --body '{\n    \"ids\": [\"eml_abc\", \"eml_def\"],\n    \"body_mode\": \"clean_json\",\n    \"max_body_chars\": 4000\n  }' \\\n  --json\n```\n\nSend a batch:\n\n```bash\nsendmux sending:send:batch \\\n  --profile sending \\\n  --idempotency-key \"$IDEMPOTENCY_KEY\" \\\n  --body-file ./messages.json \\\n  --json\n```\n\nSend through the Sending API with a local attachment:\n\n```bash\nsendmux sending:send \\\n  --profile sending \\\n  --idempotency-key \"$IDEMPOTENCY_KEY\" \\\n  --attach ./report.pdf \\\n  --body '{\"from\":{\"email\":\"sender@example.com\"},\"to\":{\"email\":\"user@example.com\"},\"subject\":\"Report\",\"html_body\":\"<p>Attached.</p>\"}' \\\n  --json\n```\n\n`sending:send --attach` uploads the file first and injects an `attachment_id` reference; it does not place base64 in the send body.\n\nUpload a Sending attachment separately:\n\n```bash\nsendmux sending:upload-attachment \\\n  --profile sending \\\n  --body-file ./report.pdf \\\n  --query filename=report.pdf \\\n  --query content_type=application/pdf \\\n  --json\n```\n\nSend a mailbox message with a local attachment:\n\n```bash\nsendmux mailbox:send-message \\\n  --profile mailbox \\\n  --idempotency-key \"$IDEMPOTENCY_KEY\" \\\n  --attach ./report.pdf \\\n  --body '{\"to\":[{\"email\":\"user@example.com\",\"name\":null}],\"subject\":\"Report\",\"text_body\":\"Attached.\"}' \\\n  --json\n```\n\nMailbox attachment upload commands share the 7,500,000 byte per-\n\nArchive v1.0.3: 3 files, 4818 bytes\n\nFiles: skill-card.md (2298b), SKILL.md (10396b), _meta.json (130b)","readmeExcerpt":"Skill: sendmux-cli Owner: sendmux.ai Summary: Use the Sendmux CLI for durable agent inbox registration, owner invites, profiles, and terminal-driven Management, Mailbox, and Sending workflows. Tags: latest:1.0.12 Version history: v1.0.12 | 2026-10-07T07:19:18.856Z | auto sendmux-cli 1.0.12 - Documentation updated: SKILL.md modified. - Obsolete or redundant file removed: skill-card.md. - No functional changes to the s","codeSnippets":[],"executableExamples":[{"language":"bash","snippet":"npm install -g @sendmux/cli\nsendmux --help"},{"language":"bash","snippet":"sendmux auth:login work --scope mailbox.read --scope email.send\nsendmux mailbox:get-connection --profile work --json"},{"language":"bash","snippet":"sendmux agent:register my-agent \\\n  --mailbox-local-part my-agent \\\n  --client-name \"My agent\" \\\n  --default \\\n  --json"},{"language":"bash","snippet":"sendmux agent:invite-owner owner@example.com --profile my-agent --json"},{"language":"bash","snippet":"sendmux mailbox:messages:list --profile my-agent --query limit=25 --json"},{"language":"bash","snippet":"SENDMUX_API_KEY=\"$SENDMUX_ROOT_KEY\" sendmux profiles:set default --default --json\nSENDMUX_API_KEY=\"$SENDMUX_MBX_KEY\" sendmux profiles:set mailbox --json\nSENDMUX_API_KEY=\"$SENDMUX_MBX_KEY\" sendmux profiles:set sending --json\nsendmux profiles:list --json\nsendmux profiles:show default --json"}],"parameters":null,"dependencies":[],"permissions":[],"extractedFiles":[{"path":"SKILL.md","content":"---\nname: \"sendmux-cli\"\ndescription: \"Use the Sendmux CLI for durable agent inbox registration, owner invites, profiles, and terminal-driven Management, Mailbox, and Sending workflows.\"\nversion: \"1.7.1\"\nmetadata:\n  openclaw:\n    skillKey: \"sendmux-cli\"\n    homepage: \"https://github.com/Sendmux/skills\"\n    primaryEnv: \"SENDMUX_API_KEY\"\n    envVars:\n      - name: \"SENDMUX_ACCESS_TOKEN\"\n        required: false\n        description: \"Optional externally managed OAuth access token for CLI HTTP requests; the CLI does not refresh it.\"\n      - name: \"SENDMUX_API_KEY\"\n        required: false\n        description: \"Optional Sendmux API key or scoped agent token used by CLI, SDK, HTTP, or MCP examples.\"\n      - name: \"SENDMUX_BASE_URL\"\n        required: false\n        description: \"Optional Sendmux API base URL override for CLI examples.\"\n      - name: \"SENDMUX_MBX_KEY\"\n        required: false\n        description: \"Optional Sendmux mailbox key for Mailbox and send-capable mailbox workflows.\"\n      - name: \"SENDMUX_PROFILE\"\n        required: false\n        description: \"Optional Sendmux CLI profile name.\"\n      - name: \"SENDMUX_ROOT_KEY\"\n        required: false\n        description: \"Optional Sendmux root key for account-level Management API setup.\"\n    install:\n      - kind: \"node\"\n        package: \"@sendmux/cli\"\n        bins:\n          - \"sendmux\"\n---\n\n# Sendmux CLI\n\n## ClawHub account note\n\nThis ClawHub skill connects OpenClaw agents to Sendmux. Some workflows require a Sendmux account and an appropriate Sendmux API key or agent token. Sendmux account usage is external to ClawHub; do not ask users to paste secrets into chat.\n\nUse this skill when the terminal is the right Sendmux surface.\n\n## Boundaries\n\n- Do not ask the user to paste API keys.\n- For API-key profiles, use `smx_root_` for `management:*` and `smx_mbx_` or scoped `smx_agent_` for `mailbox:*`.\n- OAuth profiles require the operation's approved surface, scopes and mailbox access. REST OAuth tokens authenticate HTTP, not SMTP or IMAP.\n- Durable agent profiles can read and receive mail while active, but cannot send until an invited owner accepts and approves sending.\n- After owner approval, `sending:*` commands with an agent profile automatically exchange and cache a one-hour delegated token.\n- Do not run destructive commands without explicit confirmation.\n- Use `--json` for agent-readable output.\n- Prefer task-specific Sendmux skills when the user needs strategy; use this skill for exact CLI mechanics.\n\n## Install\n\n```bash\nnpm install -g @sendmux/cli\nsendmux --help\n```\n\nThe package exposes the `sendmux` binary.\n\n## OAuth login and connection checks\n\nFor an existing user's account, create a new named OAuth profile with the required scopes:\n\n```bash\nsendmux auth:login work --scope mailbox.read --scope email.send\nsendmux mailbox:get-connection --profile work --json\n```\n\nThe CLI opens browser consent and receives the callback on the same computer. `--no-browser` only suppresses automatic browser launch an"},{"path":"_meta.json","content":"{\n  \"ownerId\": \"kn77z51yqhw8mt9vjfkpt8w74989rfb3\",\n  \"slug\": \"sendmux-cli\",\n  \"version\": \"1.0.12\",\n  \"publishedAt\": 1791357558856\n}"},{"path":"skill-card.md","content":"## Description:\n\nUse the Sendmux CLI for durable agent inbox registration, owner invites, profiles, and terminal-driven Management, Mailbox, and Sending workflows.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[sendmux.ai](https://clawhub.ai/user/sendmux.ai)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and agent operators use this skill to set up Sendmux inboxes and profiles, check access, and carry out email, mailbox, and account-management tasks from a terminal.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Credentials for mailbox, sending, or account management could be exposed or granted excessive access.\n\nMitigation: Keep keys in a secret store or environment and use scoped profiles or OAuth where possible; do not paste secrets into chat or command arguments.\n\nRisk: Sending mail or changing account settings can have unintended effects.\n\nMitigation: Review send and account-management commands before execution and confirm destructive actions explicitly.\n\nRisk: Saved profiles can retain access after the task ends.\n\nMitigation: Log out or revoke profiles when access is no longer needed.\n\n## Reference(s):\n\n- [Sendmux CLI skill on ClawHub](https://clawhub.ai/sendmux.ai/skills/sendmux-cli)\n- [Sendmux skills homepage](https://github.com/Sendmux/skills)\n- [Sendmux OAuth for REST APIs](https://sendmux.ai/docs/developer-tools/oauth)\n\n## Skill Output:\n\n**Output Type(s):** [Guidance, Shell commands, Configuration instructions]\n\n**Output Format:** [Markdown with bash and JSON examples]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [CLI responses can be requested as machine-readable JSON.]\n\n## Skill Version(s):\n\n1.0.12 (source: ClawHub release; artifact frontmatter: 1.7.1)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment."}],"languages":[],"docsSourceLabel":"CLAWHUB","editorialOverview":null,"editorialQuality":{"score":100,"threshold":65,"status":"thin","wordCount":1371,"uniquenessScore":43,"reasons":["uniqueness-below-45"]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-10-10T04:19:04.198Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-10-10T04:19:04.198Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-10T08:44:04.251Z","emptyReason":null},"items":[{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-10-09T19:11:12.944Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}