How to Send Email From AI Agents: MCP, CLIs and Skills (2026)
Sooner or later an AI agent that drafts a reply, books a slot or files a report has to tell a person about it, and that message usually goes out as email. The wiring is where teams get hurt. Give an autonomous agent a raw sending key and one bad loop can send a thousand messages and dent your domain reputation before anyone notices. The send call is easy. Getting the permissions right is the actual work: enough for the agent to be useful, few enough that a mistake stays small.
In 2026 most developer email providers shipped some form of agent tooling: MCP servers, command-line tools, installable agent skills, or all three. They made very different choices about authentication and safety, and those choices matter more than the tool counts in the launch posts. This guide compares five providers on what they ship today, then covers the domain setup and guardrails that apply whichever one you pick.
This page covers developer and transactional email APIs. Marketing platforms with MCP connectors (ActiveCampaign, MailerLite, Kit, AWeber, Omnisend, Sender) are covered in our guide to email marketing tools with AI assistants. If your agent needs to receive mail as well as send it, see inbound email for AI agents.
Three ways an agent reaches an email provider
A wrapped API call. Your agent code exposes one function, something like sendEmail(to, subject, body), and that function calls the provider. The model never sees the API key or the network. You decide exactly what it can do. This is still the safest default.
An MCP server. The Model Context Protocol exposes provider actions as tools the model calls directly: send, search logs, manage contacts, create webhooks. It is quick to set up, but the model gets a much larger surface than one send function, so scoping and client-side approval matter more.
A CLI plus agent skills. Skills are folders of instructions (a SKILL.md plus references and example code) that teach a coding agent how to use a provider’s API correctly. A CLI gives the agent, or a CI job, a deterministic way to make real calls from a terminal. Skills help an agent write integration code; an MCP server or CLI lets it operate your account. Most teams that build with coding agents end up wanting both.
Agent tooling by provider
Checked against each provider’s docs and repositories on October 5, 2026.
| Provider | MCP server | How the MCP server authenticates | CLI | Agent skills | Safety controls worth knowing |
|---|---|---|---|---|---|
| Resend | Official. Hosted at mcp.resend.com/mcp, plus open-source local resend-mcp (stdio or HTTP) |
OAuth 2.1 with PKCE, or an API key as a Bearer token for headless clients | Official resend-cli |
resend/resend-skills |
OAuth scope emails:send; send-only API keys restricted to one domain; idempotency keys; resend.dev test addresses |
| Postmark | Official @activecampaign/postmark-mcp, run locally, 24 tools |
Server API token in an environment variable | None | ActiveCampaign/postmark-skills (5 skills) |
Tool risk annotations; HTTPS-only webhooks with optional allowlist; masked logs; sandbox mode |
| Amazon SES | No SES-specific server; the general AWS MCP Server covers SES APIs | OAuth or SigV4, governed by IAM | AWS CLI (aws sesv2) |
amazon-ses/skills (2 skills) |
IAM condition keys on recipients and From address; sandbox for new accounts; mailbox simulator |
| Elastic Email | Official. Hosted at mcp.elasticemail.com, open-source self-hosted server (26 tools) |
API key in an X-Auth-Token header |
Official elastic-email-cli |
ElasticEmail/elasticemail-skills |
--dry-run on CLI sends; separate API keys you can revoke individually |
| Loops | Official. Hosted at mcp.loops.so, with a Claude connector and ChatGPT plugin |
OAuth browser sign-in | Official Loops CLI | loops-so/skills (4 skills) |
Workflow edits checked against a revision ID; Guardian content checks via API; idempotency keys |
The table hides the biggest difference: how narrowly you can scope what the agent holds. Resend and AWS let you limit a credential to sending, and AWS can restrict who it sends to. Postmark and Elastic Email give an MCP client full access to whatever the token or key covers, so isolation has to come from a separate server or account.
Resend
Resend
Modern email API for developers with React Email and TypeScript-first SDK
Resend is a modern, developer-first email API founded in 2023 by Zeno Rocha, backed by Y Combinator. It stands out with its React Email framework that lets developers build email...
Resend has shipped the most agent tooling of any provider here. The official CLI arrived on March 13, 2026, built “for humans and AI agents”. The hosted remote MCP server at mcp.resend.com/mcp launched on July 7, 2026, and OAuth support for the API followed on July 13. Plugins that bundle the MCP server with Resend’s skills are available for Claude Code, Codex and Cursor, and a Claude connector installs both in one click.
What the MCP server covers. Emails, templates, broadcasts, contacts, logs and webhooks through one integration. The hosted server runs the same open-source code published on npm as resend-mcp, which you can run yourself over stdio or HTTP if you need an air-gapped or self-hosted setup.
Authentication. Interactive clients sign in through Resend’s consent screen, and the client holds a token instead of a key. Resend implements OAuth 2.1 with PKCE and Dynamic Client Registration. Access tokens expire after 15 minutes and refresh tokens rotate on every use. Grants are listed under Team settings and can be revoked there, or by revoking the refresh token through POST /oauth/revoke.
For headless clients (CI, servers, cron jobs) you pass an API key as a Bearer token instead:
claude mcp add --transport http resend https://mcp.resend.com/mcp \
--header "Authorization: Bearer re_xxxxxxxxx"
That brings back the long-lived-key problem, so use a key created with sending_access permission. Resend lets you restrict such a key to a single sending domain.
The scope problem. OAuth has two scopes. emails:send covers send-only routes such as POST /emails and POST /broadcasts/:id/send. Everything else, including reading logs, needs full_access, which can also delete domains and manage API keys. There is no read-only scope. Resend’s OAuth guide also warns that a client which omits scope gets both scopes by default, so always request emails:send explicitly.
Attribution and safety features. Every action logged through the MCP server carries a user-agent trace, so you can tell agent activity apart from your application’s own calls. The API is rate limited to 10 requests per second per team by default. Idempotency keys on POST /emails and POST /emails/batch stop a retried send from going out twice within 24 hours. For testing, delivered@resend.dev, bounced@resend.dev and complained@resend.dev simulate each outcome without touching your reputation, though test sends do count against your quota.
Cost. The agent tooling has no separate charge. Per Resend’s pricing, the free plan covers 3,000 emails a month with a 100-per-day cap, 3 domains and 5 AI credits. Pro is $20 a month for 50,000 emails, with overages at $0.90 per 1,000. Data retention is 30 days on every self-serve plan, and Resend bills monthly only.
The tradeoff. Resend has the best credential story here, but its OAuth scopes are coarse and 30 days of logs is short for auditing an agent. It also has no visual automation builder, so an agent connected to it can send and manage contacts but cannot run lifecycle campaigns. Our Resend review and Resend pricing breakdown go deeper.
Postmark
Postmark’s MCP server started in Postmark Labs in 2025 with four tools. It is now the official @activecampaign/postmark-mcp package. The current release, v2.1.1, has 24 tools across sending, templates, message search, delivery diagnostics, bounces, suppressions, stats and webhooks. Postmark’s July 2026 write-up explains the design, which is the main reason to pick it.
Tools shaped around questions. diagnoseDelivery answers “did my email reach this person, and if not, why?” in one call. It runs message search, suppression and bounce lookups in parallel, tolerates any one of them failing, and returns a recommended action that depends on the cause: a spam complaint is permanent, a hard bounce may be reactivatable, a manual suppression can just be removed. Agents tend to get it wrong when they have to piece that together from five raw API responses.
Validation before the API call. createWebhook refuses non-HTTPS URLs, and the WEBHOOK_URL_ALLOWLIST variable restricts it to URL prefixes you own. editTemplate requires at least one field that actually changes. sendEmailWithTemplate rejects a call that supplies both a template ID and an alias.
Risk annotations. All 24 tools carry readOnlyHint, destructiveHint and idempotentHint. The README sorts them into 12 read-only tools, 4 sending tools, 4 additive tools and 4 destructive ones (editTemplate, deleteTemplate, deleteWebhook, deleteSuppressions). Clients that respect annotations can auto-approve reads and ask before anything else. Clients that ignore them give you no such gate, so check yours with a harmless delete on a test server before you rely on it.
Attribution. The server records the connecting client’s name and version, and an optional AGENT_LABEL is sent as an X-Agent-Label header on every Postmark request. Email addresses in logs are masked unless you set LOG_EMAIL_FULL=true. It needs Node 20 or newer.
Authentication is the weak spot. The server uses a Postmark server API token from an environment variable. There is no OAuth, and the README states plainly that neither of Postmark’s token types supports sub-scoped permissions. The workaround is isolation. Create a dedicated Postmark server for agent traffic, give it only the streams and sender signatures it needs, and rotate its token if it leaks. For tests, Postmark’s API accepts POSTMARK_API_TEST as a token so you can send without anything going out, and sandbox mode is available on every plan.
Skills. Postmark Skills (February 27, 2026, MIT) cover sending, inbound processing, templates, webhooks and email best practices. They teach details agents often miss, such as batch sends capping at 500 messages per request, Message Stream handling, and using StrippedTextReply rather than TextBody when parsing replies. Install with npx skills add ActiveCampaign/postmark-skills.
Cost. Per Postmark’s pricing, the free Developer plan is 100 emails a month with no overages. Basic is $15 a month for 10,000 emails ($1.80 per extra 1,000), Pro $16.50 ($1.30), and Platform $18 ($1.20). Activity retention is 45 days by default, with custom retention up to 365 days as an add-on from $5 a month on Pro and above. Basic allows 5 servers and Pro 10, and agent test servers count against that. Postmark prohibits cold outreach and promotional bulk mail through transactional streams, so it is the wrong tool for an agent that sends marketing. See the Postmark review and Postmark pricing.
| Feature | Postmark | Resend |
|---|---|---|
| Rating | 4.6/5 | 4.2/5 |
| Starting Price | $15/mo | $20/mo |
| Free Plan | 100 emails/month, never expires, test integration and side projects | 3,000 emails/month, 100 emails/day, 3 custom domains |
| Founded | 2009 | 2023 |
| Email Templates | 20 | 0 |
| Integrations | 30 | 15 |
| Deliverability Rate | 98.7% | 98% |
| Marketing Automation | No | Yes |
| A/B Testing | No | No |
| Landing Pages | No | No |
| Segmentation | No | No |
| Drag & Drop Editor | No | No |
| SMS Marketing | No | No |
| Ecommerce Features | No | No |
| API Access | Yes | Yes |
| Multi-Language | No | No |
| Web Push Notifications | No | No |
| Live Chat | No | No |
| Advanced Analytics | Yes | No |
Amazon SES
Amazon SES
Cheapest email at scale on AWS infrastructure
Amazon SES is AWS's cloud-based email sending service that processes over a trillion emails annually for customers like Netflix and Duolingo. At just $0.10 per 1,000 emails with no...
SES has no MCP server of its own. It does have the strongest permission model in this list, because every call goes through AWS IAM.
Agent skills. On June 4, 2026, the SES team released Amazon SES Agent Skills (Apache-2.0) for Claude Code, Kiro and any agent that reads the open Agent Skills format. There are two: aws-ses for sending with the SES v2 API (identity verification, configuration sets, tenants, suppression lists, deliverability), and aws-mail-manager for inbound processing with Mail Manager. AWS’s announcement lists what they fix: agents that reach for the legacy V1 ses client, skip identity verification, or forget production requirements. Install with npx skills add amazon-ses/skills. The repository describes itself as sample code for non-production use, so review what the agent produces.
MCP access. The managed AWS MCP Server is a remote server covering AWS APIs in general, SES included. It authenticates with OAuth or SigV4, and its migration notes say every call is recorded in CloudTrail. It replaces the older self-hosted AWS API MCP Server, which offered READ_OPERATIONS_ONLY and REQUIRE_MUTATION_CONSENT switches. Either way, an agent with broad AWS credentials can touch far more than email, so give it a role that only allows SES.
Scoping that the other providers can’t match. SES IAM policies support the condition keys ses:Recipients and ses:FromAddress on SendEmail and SendRawEmail. You can write a policy that only lets the agent’s role send from notifications@yourapp.com to addresses at your own domain. AWS enforces that allowlist itself, outside any code the model might route around.
Built-in brakes. New SES accounts start in the sandbox: you can only send to verified addresses or the mailbox simulator, with a maximum of 200 messages per 24 hours, until AWS approves a production-access request. The simulator addresses (success@, bounce@ and complaint@simulator.amazonses.com) trigger each event on demand.
Pricing changed in July 2026. Since July 21, 2026, new SES accounts start on the Essentials plan at $0.16 per 1,000 emails for the first 10 million a month, per the SES pricing page. You can switch to à la carte pricing, where AWS’s own examples use $0.10 per 1,000, or move up to Pro ($105 per account per region per month, plus per-email fees). New AWS customers get up to $200 in Free Tier credits that apply to SES. Check the Amazon SES pricing breakdown for volume math.
The tradeoff. SES is infrastructure. You build bounce handling, complaint processing and reputation monitoring yourself, and setup involves IAM, identity verification and event destinations. Skills make an agent write better SES code; they don’t remove that work. Our Amazon SES review covers it.
Elastic Email
Elastic Email is the budget option with full agent tooling. Its MCP server is hosted at mcp.elasticemail.com, and the same server is open source (C#, .NET 10) if you want to run it yourself. The self-hosted README lists 26 tools covering transactional and bulk sends, contacts, lists, campaigns, segments and templates. Elastic Email also publishes official agent skills and, since September 8, 2026, an open-source CLI.
Authentication is a plain API key. Clients send the key in an X-Auth-Token header. Elastic Email’s help article says the key needs view and modify access to Account, Templates, Campaigns, Contacts, Files and Send HTTP, plus view access to Access Tokens, and the self-hosted server rejects keys that can’t list API keys. In practice you can’t hand the MCP server a send-only key. Every plan, including Free, allows 15 API keys, so create one just for the agent and revoke it on its own if something goes wrong. If you self-host, the server speaks plain HTTP, so keep it on localhost or behind a TLS proxy.
Plan limits on the MCP. The help article notes that not every MCP action works on every plan: the campaign and contact endpoints aren’t available on Email API plans.
The CLI. elastic-email-cli (MIT, Node 20+) opens an interactive terminal UI when run on its own, with a send wizard that shows a review screen before anything goes out. In scripts, every command accepts --json, exit codes distinguish failures such as a missing key from a malformed address, and sends accept --dry-run to print the exact request without sending it. The key resolves from the --api-key flag, then ELASTIC_EMAIL_API_KEY, then a local config file stored in plaintext with 0600 permissions. Use the environment variable on CI runners and shared machines.
Cost and the catch. Per the Email API pricing page, Free is $0 for up to 3,000 emails a month at 100 a day, Starter is $19 a month and Pro $49 a month, both starting at 50,000 emails. MCP access is included at no extra charge. The catch is log storage: 3 days on Free and Starter, 7 on Pro. If someone asks on Monday what an agent sent on Thursday, a Starter account no longer has the record. Keep your own send log. See Elastic Email pricing.
Loops
Loops is a marketing and transactional platform built for SaaS, and its agent tooling reaches further into automation than anyone else’s here. The CLI and skills arrived on April 16, 2026. An August 12, 2026 release added a full Workflows API and an official Claude connector.
MCP server. Hosted at mcp.loops.so. Clients sign in to Loops in the browser through OAuth, and the docs require clients to support Client ID Metadata Documents. Per the MCP docs, it covers contacts, mailing lists, events, transactional sends, campaigns, workflows and email content. There is a Claude connector in the directory and a ChatGPT plugin. In Claude Code:
claude mcp add loops https://mcp.loops.so --scope user --transport http
CLI and skills. The Loops CLI (Go, MIT) stores keys in the system keyring or reads LOOPS_API_KEY, and supports multiple teams. Four agent skills cover the API, the CLI, LMX (Loops’ email markup language) and email best practices. One command installs the CLI and skills together: curl -fsSL https://install.loops.so/wizard | sh.
Workflows from code. The Workflows API exposes the full automation graph: list, create, read and edit workflows, nodes and branches. New workflows start as drafts. Edits pass the workflow’s latest revision ID, which keeps an agent from overwriting changes made since it last read the graph. That catches stale writes. It doesn’t stop a confused agent from making a confident wrong edit, so review agent-made workflow changes before they go live.
Other useful controls. An API endpoint runs Guardian content checks on an email before you publish it, and another sends previews to test addresses. Transactional sends accept an Idempotency-Key header; a repeated key within 24 hours returns 409 Conflict. The API allows 10 requests per second per team, and the content endpoints (campaigns, workflows, email messages) are capped at 60 requests per 60 seconds.
Cost. Per Loops pricing, the free plan covers 1,000 subscribed contacts and 4,000 sends in any rolling 30 days, at up to 10 emails per second, with a “Powered by Loops” footer. Paid plans start at $49 a month for 1,001 to 5,000 subscribed contacts, with unlimited sends at up to 1,000 per second. There is no cheaper paid step, and Loops assumes your app sends it events. See the Loops review and Loops pricing.
Set up and authenticate a sending domain
None of this tooling changes deliverability rules. An agent-written email fails authentication the same way a hand-written one does.
Use a dedicated subdomain for agent traffic, such as notifications.yourapp.com, so a misbehaving agent can’t damage the reputation of the mail your team sends by hand. Publish SPF, DKIM and DMARC on it. Start DMARC at p=none while you read the reports, then tighten to quarantine or reject once legitimate traffic passes cleanly. Our SPF, DKIM and DMARC guide walks through the records.
Give the agent a narrow tool, not your account
Get this step wrong and one bad agent run becomes an incident. The model should hold the narrowest credential the provider offers, and your code should check every send.
Scope the credential. Per provider, that means:
- Resend: OAuth with
emails:sendrequested explicitly, or asending_accessAPI key restricted to one domain. - Postmark: a dedicated server whose token only reaches that server’s streams and templates.
- Amazon SES: an IAM role limited to
ses:SendEmail, withses:FromAddressandses:Recipientsconditions. - Elastic Email: a separate API key for the agent, revoked independently, ideally on an account that holds no production contacts.
- Loops: OAuth sign-in to a team the agent is allowed to change, with workflow edits reviewed before they go live.
Wrap the send. If you write your own tool, accept only the fields the agent needs (recipient, subject, body, or a template ID with variables). Validate the recipient against an allowlist or your user table, reject malformed addresses, and set the sender identity in code so the agent can’t spoof it.
Set a hard rate limit per minute and per day in your wrapper, sized to real need plus a small margin. If the agent sends at most fifty messages an hour, cap it at sixty and alert at the ceiling. Provider limits (10 requests per second at Resend and Loops, 100 a day on the Resend and Elastic Email free plans) are much higher than an agent should normally need, so don’t treat them as your brake.
Require human approval for first-time or high-stakes flows. The agent drafts and queues; a person clicks send. In MCP clients, keep confirmation on for sending and destructive tools, and never auto-approve them in an environment that processes untrusted content.
Use idempotency keys so a retry or a re-planned step doesn’t deliver the same message three times. Resend and Loops support them on send endpoints. Where a provider doesn’t, store a dedupe key per logical send yourself.
Test before anything real goes out
Every provider here gives you a way to exercise the full path without sending to real people:
- Resend:
delivered@,bounced@andcomplained@resend.devsimulate each outcome. These test sends count against your quota. - Postmark: the
POSTMARK_API_TESTtoken accepts API calls without sending, and sandbox mode is available on every plan. - Amazon SES: the mailbox simulator triggers delivery, bounce and complaint events, and the sandbox blocks unverified recipients until you get production access.
- Elastic Email:
--dry-runon CLI sends prints the request without sending it. - Loops: preview sends go to addresses you choose, and Guardian checks flag content problems before publishing.
A good first session with any MCP server goes like this. Call a read-only tool to prove the connection. Send one test message to yourself. Check that the provider’s log identifies the agent. Then deliberately trigger a guardrail, for example an http:// webhook URL on Postmark or a revoked OAuth grant on Resend, and confirm it fails. Don’t rely on a safety feature you have never seen fire.
Log and monitor every send
Record every attempt: who the agent tried to email, what it sent, whether the provider accepted it, and the final delivery result. Feed delivered, bounced and complaint webhooks back into your logs, and alert when bounce or complaint rates rise past a low threshold. A rising complaint rate is the first sign an agent is sending mail people don’t want.
Retention decides how far back you can investigate using the provider alone:
| Provider | Default activity or log retention |
|---|---|
| Resend | 30 days on every self-serve plan |
| Postmark | 45 days, extendable to 365 on Pro and above (paid add-on) |
| Elastic Email | 3 days (Free, Starter), 7 days (Pro) |
Agent problems often surface weeks later, when someone notices an odd email. If your provider keeps less history than that, export send records to your own store. Watch volume as well. A sudden spike against your normal baseline usually means a loop or a planning bug, and catching it in monitoring beats hearing about it from the provider’s abuse team.
Common mistakes
- Connecting production first. Use a separate Postmark server, Resend account, Elastic Email key or AWS role, and let the agent make its mistakes there.
- Granting more scope than the job needs. Requesting Resend’s
full_accessbecause an example did, or giving an AWS role full SES permissions when it only sends. - Bearer tokens where OAuth would work. A long-lived key in a config file doesn’t expire, doesn’t rotate and can’t be revoked from a consent screen. Use it only where a browser login is impossible.
- Trusting annotations your client ignores. Postmark’s risk hints only help if your MCP client acts on them.
- Sending from the primary domain on a cold start. A dedicated, warmed-up subdomain keeps a bad day contained.
- No allowlist. An agent that can email any external address is one malicious prompt away from becoming an open relay.
What success looks like
A good setup is quiet. Sends go through a scoped credential and, ideally, one wrapped function. The sending subdomain passes SPF, DKIM and DMARC at quarantine or reject. Rate limits and an allowlist sit in front of every send, sensitive flows wait for approval, and idempotency keys prevent duplicates. Provider logs label agent traffic as agent traffic. Revoking the agent’s grant or rotating its token makes the next tool call fail, and your production account holds no agent credentials at all.
Which provider to pick
- Resend if you want hosted MCP with OAuth and the smoothest setup across agent clients.
- Postmark if you care most about how the tools behave and about delivery diagnostics, and you can isolate the agent on its own server.
- Amazon SES if you send at volume, already run on AWS, and want the provider to enforce recipient and sender restrictions.
- Elastic Email if price matters most and you keep your own send logs.
- Loops if you’re a SaaS team that wants agents to edit lifecycle automation as well as send.
For a wider view, see our best transactional email services ranking, the best email APIs for AI-built apps, the Postmark vs SendGrid comparison, or the best email tools for SaaS if your agent also handles lifecycle messaging.
Postmark
Transactional email with exceptional deliverability, now by ActiveCampaign
Free plan · from $15/mo
Sources
- Model Context Protocol: documentation — accessed 2026-10-05
- Resend: Remote MCP Server (changelog) — accessed 2026-10-05
- Resend: OAuth Support (changelog) — accessed 2026-10-05
- Resend: Building an OAuth client (scopes) — accessed 2026-10-05
- Resend: MCP server documentation — accessed 2026-10-05
- Resend: Changelog — accessed 2026-10-05
- Resend: CLI documentation — accessed 2026-10-05
- Resend: Create API key (permissions) — accessed 2026-10-05
- Resend: Usage limits — accessed 2026-10-05
- Resend: Idempotency keys — accessed 2026-10-05
- Resend: Send test emails — accessed 2026-10-05
- Resend: Domain and IP warm-up guide — accessed 2026-10-05
- Resend: Pricing — accessed 2026-10-05
- Postmark: The Postmark MCP server, one year later — accessed 2026-10-05
- GitHub: ActiveCampaign/postmark-mcp — accessed 2026-10-05
- Postmark: Teach your AI coding agent with Postmark Skills — accessed 2026-10-05
- Postmark: API overview (test token) — accessed 2026-10-05
- Postmark: Pricing — accessed 2026-10-05
- AWS: Getting started with Amazon SES Agent Skills — accessed 2026-10-05
- GitHub: amazon-ses/skills — accessed 2026-10-05
- AWS: Getting started with the AWS MCP Server — accessed 2026-10-05
- GitHub: AWS API MCP Server migration guide — accessed 2026-10-05
- Amazon SES: Controlling access with IAM — accessed 2026-10-05
- Amazon SES: Request production access (sandbox) — accessed 2026-10-05
- Amazon SES: Pricing — accessed 2026-10-05
- Elastic Email: Meet the Elastic Email CLI — accessed 2026-10-05
- Elastic Email: MCP help article — accessed 2026-10-05
- GitHub: ElasticEmail/elasticemail-mcp-server — accessed 2026-10-05
- GitHub: ElasticEmail/elasticemail-skills — accessed 2026-10-05
- Elastic Email: Email API pricing — accessed 2026-10-05
- Loops: Changelog — accessed 2026-10-05
- Loops: MCP server documentation — accessed 2026-10-05
- Loops: Agent skills — accessed 2026-10-05
- GitHub: loops-so/cli — accessed 2026-10-05
- Loops: API introduction (rate limits) — accessed 2026-10-05
- Loops: Workflows API examples — accessed 2026-10-05
- Loops: Send transactional email (idempotency) — accessed 2026-10-05
- Loops: Pricing — accessed 2026-10-05
Related Articles
Inbound Email for AI Agents: Best Tools for Receiving Mail in 2026
Your agent can send email. Receiving it is the hard part. Five inbound email providers compared on parsing, threading, routing and what each one costs.
GuideBest Email APIs for AI-Built Apps in 2026
You shipped an app with Bolt, v0, or Lovable. Now it needs to send email. Here are the email APIs that fit fastest, compared on price and developer experience.
ComparisonAmazon SES vs Mailgun: Which Transactional Email API Wins?
Amazon SES vs Mailgun for developers: pricing at scale, API design, deliverability, and when each transactional email service makes sense.