Hoppa till innehållet

Tools

MCP server

Sendora’s MCP server gives a coding agent, such as Claude Code, Cursor or VS Code, Sendora’s documentation and tools while it builds your integration. The agent can read the guides and the API reference, send a test mail and read what happened to it, and set up streams, webhooks and sending domains.

It runs two ways, with the same tools:

  • Locally, as npx -y @sendora/mcp, over stdio. The documentation is built into the package, so it answers offline.
  • Hosted, at https://mcp.sendora.se/mcp, with your key as a bearer token. Without a key, https://mcp.sendora.se/docs serves the documentation.

Before you start

  • The local server needs Node 20.19 or newer. The hosted server and the Claude Desktop bundle need nothing installed.
  • The agent needs a key for anything beyond the documentation. Choose a key says which.

Choose a key

The MCP server lists only the tools your key allows, so the agent cannot call any other:

  • With a test server’s key (sk_test_…), the agent can do everything on that server, and no mail is delivered. Start here. A test server works before your account is approved. It takes mail as a live one does, and its simulator’s addresses act out bounces, deferrals and complaints.
  • With a live server’s key (sk_…), the agent reads the server’s message log, received mail and settings. Once you turn on changes, it can also send real mail to real people and make other changes.
  • With the account key (ak_…), the agent reads the account’s servers and sending domains. With changes on, it can also add a sending domain or delete a test server, never a live one.
  • With no key, the agent reads the documentation alone.
What the tool doesNo keyTest keyLive keyAccount key
Reads the documentationyesyesyesyes
Readsnoyesyesyes
Changesnoyeswith changes onwith changes on
Shows a new key or signing secretnoyesnono
Cannot be undonenoyesnowith changes on

Cannot be undone covers revoking a key, deleting a webhook or a test server, archiving a stream, and sending or cancelling a broadcast. A new key or a webhook’s signing secret reaches the agent only on a test server. With a live key, the agent sends you to the dashboard to make one. Keys says where each key is made.

Install

Set your key as the environment variable SENDORA_API_TOKEN, from your shell profile or your secret manager. The configurations for Claude Code, Cursor and Codex read it from there. VS Code and Claude Desktop ask for the key instead and keep it in their own secret storage. Either way, no file you commit holds the key.

Open your client’s setup:

Claude Code

Add Sendora to .mcp.json at your project’s root. Claude Code fills in ${SENDORA_API_TOKEN} from its environment when it connects, so the file holds no key and you can commit it. Locally:

{
  "mcpServers": {
    "sendora": {
      "type": "stdio",
      "command": "npx",
      "args": ["-y", "@sendora/mcp"],
      "env": { "SENDORA_API_TOKEN": "${SENDORA_API_TOKEN}" }
    }
  }
}

Or hosted, with a timeout that lets send_email wait up to a minute to learn whether the message was delivered:

{
  "mcpServers": {
    "sendora": {
      "type": "http",
      "url": "https://mcp.sendora.se/mcp",
      "headers": { "Authorization": "Bearer ${SENDORA_API_TOKEN}" },
      "timeout": 90000
    }
  }
}

Don’t add the server with claude mcp add and the key in --header or --env. Your shell puts the key’s value in the command, and Claude Code writes it to its configuration. Without a key, one command adds the documentation:

claude mcp add --transport http sendora-docs https://mcp.sendora.se/docs
Cursor

Add to Cursor installs the local server in one click, with the key from SENDORA_API_TOKEN.

By hand, edit .cursor/mcp.json in your project, or ~/.cursor/mcp.json for every project. Cursor fills in ${env:SENDORA_API_TOKEN} from its environment. Locally:

{
  "mcpServers": {
    "sendora": {
      "type": "stdio",
      "command": "npx",
      "args": ["-y", "@sendora/mcp"],
      "env": { "SENDORA_API_TOKEN": "${env:SENDORA_API_TOKEN}" }
    }
  }
}

Or hosted:

{
  "mcpServers": {
    "sendora": {
      "url": "https://mcp.sendora.se/mcp",
      "headers": { "Authorization": "Bearer ${env:SENDORA_API_TOKEN}" }
    }
  }
}
VS Code

Add to VS Code installs the local server in your profile in one click.

By hand, edit .vscode/mcp.json in your project. Either way, VS Code asks for the key the first time the server starts, and keeps it in its secret storage. Locally:

{
  "inputs": [
    {
      "type": "promptString",
      "id": "sendora-key",
      "description": "Sendora key",
      "password": true
    }
  ],
  "servers": {
    "sendora": {
      "type": "stdio",
      "command": "npx",
      "args": ["-y", "@sendora/mcp"],
      "env": { "SENDORA_API_TOKEN": "${input:sendora-key}" }
    }
  }
}

Or hosted:

{
  "inputs": [
    {
      "type": "promptString",
      "id": "sendora-key",
      "description": "Sendora key",
      "password": true
    }
  ],
  "servers": {
    "sendora": {
      "type": "http",
      "url": "https://mcp.sendora.se/mcp",
      "headers": { "Authorization": "Bearer ${input:sendora-key}" }
    }
  }
}
Codex

Edit ~/.codex/config.toml. Don’t use codex mcp add --env, which writes the key’s value into the file.

Codex passes a local server a few system variables, such as PATH and HOME, and of the rest only those you name. It gives a tool a minute unless told otherwise, so both entries set tool_timeout_sec to let send_email wait its full minute. Locally:

[mcp_servers.sendora]
command = "npx"
args = ["-y", "@sendora/mcp"]
env_vars = ["SENDORA_API_TOKEN"]
tool_timeout_sec = 90

Or hosted:

[mcp_servers.sendora]
url = "https://mcp.sendora.se/mcp"
bearer_token_env_var = "SENDORA_API_TOKEN"
tool_timeout_sec = 90
Claude Desktop

Download the bundle and open it. Claude Desktop asks whether to install it, and runs it on the Node it brings.

  1. Paste your key into Sendora key, which Claude Desktop keeps in your operating system’s secure storage. Leave it empty for the documentation alone.
  2. Tick Allow changes only when you want changes on.

Each release comes with a new bundle here, which you install over the old one. A custom connector, in Claude Desktop or on claude.ai, cannot send a key of your own, so use the bundle.

Check the connection

Ask the agent which Sendora server it is connected to. With a server’s key, it calls get_server, which returns the server’s name and mode, whether changes are on, its limits and the sending domains its mail may come from. With the account key, it calls list_servers.

What you seeWhyWhat to do
The agent has only search_docs and read_docNo key reached the serverSet SENDORA_API_TOKEN in the environment the client starts from, or enter the key in VS Code’s prompt or Claude Desktop’s Sendora key. Then start the client again
The client shows the server as failedThe key did not reach the server, or the API refused itCheck that the client has the key, and that the key is still live in the dashboard

Then give the agent a task:

  • With a test server’s key, ask: “Send a test mail to any address you like, and tell me whether it was delivered.”
  • With a live server’s key, ask: “Why did the last message to anna@example.com bounce?”
  • With no key, ask: “Add a password-reset mail to this app with @sendora/sdk.”

Turn on changes

A live server’s key and the account key list only the reading tools until you turn on changes for the connection:

  • Locally, add --allow-writes after @sendora/mcp in the arguments, or set SENDORA_ALLOW_WRITES=true in the server’s environment.
  • Hosted, send the header Sendora-Allow-Writes: true beside the key.
  • In Claude Desktop, tick Allow changes.

Any value but true leaves changes off. A test server’s key needs no switch.

With changes on, the MCP server tells the agent to confirm with you before anything reaches a real person. Your client also asks before any call you have not allowed.

The switch decides which tools the MCP server lists. It does not limit the key itself. An agent that runs commands or reads files on your machine can read a key kept in its environment, and call the API with it directly. So give an agent a live key only if you would trust it with everything the key can do. VS Code’s prompt and Claude Desktop’s bundle keep the key out of your environment.

Received mail

A live server’s key lists the tools that read the mail your inbound stream receives. The sender wrote everything in that mail, and an agent reading it may also have your terminal, your files and your other MCP servers. So the tools limit what the agent sees:

  • search_inbound returns only two of the addresses the sender chose: the From address and the address the mail was sent to.
  • read_inbound_message returns the rest between two markers with a new random value each time. Before them comes a notice that everything between the markers is data from the sender, not instructions.

This lessens prompt injection without preventing it. A model can still do what a mail asks: run a command, read a file, call another server’s tool, answer the mail, or send your key somewhere. The two addresses sit outside the markers, and the sender wrote them too. The From address is wholly theirs. In the address the mail was sent to, they chose the text after + on a stream’s address at inbound.sendora.se, and the whole local part on your own domain.

  • Read what the agent proposes before you approve it.
  • Keep changes off unless the task needs them.
  • Give an agent that reads received mail no more tools than the task needs.
  • If you think a key reached someone it should not have, revoke it in the dashboard.

Tools

The table lists every tool of the MCP server. Keys says which keys list each one: test for a test server’s key, live for a live server’s and account for the account key. “With changes on” marks a tool that needs the switch.

ToolWhat it doesKeys
search_docsSearch the Sendora docsany, or none
read_docRead a Sendora documentany, or none
get_serverRead the server this key belongs totest, live
send_emailSend one emailtest, live with changes on
search_messagesSearch the message logtest, live
get_messageRead one message and its timelinetest, live
list_suppressionsList a stream's suppression listtest, live
remove_suppressionLift a suppressiontest, live with changes on
create_streamAdd a streamtest, live with changes on
archive_streamArchive a streamtest
send_broadcastSend a test broadcasttest
get_broadcastRead a broadcasttest, live
cancel_broadcastCancel a broadcasttest
list_webhooksList the server's webhookstest, live
list_webhook_deliveriesList a webhook's deliveriestest, live
replay_webhook_deliveryReplay a webhook deliverytest, live with changes on
create_webhookAdd a webhooktest
delete_webhookDelete a webhooktest
list_keysList the server's keystest, live
create_keyCreate a keytest
revoke_keyRevoke a keytest
search_inboundSearch received maillive
read_inbound_messageRead a received messagelive
list_inbound_domainsList the domains for receivinglive
check_inbound_domainCheck a domain for receivinglive
add_inbound_domainAdd a domain for receivinglive with changes on
list_serversList the account's serversaccount
list_domainsList the sending domainsaccount
check_domainCheck a sending domainaccount
add_domainAdd a sending domainaccount with changes on
delete_test_serverDelete a test serveraccount with changes on

Documents and prompts

The documentation is built into the MCP server at each release, from the same sources as these pages:

  • the guides, as sendora://docs/…
  • the API reference, as sendora://reference/…
  • the error codes, as sendora://errors
  • the TypeScript SDK’s README and rules for agents, as sendora://sdk/readme and sendora://sdk/skill
  • the Python SDK’s, as sendora://sdk/python/readme and sendora://sdk/python/skill

sendora://index lists them all. search_docs searches every document but the rules, which an agent reads whole. read_doc reads one document whole.

The server has three prompts, which a client offers as commands:

  • set_up_sendora: install the SDK for the project’s language, keep the key in the environment, send a test through a test server and verify webhooks.
  • why_not_delivered: read a message’s timeline, the suppression list and the error codes, and explain what happened.
  • verify_webhooks: implement signature verification for the webhook endpoint and test it.

The official server

Sendora’s MCP server is @sendora/mcp on npm, the hosted server at https://mcp.sendora.se/mcp and https://mcp.sendora.se/docs, and the bundle on this site, and nothing else. A server under another name is not Sendora’s, and it could read every key and message it is given.