Overview
Emailit MCP server
Connect ChatGPT, Claude, Cursor, Codex, Grok and other AI tools to Emailit with the hosted MCP server, OAuth sign-in and the full API v2 as tools.
The Emailit MCP server connects AI assistants to your Emailit account through the Model Context Protocol. Ask in plain language to send an email, add and verify a domain, find out why a message bounced, build an audience or launch a campaign, and the assistant calls the matching Emailit tool.
Emailit hosts the server. There is nothing to install and no API key to paste: you sign in to Emailit in your browser, choose the workspaces the assistant may use and approve access.
| Server URL | https://api.emailit.com/mcp |
| Transport | Streamable HTTP (stateless, POST) |
| Sign-in | OAuth 2.1 with PKCE, or an API key as a bearer token |
| Tools | 109, covering the full API v2 |
| Discovery | https://api.emailit.com/.well-known/oauth-protected-resource/mcp |
Connect your AI tool
| Client | How to connect | Guide |
|---|---|---|
| ChatGPT | Emailit plugin | ChatGPT |
| Claude (claude.ai, Desktop and mobile) | Emailit connector | Claude |
| Claude Code | Emailit plugin or claude mcp add |
Claude Code |
| Cursor | Emailit plugin or Add to Cursor | Cursor |
| Codex | Emailit plugin or codex mcp add |
Codex |
| Grok | grok.com connector, Grok Build plugin or the xAI API | Grok |
| VS Code, Windsurf, Zed and others | Remote MCP server URL | Other clients |
For any other MCP client, add a remote (Streamable HTTP) server with the URL https://api.emailit.com/mcp. Clients that support MCP authorization find the sign-in automatically from the discovery URL above, so the URL is all they need.
The Emailit plugins for ChatGPT, Codex, Claude Code, Cursor and Grok add skills on top of the server: guidance that teaches the assistant how to set up domains, fix deliverability, run campaigns, verify webhooks and pick an SDK.
What happens when you connect
-
Sign in. Your AI tool opens an Emailit sign-in page. Enter your email and password, plus your authenticator code if you use two-factor authentication.
-
Choose workspaces. Pick All my workspaces, which includes ones you create or join later, or Only these workspaces with the ones you tick. If you allow more than one, choose the one the tool starts in.
-
Allow access. Review the access the tool asks for (
sendingorfull) and select Allow access.
The tool receives an access token that lasts 15 minutes and a refresh token that keeps it connected for up to 60 days of inactivity. Refresh tokens rotate on every use, and reusing an old one revokes the connection. Every connection appears under AccountConnected apps.
Multiple workspaces
One connection covers every workspace you allowed, so you can manage several brands or client accounts from the same chat. Name the workspace in your request:
“In Acme Client, list the domains.”
The assistant passes workspace: "Acme Client" to that one tool call. It accepts a workspace ID or the exact workspace name, and it doesn’t change the connection’s default workspace, so two chats working in different workspaces at the same time don’t get in each other’s way.
- “Which Emailit workspaces can you use?” lists the allowed workspaces and your role in each.
- “Switch to my Marketing workspace” changes the default for later requests that don’t name a workspace.
- To add or remove workspaces, open AccountConnected apps and choose Edit access. Changes apply on the app’s next request, without reconnecting.
- If you leave a workspace or someone removes you, the app loses access to it too.
The tool works with your role in each workspace, the same as the dashboard: Members can’t manage API keys or delete domains. See Workspaces and permissions.
Access levels
| Scope | What the tool can do |
|---|---|
sending |
Send, schedule, reschedule, cancel, retry and forward email. Check and switch workspaces. |
full |
Everything in API v2: domains, DMARC reports, templates, API keys, audiences, contacts, suppressions, webhooks, campaigns, automations, forms, email verification, events and creating workspaces. |
Most AI tools ask for both scopes. If a connection without full calls a tool that needs it, the tool returns an error asking you to reconnect with full access. Clients that support step-up authorization, such as ChatGPT, show the approval screen again.
Trim the tool list
Some clients limit how many tools they load. Add these options to the server URL, or send them as headers, to expose fewer tools:
| Option | Query | Header | Example |
|---|---|---|---|
| Only some toolsets | ?toolsets= |
X-MCP-Toolsets |
emails,domains,events |
| Hide write tools | ?read_only=true |
X-MCP-Readonly |
true |
For example, https://api.emailit.com/mcp?toolsets=emails,domains&read_only=true gives the assistant read access to emails and domains only. The workspace tools are always included. See Toolsets and read-only mode for the full list.
Use an API key instead
Servers, scripts, CI jobs and headless agents can’t open a browser to sign in. Create an API key and send it as a bearer token:
{
"mcpServers": {
"emailit": {
"url": "https://api.emailit.com/mcp",
"headers": {
"Authorization": "Bearer your_api_key"
}
}
}
}An API key is tied to the workspace it was created in and can’t reach other workspaces, and the server only lists the tools that the key’s scope allows. Prefer OAuth in desktop and chat apps, because a key saved in a config file can leak.
Disconnect an app
Open AccountConnected apps. The page lists every AI tool and app you approved, with the workspaces it can use, its access level and when it connected. Choose Edit access to change its workspaces, or Revoke access to cut it off: its tokens stop working immediately. See Connected apps.
Security
- Labeled tools. Every tool carries MCP annotations (read-only, destructive, open-world), so clients can ask before running anything that writes, deletes or reaches the outside world.
- Built-in instructions. The server tells assistants to confirm recipients, sender and content before sending real email, to look up IDs instead of guessing, and to ask before deleting or canceling anything.
- Untrusted content. Email bodies, contact fields and form submissions can contain text written by other people. Review what the assistant plans to do before you approve a send or a delete.
- Network checks. Webhook URLs are checked so requests can’t reach private networks.
- Your role applies. Assistants can never do more than you can in each workspace.
- Keys stay out of code. Never commit API keys; the Cursor rule in the Emailit plugin warns the agent about it.