Mailtrap for AI agents
Mailtrap is an email delivery platform developers use to test transactional emails safely in a sandbox before sending them to real customers. Connect it once through Arc0, and your agent, or Claude, ChatGPT and Cursor, can use it through one MCP endpoint, limited to what each user approved.
What agents do in Mailtrap.
Check sending stats by domain
Pull sending stats for a domain to check delivery health, a read-only lookup.
Create a contact list
Create a new contact list to organize recipients for a transactional campaign.
Approve before deleting a project
Require approval before deleting a project, since it removes its templates and sending history.
49 Mailtrap actions, graded by risk.
Every Mailtrap action is tagged read, write or destructive, so one policy covers the whole app and new actions inherit the right default.
read
26Look things up. Allowed by default.
- mailtrap.get_inboxGet Inbox Attributes
- mailtrap.get_contactGet Contact
- mailtrap.get_projectGet Project by ID
- mailtrap.list_inboxesList Inboxes
- mailtrap.list_accountsList Accounts
- mailtrap.list_messagesList Messages in Inbox
- mailtrap.list_projectsList Projects
- mailtrap.get_contact_listGet Contact List
- mailtrap.get_message_htmlGet Message HTML Body
- mailtrap.get_billing_usageGet Billing Usage
- mailtrap.get_contact_fieldGet Contact Field
- mailtrap.get_sending_statsGet Sending Stats
- mailtrap.list_suppressionsList Email Suppressions
- mailtrap.get_contact_exportGet Contact Export
- mailtrap.get_contact_importGet Contact Import Status
- mailtrap.get_email_templateGet Email Template
write
16Create and change things. Allow, or ask the user first.
- mailtrap.update_inboxUpdate inbox
- mailtrap.create_contactCreate Contact
- mailtrap.update_contactUpdate contact
- mailtrap.update_projectUpdate project
- mailtrap.create_contact_listCreate Contact List
- mailtrap.update_contact_listUpdate Contact List
- mailtrap.create_contact_eventCreate Contact Event
- mailtrap.create_contact_fieldCreate Contact Field
- mailtrap.update_contact_fieldUpdate Contact Field
- mailtrap.create_contact_exportCreate Contact Export
- mailtrap.create_email_templateCreate Email Template
- mailtrap.create_sending_domainCreate Sending Domain
- mailtrap.update_email_templateUpdate Email Template
- mailtrap.clean_inboxClean Inbox
- mailtrap.import_contactsImport Contacts
- mailtrap.mark_inbox_as_readMark Inbox as Read
destructive
7Delete, cancel or archive. Ask first, or deny outright.
- mailtrap.delete_contactDelete Contact
- mailtrap.delete_projectDelete Project
- mailtrap.delete_contact_listDelete Contact List
- mailtrap.delete_contact_fieldDelete Contact Field
- mailtrap.delete_email_templateDelete Email Template
- mailtrap.delete_sending_domainDelete Sending Domain
- mailtrap.reset_inbox_credentialsReset Inbox Credentials
Mailtrap in three steps.
- 01Your users connect MailtrapThey add their Mailtrap bearer token on Arc0 Connect, under your brand. It goes straight into the vault.
- 02You set the rulesReads run, writes like “create Contact” can wait for the user, and “delete Contact” can be denied outright.
- 03Any agent can actYour agent calls Mailtrap through the Arc0 SDK or MCP, and so can Claude, ChatGPT and Cursor. Every call lands on the audit log.
await arc0.policies.set('mailtrap', { read: 'allow', write: 'ask', // create_contact destructive: 'deny', // delete_contact }) # Claude Code: the same connection, one URL $ claude mcp add --transport http arc0 \ https://mcp.arc0.ai/u/u_8f2
How Mailtrap connects.
Users add their Mailtrap bearer token on Arc0 Connect. It is encrypted in the vault, never shown to the model, and each user can rotate or revoke it at any time.
The same Mailtrap connection serves your agent over MCP and your own backend over REST and the proxy, so a user connects once. How Arc0 handles credentials →
- AUTH
- Bearer token
- CREDENTIALS
- Per-tenant encrypted vault
- MODEL SEES
- Results only, never credentials
- AUDIT LOG
- Every call, on every plan
Use Mailtrap from any agent.
Mailtrap and Arc0, answered.
Can I use Mailtrap with Claude, ChatGPT or Cursor?
Yes. Connect Mailtrap to Arc0 once, then add your Arc0 MCP URL to Claude, ChatGPT, Cursor, Claude Code or any other remote-MCP client. Each assistant only gets the Mailtrap actions you allow.
How do users connect Mailtrap?
Users add their Mailtrap bearer token on Arc0 Connect. It is encrypted in the vault, never shown to the model, and each user can rotate or revoke it at any time.
Which Mailtrap actions can my agent take?
49 in total: 26 read, 16 write and 7 destructive, such as “create Contact”. Your policies decide which of them each agent may call.
Can I stop my agent from deleting things in Mailtrap?
Yes. Actions like “delete Contact” are graded destructive. Set destructive actions to deny, or to ask so the user approves each one, and blocked calls still show up on the audit log.
Can my own backend call Mailtrap too?
Yes. The same Mailtrap connection is available over REST and through the Arc0 proxy, so your product and your agent share one connection per user.
Plug Mailtrap into your agent.
Your users connect Mailtrap once, under your brand. Your agent gets 49 actions behind your policies, with every call on the record.
Free to build · MCP + REST · Audit log on every plan