# Goshen Email

> Email inboxes for AI agents with threads, attachments, scoped API keys, quarantine, and REST, CLI, and MCP access.

Goshen Email, made by Boring Computers, gives each AI agent a real email address with threads, attachments, and an API key that reaches only its own mail. Agents work through a REST API, a JSON CLI, or an MCP server, while people follow the same mail in a dashboard. It is offered as a hosted service and as source-available software that can be self-hosted on Cloudflare.

## What It Is

Goshen Email is an email service built for agents rather than people. One API call creates an inbox that can send, receive, and reply, and replies stay threaded with the original conversation. The dashboard shows the same inboxes, so a person can reply, check delivery, and review held messages.

## How agents use it

The REST API has 17 operations described in a single OpenAPI document. The CLI and the MCP server (hosted over HTTP or local over stdio) expose the same operations. The README states there is no SDK, so the REST API is called from any language. Every send carries an idempotency key, so retrying a timed-out send with the same key and contents does not send a second copy. Optional triage labels new mail with a category, whether a reply is needed, and an urgency score. Signed webhooks report new mail and delivery outcomes such as delivered, deferred, bounced, failed, rejected, and complained.

## Keys and quarantine

An account key reaches the account's inboxes with only the scopes you pick, and a mailbox key reaches a single inbox. No key can release quarantine or create other keys. Mail on custom domains passes through an SMTP gateway that checks SPF, DKIM, and DMARC and scans with Rspamd and ClamAV. Spam, failed authentication, and malware wait in quarantine until a person releases them from the dashboard. Sign-in uses a link or code sent by email rather than a password.

## Self-hosting model

The API Worker, dashboard, and SMTP gateway live in one public repository under the Functional Source License 1.1, which allows any use except a competing commercial product or service; each release converts to Apache 2.0 two years after publication. Self-hosting needs a Cloudflare account on the Workers Paid plan, a PostgreSQL database reachable through Hyperdrive, and an R2 bucket with delivery queues. A local fixture runs the API and dashboard against an in-memory database with no accounts or credentials.

## Features
- Real email inboxes for agents with threads and attachments
- REST API with 17 operations and OpenAPI document
- JSON CLI
- Hosted and stdio MCP server
- Scoped account and mailbox API keys
- Idempotency keys for safe send retries
- Quarantine for spam, spoofing, and malware released only by a person
- SPF, DKIM, and DMARC checks with Rspamd and ClamAV scanning
- Signed webhooks for new mail and delivery outcomes
- Optional triage with category, needs-reply, and urgency
- Custom domains
- Dashboard for people to read, reply, and review
- Passwordless sign-in
- Self-hosting on Cloudflare

## Integrations
MCP, Claude Code, Cursor, Codex, Cloudflare Workers, Cloudflare R2, Cloudflare Email Routing and Sending, PostgreSQL, Hyperdrive, Rspamd, ClamAV, Postfix, Autumn, Stripe

## Platforms
WEB, API, CLI

## Pricing
Freemium — Free tier available with paid upgrades

## Links
- Website: https://goshenemail.com
- Documentation: https://goshenemail.com/docs
- Repository: https://github.com/boringcomputers/goshen-email
- EveryDev.ai: https://www.everydev.ai/tools/goshen-email
