MinuteMail
REMOTE · MCP.MINUTEMAIL.CO · SCANNED SEP 27
Ephemeral mailboxes and a mock OAuth IdP for testing email and auth flows — 39 API-driven tools
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security46
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- Authorisation check failed: no authorisation is required to call this server, and it exposes a tool marked destructive (mailboxes.delete). See how to fix → View diagnostics → Fail
- HTTPS enforcement could not be verified: the plaintext port answered with HTTP 405, which proves neither a plaintext path nor enforcement. View diagnostics → Unverified
- HSTS check failed: the Strict-Transport-Security header is absent. See how to fix → View diagnostics → Fail
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability77
- AI-judged instruction clarity (good).Pass
- Tool/resource definitions use about 1923 tokens (~48/item across 40 items; 40 tools + 0 resources), lean.Pass
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management100
- No destabilizing schema changes in the last 30 days.Pass
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 100% of tool parameters carry a description.Pass
- Structured output schemas are declared (100% of tools); any adoption earns full credit.Pass
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- All 12 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation.Pass
- An AI judge read all 40 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities60
- Spec-recency check failed: implements MCP spec 2025-06-18; the latest is 2026-07-28. See how to fix → Fail
How do I install the MinuteMail MCP server?
MinuteMail is a hosted endpoint at https://mcp.minutemail.co/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · mcp.minutemail.co
claude mcp add --transport http minutemailco-mcp-server 'https://mcp.minutemail.co/mcp'
{
"mcpServers": {
"minutemailco-mcp-server": {
"url": "https://mcp.minutemail.co/mcp"
}
}
} {
"servers": {
"minutemailco-mcp-server": {
"type": "http",
"url": "https://mcp.minutemail.co/mcp"
}
}
} [mcp_servers.minutemailco-mcp-server] url = "https://mcp.minutemail.co/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"minutemailco-mcp-server": {
"type": "remote",
"url": "https://mcp.minutemail.co/mcp",
"enabled": true
}
}
} openclaw mcp add minutemailco-mcp-server --url 'https://mcp.minutemail.co/mcp' --transport streamable-http
mcp_servers:
minutemailco-mcp-server:
url: "https://mcp.minutemail.co/mcp" {
"McpServers": {
"minutemailco-mcp-server": {
"Transport": "http",
"Url": "https://mcp.minutemail.co/mcp"
}
}
} assistant mcp add minutemailco-mcp-server -t streamable-http -u 'https://mcp.minutemail.co/mcp'
{
"mcpServers": {
"minutemailco-mcp-server": {
"type": "http",
"url": "https://mcp.minutemail.co/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 25 Sept 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 23 Sept 26 +1
- Stability: 0.97 → pass security
- 21 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 90 to 93. That category is still filling its 30-day observation window: 27 days of observed history at the previous scan, 28 at this one. The score rises as the window fills, whether or not the server changes.
- 19 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 83 to 87. That category is still filling its 30-day observation window: 25 days of observed history at the previous scan, 26 at this one. The score rises as the window fills, whether or not the server changes.
- 17 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 77 to 80. That category is still filling its 30-day observation window: 23 days of observed history at the previous scan, 24 at this one. The score rises as the window fills, whether or not the server changes.
- 15 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 70 to 73. That category is still filling its 30-day observation window: 21 days of observed history at the previous scan, 22 at this one. The score rises as the window fills, whether or not the server changes.
- 13 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 63 to 67. That category is still filling its 30-day observation window: 19 days of observed history at the previous scan, 20 at this one. The score rises as the window fills, whether or not the server changes.
- 10 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 53 to 57. That category is still filling its 30-day observation window: 16 days of observed history at the previous scan, 17 at this one. The score rises as the window fills, whether or not the server changes.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 27 Sept 2026 · Probed https://mcp.minutemail.co/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=mcp.minutemail.co | CN=YR1,O=Let's Encrypt,C=US | 19 Aug 2026 | 17 Nov 2026 | RSA 2048 | SHA256-RSA | 51f54ccfd54bc81238a6e9c01ccb264c7b4 |
| SANs: mcp.minutemail.co | ||||||
| CN=YR1,O=Let's Encrypt,C=US (CA) | CN=Root YR,O=ISRG,C=US | 3 Sept 2025 | 2 Sept 2028 | RSA 2048 | SHA256-RSA | a20253f15f2691c05dc1ce13b9bcca4e |
| CN=Root YR,O=ISRG,C=US (CA) | CN=ISRG Root X1,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | RSA 4096 | SHA256-RSA | f24b6d17f9d9ad7cb1c9fea78782699f |
Background: What to check on a remote MCP endpoint →
DNSSEC insecure
Validation of mcp.minutemail.co. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| co. | present | 7786 | 8 | Verified |
| minutemail.co. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://mcp.minutemail.co/mcp | Verified | 200 | |
| http (plaintext) | http://mcp.minutemail.co/mcp | Inconclusive | 405 |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
archived.delete Delete archived mailbox ~26
Permanently delete an archived mailbox.
| Name | Type | Req | Description |
|---|---|---|---|
| mailboxId | string | yes | Archived mailbox ID |
| Name | Type | Req | Description |
|---|---|---|---|
| http_status | integer | yes | HTTP status of the API response |
| status | string | yes | – |
No examples provided.
archived.get Get archived mailbox ~27
Fetch a single archived mailbox by ID.
| Name | Type | Req | Description |
|---|---|---|---|
| mailboxId | string | yes | Archived mailbox ID |
| Name | Type | Req | Description |
|---|---|---|---|
| address | string | yes | Full mailbox address |
| alias | string | – | Local part of the address |
| createdAt | string | – | Creation timestamp (RFC 3339) |
| domain | string | – | Mailbox domain |
| expiresAt | string | – | Expiry timestamp (RFC 3339); null when permanent |
| id | string | yes | Mailbox ID |
| messageCount | integer | – | Number of mails in the mailbox |
| owner | string | – | Owner (tenant) ID |
| permanent | boolean | – | Whether the mailbox never expires |
| recoverable | boolean | – | Whether the mailbox can be recovered after expiry |
No examples provided.
archived.list List archived mailboxes ~22
List the tenant's archived (expired but recoverable) mailboxes.
Input schema present but exposes no named parameters.
| Name | Type | Req | Description |
|---|---|---|---|
| items | array | yes | – |
No examples provided.
archived.reactivate Reactivate archived mailbox ~49
Reactivate an archived mailbox back to active state.
| Name | Type | Req | Description |
|---|---|---|---|
| expiresIn | integer | – | New lifetime in minutes, 1-60. Optional. |
| mailboxId | string | yes | Archived mailbox ID |
| Name | Type | Req | Description |
|---|---|---|---|
| address | string | yes | Full mailbox address |
| alias | string | – | Local part of the address |
| createdAt | string | – | Creation timestamp (RFC 3339) |
| domain | string | – | Mailbox domain |
| expiresAt | string | – | Expiry timestamp (RFC 3339); null when permanent |
| id | string | yes | Mailbox ID |
| messageCount | integer | – | Number of mails in the mailbox |
| owner | string | – | Owner (tenant) ID |
| permanent | boolean | – | Whether the mailbox never expires |
| recoverable | boolean | – | Whether the mailbox can be recovered after expiry |
No examples provided.
attachments.add Add attachment ~121
Attach a file to a test-injected email (base64 payload).
| Name | Type | Req | Description |
|---|---|---|---|
| contentType | string | – | MIME type, defaults to application/octet-stream |
| data | string | yes | File contents, standard base64 |
| expiresIn | integer | – | Attachment lifetime in minutes (>=1). Optional. |
| filename | string | yes | Attachment file name |
| mailId | string | yes | Mail ID |
| mailboxId | string | yes | Mailbox ID |
| sizeBytes | integer | – | Expected size in bytes. Optional; validated against the decoded data when set. |
| Name | Type | Req | Description |
|---|---|---|---|
| contentType | string | – | MIME type |
| expiresAt | string | – | Expiry timestamp (RFC 3339) |
| filename | string | yes | Attachment file name |
| id | string | yes | Attachment ID |
| sizeBytes | integer | – | Size in bytes |
No examples provided.
attachments.delete Delete attachment ~44
Delete a single attachment.
| Name | Type | Req | Description |
|---|---|---|---|
| attachmentId | string | yes | Attachment ID |
| mailId | string | yes | Mail ID |
| mailboxId | string | yes | Mailbox ID |
| Name | Type | Req | Description |
|---|---|---|---|
| http_status | integer | yes | HTTP status of the API response |
| status | string | yes | – |
No examples provided.
attachments.delete_bulk Bulk delete attachments ~50
Delete several attachments of one email at once.
| Name | Type | Req | Description |
|---|---|---|---|
| ids | array | yes | Attachment IDs to delete |
| mailId | string | yes | Mail ID |
| mailboxId | string | yes | Mailbox ID |
| Name | Type | Req | Description |
|---|---|---|---|
| http_status | integer | yes | HTTP status of the API response |
| status | string | yes | – |
No examples provided.
attachments.get Get attachment ~60
Download an attachment. The file contents are returned base64-encoded in the JSON "data" field.
| Name | Type | Req | Description |
|---|---|---|---|
| attachmentId | string | yes | Attachment ID |
| mailId | string | yes | Mail ID |
| mailboxId | string | yes | Mailbox ID |
| Name | Type | Req | Description |
|---|---|---|---|
| contentType | string | – | MIME type |
| data | string | yes | File contents, standard base64 |
| expiresAt | string | – | Expiry timestamp (RFC 3339) |
| filename | string | yes | Attachment file name |
| id | string | yes | Attachment ID |
| sizeBytes | integer | – | Size in bytes |
No examples provided.
attachments.list List attachments ~39
List the attachments of an email (metadata only).
| Name | Type | Req | Description |
|---|---|---|---|
| mailId | string | yes | Mail ID |
| mailboxId | string | yes | Mailbox ID |
| Name | Type | Req | Description |
|---|---|---|---|
| items | array | yes | – |
No examples provided.
domains.delete Delete domain ~24
Delete a registered custom domain.
| Name | Type | Req | Description |
|---|---|---|---|
| domainId | string | yes | Domain ID |
| Name | Type | Req | Description |
|---|---|---|---|
| http_status | integer | yes | HTTP status of the API response |
| status | string | yes | – |
No examples provided.
domains.list List domains ~20
List the tenant's custom domains with their DNS verification status.
Input schema present but exposes no named parameters.
| Name | Type | Req | Description |
|---|---|---|---|
| items | array | yes | – |
No examples provided.
domains.register Register domain ~47
Register a new custom domain. DNS records (TXT token + MX) must then be added before verification can succeed.
| Name | Type | Req | Description |
|---|---|---|---|
| name | string | yes | Domain name, e.g. mail.example.com |
| Name | Type | Req | Description |
|---|---|---|---|
| createdAt | string | – | Creation timestamp (RFC 3339) |
| id | string | yes | Domain ID |
| mxTarget | string | – | MX target to add to the domain's DNS before verification |
| name | string | yes | Domain name |
| status | string | yes | DNS verification status |
| txtToken | string | – | TXT token to add to the domain's DNS before verification |
No examples provided.
domains.verify Verify domain ~31
Trigger DNS verification (TXT + MX) of a registered domain.
| Name | Type | Req | Description |
|---|---|---|---|
| domainId | string | yes | Domain ID |
| Name | Type | Req | Description |
|---|---|---|---|
| createdAt | string | – | Creation timestamp (RFC 3339) |
| id | string | yes | Domain ID |
| mxTarget | string | – | MX target to add to the domain's DNS before verification |
| name | string | yes | Domain name |
| status | string | yes | DNS verification status |
| txtToken | string | – | TXT token to add to the domain's DNS before verification |
No examples provided.
identities.create Create identity ~148
Create a mock identity bound to a mailbox for OAuth flow testing.
| Name | Type | Req | Description |
|---|---|---|---|
| avatarUrl | string | – | Avatar URL. Optional. |
| claims | object | – | Custom claims (e.g. role, plan) merged into the ID token and userinfo. Custom-provider clients only — rejected for google/github/apple/facebook. Optional. |
| clientId | string | yes | OAuth client ID the identity belongs to |
| emailVerified | boolean | – | Value of the email_verified claim issued for this identity. Optional. |
| mailboxAddress | string | yes | Mailbox address the identity is linked to (must exist) |
| name | string | – | Display name. Optional. |
| username | string | – | Identity username. Optional. |
| Name | Type | Req | Description |
|---|---|---|---|
| avatarUrl | string | – | Avatar URL |
| clientId | string | yes | OAuth client ID the identity belongs to |
| id | string | yes | Identity ID |
| mailboxAddress | string | yes | Mailbox address the identity is linked to |
| name | string | – | Display name |
| username | string | – | Identity username |
No examples provided.
identities.delete Delete identity ~23
Delete a mock identity.
| Name | Type | Req | Description |
|---|---|---|---|
| identityId | string | yes | Identity ID |
| Name | Type | Req | Description |
|---|---|---|---|
| http_status | integer | yes | HTTP status of the API response |
| status | string | yes | – |
No examples provided.
identities.get Get identity ~26
Fetch a single mock identity by ID.
| Name | Type | Req | Description |
|---|---|---|---|
| identityId | string | yes | Identity ID |
| Name | Type | Req | Description |
|---|---|---|---|
| avatarUrl | string | – | Avatar URL |
| clientId | string | yes | OAuth client ID the identity belongs to |
| id | string | yes | Identity ID |
| mailboxAddress | string | yes | Mailbox address the identity is linked to |
| name | string | – | Display name |
| username | string | – | Identity username |
No examples provided.
identities.list List identities ~53
List the tenant's mock identities, optionally filtered by OAuth client or mailbox address.
| Name | Type | Req | Description |
|---|---|---|---|
| clientId | string | – | Filter by OAuth client ID. Optional. |
| mailboxAddress | string | – | Filter by mailbox address. Optional. |
| Name | Type | Req | Description |
|---|---|---|---|
| items | array | yes | – |
No examples provided.
identities.update Update identity ~159
Update a mock identity: profile fields, isActive (activate/deactivate), emailVerified, and custom claims merged into the ID token and userinfo.
| Name | Type | Req | Description |
|---|---|---|---|
| avatarUrl | string | – | Avatar URL. Optional. |
| claims | object | – | Custom claims (e.g. role, plan) merged into the ID token and userinfo. Replaces existing claims. Reserved claim names are rejected. Optional. |
| emailVerified | boolean | – | Value of the email_verified claim issued for this identity. Optional. |
| identityId | string | yes | Identity ID |
| isActive | boolean | – | Whether the identity can be used in OAuth flows. Optional. |
| name | string | – | Display name. Optional. |
| username | string | – | Identity username. Optional. |
| Name | Type | Req | Description |
|---|---|---|---|
| avatarUrl | string | – | Avatar URL |
| clientId | string | yes | OAuth client ID the identity belongs to |
| id | string | yes | Identity ID |
| mailboxAddress | string | yes | Mailbox address the identity is linked to |
| name | string | – | Display name |
| username | string | – | Identity username |
No examples provided.
mailboxes.create Create mailbox ~141
Create a new temporary mailbox. The domain defaults to the tenant's default domain; the owner is always the API key's owner.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | – | Mailbox domain. Defaults to the tenant default domain (e.g. minutemail.cc). |
| expiresIn | integer | – | Lifetime in minutes, 1-60. Omit for the service default TTL. |
| noExpiration | boolean | – | Set true for a permanent mailbox (mutually exclusive with expiresIn). |
| recoverable | boolean | – | Set true to keep the mailbox recoverable after expiry (requires tag). |
| tag | string | – | Recovery tag, required when recoverable is true. |
| Name | Type | Req | Description |
|---|---|---|---|
| address | string | yes | Full mailbox address |
| alias | string | – | Local part of the address |
| createdAt | string | – | Creation timestamp (RFC 3339) |
| domain | string | – | Mailbox domain |
| expiresAt | string | – | Expiry timestamp (RFC 3339); null when permanent |
| id | string | yes | Mailbox ID |
| messageCount | integer | – | Number of mails in the mailbox |
| owner | string | – | Owner (tenant) ID |
| permanent | boolean | – | Whether the mailbox never expires |
| recoverable | boolean | – | Whether the mailbox can be recovered after expiry |
No examples provided.
mailboxes.delete Delete mailbox ~29
Delete a mailbox and its contents by ID.
| Name | Type | Req | Description |
|---|---|---|---|
| mailboxId | string | yes | Mailbox ID |
| Name | Type | Req | Description |
|---|---|---|---|
| http_status | integer | yes | HTTP status of the API response |
| status | string | yes | – |
No examples provided.
mailboxes.delete_bulk Bulk delete mailboxes ~31
Delete several mailboxes at once by ID.
| Name | Type | Req | Description |
|---|---|---|---|
| ids | array | yes | Mailbox IDs to delete |
| Name | Type | Req | Description |
|---|---|---|---|
| http_status | integer | yes | HTTP status of the API response |
| status | string | yes | – |
No examples provided.
mailboxes.get Get mailbox ~27
Fetch a single mailbox by ID.
| Name | Type | Req | Description |
|---|---|---|---|
| mailboxId | string | yes | Mailbox ID |
| Name | Type | Req | Description |
|---|---|---|---|
| address | string | yes | Full mailbox address |
| alias | string | – | Local part of the address |
| createdAt | string | – | Creation timestamp (RFC 3339) |
| domain | string | – | Mailbox domain |
| expiresAt | string | – | Expiry timestamp (RFC 3339); null when permanent |
| id | string | yes | Mailbox ID |
| messageCount | integer | – | Number of mails in the mailbox |
| owner | string | – | Owner (tenant) ID |
| permanent | boolean | – | Whether the mailbox never expires |
| recoverable | boolean | – | Whether the mailbox can be recovered after expiry |
No examples provided.
mailboxes.list List mailboxes ~61
List the tenant's active mailboxes (owner is derived from the API key). Optionally look up a single mailbox by exact address.
| Name | Type | Req | Description |
|---|---|---|---|
| address | string | – | Exact mailbox address to look up (e.g. user@minutemail.cc). Optional. |
| Name | Type | Req | Description |
|---|---|---|---|
| items | array | yes | – |
No examples provided.
mails.delete Delete mail ~34
Delete a single email.
| Name | Type | Req | Description |
|---|---|---|---|
| mailId | string | yes | Mail ID |
| mailboxId | string | yes | Mailbox ID |
| Name | Type | Req | Description |
|---|---|---|---|
| http_status | integer | yes | HTTP status of the API response |
| status | string | yes | – |
No examples provided.
mails.delete_bulk Bulk delete mails ~40
Delete several emails of one mailbox at once.
| Name | Type | Req | Description |
|---|---|---|---|
| ids | array | yes | Mail IDs to delete |
| mailboxId | string | yes | Mailbox ID |
| Name | Type | Req | Description |
|---|---|---|---|
| http_status | integer | yes | HTTP status of the API response |
| status | string | yes | – |
No examples provided.
mails.get Get mail ~42
Fetch a single email by ID, including body and attachment metadata.
| Name | Type | Req | Description |
|---|---|---|---|
| mailId | string | yes | Mail ID |
| mailboxId | string | yes | Mailbox ID |
| Name | Type | Req | Description |
|---|---|---|---|
| body | string | – | Plain-text body (present on single-mail fetches) |
| expiresAt | string | – | Expiry timestamp (RFC 3339) |
| id | string | yes | Mail ID |
| receivedAt | string | – | Received timestamp (RFC 3339) |
| sender | string | yes | Sender email address |
| subject | string | yes | Email subject |
No examples provided.
mails.inject Inject test mail ~104
Inject a simulated inbound email into a mailbox (multipart upload). No external mail is sent; use this to simulate inbound mail for flow testing.
| Name | Type | Req | Description |
|---|---|---|---|
| attachments | array | – | Attachments to include |
| body | string | yes | Plain-text body |
| expiresIn | integer | – | Mail lifetime in minutes (>=1). Optional. |
| mailboxId | string | yes | Mailbox ID |
| sender | string | yes | Sender email address |
| subject | string | yes | Email subject |
| Name | Type | Req | Description |
|---|---|---|---|
| body | string | – | Plain-text body (present on single-mail fetches) |
| expiresAt | string | – | Expiry timestamp (RFC 3339) |
| id | string | yes | Mail ID |
| receivedAt | string | – | Received timestamp (RFC 3339) |
| sender | string | yes | Sender email address |
| subject | string | yes | Email subject |
No examples provided.
mails.list List mails ~29
List the emails in a mailbox, newest first.
| Name | Type | Req | Description |
|---|---|---|---|
| mailboxId | string | yes | Mailbox ID |
| Name | Type | Req | Description |
|---|---|---|---|
| items | array | yes | – |
No examples provided.
oauth.clients.create Create OAuth client ~83
Register an OAuth client for mock identity flows. The plaintext clientSecret is returned once at creation.
| Name | Type | Req | Description |
|---|---|---|---|
| name | string | yes | Client display name |
| providerLabel | string | – | Custom provider label. Required when providerType is custom. |
| providerType | string | – | Identity provider type |
| redirectUris | array | yes | Allowed redirect URIs (at least one) |
| Name | Type | Req | Description |
|---|---|---|---|
| clientId | string | yes | Public OAuth client ID |
| clientSecret | string | – | Plaintext secret — returned once at creation or rotation |
| createdAt | string | – | Creation timestamp (RFC 3339) |
| name | string | yes | Client display name |
| providerLabel | string | – | Custom provider label |
| providerType | string | – | Identity provider type |
| redirectUris | array | – | Allowed redirect URIs |
No examples provided.
oauth.clients.delete Delete OAuth client ~31
Delete an OAuth client by its public client ID.
| Name | Type | Req | Description |
|---|---|---|---|
| clientId | string | yes | Public OAuth client ID |
| Name | Type | Req | Description |
|---|---|---|---|
| http_status | integer | yes | HTTP status of the API response |
| status | string | yes | – |
No examples provided.
oauth.clients.get Get OAuth client ~32
Fetch a single OAuth client by its public client ID.
| Name | Type | Req | Description |
|---|---|---|---|
| clientId | string | yes | Public OAuth client ID |
| Name | Type | Req | Description |
|---|---|---|---|
| clientId | string | yes | Public OAuth client ID |
| clientSecret | string | – | Plaintext secret — returned once at creation or rotation |
| createdAt | string | – | Creation timestamp (RFC 3339) |
| name | string | yes | Client display name |
| providerLabel | string | – | Custom provider label |
| providerType | string | – | Identity provider type |
| redirectUris | array | – | Allowed redirect URIs |
No examples provided.
oauth.clients.list List OAuth clients ~20
List the tenant's OAuth clients for mock identity testing.
Input schema present but exposes no named parameters.
| Name | Type | Req | Description |
|---|---|---|---|
| clients | array | – | – |
No examples provided.
oauth.clients.rotate_secret Rotate client secret ~36
Rotate an OAuth client's secret. The new plaintext secret is returned once.
| Name | Type | Req | Description |
|---|---|---|---|
| clientId | string | yes | Public OAuth client ID |
| Name | Type | Req | Description |
|---|---|---|---|
| clientId | string | yes | Public OAuth client ID |
| clientSecret | string | – | Plaintext secret — returned once at creation or rotation |
| createdAt | string | – | Creation timestamp (RFC 3339) |
| name | string | yes | Client display name |
| providerLabel | string | – | Custom provider label |
| providerType | string | – | Identity provider type |
| redirectUris | array | – | Allowed redirect URIs |
No examples provided.
team.invitations.create Create invitation ~40
Create a team invitation for an email address (SMTP invite is sent by the team service).
| Name | Type | Req | Description |
|---|---|---|---|
| string | yes | Invitee email address |
| Name | Type | Req | Description |
|---|---|---|---|
| createdAt | string | – | Creation timestamp (RFC 3339) |
| string | yes | Invitee email address | |
| id | string | yes | Invitation ID |
| status | string | yes | Invitation status (e.g. PENDING) |
No examples provided.
team.invitations.delete Delete invitation ~27
Revoke a team invitation.
| Name | Type | Req | Description |
|---|---|---|---|
| invitationId | string | yes | Invitation ID |
| Name | Type | Req | Description |
|---|---|---|---|
| http_status | integer | yes | HTTP status of the API response |
| status | string | yes | – |
No examples provided.
team.invitations.list List invitations ~18
List the tenant's team invitations.
Input schema present but exposes no named parameters.
| Name | Type | Req | Description |
|---|---|---|---|
| items | array | yes | – |
No examples provided.
team.members.add Add team member ~62
Add a team member directly (no invitation flow).
| Name | Type | Req | Description |
|---|---|---|---|
| string | yes | Member email address | |
| status | string | yes | Member status, conventionally ACTIVE |
| user_id | string | yes | Member user ID |
| username | string | yes | Member username |
| Name | Type | Req | Description |
|---|---|---|---|
| createdAt | string | – | Creation timestamp (RFC 3339) |
| string | yes | Member email address | |
| id | string | yes | Member ID |
| status | string | yes | Member status (e.g. ACTIVE) |
| user_id | string | – | Member user ID |
| username | string | – | Member username |
No examples provided.
team.members.delete Delete team member ~24
Remove a team member.
| Name | Type | Req | Description |
|---|---|---|---|
| memberId | string | yes | Member ID |
| Name | Type | Req | Description |
|---|---|---|---|
| http_status | integer | yes | HTTP status of the API response |
| status | string | yes | – |
No examples provided.
team.members.get Get team member ~27
Fetch a single team member by ID.
| Name | Type | Req | Description |
|---|---|---|---|
| memberId | string | yes | Member ID |
| Name | Type | Req | Description |
|---|---|---|---|
| createdAt | string | – | Creation timestamp (RFC 3339) |
| string | yes | Member email address | |
| id | string | yes | Member ID |
| status | string | yes | Member status (e.g. ACTIVE) |
| user_id | string | – | Member user ID |
| username | string | – | Member username |
No examples provided.
team.members.list List team members ~16
List the tenant's team members.
Input schema present but exposes no named parameters.
| Name | Type | Req | Description |
|---|---|---|---|
| items | array | yes | – |
No examples provided.
What is the MinuteMail MCP server?
MinuteMail is an MCP server listed in the public MCP registry as io.github.minutemailco/mcp-server. Ephemeral mailboxes and a mock OAuth IdP for testing email and auth flows, 39 API-driven tools. This page covers its hosted endpoint (https://mcp.minutemail.co/mcp).
Is the MinuteMail MCP server safe to use?
MinuteMail scores 73 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the MinuteMail MCP server expose?
MinuteMail exposes 40 tools: mailboxes.list, mailboxes.create, mailboxes.get, mailboxes.delete, mailboxes.delete_bulk, and 35 more. Their descriptions and schemas cost roughly 1,923 tokens of context every time the server is loaded.
Does the MinuteMail MCP server require authentication?
No. We connected to MinuteMail without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.
Is the MinuteMail MCP server still maintained?
MinuteMail is still listed as active in the MCP registry. We last reached this channel on 27 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.