Scoped agent identities
Operators create readable addresses and API keys for each agent, then pause, resume, archive, or route them through catch-all rules.
Open-source email infrastructure that gives software agents an inbox, an identity, and enforceable sending rules.
Agents need email accounts that operators can inspect and restrict. AgentBox provides the control plane while the customer keeps mail delivery inside their own AWS account.
AgentBox provisions Amazon SES, S3, and SNS without replacing an existing receipt-rule set. It ingests raw MIME, threads messages, stores attachments, and exposes mail through REST, realtime events, SDKs, MCP tools, and an operator console.
Operators create readable addresses and API keys for each agent, then pause, resume, archive, or route them through catch-all rules.
Allow lists, approval queues, daily limits, suppressions, and loop prevention put boundaries around autonomous sending.
Idempotent ingestion, cursor-based events, signed webhooks, retries, and dead-letter replay protect mail workflows from duplicate or lost work.
The console, audit log, health views, and configuration diff give a human a clear record of each agent mailbox.
Customer AWS accounts remain the mail servers. AgentBox manages configuration and agent access from a separate control plane.
Email is untrusted model input. The system narrows its effects with scoped keys, recipient rules, and operator approvals.