Skip to content
Oct 3, 2026NewsletterRSS

AgentMail Agents Can Now Sign Themselves Up but Can't Send Alone

AgentMail now lets AI agents sign up with no human email and get a receive-only inbox. Five breaking changes shipped in the same two weeks.

3 min read

AgentMailAgent inboxes

Hand-drawn illustration of a small robot-shaped mailbox taking letters into its intake slot, with a padlock on its outgoing slot on a yellow background

AI agents can now create an AgentMail account without giving a human’s email address, AgentMail said in its Sept. 28 changelog entry. The agent gets an inbox that receives mail right away, but “sending stays locked until a human is attached.”

Receive first, send after a human verifies

The human_email field is now optional on POST /v0/agent/sign-up. Without it, the inbox “cannot send to anyone until a human is attached,” the entry says. The API key from that sign-up can’t be recovered. Calling sign-up again without a human email creates a new organization with a different username.

A new endpoint, POST /v0/agent/human, attaches a person later. That person gets a six-digit passcode for POST /v0/agent/verify. Until they verify, the agent can email them. An organization can swap the attached human up to two times.

The same entry includes a breaking change. Unverified organizations can no longer create, update or delete pods. AgentMail uses pods to keep each tenant’s inboxes apart. They get a 403 until they verify.

Five breaking changes in two weeks

AgentMail’s changelog tags five entries from Sept. 16 to Sept. 30 as breaking changes. In the largest, on Sept. 30, “providers are now apps.” The /v0/providers routes, client.providers in the SDKs and agentmail providers in the CLI “are removed, not deprecated.” A second Sept. 30 entry renames two API key permissions to app_connect and app_share_owner. “There is no deprecation window,” it says. TypeScript SDK 0.5.32, Python SDK 2.0.6, CLI 1.7.0 and earlier releases can’t set or read those permissions.

The other two came earlier. On Sept. 23, signed attachment links began downloading files instead of opening them as web pages. The change reduces the risk of running content a sender controls. On Sept. 16, the inbox authorize endpoint started returning only a key ID and an instructions line.

Paused inboxes drop incoming mail

Mail sent to a paused inbox “is neither delivered nor bounced, then or when the inbox is resumed,” AgentMail said Oct. 1. That day it documented pausing in the API reference. The API already supported the feature. Sends from a paused inbox return 403 with code inbox_paused. The Python and TypeScript SDKs don’t accept the status field yet, the entry says.

Key takeaways

  • Agents can sign up with no human email and receive mail at once. They can’t send until a human verifies.
  • Unverified organizations can no longer manage pods.
  • Five changelog entries from Sept. 16 to Sept. 30 are tagged breaking. Some removed old names with no deprecation window.
  • Mail sent to a paused inbox is lost. The sender gets no bounce.

The take

We think the receive-only start is good design. The danger in letting software open its own email account is what it sends: spam, abusive sign-ups and mail to strangers. Receiving mail harms no one but the agent’s owner. Locking sending until a verified person is attached puts responsibility on a human. That is where mailbox providers expect it.

The pace of breaking changes is the cost. A deprecation window keeps the old name working for a while beside the new one. Teams can then upgrade when it suits them. Without one, an older SDK fails the day the server changes. Teams building on AgentMail should pin SDK versions, follow the changelog’s RSS feed and test upgrades against anything tagged breaking. Paused inboxes drop mail without a bounce. We’d treat a pause as a short hold, not a place to park an address.