REST send
Apps post JSON to https://mail.mailerz.net/api/v1/send. Bearer mz_live_. Desk login JWTs are rejected.
Developers
MailerZ API and MCP share one workspace key, so you can send as a custom domain you host. Mint that key on the desk. POST /api/v1/send for apps. POST /api/mcp for Claude, Cursor, Hermes, Cline, Continue, Windsurf, VS Code, and ChatGPT actions. From must be an address you host. We never rewrite header From. We do not accept mail for names we do not host.
Two doors. Same key. Same gates.
Apps post JSON to https://mail.mailerz.net/api/v1/send. Bearer mz_live_. Desk login JWTs are rejected.
Agents POST JSON-RPC 2.0 to https://mail.mailerz.net/api/mcp. Same key. Same paid send-as, SPF, DKIM, and alias gates.
mz_live_ key. Desk login JWTs are rejected.SEND_AS_LOCKED.A paid plan with send-as on. Free returns SEND_AS_LOCKED.
A verified domain you host. Not an open relay.
Live SPF and DKIM.
An enabled alias such as hello@. Catch-all * is not a From.
Envelope mail is rewritten with SRS. Header From is never rewritten. Limits and scan rules are the same for REST and MCP. See pricing and security. Protocol spec: Model Context Protocol.
curl -X POST https://mail.mailerz.net/api/v1/send \
-H "Authorization: Bearer mz_live_YOUR_KEY" \
-H "Content-Type: application/json; charset=utf-8" \
-d '{"from":"hello@your-domain.com","to":"user@gmail.com","subject":"Hello","text":"Plain body"}'{"jsonrpc":"2.0","id":1,"method":"initialize","params":{"protocolVersion":"2025-03-26","capabilities":{},"clientInfo":{"name":"demo","version":"1"}}}{"jsonrpc":"2.0","method":"notifications/initialized"}{"jsonrpc":"2.0","id":3,"method":"tools/call","params":{"name":"mailerz_whoami","arguments":{}}}A JSON-RPC 2.0 server on the MailerZ API. Agents call the same send, mailbox, and block tools the desk uses.
No. Use the Send API key from desk → Developer. mz_live_ for a workspace. mz_root_ is operator-only.
Yes. Cursor and Hermes can POST HTTP to /api/mcp. Claude Desktop and other stdio clients use npm run mcp as a proxy.
No.
No. Upgrade so send-as is on, then publish SPF + DKIM.
No.
No. Any client that speaks MCP JSON-RPC or stdio can connect.
Register or sign in on the desk, then Developer → API Key.
Start free with one domain. After the account exists, open Developer and copy mz_live_.