Sendmux sdk agent

Official monorepo of SDKs, CLI, and MCP servers for Sendmux email APIs across TypeScript, Python, Go, PHP, Rust, and Ruby.

by Sendmux·MIT license·★ 65 Stars on the repo·GitHub ↗

Files of Sendmux sdk

Sendmux/main1 file
README.md
Show the full text253 lines

Sendmux SDKs

npm version PyPI version Go Reference crates.io version CI npm downloads Licence: MIT

Official SDK, CLI, and MCP workspace for Sendmux.

Packages

Ecosystem Package Surface API-key / hosted auth Install Source
npm @sendmux/core Shared TypeScript helpers n/a npm install @sendmux/core packages/ts/core
npm @sendmux/sending Sending API smx_mbx_* or owner-approved smx_agent_* npm install @sendmux/sending packages/ts/sending
npm @sendmux/mailbox Mailbox API smx_mbx_* or smx_agent_* npm install @sendmux/mailbox packages/ts/mailbox
npm @sendmux/management Management API smx_root_* npm install @sendmux/management packages/ts/management
npm @sendmux/sdk TypeScript umbrella package surface-specific npm install @sendmux/sdk packages/ts/sdk
npm @sendmux/cli sendmux CLI command/profile-specific npm install -g @sendmux/cli packages/ts/cli
npm sendmux-mcp stdio bridge to hosted MCP OAuth npx -y sendmux-mcp packages/ts/mcp
npm @sendmux/ai-sdk Vercel AI SDK tools (agent inbox + sending) send + receive smx_mbx_* or smx_agent_* npm install @sendmux/ai-sdk packages/ts/ai-sdk
Homebrew sendmux sendmux CLI command/profile-specific brew install sendmux/tap/sendmux Sendmux/homebrew-tap
PyPI sendmux-core Shared Python helpers n/a pip install sendmux-core packages/python/core
PyPI sendmux-sending Sending API smx_mbx_* or owner-approved smx_agent_* pip install sendmux-sending packages/python/sending
PyPI sendmux-mailbox Mailbox API smx_mbx_* or smx_agent_* pip install sendmux-mailbox packages/python/mailbox
PyPI sendmux-management Management API smx_root_* pip install sendmux-management packages/python/management
PyPI sendmux-sdk Python umbrella package surface-specific pip install sendmux-sdk packages/python/sdk
PyPI sendmux-mcp Local MCP plus hosted MCP and A2A servers OAuth for hosted; surface-specific keys for local pip install sendmux-mcp packages/python/mcp
PyPI langchain-sendmux LangChain toolkit (agent inbox + sending) REST OAuth or send + receive smx_mbx_* / smx_agent_* pip install langchain-sendmux packages/python/langchain
Go sendmux.ai/go/v3/core Shared Go helpers n/a go get sendmux.ai/go/[email protected] go/core
Go sendmux.ai/go/v3/sending Sending API smx_mbx_* or owner-approved smx_agent_* go get sendmux.ai/go/[email protected] go/sending
Go sendmux.ai/go/v3/mailbox Mailbox API smx_mbx_* or smx_agent_* go get sendmux.ai/go/[email protected] go/mailbox
Go sendmux.ai/go/v3/management Management API smx_root_* go get sendmux.ai/go/[email protected] go/management
Go sendmux.ai/go/v3/sdk Go umbrella package surface-specific go get sendmux.ai/go/[email protected] go/sdk
crates.io sendmux Rust umbrella crate surface-specific cargo add sendmux rust
Packagist sendmux/core Shared PHP helpers n/a composer require sendmux/core:^2.1 packages/php/core
Packagist sendmux/sending Sending API smx_mbx_* or owner-approved smx_agent_* composer require sendmux/sending:^2.1 packages/php/sending
Packagist sendmux/mailbox Mailbox API smx_mbx_* or smx_agent_* composer require sendmux/mailbox:^2.1 packages/php/mailbox
Packagist sendmux/management Management API smx_root_* composer require sendmux/management:^2.1 packages/php/management
Packagist sendmux/sdk PHP umbrella package surface-specific composer require sendmux/sdk:^2.1 packages/php/sdk
RubyGems sendmux-core Shared Ruby helpers n/a gem install sendmux-core packages/ruby/core
RubyGems sendmux-sending Sending API smx_mbx_* or owner-approved smx_agent_* gem install sendmux-sending packages/ruby/sending
RubyGems sendmux-mailbox Mailbox API smx_mbx_* or smx_agent_* gem install sendmux-mailbox packages/ruby/mailbox
RubyGems sendmux-management Management API smx_root_* gem install sendmux-management packages/ruby/management
RubyGems sendmux-sdk Ruby umbrella package surface-specific gem install sendmux-sdk packages/ruby/sdk

Quick start

Install only the package for the surface you need.

npm install @sendmux/sending
pip install sendmux-sending
go get sendmux.ai/go/[email protected]
cargo add sendmux
composer require sendmux/sending:^2.1
gem install sendmux-sending

Use send-capable smx_mbx_* keys or owner-approved Sending-resource smx_agent_* tokens for Sending clients. Use smx_mbx_* keys or scoped smx_agent_* tokens for Mailbox clients. Use root smx_root_* keys for Management clients. Agent tokens remain limited by server-side scopes; pre-claim self-registered agent tokens do not include email.send.

OAuth authentication

TypeScript, Python, Go, PHP, Ruby, and Rust surface clients accept a bare REST OAuth access token or a provider that resolves one before each request. Use the explicit token API below; API-key configuration continues to validate key prefixes.

Client Access-token configuration
TypeScript accessToken: token or accessToken: () => token; async providers are supported.
Vercel AI SDK sendmux({ accessToken: token }) or an async token provider; grant mailbox.read and email.send for one mailbox.
Python access_token=token or a callable.
LangChain SendmuxToolkit(access_token=token) or a callable; grant mailbox.read and email.send for one mailbox.
Go NewWithAccessToken(token) or NewWithTokenProvider(provider); providers receive the request context.
PHP ClientFactory::createMetaApiWithAccessToken($token) or a callable; each API factory has a WithAccessToken variant.
Ruby access_token: token or a callable.
Rust new_with_access_token(token) or new_with_token_provider(provider); providers return a future.

Choose one credential source. Your application owns secure storage and refresh coordination. Request resource=https://sendmux.ai/api; each API still checks its required scopes and granted surface. The CLI manages browser login and token refresh with sendmux auth:login; use sendmux auth:logout to revoke its connection.

OAuth setup and lifecycle.

Command-line access

For command-line access, install the CLI:

brew install sendmux/tap/sendmux
npm install -g @sendmux/cli
sendmux agent:register my-agent --mailbox-local-part my-agent --default --json

Agent registration does not require an existing account or API key. It creates a local profile with a durable, revocable credential for reading and receiving mail. To send, invite the owner with sendmux agent:invite-owner [email protected] --profile my-agent; after the owner accepts and approves sending, Sending API commands exchange and cache a one-hour delegated token automatically.

For stdio MCP clients, run the hosted OAuth bridge with Node.js 22 or later:

npx -y sendmux-mcp

Complete the browser sign-in on first connection. The npm bridge configuration forwards the hosted tools without a Python installation.

For local MCP with API keys, install the Python package:

pip install sendmux-mcp
sendmux-mcp-mailbox --help

The hosted MCP endpoint is https://mcp.sendmux.ai/mcp. Local MCP commands support stdio and HTTP transports; hosted MCP uses OAuth and does not require manual API keys or custom OAuth endpoints.

For A2A 1.0 clients, discover the hosted HTTP+JSON service from https://a2a.sendmux.ai/.well-known/agent-card.json. It exposes the same curated mailbox, management, and sending operations with an OAuth grant bound specifically to https://a2a.sendmux.ai/a2a/v1.

For AI-agent frameworks, first-party tool wrappers are available:

npm install @sendmux/ai-sdk ai zod   # Vercel AI SDK: sendmux({ apiKey }) returns a ToolSet
pip install langchain-sendmux        # LangChain: SendmuxToolkit(api_key=...).get_tools()

Both wrap the generated Sending and Mailbox clients, so the OpenAPI spec stays the single source of truth.

Connection checks

Authenticated connection checks for all three API surfaces return the current team, credential identity, connection label, permissions and authorised mailboxes. Mailbox checks need no mailbox selector or provisioned storage; Sending checks require email.send without sending an email or checking delivery readiness. Existing mailboxGetMe behaviour is unchanged.

Use TypeScript Sending 1.4.0, Mailbox 1.5.0 and Management 1.3.0 (or umbrella SDK 1.4.2), CLI 1.5.0, MCP 1.7.0, Ruby SDK 1.2.0, Rust 0.3.0, Go 1.5.0, PHP 2.0.0, or Python Sending 1.4.0, Mailbox 1.4.0 and Management 1.3.0 (or umbrella SDK 1.1.1).

Surface TypeScript operation CLI command MCP tool
Management managementGetConnection management:get-connection management_get_connection
Mailbox mailboxGetConnection mailbox:get-connection mailbox_get_connection
Sending sendingGetConnection sending:get-connection sending_get_connection

Use the corresponding client factory and credential. For example, with SENDMUX_API_KEY set to a Management key:

import { createManagementClient, managementGetConnection } from "@sendmux/sdk";

const client = createManagementClient({ apiKey: process.env.SENDMUX_API_KEY! });
const response = await managementGetConnection({ client });
console.log(response.data?.data.label);
sendmux management:get-connection --json

Each Rust client exposes get_connection(), returning Response<Connection>. Generated Go, Python, PHP and Ruby references include the corresponding GetConnection operation for each surface. Use the released package versions listed above; source code for pending releases is not yet available through package registries.

Attachments And Live Mailbox Events

Mailbox attachment metadata now includes a short-lived download_url. Fetch that URL promptly with a plain HTTP client; it does not require an Authorization header, but it expires after a short TTL. If a download URL expires, re-fetch the message or attachment metadata to receive a fresh URL.

For outbound files, avoid manually placing base64 in prompts or source strings. Use the zero-context path for your lane:

  • CLI: sendmux mailbox:send-message --attach ./report.pdf or sendmux sending:send --attach ./report.pdf.
  • TypeScript: use @sendmux/mailbox/node sendMailboxMessageWithFiles(...) or @sendmux/sending/node sendEmailWithFiles(...).
  • Python: use sendmux_mailbox.send_mailbox_message_with_files(...) or sendmux_sending.send_email_with_files(...).
  • MCP: agents can mint a presigned upload URL, PUT bytes to it without an API key, then send with the returned blob_id.

Mailbox direct uploads, presigned uploads, CLI --attach, and mailbox SDK file helpers share the mailbox attachment cap: currently 7,500,000 bytes per attachment. Sending API attachment helpers upload file bytes and send attachment references; the generated Sending API limit is max 10 attachments and a 25 MB request body.

Small generated attachments can still use inline base64 where the API schema supports them. MCP inline base64 is capped at 32 KiB decoded; use presigned upload, CLI --attach, or SDK file helpers for real files.

Live mailbox events are available through idiomatic lanes:

  • TypeScript: streamMailboxEvents(...) returns an async iterator over typed mailbox realtime events.
  • Python: iter_mailbox_events(...) yields typed MailboxRealtimeEvent models from the generated mailbox client.
  • CLI: sendmux mailbox:stream-events --follow prints one JSON event per line until the stream closes or the process is interrupted.
  • MCP: use mailbox_wait_for_message for bounded waits inside agent tool calls, then mailbox_get_attachment to renew attachment metadata and fetch download_url.

Repository structure

Maintainers: use the protected live E2E matrix for credential-free planning, explicit identity/send gates, cleanup evidence, and fresh-run audit rules. Static coverage and expected API negatives are not live capability certification. Attachment byte scenarios require trusted retention verification before live execution.

Path Purpose
packages/ts TypeScript SDK packages and the sendmux CLI.
packages/python Python SDK packages and the sendmux-mcp package.
go Go module sendmux.ai/go/v3 and subpackages.
rust Rust crate published as sendmux on crates.io.
packages/php PHP package sources used for Packagist packages and public split repositories.
packages/ruby RubyGem package sources.
codegen Generator configuration and templates.
scripts Generation, verification, publishing, and release helper scripts.
docs Surface-coverage and live E2E audit artefacts.
.github/workflows CI, canary, live E2E, and release workflows.

Versioning and support

Maintain package contracts

In a source checkout, maintainers can inspect the generated MCP package contract for the actual tool catalogue, schemas, upload workflows, hosted resource, and frozen protocol revisions. It describes this checkout, not the version already available from a package registry. Source hashes and native distribution metadata bind the artifact to its inputs; local transports and upstream API origins are separate from the hosted OAuth resource.

With the workspace dependencies installed and Python 3.10 or newer available, run these commands from the repository root:

pnpm generate:mcp
pnpm test:release-state
pnpm build:mcp

Generation refreshes editable Python metadata before discovering tools without upstream requests. The build checks wheel and source-distribution contents, an installed-wheel consumer outside the checkout, and the frozen conformance requirements. pnpm drift:check rejects generated changes that have not been staged or committed. Regenerate and review the contract when a release PR changes MCP's native version; do not reuse a contract from the previous version.

Native release validation covers TypeScript, Python, Rust, Ruby, and Go's component/tag convention. Go has no in-module version field. PHP versions belong to split-repository tags, not composer.version or release-please; Composer identities and dependencies are checked without treating a local path-repository version as publication evidence. Exact published tags and versions remain release gates.

Maintainers: native publication gates bind the supported release-workflow entries and PHP split command to immutable candidates and require fresh, strict live-schema parity before their first write. Low-level Ruby, npm, and Homebrew helpers are not guarded standalone release procedures; manual Snap promotion remains owner-approved policy.

Verify runtime compatibility from source

Maintainers: the CI workflow separates the generation/static build from language runtime checks. A configured cell is a required check, not a claim that an unreleased checkout has passed remotely. Compatibility floors aren't recommendations to deploy upstream-EOL runtimes.

Runtime Required CI cells Candidate package boundary
Node 22, 24, 26 on Ubuntu, macOS, Windows Six explicitly installed tarballs and CLI
Python 3.10–3.14 on Ubuntu Seven wheels with runtime tests; seven sdists with isolated installation
Go 1.23.4, 1.26, 1.27 on Ubuntu External module with an explicit candidate replacement; no toolchain auto-upgrade
PHP 8.2–8.5 on Ubuntu Five individual splits and an all-local umbrella consumer
Ruby 3.1, 3.2, 3.3, 3.4.1, 4.0 on Ubuntu Five locally installed gems; development tooling only on 3.4.1
Rust 1.82.0 and stable/latest on Ubuntu Independent source locks, verified crate, separately locked floor consumer

After the corresponding source build, run node scripts/ci-consumers.mjs node, python, go, or ruby from the repository root to verify installed imports outside the checkout. Python's repository-only MCP contract/packaging tests remain in source checks; the wheel consumer runs runtime tests and installed load_contract() without source-path injection. PHP uses node scripts/check-php-splits.mjs for the all-local composition check; individual splits can resolve published sibling dependencies and aren't that proof.

Linux Node cells additionally run node scripts/ci-consumers.mjs ai for the 12 exact AI/Zod pairs recorded in that helper. The candidate AI wrapper requires Zod 3.25.76 or newer and retains AI 5/6/7 coverage, including the historical AI 5.0.0/Zod 4.0.0 intersection. The published 0.4.0 wrapper still advertises the older Zod floor; this correction requires a later release.

For Rust, run the locked all-target/all-feature and doc tests with cargo +1.82.0, then node scripts/ci-consumers.mjs rust with stable and 1.82.0 installed (stable needs Clippy). That helper resolves latest dependencies in a temporary copy, tests and verifies cargo +stable package --locked, and checks the unpacked crate using rust/ci/floor-consumer/Cargo.lock. It never substitutes the library's embedded lock for the consumer lock. Surface coverage and Rust operation decisions distinguish named methods from partial/raw/unsupported operations.

Package release boundaries

SDK packages track the Sendmux public API contracts. Patch versions can differ between packages when a fix only affects one ecosystem or runtime.

Generated clients are built from committed OpenAPI snapshots. Any API contract change must update the snapshots and generated output in the same change.

For help, open a GitHub issue with the package name, version, command or import path, and the request ID from any API error response.

Contributing

Open pull requests against this repository. Keep generated output, source snapshots, and verification artefacts together in the same change.

Security issues should be reported through GitHub Security Advisories.

Licence

This repository is available under the MIT licence.

1# Sendmux SDKs
2 
3[![npm version](https://img.shields.io/npm/v/@sendmux/sdk?label=npm)](https://www.npmjs.com/package/@sendmux/sdk)
4[![PyPI version](https://img.shields.io/pypi/v/sendmux-sdk?label=pypi)](https://pypi.org/project/sendmux-sdk/)
5[![Go Reference](https://pkg.go.dev/badge/sendmux.ai/go/v3.svg)](https://pkg.go.dev/sendmux.ai/go/v3)
6[![crates.io version](https://img.shields.io/crates/v/sendmux?label=crates.io)](https://crates.io/crates/sendmux)
7[![CI](https://github.com/Sendmux/sendmux-sdk/actions/workflows/ci.yml/badge.svg)](https://github.com/Sendmux/sendmux-sdk/actions/workflows/ci.yml)
8[![npm downloads](https://img.shields.io/npm/dm/@sendmux/sdk?label=npm%20downloads)](https://www.npmjs.com/package/@sendmux/sdk)
9[![Licence: MIT](https://img.shields.io/badge/licence-MIT-blue.svg)](LICENSE)
10 
11Official SDK, CLI, and MCP workspace for Sendmux.
12 
13- Product documentation: [sendmux.ai/docs](https://sendmux.ai/docs)
14- Management API reference: [sendmux.ai/docs/api/introduction](https://sendmux.ai/docs/api/introduction)
15- Mailbox API reference: [sendmux.ai/docs/mailbox-api/introduction](https://sendmux.ai/docs/mailbox-api/introduction)
16- Sending API reference: [sendmux.ai/docs/sending-api/introduction](https://sendmux.ai/docs/sending-api/introduction)
17- MCP guide: [sendmux.ai/docs/ai-integrations/mcp](https://sendmux.ai/docs/ai-integrations/mcp)
18 
19## Packages
20 
21| Ecosystem | Package | Surface | API-key / hosted auth | Install | Source |
22| --- | --- | --- | --- | --- | --- |
23| npm | `@sendmux/core` | Shared TypeScript helpers | n/a | `npm install @sendmux/core` | [`packages/ts/core`](packages/ts/core) |
24| npm | `@sendmux/sending` | Sending API | `smx_mbx_*` or owner-approved `smx_agent_*` | `npm install @sendmux/sending` | [`packages/ts/sending`](packages/ts/sending) |
25| npm | `@sendmux/mailbox` | Mailbox API | `smx_mbx_*` or `smx_agent_*` | `npm install @sendmux/mailbox` | [`packages/ts/mailbox`](packages/ts/mailbox) |
26| npm | `@sendmux/management` | Management API | `smx_root_*` | `npm install @sendmux/management` | [`packages/ts/management`](packages/ts/management) |
27| npm | `@sendmux/sdk` | TypeScript umbrella package | surface-specific | `npm install @sendmux/sdk` | [`packages/ts/sdk`](packages/ts/sdk) |
28| npm | `@sendmux/cli` | `sendmux` CLI | command/profile-specific | `npm install -g @sendmux/cli` | [`packages/ts/cli`](packages/ts/cli) |
29| npm | `sendmux-mcp` | stdio bridge to hosted MCP | OAuth | `npx -y sendmux-mcp` | [`packages/ts/mcp`](packages/ts/mcp) |
30| npm | `@sendmux/ai-sdk` | Vercel AI SDK tools (agent inbox + sending) | send + receive `smx_mbx_*` or `smx_agent_*` | `npm install @sendmux/ai-sdk` | [`packages/ts/ai-sdk`](packages/ts/ai-sdk) |
31| Homebrew | `sendmux` | `sendmux` CLI | command/profile-specific | `brew install sendmux/tap/sendmux` | [`Sendmux/homebrew-tap`](https://github.com/Sendmux/homebrew-tap) |
32| PyPI | `sendmux-core` | Shared Python helpers | n/a | `pip install sendmux-core` | [`packages/python/core`](packages/python/core) |
33| PyPI | `sendmux-sending` | Sending API | `smx_mbx_*` or owner-approved `smx_agent_*` | `pip install sendmux-sending` | [`packages/python/sending`](packages/python/sending) |
34| PyPI | `sendmux-mailbox` | Mailbox API | `smx_mbx_*` or `smx_agent_*` | `pip install sendmux-mailbox` | [`packages/python/mailbox`](packages/python/mailbox) |
35| PyPI | `sendmux-management` | Management API | `smx_root_*` | `pip install sendmux-management` | [`packages/python/management`](packages/python/management) |
36| PyPI | `sendmux-sdk` | Python umbrella package | surface-specific | `pip install sendmux-sdk` | [`packages/python/sdk`](packages/python/sdk) |
37| PyPI | `sendmux-mcp` | Local MCP plus hosted MCP and A2A servers | OAuth for hosted; surface-specific keys for local | `pip install sendmux-mcp` | [`packages/python/mcp`](packages/python/mcp) |
38| PyPI | `langchain-sendmux` | LangChain toolkit (agent inbox + sending) | REST OAuth or send + receive `smx_mbx_*` / `smx_agent_*` | `pip install langchain-sendmux` | [`packages/python/langchain`](packages/python/langchain) |
39| Go | `sendmux.ai/go/v3/core` | Shared Go helpers | n/a | `go get sendmux.ai/go/[email protected]` | [`go/core`](go/core) |
40| Go | `sendmux.ai/go/v3/sending` | Sending API | `smx_mbx_*` or owner-approved `smx_agent_*` | `go get sendmux.ai/go/[email protected]` | [`go/sending`](go/sending) |
41| Go | `sendmux.ai/go/v3/mailbox` | Mailbox API | `smx_mbx_*` or `smx_agent_*` | `go get sendmux.ai/go/[email protected]` | [`go/mailbox`](go/mailbox) |
42| Go | `sendmux.ai/go/v3/management` | Management API | `smx_root_*` | `go get sendmux.ai/go/[email protected]` | [`go/management`](go/management) |
43| Go | `sendmux.ai/go/v3/sdk` | Go umbrella package | surface-specific | `go get sendmux.ai/go/[email protected]` | [`go/sdk`](go/sdk) |
44| crates.io | `sendmux` | Rust umbrella crate | surface-specific | `cargo add sendmux` | [`rust`](rust) |
45| Packagist | `sendmux/core` | Shared PHP helpers | n/a | `composer require sendmux/core:^2.1` | [`packages/php/core`](packages/php/core) |
46| Packagist | `sendmux/sending` | Sending API | `smx_mbx_*` or owner-approved `smx_agent_*` | `composer require sendmux/sending:^2.1` | [`packages/php/sending`](packages/php/sending) |
47| Packagist | `sendmux/mailbox` | Mailbox API | `smx_mbx_*` or `smx_agent_*` | `composer require sendmux/mailbox:^2.1` | [`packages/php/mailbox`](packages/php/mailbox) |
48| Packagist | `sendmux/management` | Management API | `smx_root_*` | `composer require sendmux/management:^2.1` | [`packages/php/management`](packages/php/management) |
49| Packagist | `sendmux/sdk` | PHP umbrella package | surface-specific | `composer require sendmux/sdk:^2.1` | [`packages/php/sdk`](packages/php/sdk) |
50| RubyGems | `sendmux-core` | Shared Ruby helpers | n/a | `gem install sendmux-core` | [`packages/ruby/core`](packages/ruby/core) |
51| RubyGems | `sendmux-sending` | Sending API | `smx_mbx_*` or owner-approved `smx_agent_*` | `gem install sendmux-sending` | [`packages/ruby/sending`](packages/ruby/sending) |
52| RubyGems | `sendmux-mailbox` | Mailbox API | `smx_mbx_*` or `smx_agent_*` | `gem install sendmux-mailbox` | [`packages/ruby/mailbox`](packages/ruby/mailbox) |
53| RubyGems | `sendmux-management` | Management API | `smx_root_*` | `gem install sendmux-management` | [`packages/ruby/management`](packages/ruby/management) |
54| RubyGems | `sendmux-sdk` | Ruby umbrella package | surface-specific | `gem install sendmux-sdk` | [`packages/ruby/sdk`](packages/ruby/sdk) |
55 
56## Quick start
57 
58Install only the package for the surface you need.
59 
60```sh
61npm install @sendmux/sending
62pip install sendmux-sending
63go get sendmux.ai/go/[email protected]
64cargo add sendmux
65composer require sendmux/sending:^2.1
66gem install sendmux-sending
67```
68 
69Use send-capable `smx_mbx_*` keys or owner-approved Sending-resource `smx_agent_*` tokens for Sending clients. Use `smx_mbx_*` keys or scoped `smx_agent_*` tokens for Mailbox clients. Use root `smx_root_*` keys for Management clients. Agent tokens remain limited by server-side scopes; pre-claim self-registered agent tokens do not include `email.send`.
70 
71## OAuth authentication
72 
73TypeScript, Python, Go, PHP, Ruby, and Rust surface clients accept a bare REST OAuth access token or a provider that resolves one before each request. Use the explicit token API below; API-key configuration continues to validate key prefixes.
74 
75| Client | Access-token configuration |
76| --- | --- |
77| TypeScript | `accessToken: token` or `accessToken: () => token`; async providers are supported. |
78| Vercel AI SDK | `sendmux({ accessToken: token })` or an async token provider; grant `mailbox.read` and `email.send` for one mailbox. |
79| Python | `access_token=token` or a callable. |
80| LangChain | `SendmuxToolkit(access_token=token)` or a callable; grant `mailbox.read` and `email.send` for one mailbox. |
81| Go | `NewWithAccessToken(token)` or `NewWithTokenProvider(provider)`; providers receive the request context. |
82| PHP | `ClientFactory::createMetaApiWithAccessToken($token)` or a callable; each API factory has a `WithAccessToken` variant. |
83| Ruby | `access_token: token` or a callable. |
84| Rust | `new_with_access_token(token)` or `new_with_token_provider(provider)`; providers return a future. |
85 
86Choose one credential source. Your application owns secure storage and refresh coordination. Request `resource=https://sendmux.ai/api`; each API still checks its required scopes and granted surface. The CLI manages browser login and token refresh with `sendmux auth:login`; use `sendmux auth:logout` to revoke its connection.
87 
88[OAuth setup and lifecycle](https://sendmux.ai/docs/developer-tools/oauth).
89 
90## Command-line access
91 
92For command-line access, install the CLI:
93 
94```sh
95brew install sendmux/tap/sendmux
96npm install -g @sendmux/cli
97sendmux agent:register my-agent --mailbox-local-part my-agent --default --json
98```
99 
100Agent registration does not require an existing account or API key. It creates a local profile with a durable, revocable credential for reading and receiving mail. To send, invite the owner with `sendmux agent:invite-owner [email protected] --profile my-agent`; after the owner accepts and approves sending, Sending API commands exchange and cache a one-hour delegated token automatically.
101 
102For stdio MCP clients, run the hosted OAuth bridge with Node.js 22 or later:
103 
104```sh
105npx -y sendmux-mcp
106```
107 
108Complete the browser sign-in on first connection. The [npm bridge configuration](packages/ts/mcp/README.md) forwards the hosted tools without a Python installation.
109 
110For local MCP with API keys, install the Python package:
111 
112```sh
113pip install sendmux-mcp
114sendmux-mcp-mailbox --help
115```
116 
117The hosted MCP endpoint is `https://mcp.sendmux.ai/mcp`. Local MCP commands support stdio and HTTP transports; hosted MCP uses OAuth and does not require manual API keys or custom OAuth endpoints.
118 
119For A2A 1.0 clients, discover the hosted HTTP+JSON service from `https://a2a.sendmux.ai/.well-known/agent-card.json`. It exposes the same curated mailbox, management, and sending operations with an OAuth grant bound specifically to `https://a2a.sendmux.ai/a2a/v1`.
120 
121For AI-agent frameworks, first-party tool wrappers are available:
122 
123```sh
124npm install @sendmux/ai-sdk ai zod # Vercel AI SDK: sendmux({ apiKey }) returns a ToolSet
125pip install langchain-sendmux # LangChain: SendmuxToolkit(api_key=...).get_tools()
126```
127 
128Both wrap the generated Sending and Mailbox clients, so the OpenAPI spec stays the single source of truth.
129 
130## Connection checks
131 
132Authenticated connection checks for all three API surfaces return the current team, credential identity, connection label, permissions and authorised mailboxes. Mailbox checks need no mailbox selector or provisioned storage; Sending checks require `email.send` without sending an email or checking delivery readiness. Existing `mailboxGetMe` behaviour is unchanged.
133 
134Use TypeScript Sending 1.4.0, Mailbox 1.5.0 and Management 1.3.0 (or umbrella SDK 1.4.2), CLI 1.5.0, MCP 1.7.0, Ruby SDK 1.2.0, Rust 0.3.0, Go 1.5.0, PHP 2.0.0, or Python Sending 1.4.0, Mailbox 1.4.0 and Management 1.3.0 (or umbrella SDK 1.1.1).
135 
136| Surface | TypeScript operation | CLI command | MCP tool |
137| --- | --- | --- | --- |
138| Management | `managementGetConnection` | `management:get-connection` | `management_get_connection` |
139| Mailbox | `mailboxGetConnection` | `mailbox:get-connection` | `mailbox_get_connection` |
140| Sending | `sendingGetConnection` | `sending:get-connection` | `sending_get_connection` |
141 
142Use the corresponding client factory and credential. For example, with `SENDMUX_API_KEY` set to a Management key:
143 
144```ts
145import { createManagementClient, managementGetConnection } from "@sendmux/sdk";
146 
147const client = createManagementClient({ apiKey: process.env.SENDMUX_API_KEY! });
148const response = await managementGetConnection({ client });
149console.log(response.data?.data.label);
150```
151 
152```sh
153sendmux management:get-connection --json
154```
155 
156Each Rust client exposes `get_connection()`, returning `Response<Connection>`. Generated Go, Python, PHP and Ruby references include the corresponding `GetConnection` operation for each surface. Use the released package versions listed above; source code for pending releases is not yet available through package registries.
157 
158## Attachments And Live Mailbox Events
159 
160Mailbox attachment metadata now includes a short-lived `download_url`. Fetch that URL promptly with a plain HTTP client; it does not require an `Authorization` header, but it expires after a short TTL. If a download URL expires, re-fetch the message or attachment metadata to receive a fresh URL.
161 
162For outbound files, avoid manually placing base64 in prompts or source strings. Use the zero-context path for your lane:
163 
164- CLI: `sendmux mailbox:send-message --attach ./report.pdf` or `sendmux sending:send --attach ./report.pdf`.
165- TypeScript: use `@sendmux/mailbox/node` `sendMailboxMessageWithFiles(...)` or `@sendmux/sending/node` `sendEmailWithFiles(...)`.
166- Python: use `sendmux_mailbox.send_mailbox_message_with_files(...)` or `sendmux_sending.send_email_with_files(...)`.
167- MCP: agents can mint a presigned upload URL, `PUT` bytes to it without an API key, then send with the returned `blob_id`.
168 
169Mailbox direct uploads, presigned uploads, CLI `--attach`, and mailbox SDK file helpers share the mailbox attachment cap: currently `7,500,000` bytes per attachment. Sending API attachment helpers upload file bytes and send attachment references; the generated Sending API limit is max 10 attachments and a 25 MB request body.
170 
171Small generated attachments can still use inline base64 where the API schema supports them. MCP inline base64 is capped at `32 KiB` decoded; use presigned upload, CLI `--attach`, or SDK file helpers for real files.
172 
173Live mailbox events are available through idiomatic lanes:
174 
175- TypeScript: `streamMailboxEvents(...)` returns an async iterator over typed mailbox realtime events.
176- Python: `iter_mailbox_events(...)` yields typed `MailboxRealtimeEvent` models from the generated mailbox client.
177- CLI: `sendmux mailbox:stream-events --follow` prints one JSON event per line until the stream closes or the process is interrupted.
178- MCP: use `mailbox_wait_for_message` for bounded waits inside agent tool calls, then `mailbox_get_attachment` to renew attachment metadata and fetch `download_url`.
179 
180## Repository structure
181 
182Maintainers: use the [protected live E2E matrix](docs/live-e2e-matrix.md) for credential-free planning, explicit identity/send gates, cleanup evidence, and fresh-run audit rules. Static coverage and expected API negatives are not live capability certification. Attachment byte scenarios require trusted retention verification before live execution.
183 
184| Path | Purpose |
185| --- | --- |
186| [`packages/ts`](packages/ts) | TypeScript SDK packages and the `sendmux` CLI. |
187| [`packages/python`](packages/python) | Python SDK packages and the `sendmux-mcp` package. |
188| [`go`](go) | Go module `sendmux.ai/go/v3` and subpackages. |
189| [`rust`](rust) | Rust crate published as `sendmux` on crates.io. |
190| [`packages/php`](packages/php) | PHP package sources used for Packagist packages and public split repositories. |
191| [`packages/ruby`](packages/ruby) | RubyGem package sources. |
192| [`codegen`](codegen) | Generator configuration and templates. |
193| [`scripts`](scripts) | Generation, verification, publishing, and release helper scripts. |
194| [`docs`](docs) | Surface-coverage and live E2E audit artefacts. |
195| [`.github/workflows`](.github/workflows) | CI, canary, live E2E, and release workflows. |
196 
197## Versioning and support
198 
199### Maintain package contracts
200 
201In a source checkout, maintainers can inspect the generated [MCP package contract](packages/python/mcp/sendmux_mcp/mcp-contract.json) for the actual tool catalogue, schemas, upload workflows, hosted resource, and frozen protocol revisions. It describes this checkout, not the version already available from a package registry. Source hashes and native distribution metadata bind the artifact to its inputs; local transports and upstream API origins are separate from the hosted OAuth resource.
202 
203With the workspace dependencies installed and Python 3.10 or newer available, run these commands from the repository root:
204 
205```sh
206pnpm generate:mcp
207pnpm test:release-state
208pnpm build:mcp
209```
210 
211Generation refreshes editable Python metadata before discovering tools without upstream requests. The build checks wheel and source-distribution contents, an installed-wheel consumer outside the checkout, and the frozen conformance requirements. `pnpm drift:check` rejects generated changes that have not been staged or committed. Regenerate and review the contract when a release PR changes MCP's native version; do not reuse a contract from the previous version.
212 
213Native release validation covers TypeScript, Python, Rust, Ruby, and Go's component/tag convention. Go has no in-module version field. PHP versions belong to split-repository tags, not `composer.version` or release-please; Composer identities and dependencies are checked without treating a local path-repository version as publication evidence. Exact published tags and versions remain release gates.
214 
215Maintainers: [native publication gates](docs/native-publication.md) bind the supported release-workflow entries and PHP split command to immutable candidates and require fresh, strict live-schema parity before their first write. Low-level Ruby, npm, and Homebrew helpers are not guarded standalone release procedures; manual Snap promotion remains owner-approved policy.
216 
217### Verify runtime compatibility from source
218 
219Maintainers: the [CI workflow](.github/workflows/ci.yml) separates the generation/static build from language runtime checks. A configured cell is a required check, not a claim that an unreleased checkout has passed remotely. Compatibility floors aren't recommendations to deploy upstream-EOL runtimes.
220 
221| Runtime | Required CI cells | Candidate package boundary |
222| --- | --- | --- |
223| Node | 22, 24, 26 on Ubuntu, macOS, Windows | Six explicitly installed tarballs and CLI |
224| Python | 3.10–3.14 on Ubuntu | Seven wheels with runtime tests; seven sdists with isolated installation |
225| Go | 1.23.4, 1.26, 1.27 on Ubuntu | External module with an explicit candidate replacement; no toolchain auto-upgrade |
226| PHP | 8.2–8.5 on Ubuntu | Five individual splits and an all-local umbrella consumer |
227| Ruby | 3.1, 3.2, 3.3, 3.4.1, 4.0 on Ubuntu | Five locally installed gems; development tooling only on 3.4.1 |
228| Rust | 1.82.0 and stable/latest on Ubuntu | Independent source locks, verified crate, separately locked floor consumer |
229 
230After the corresponding source build, run `node scripts/ci-consumers.mjs node`, `python`, `go`, or `ruby` from the repository root to verify installed imports outside the checkout. Python's repository-only MCP contract/packaging tests remain in source checks; the wheel consumer runs runtime tests and installed `load_contract()` without source-path injection. PHP uses `node scripts/check-php-splits.mjs` for the all-local composition check; individual splits can resolve published sibling dependencies and aren't that proof.
231 
232Linux Node cells additionally run `node scripts/ci-consumers.mjs ai` for the 12 exact AI/Zod pairs recorded in that helper. The candidate AI wrapper requires Zod 3.25.76 or newer and retains AI 5/6/7 coverage, including the historical AI 5.0.0/Zod 4.0.0 intersection. The published 0.4.0 wrapper still advertises the older Zod floor; this correction requires a later release.
233 
234For Rust, run the locked all-target/all-feature and doc tests with `cargo +1.82.0`, then `node scripts/ci-consumers.mjs rust` with stable and 1.82.0 installed (stable needs Clippy). That helper resolves latest dependencies in a temporary copy, tests and verifies `cargo +stable package --locked`, and checks the unpacked crate using `rust/ci/floor-consumer/Cargo.lock`. It never substitutes the library's embedded lock for the consumer lock. [Surface coverage](docs/surface-coverage.md) and [Rust operation decisions](rust/operation-decisions.json) distinguish named methods from partial/raw/unsupported operations.
235 
236### Package release boundaries
237 
238SDK packages track the Sendmux public API contracts. Patch versions can differ between packages when a fix only affects one ecosystem or runtime.
239 
240Generated clients are built from committed OpenAPI snapshots. Any API contract change must update the snapshots and generated output in the same change.
241 
242For help, open a [GitHub issue](https://github.com/Sendmux/sendmux-sdk/issues) with the package name, version, command or import path, and the request ID from any API error response.
243 
244## Contributing
245 
246Open pull requests against this repository. Keep generated output, source snapshots, and verification artefacts together in the same change.
247 
248Security issues should be reported through [GitHub Security Advisories](https://github.com/Sendmux/sendmux-sdk/security/advisories).
249 
250## Licence
251 
252This repository is available under the [MIT licence](LICENSE).
253 

Discussion

Alternatives

Xberg Document ExtractionExtract text, tables, metadata, and images from 107 document formats (PDF, Office, images, HTML, email, archives, academic) using Xberg. Use when writing code that calls Xberg APIs in Python, Node.js/TypeScript, Rust, or CLI. Covers installation, extraction (sync/async), configuration (OCR, chunking, output format), batch processing, error handling, and plugins.Coding · MITCode migrationMove code from one implementation to another function by function, tests first and code second, and check two implementations of one app for parity, with jscpd --compare as the progress measure and a coverage map binding each function to its tests. Use when porting a library or app to another language or framework (Java to Kotlin, JavaScript to Rust, a Python library to TypeScript, an iOS app to Android), when asked what is left to port, or when comparing the Android and iOS versions of an app.Coding · MITAhrefs pythonManages Ahrefs API usage in Python using `ahrefs-python` library. Use when working with SEO / marketing related tasks or with data including backlinks, keywords, domain ratings, organic traffic, site audits, rank tracking, and brand monitoring. Covers `ahrefs-python` usage including AhrefsClient / AsyncAhrefsClient, typed request/response models, error handling, and all API sections.Coding · MITadeuDocx ↔ LLM translator. Projects .docx office files to Markdown for editing. Projects edits back to OOXML as tracked changes (redlines). Python and Node.js implementations.Content & docs · MIT