MCP server for ReplyLayer — safe email for AI agents
Inferred from the transports this listing declares (stdio, streamable-http). A client not listed here hasn’t been ruled out — it just isn’t something Forge can confirm.
REPLYLAYER_API_KEYAPI keyoptionalReplyLayer API key. Optional if you ran `npx -y replylayer-mcp init`, which stores it locally.
Declared by the author in the official MCP registry. Forge does not store, broker, or ever see these values — the config below is scaffolded with placeholders you fill in locally.
Verification confirms publisher identity (repo ownership), not code safety. The security scan covers known CVEs and suspicious install scripts.
Read out of the source npm actually ships, at scan time. The package was never executed. Tools registered dynamically at runtime, or hidden inside bundled or minified code, can be missed — so this is a floor on the tool surface, not a complete census of it.
add_inbound_allowlist_bulkBulk-add up to 1000 sender email addresses or @domain patterns to the inbound allowlist for a mailbox in a single call. Useful for onboarding/migration when importing an existing trusted-senders list. Returns a partial-success response: added[], already_existed[], invalid[] (with per-email reason),…Bulk-add up to 1000 sender email addresses or @domain patterns to the inbound allowlist for a mailbox in a single call. Useful for onboarding/migration when importing an existing trusted-senders list. Returns a partial-success response: added[], already_existed[], invalid[] (with per-email reason),…
No input schema was published for this tool.
add_inbound_allowlist_entryAdd a sender (email or @domain) to the inbound allowlist for a mailbox. When the mailbox is in `allowlist` mode, only senders matching an entry on this list will be delivered; everyone else lands in state="firewall_blocked". Accepts an exact email or @domain pattern. Idempotent — repeat adds return…Add a sender (email or @domain) to the inbound allowlist for a mailbox. When the mailbox is in `allowlist` mode, only senders matching an entry on this list will be delivered; everyone else lands in state="firewall_blocked". Accepts an exact email or @domain pattern. Idempotent — repeat adds return…
No input schema was published for this tool.
add_inbound_blocklist_bulkBulk-add up to 1000 sender email addresses or @domain patterns to the account-wide inbound blocklist in a single call. Useful for onboarding/migration when importing an existing spam/blocked-sender list. Returns a partial-success response: added[], already_existed[], invalid[] (with per-email reaso…Bulk-add up to 1000 sender email addresses or @domain patterns to the account-wide inbound blocklist in a single call. Useful for onboarding/migration when importing an existing spam/blocked-sender list. Returns a partial-success response: added[], already_existed[], invalid[] (with per-email reaso…
No input schema was published for this tool.
add_inbound_blocklistAdd an email or domain pattern to the inbound (incoming) blocklist. Mirrors `add_suppression` for the inbound side: customer-protective do-not-receive list. Accepts an exact email (alice@spam.com) or @domain (@spam.com). Server forces reason="manual" + source="customer". Idempotent — repeat adds re…Add an email or domain pattern to the inbound (incoming) blocklist. Mirrors `add_suppression` for the inbound side: customer-protective do-not-receive list. Accepts an exact email (alice@spam.com) or @domain (@spam.com). Server forces reason="manual" + source="customer". Idempotent — repeat adds re…
No input schema was published for this tool.
add_recipientAdd a person to the account's recipient list so you can email them. Only for accounts on the free Sandbox; other accounts don't use this list and get an error here.Add a person to the account's recipient list so you can email them. Only for accounts on the free Sandbox; other accounts don't use this list and get an error here.
No input schema was published for this tool.
add_suppressionNo description publishedThis tool published no description. Forge does not invent one.
add_suppressions_bulkBulk-add up to 1000 email addresses or @domain patterns to the do-not-contact list in a single call. Useful for onboarding/migration when importing an existing suppression/unsubscribe list. Returns a partial-success response: added[], already_existed[], invalid[] (with per-email reason), and a coun…Bulk-add up to 1000 email addresses or @domain patterns to the do-not-contact list in a single call. Useful for onboarding/migration when importing an existing suppression/unsubscribe list. Returns a partial-success response: added[], already_existed[], invalid[] (with per-email reason), and a coun…
No input schema was published for this tool.
approve_reviewApprove a state="pending_review" message and dispatch it. Wire status reports the dispatch outcome ("sent" or "blocked" — release-style); audit_log + message.review.approved webhook fire regardless of dispatch outcome. Auth: admin API keys + session only — agent keys 403. Optional reason text (max…Approve a state="pending_review" message and dispatch it. Wire status reports the dispatch outcome ("sent" or "blocked" — release-style); audit_log + message.review.approved webhook fire regardless of dispatch outcome. Auth: admin API keys + session only — agent keys 403. Optional reason text (max…
No input schema was published for this tool.
block_quarantined_messageBlock a state="quarantined" INBOUND message (→ terminal blocked, no delivery). INBOUND-ONLY: the tool pre-fetches the message and refuses an outbound row (manage outbound quarantines from the dashboard). Optional reason is persisted to the audit log. Mailbox-bound agent keys can only block messages…Block a state="quarantined" INBOUND message (→ terminal blocked, no delivery). INBOUND-ONLY: the tool pre-fetches the message and refuses an outbound row (manage outbound quarantines from the dashboard). Optional reason is persisted to the audit log. Mailbox-bound agent keys can only block messages…
No input schema was published for this tool.
create_draftNo description publishedThis tool published no description. Forge does not invent one.
delete_draftprivilegedSoft-delete a draft (sets state="deleted"; hides it from list_drafts). The row remains in the database and the raw MIME body persists in storage for operator recovery. If the draft was scheduled for future dispatch, the schedule is cancelled and a message.schedule_cancelled webhook fires. This dele…Soft-delete a draft (sets state="deleted"; hides it from list_drafts). The row remains in the database and the raw MIME body persists in storage for operator recovery. If the draft was scheduled for future dispatch, the schedule is cancelled and a message.schedule_cancelled webhook fires. This dele…
No input schema was published for this tool.
delete_messageprivilegedPermanently delete a message: soft-deletes the row and purges its raw MIME and attachment derivatives from object storage. Works on any direction (inbound or outbound) in a deletable state; draft, scheduled, and dispatching rows are refused with a conflict. Idempotent (re-deleting returns success).…Permanently delete a message: soft-deletes the row and purges its raw MIME and attachment derivatives from object storage. Works on any direction (inbound or outbound) in a deletable state; draft, scheduled, and dispatching rows are refused with a conflict. Idempotent (re-deleting returns success).…
No input schema was published for this tool.
deny_reviewDeny a state="pending_review" message; terminal block (no dispatch). Audit_log + message.review.denied webhook fire on commit. Auth: admin API keys + session only — agent keys 403. Optional reason text (max 500 chars) is persisted to messages.review_reason and included in the audit/webhook payloads.Deny a state="pending_review" message; terminal block (no dispatch). Audit_log + message.review.denied webhook fire on commit. Auth: admin API keys + session only — agent keys 403. Optional reason text (max 500 chars) is persisted to messages.review_reason and included in the audit/webhook payloads.
No input schema was published for this tool.
get_account_usageGet account usage, limits, storage quota state, and storage byte breakdown.Get account usage, limits, storage quota state, and storage byte breakdown.
No input schema was published for this tool.
get_agent_quotaGet the current send-budget quota (sends today, effective daily limit, remaining, reset time, bound mailbox IDs). Works with agent-scoped keys. Includes a warmup object while a new paid account ramps on the shared domain.Get the current send-budget quota (sends today, effective daily limit, remaining, reset time, bound mailbox IDs). Works with agent-scoped keys. Includes a warmup object while a new paid account ramps on the shared domain.
No input schema was published for this tool.
get_attachment_previewGet a derived text preview of an inbound message attachment. Returns extracted text for plain-text, CSV, PDF, and Office (DOCX/PPTX/XLSX) attachments on mailboxes with attachment_exposure_mode="derived_content". Content is hard-capped at 20 000 characters; check preview.truncated and preview.char_c…Get a derived text preview of an inbound message attachment. Returns extracted text for plain-text, CSV, PDF, and Office (DOCX/PPTX/XLSX) attachments on mailboxes with attachment_exposure_mode="derived_content". Content is hard-capped at 20 000 characters; check preview.truncated and preview.char_c…
No input schema was published for this tool.
get_draftRead a specific draft by ID. Returns the full draft including body, scan results, scheduled-send fields, and sub-address fields if set.Read a specific draft by ID. Returns the full draft including body, scan results, scheduled-send fields, and sub-address fields if set.
No input schema was published for this tool.
get_link_scanning_statusGet malicious link scanning (URL reputation) activation statusGet malicious link scanning (URL reputation) activation status
No input schema was published for this tool.
get_threadRead a full email thread as one ordered conversation (every message in the thread, oldest → newest, safe-view only). Pass the thread_id from list_threads or a message's thread_id. A thread key can resolve in more than one mailbox — a `NOT_FOUND` error means the thread is either absent or the key is…Read a full email thread as one ordered conversation (every message in the thread, oldest → newest, safe-view only). Pass the thread_id from list_threads or a message's thread_id. A thread key can resolve in more than one mailbox — a `NOT_FOUND` error means the thread is either absent or the key is…
No input schema was published for this tool.
list_allowlist_blocked_attemptsNo description publishedThis tool published no description. Forge does not invent one.
list_allowlistNo description publishedThis tool published no description. Forge does not invent one.
list_draftsList drafts in a ReplyLayer mailbox. Drafts are scan-then-review-then-send entries; use create_draft to make one and send_draft to dispatch it.List drafts in a ReplyLayer mailbox. Drafts are scan-then-review-then-send entries; use create_draft to make one and send_draft to dispatch it.
No input schema was published for this tool.
list_inbound_allowlistList per-mailbox inbound allowlist entries (senders permitted in `allowlist` mode). Mirrors `list_allowlist` for the inbound side. Read-only. Returns up to `limit` rows (default 100, max 500); pass `cursor` to paginate.List per-mailbox inbound allowlist entries (senders permitted in `allowlist` mode). Mirrors `list_allowlist` for the inbound side. Read-only. Returns up to `limit` rows (default 100, max 500); pass `cursor` to paginate.
No input schema was published for this tool.
list_inbound_blocklistList account-wide inbound sender blocklist entries (the do-not-receive list). Mirrors `list_suppressions` for the inbound side. Returns up to `limit` rows (default 100, max 500); pass `cursor` to paginate. Read-only.List account-wide inbound sender blocklist entries (the do-not-receive list). Mirrors `list_suppressions` for the inbound side. Returns up to `limit` rows (default 100, max 500); pass `cursor` to paginate. Read-only.
No input schema was published for this tool.
list_inbound_firewall_blocked_attemptsList incoming senders rejected by the inbound firewall for a mailbox. Default aggregated view groups by (sender, matched_field, mode, reason_code) ordered by most recent. Pass aggregate=false for raw per-attempt history with tuple-cursor pagination. within_days filters by recency (1..365). Read-onl…List incoming senders rejected by the inbound firewall for a mailbox. Default aggregated view groups by (sender, matched_field, mode, reason_code) ordered by most recent. Pass aggregate=false for raw per-attempt history with tuple-cursor pagination. within_days filters by recency (1..365). Read-onl…
No input schema was published for this tool.
list_mailboxesList all mailboxes on the account. Returns name, full address, status, and the recipient-visible From identity (effective_from_display) for each mailbox.List all mailboxes on the account. Returns name, full address, status, and the recipient-visible From identity (effective_from_display) for each mailbox.
No input schema was published for this tool.
list_messagesList / search messages in a ReplyLayer mailbox. Filter by keyword search, sender, date range, direction, and status — including the held-mail states for triage: status="quarantined" or status="pending_review" (then release_quarantined_message / approve_review). Page older by passing before=<id of t…List / search messages in a ReplyLayer mailbox. Filter by keyword search, sender, date range, direction, and status — including the held-mail states for triage: status="quarantined" or status="pending_review" (then release_quarantined_message / approve_review). Page older by passing before=<id of t…
No input schema was published for this tool.
list_recipientsList recipients with confirmation status. Sandbox-tier accounts can only send to confirmed recipients.List recipients with confirmation status. Sandbox-tier accounts can only send to confirmed recipients.
No input schema was published for this tool.
list_suppressionsList addresses on the do-not-contact list (suppressions). Includes both system-added entries (hard bounces, spam complaints, RFC 8058 unsubscribes) and customer-added entries (reason="manual", source="customer"). Useful for verifying that an address is or is not blocked before attempting to send. E…List addresses on the do-not-contact list (suppressions). Includes both system-added entries (hard bounces, spam complaints, RFC 8058 unsubscribes) and customer-added entries (reason="manual", source="customer"). Useful for verifying that an address is or is not blocked before attempting to send. E…
No input schema was published for this tool.
list_threadsNo description publishedThis tool published no description. Forge does not invent one.
mark_message_readNo description publishedThis tool published no description. Forge does not invent one.
mark_thread_readNo description publishedThis tool published no description. Forge does not invent one.
read_messageNo description publishedThis tool published no description. Forge does not invent one.
release_firewall_blocked_messageNo description publishedThis tool published no description. Forge does not invent one.
release_quarantined_messageNo description publishedThis tool published no description. Forge does not invent one.
remove_suppressionprivilegedNo description publishedThis tool published no description. Forge does not invent one.
reply_to_messageNo description publishedThis tool published no description. Forge does not invent one.
report_and_blockNo description publishedThis tool published no description. Forge does not invent one.
send_draftNo description publishedThis tool published no description. Forge does not invent one.
send_emailNo description publishedThis tool published no description. Forge does not invent one.
25 of 40 tools published a description.
Tool names and descriptions are written by the publisher and shown verbatim as inert text. They are the strings an MCP client passes to a model, so Forge scans them for prompt-injection patterns — any finding appears with the security scan above. “Privileged” is a keyword match on the tool name, not an audit of what the tool does: a benign-sounding name can still do anything.
MCP server for ReplyLayer — safe email for AI agents
Linked names open Forge’s index of every entry observed exposing that tool. Browse all indexed tools.
Not followed: peerDependencies. This tree covers runtime dependencies only, so anything those pull in was never resolved.