What we have shipped, newest first. Breaking API changes are announced here at least 90 days ahead; see versioning.
Docs: security, versioning and limits
New Security page (hosting, encryption, retention, subprocessors, how to report a vulnerability) and a security.txt. New versioning policy: v1 changes are additive only, and breaking changes get at least 90 days' notice. The API reference now lists per-key rate limits, and the quickstart has a 60-second path that needs no signup.
Outbound sending endpoints, which are not available, were removed from the public reference and OpenAPI spec.
MCP server 0.2.3: since on wait tools
wait_for_otp and wait_for_link accept an optional since (ISO 8601, unix seconds or a message id), so a reused inbox returns the new code instead of an older one. Results now include the message id and received_at, which you can pass as since on the next call.
Python and TypeScript SDK 0.1.3, MCP server 0.2.2
The TypeScript SDK (mailsocket-sdk) ships a CommonJS build next to ESM, so require("mailsocket-sdk") works. The Python SDK (mailsocket) rejects an empty id, . or .. before sending a request, matching the TypeScript SDK. MCP server 0.2.2 requires mailsocket>=0.1.3.
Security fixes
Suspending a user now also blocks their team memberships, the workspaces they own, their API keys and catch-all delivery. Password reset is refused for accounts that have no login (agent and workspace accounts). Accepting a team invite now counts only current members, so every paid seat can be filled.
Launch week, 22 to 30 September 2026
Python and TypeScript SDK 0.1.2, MCP server 0.2.0 and 0.2.1
Both SDKs accept extra request headers and URL-encode ids. The TypeScript SDK rejects empty, . and .. ids and uses whole-millisecond abort timeouts. MCP server 0.2.0 adds the remote server below; 0.2.1 removes request paths from its access logs.
Business plan now available
You can now buy the Business plan yourself for $149/mo from Pricing or the Billing page in your dashboard. It includes 200 inboxes, 250,000 messages a month, 90-day retention and 16 concurrent waits, plus custom domains, catch-all addresses and team seats. Current limits are always on Pricing.
If you already pay for Pro or Scale, upgrading changes your current subscription and does not start a second one. You are charged the prorated difference right away.
Enterprise is now arranged through our sales team at sales@mailsocket.app. Pricing is custom.
Remote MCP server
The MCP tools (create_inbox, wait_for_otp, wait_for_link and the rest) are now also hosted at https://mcp.mailsocket.app/mcp over Streamable HTTP, with no install. Send your API key as an Authorization: Bearer header on every request; putting it in the URL is rejected. Remote waits cap at 55 seconds per call (call again if nothing has arrived yet), and the server is stateless with per-key concurrency limits.
Works today with Claude Code, Cursor and VS Code. Claude.ai, Claude Desktop connectors and Smithery need OAuth, which is planned but not available yet. Use the local stdio server in those clients for now.
Three API responses change. Clients that send only documented values are not affected, and that includes our SDKs, the MCP server and the n8n node.
GET /api/v1/inboxes/{id}/messages/wait and GET /api/v1/inboxes/{id}/stream: an unknown require value, such as OTP or links, now returns 422 validation_error. It is no longer silently treated as the default. Allowed values are otp, link and any. Omitting require still uses the default.
POST /api/v1/domains on a plan without custom domains now returns 403 domain_entitlement_required before the request body is checked. See plan gating. Listing domains still returns an empty list.
PATCH /api/v1/messages/{id} accepts only read. Any other field now returns 422 validation_error naming that field, even when read is also sent, and nothing is changed.
SDKs 0.1.1, MCP Registry listing and n8n node
The Python SDK (mailsocket), TypeScript SDK (mailsocket-sdk) and MCP server (mailsocket-mcp) were released as 0.1.1, with clearer READMEs, tool annotations, and paginated list tools in the MCP server.
The MCP server is listed in the official MCP Registry as app.mailsocket/mailsocket-mcp.
The new n8n community node, n8n-nodes-mailsocket, can create an inbox, wait for an OTP or link, get the latest message, list messages and delete an inbox.
We fixed a regression where a new message's OTP and magic link could take up to about a minute to appear on messages/wait. Messages are now parsed again as soon as they are received.
Mark read, batch operations and webhook test
There are three new endpoints:
PATCH /api/v1/messages/{id} marks a message read or unread.
POST /api/v1/messages/batch marks as read, deletes or fetches up to 100 messages in one call, on paid plans.
POST /api/v1/inboxes/{id}/webhook/test sends one signed test delivery, so you can check your receiver before enabling it.
Server-Sent Events stream
GET /api/v1/inboxes/{id}/stream pushes each new matching message as an SSE event. It is an alternative to the messages/wait long-poll, uses the same require filter and sends heartbeats while it waits.
OpenAPI spec + message search/filter
A machine-readable OpenAPI 3.1 contract (/docs/openapi.yaml) validated in CI, plus shared message filtering (has_otp, subject_contains and from) across the REST API and the dashboard.
API-key cap
An account can have at most 20 active API keys, and key creation is rate-limited per hour.
The landing page now leads with the core use case: "Wait for the OTP. One API call.", with a live curl and Python sample for the wait endpoint.
Onboarding
After signup, your first inbox and a welcome message are created automatically, and the dashboard offers a one-click API key with ready-to-run code snippets.
Wait for an OTP or magic link
The messages/wait long-poll: one call blocks until the OTP or magic link arrives, instead of a polling loop.
REST API v1
Bearer-authenticated REST API: inboxes, message listing and retrieval, cursor pagination and per-key rate limits.
Signed webhooks
Webhooks delivered over HTTPS to public addresses only, signed with a per-webhook HMAC secret.
Inbound email
Inbound mail: our mail server stores each message before accepting it, then extracts OTPs and magic links. If the app is down, mail stays queued and delivery is retried.