https://mcp.paubox.com/mcp and the @paubox/mcp stdio package. How each one receives your API key is the only difference.
The optional
apiKey parameter listed on every tool below exists only on the HTTP transport. Over stdio the key comes from the PAUBOX_API_KEY environment variable and the parameter is not accepted; omit it. Over HTTP the key is resolved from the OAuth token, the x-paubox-api-key header, or that parameter.Parameters use camelCase (formId, subscriptionListId) even where the underlying REST API uses snake_case.send_secure_email
Sends a single HIPAA compliant email through the Paubox Email API. The sender address must belong to a domain you have verified in the Paubox dashboard.
Example payload
Send
html when the message is designed as an email — styled headings, linked phrases, an inline logo. Because the automatic HTML version escapes markup characters, markup placed in message arrives as literal text; html is the way to send real markup. It is used exactly as given and is not sanitized, so send only markup you control, and keep message a readable plain-text equivalent for clients that do not render HTML. schedule_email accepts html in exactly the same form.content must be the base64 encoding of the file’s bytes, with no data: URI prefix. fileName must be a bare filename — a path such as reports/visit.pdf is rejected. schedule_email accepts attachments in exactly the same form.sourceTrackingId string you can pass to check_email_status.
check_email_status
Retrieves the current delivery status of a message sent viasend_secure_email.
Example payload
schedule_email
Schedules a HIPAA compliant email for future delivery. The message is queued and sent at the specified time.
Example payload
sourceTrackingId, scheduledAt, and state. Save the tracking ID to check status, reschedule, or cancel.
get_scheduled_email
Checks the status of a scheduled email.
Example payload
state (e.g. pending, sent, cancelled) and scheduledAt time.
reschedule_email
Changes the scheduled delivery time of a pending email.
Example payload
scheduledAt and current state.
cancel_scheduled_email
Cancels a scheduled email that has not yet been sent.
Example payload
state (cancelled).
validate_credentials
Verifies that the Paubox API credentials are present and valid by making a live check against the Paubox API. Useful as a first step before sending email.
When connecting via stdio (Claude Code), the API key comes from an environment variable and no parameters are needed.
Example payload
Receiving
Manage inbound email domains, mailboxes, and messages. These tools use the same API key as the email tools.list_receiving_domains
Lists all receiving domains for the authenticated account.
Response: returns an array of receiving domains with
id, domain, and state.
create_receiving_domain
Provisions a new receiving domain underinbound.paubox.email. DNS is configured automatically.
Example payload
domain name and state.
get_receiving_domain
Retrieves a receiving domain by ID.
Response: returns the domain with
id, domain, state, and dns_records.
delete_receiving_domain
Deletes a receiving domain and all its mailboxes.
Response: returns an empty object on success.
list_receiving_mailboxes
Lists all mailboxes on a receiving domain.
Response: returns an array of mailboxes with
id, email, and quota_bytes.
create_receiving_mailbox
Creates a new mailbox on a receiving domain.
Example payload
email address.
get_receiving_mailbox
Retrieves a mailbox by domain and mailbox ID.
Response: returns the mailbox details.
delete_receiving_mailbox
Deletes a mailbox.
Response: returns an empty object on success.
list_received_emails
Lists received emails across all active receiving domains, sorted by most recent.
Response: returns
data (array of emails), has_more, and object: "list".
get_received_email
Retrieves a single received email with full content, headers, and attachment metadata.
Response: returns the email with
from, to, subject, body (text and html), and attachments.
get_received_email_attachment
Downloads a received email attachment.
Response: returns the attachment bytes.
Forms
The two tools below need no credentials. Everything after them manages forms and submissions and requires an API key carrying theforms scope, sent as a Bearer token; scoped keys are managed in the Paubox admin dashboard. See Forms authentication.
get_form
Retrieves the full definition of a Paubox Form, including its title, description, and field schema, so an agent can present the form questions in a conversation. No authentication is required for active forms. When an API key carrying theforms scope is available, inactive and archived forms become retrievable too.
Example payload
title, description, form_json (field definitions), and metadata fields (active, signable, submission_count, created_at, updated_at).
submit_form
Submits a completed response to a Paubox Form. No authentication is required for this tool.
Example payload: text fields only
list_forms
Lists a customer’s Paubox Forms with search, filtering, ordering, and pagination.
Example payload
create_form
Creates a new Paubox Form.
Example payload
Form schema (formJson)
formJson is not a free-form field list. The Paubox form renderer reads exactly one
top-level key, body, holding an ordered array of components. Anything else is stored
verbatim and renders as an empty form, with no error (PPD-9105).
Each entry in body needs three keys:
Component types:
Text, Divider, TextInput, TextArea, Dropdown, Checkboxes,
Radiobutton, FileUpload, Signature, Button, Conditional, Logo.
Note Radiobutton — lowercase b, unlike the others.
Input components (TextInput, TextArea, Dropdown, Checkboxes, Radiobutton,
FileUpload, Signature) carry the label block — label_enabled, label_position,
label_font, label_font_size, label_color, text_align, margin, subtext_enabled,
subtext — plus:
Static components (
Text, Divider, Button, Logo) take no field_name and never
appear in submissions. Text uses font, font_size, color, text_align, margin, and
text (HTML).
Values like
%{defaultFont} and %{defaultLabelColor} are theming tokens resolved against the
form’s design settings at render time. Copy them as written rather than substituting literal
fonts and colors, so the form follows the customer’s branding.update_form
Updates an existing Paubox Form. Only the fields you provide change; omitted fields stay as they are.
Example payload
archive_form
Archives a Paubox Form. This setsarchived to true and active to false.
Response: returns the archived form.
unarchive_form
Restores a previously archived Paubox Form.
Response: returns the restored form.
copy_form
Duplicates an existing Paubox Form under a new title.
Response: returns the new form, including its UUID.
get_form_stats
Returns aggregate Paubox Forms statistics: active form count, total submission count, and submissions in the last 7 days.
Response: returns
active_form_count, submission_count, and submissions_last_7_days.
list_form_submissions
Lists a form’s submissions, with each submission’sform_data parsed into structured key/value pairs.
Response: returns submissions with parsed field data, submitter email, and attachment info.
export_submissions_csv
Exports a form’s submissions as CSV text.
Response: returns CSV text.
export_submission_pdf
Exports a single form submission as a PDF.
Response: returns the PDF, base64-encoded.
Email Marketing
These tools read and write Paubox Email Marketing data. They use the same API key as the email tools — no additional scope is required — but the account must have Email Marketing provisioned. Callvalidate_marketing_access first if another marketing tool reports that no marketing customer was found.
This set is read-only plus safe subscriber and list writes. Campaign sending and bulk deletion are deliberately not exposed over MCP.
apiKey string parameter, which behaves as described above; it is omitted from the tables that have no other parameters.
validate_marketing_access
Checks whether the account has Email Marketing provisioned and returns the marketing customer profile. Example payloadfrom_name, from_email, physical address, and global unsubscribe setting.
list_subscribers
Lists Email Marketing subscribers. OmitsubscriptionListId to search the account’s default “All contacts” list.
Response: returns a paginated list of subscribers.
get_subscriber
Retrieves one subscriber by UUID, including custom field values and subscription list memberships.
Response: returns the subscriber object.
create_subscriber
Adds a subscriber. Requires an email address or a phone number. The subscriber always joins the default “All contacts” list, plussubscriptionListId when given. An existing subscriber matching the same email or phone is updated rather than duplicated. Custom field names that do not exist yet are created automatically.
* One of
email or phoneNumber is required.
Example payload
update_subscriber
Updates an existing subscriber by UUID. Only the fields you provide change.
Response: returns the updated subscriber.
get_subscribed_count
Counts currently subscribed contacts on a list, excluding unsubscribed and deleted contacts.
Response: returns the subscribed contact count.
list_subscriber_custom_fields
Lists the custom subscriber field types defined for the account. Use this to discover which custom field namescreate_subscriber and update_subscriber can set.
Example payload
list_marketing_lists
Lists all audiences — both static subscription lists and filter-based dynamic lists — in one view with subscriber counts. Uselist_subscription_lists or list_dynamic_lists when you need one kind specifically.
Response: returns all audiences with their kind, ID, and subscriber count.
list_subscription_lists
Lists static subscription lists with their integer IDs, subscriber counts, and which one is the default “All contacts” list. The IDs returned here are whatsubscriptionListId expects elsewhere.
Response: returns subscription lists with integer IDs and subscriber counts.
create_subscription_list
Creates a new, empty subscription list.
Response: returns the new list’s integer ID, for use with
create_subscriber and list_subscribers.
list_dynamic_lists
Lists dynamic lists — filter-based segments that recompute their membership — with their UUIDs, filter definitions, and subscriber counts.
Response: returns dynamic lists with UUIDs, filter definitions, and subscriber counts.
list_campaign_sends
Lists campaign sends — each time a marketing email went out to a list — with per-send counts for delivered, viewed, clicked, bounced, and unsubscribed.
Response: returns campaign sends with their integer IDs and per-send engagement counts.
list_campaign_deliveries
Lists individual deliveries — one row per recipient per campaign — showing what happened to each message.
Response: returns per-recipient delivery rows.
get_campaign_analytics
Runs an Email Marketing analytics report.
Example payload
get_marketing_bulk_job
Checks the progress of an asynchronous bulk job. Bulk subscriber imports and CSV exports return a job ID (jid or bid) instead of a result; pass it here.
Response: returns total, pending, and failed counts for the job.