Disposable e-mail for AI agents
OTPBox gives your agent its own throwaway addresses. It signs up on any site, then reads the one-time code or the verification link through MCP or the REST API. No shared mailbox, no IMAP, no copying codes by hand.
Included in rc.center Pro, US$ 9/month.
How it works
The same flow works for an agent in a chat, a test runner or a CI job.
Your agent calls inbox_create (or POST /v1/inboxes) and gets a fresh address on your own subdomain.
It types the address into the sign-up form, the magic-link login or the password reset. Our receive-only servers take the mail and seal it with your account's key.
message_wait waits until the mail lands and returns the one-time codes, best match first, and the verification link. Prefer push? Set a signed webhook per inbox.
Addresses look like signup.k3m9qa@<account>.otpbox.org (or .otpbox.top). The account part is a random subdomain that belongs to you alone.
Use cases
Give Claude or your own agent an address it controls, so it can finish sign-ups, magic-link logins and e-mail codes without asking you to paste anything.
Each Playwright or Cypress run creates its own inbox, submits the form and checks the real e-mail, code and link included.
One HTTP call creates the inbox, another waits for the message with a timeout. API keys work headless: no browser, no IMAP.
Confirm that your own password reset, invite and receipt e-mails arrive, with the right subject and links, plus their SPF, DKIM and DMARC results.
Works with
Connect once with your rc.center account. MCP clients sign in with OAuth and you approve each permission.
Settings, Connectors, Add custom connector. Paste this URL and connect:
https://otpbox.rc.center/mcpRun this, then /mcp inside Claude Code to sign in:
claude mcp add --transport http otpbox https://otpbox.rc.center/mcpAdd this to ~/.cursor/mcp.json:
{"mcpServers": {"otpbox": {"url": "https://otpbox.rc.center/mcp"}}}Add the server and sign in:
codex mcp add otpbox --url https://otpbox.rc.center/mcp
codex mcp login otpboxCreate an API key in the web app and send it as a bearer token. The same features, described in /v1/openapi.json:
curl -s -X POST https://otpbox.rc.center/v1/inboxes \
-H "Authorization: Bearer $OTPBOX_KEY" \
-H 'Content-Type: application/json' -d '{"prefix":"signup"}'
curl -s "https://otpbox.rc.center/v1/inboxes/$INBOX_ID/wait?timeout=60&subject=verification" \
-H "Authorization: Bearer $OTPBOX_KEY"Streamable HTTP with OAuth 2.1: dynamic client registration and PKCE. You see every connected app and can disconnect it at any time.
12 MCP tools, each with a REST twin:
inbox_createinbox_listinbox_getinbox_deleteinbox_webhook_setinbox_webhook_clearmessages_listmessage_getmessage_waitmessage_deleteattachment_getusage_getSecurity and privacy
OTPBox never sends e-mail. Our servers accept mail only for our own domains and refuse to relay anything.
Each account has its own data key, wrapped by a key in OCI Vault. Messages are sealed with AES-256-GCM before they are stored, and the database holds no message content in clear.
The mail servers can add new messages to storage but cannot read, list or delete stored mail.
Messages are deleted when your plan's retention ends (30 days on Pro). Delete any message or inbox sooner whenever you want. Closing your rc.center account destroys your key, so every stored message becomes unreadable at once.
Every account receives on its own random subdomain, and every address has a random part, so addresses are never shared or guessable.
MCP clients get only the permissions you approve. API keys are created by you in the web app, never by an agent.
Message HTML is sanitized and shown in a sandboxed frame with remote images blocked, so opening a mail does not tell the sender.
Mass sign-ups on third-party services and illegal use are forbidden. Every account has receive limits.
Pricing
One rc.center subscription covers OTPBox and the AI hub.
Promotional price for a limited time; subscribers are notified before any change. The free rc.center plan does not include OTPBox.
US$ 9/month
or R$ 49/month in Brazil
Also included: the AI hub with unlimited vault items.
Subscribe at rc.center Already on Pro? Sign inFAQ
No. OTPBox is part of the rc.center Pro plan: US$ 9/month, or R$ 49/month in Brazil. A free rc.center account can sign in, but creating inboxes needs Pro.
Addresses end in <account>.otpbox.org or <account>.otpbox.top, where <account> is a random subdomain that only your account receives on. The inbox part is an optional prefix you choose plus a random part. A +tag after the local part still reaches the same inbox.
Until your plan's retention ends: 30 days on Pro. Then they are deleted from the index and from storage. You can delete a message or a whole inbox earlier at any time.
No. OTPBox is receive-only. It never sends mail from its domains, so it cannot be used for outreach or replies.
No. Mass sign-ups on third-party services and any illegal use are forbidden. Each account has inbox, per-minute and monthly limits, and accounts that abuse the service are suspended.
On claude.ai, add a custom connector with the URL https://otpbox.rc.center/mcp. In Claude Code, run: claude mcp add --transport http otpbox https://otpbox.rc.center/mcp, then /mcp to sign in with rc.center.
No. Everything the MCP tools do is also in the REST API, with API keys for scripts and CI, and per-inbox webhooks if you prefer push.
Sign in with rc.center, connect your MCP client and create your first address.
Get started