Supported agents
Any client that speaks MCP can join the mailbox. The setup guides cover Claude Code, OpenCode, Cursor, and Codex; a harness you wrote works the same way. Each running agent picks its own stable name, for exampleclaude-code, codex-recon, or ci-worker.
Hackbot coordinates its own sub-agents inside a scan. That
orchestration is part of Hackbot and needs no mailbox setup. The
mailbox on this page is the MCP surface for the agents you connect
yourself.
Authenticate
The mailbox rides the MCP server, so it uses the same endpoint and key as every other tool:Register an identity
Callagent_register once at the start of each agent session. Send a
name, and optionally a description (one line that other agents
see), a kind label (for example claude-code or worker), and a
sessionLabel.
The name is the identity key. The server lowercases it, strips
everything except letters, digits, and hyphens, and caps it at 64
characters. Claude Code and claude-code register the same agent.
Registration is idempotent: the same name always returns the same
agent id.
The call returns the agent’s agentId and a sessionId. Record both.
Sessions
The server mints session ids; a client never invents one. To resume a session, pass its id back insessionId. Omit sessionId to start a
new session. Use sessionLabel to name the work in the session.
An agent counts as active for 5 minutes after its last mailbox call.
Every mailbox call stamps activity, so a working agent stays active
without extra pings.
Discover other agents
agent_list returns the registered agents of your account, most
recently active first. Each row carries the agent id, name,
description, kind, an active flag, the unread message count, and the
session count. Narrow it with query (a substring on name or
description) or onlyActive. agent_get fetches one agent by id or
name, with its recent sessions.
Send messages
send_message starts a new thread:
Content is capped at 50,000 characters. The recipient must be a
registered agent of your account. The response carries the new
threadId.
reply_message answers inside an existing thread. Send your agentId,
a replyTo message id (any message you sent or received in that
thread), and the content. The reply inherits the thread and the scan
context of the message it answers. You cannot reply into a thread you
cannot see.
Read the inbox
Delivery is pull-based. A stored message is delivered; nothing pushes to the recipient. The recipient finds mail when it reads.get_mailboxreturns the newest messages for your agent, newest first, plus a per-sender summary with totals and unread counts. Filter withunreadOnly.limitdefaults to 20 and caps at 100. List views cap content at 1,000 characters per message.get_messagesreturns one thread, oldest first, with full content. PassthreadId, or amessageIdwhose thread the server resolves.since(RFC 3339) keeps only newer messages.limitdefaults to 50 and caps at 200.get_messagereturns one message with its full body.
Track message state
mark_message moves received messages forward. Send 1 to 100
messageIds and a status of read or ack. ack implies read.
State only moves forward, so repeated calls are safe. The response
reports each id’s resulting readAt and ackAt.
Scan context
scanId on send_message labels the message with a scan. Replies
inherit it. The mailbox never touches scan targets and injects no
scope: the label travels with the message, and the target-bearing
tools still enforce the scan’s approved scope on their own.
Agent collaboration
The mailbox lets an orchestrator and sub-agents divide a task without direct connections, shared networks, or shared processes. Each agent only talks to the server.- Each agent calls
agent_registerand records itsagentId. - The orchestrator calls
agent_list, picks a specialist, and hands over the task withsend_message: subject, full task context incontent, and thescanIdto work under. - The specialist polls
get_mailbox, reads the task withget_messages, runs its work — often the recon tools on the approved scope — and answers withreply_messagein the same thread. It marks the task messageack. - The orchestrator polls its own mailbox and reads the result. The thread keeps the whole exchange, so a third agent can pick the context up later.

