Back to Browse

Zerodrop MCP Server

Developer ToolsModerate7.2MCP RegistryLocal
Free

Server data from the Official MCP Registry

Disposable email inboxes for AI agents — OTPs and magic links auto-extracted. No signup needed.

About

Disposable email inboxes for AI agents — OTPs and magic links auto-extracted. No signup needed.

Security Report

7.2
Moderate7.2Low Risk

Well-structured MCP server with proper authentication handling, clean code quality, and appropriate permissions for its stated purpose. The server makes network requests only to a configurable ZeroDrop endpoint, uses environment variables correctly for API key storage, and implements basic input validation via zod schemas. Minor improvements could be made to error handling specificity and request timeout configuration. Supply chain analysis found 1 known vulnerability in dependencies (0 critical, 1 high severity). Package verification found 1 issue.

3 files analyzed · 6 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

HTTP Network Access

Connects to external APIs or services over the internet.

env_vars

Check that this permission is expected for this type of plugin.

What You'll Need

Set these up before or after installing:

ZeroDrop Workspace API key. Omit for free sandbox mode.Required

Environment variable: ZERODROP_API_KEY

Override for self-hosted ZeroDrop instances.Optional

Environment variable: ZERODROP_BASE_URL

How to Install

Add this to your MCP configuration file:

{
  "mcpServers": {
    "dev-zerodrop-zerodrop-mcp": {
      "env": {
        "ZERODROP_API_KEY": "your-zerodrop-api-key-here",
        "ZERODROP_BASE_URL": "your-zerodrop-base-url-here"
      },
      "args": [
        "-y",
        "zerodrop-mcp"
      ],
      "command": "npx"
    }
  }
}

Documentation

View on GitHub

From the project's GitHub README.

zerodrop-mcp

npm CI license

Email verification for AI agents — an MCP server that gives Claude, Cursor, Claude Code, and any MCP client disposable email inboxes with auto-extracted OTPs and magic links.

Your agent signs up for a service. The service sends a verification code. Without an inbox it can read, the agent is stuck. With zerodrop-mcp:

Agent: generate_inbox()
  → swift-x7k29ab@zerodrop-sandbox.online

Agent: [fills the signup form with that address]

Agent: wait_for_email(inbox, require_otp: true)
  → { "otp": "847291", "subject": "Verify your email", ... }

Agent: [enters 847291 — flow complete]

No Docker. No SMTP. No API key. No signup. Free tier works out of the box.

Install

Claude Code

claude mcp add zerodrop -- npx -y zerodrop-mcp

Claude Desktop

Add to claude_desktop_config.json:

{
  "mcpServers": {
    "zerodrop": {
      "command": "npx",
      "args": ["-y", "zerodrop-mcp"]
    }
  }
}

Cursor

Add to .cursor/mcp.json (project) or ~/.cursor/mcp.json (global):

{
  "mcpServers": {
    "zerodrop": {
      "command": "npx",
      "args": ["-y", "zerodrop-mcp"]
    }
  }
}

Tools

generate_inbox

Creates a disposable email address. Local and instant — no network request.

ParamTypeDescription
prefixstring, optionalPrefix for the inbox name, e.g. your app name

Returns the inbox address and a live watch URL.

wait_for_email

Blocks until a matching email arrives, then returns it with the OTP and magic link already extracted — the agent never parses HTML or regexes a body.

ParamTypeDescription
inboxstringAddress from generate_inbox
timeout_secondsnumber, optionalDefault 30, max 120
from_containsstring, optionalFilter by sender
subject_containsstring, optionalFilter by subject
require_otpboolean, optionalOnly match emails with an OTP
require_magic_linkboolean, optionalOnly match emails with a magic link

Returns:

{
  "from": "noreply@yourapp.com",
  "subject": "Your verification code",
  "received_at": "2026-07-18T12:34:56Z",
  "otp": "847291",
  "magic_link": null,
  "body_preview": "Your code is: 847291..."
}

check_inbox

Non-blocking snapshot of the inbox — recent emails with extracted fields, or an empty list.

What agents use this for

  • Testing auth flows end to end — signup → OTP → verified, driven entirely by the agent
  • QA automation — Claude Code writing and running Playwright tests that need real inboxes
  • Autonomous workflows — any agent task that hits an email-verification wall
  • Development — "sign up for my own app and tell me if the verification email works"

How it works

Emails sent to a generated inbox are caught at Cloudflare's edge by ZeroDrop's open-source worker. OTPs and magic links are extracted at the edge before your agent reads them. Inboxes auto-delete after 30 minutes on the free tier.

Configuration

Environment variables (set in your MCP client config):

VariableDefaultDescription
ZERODROP_API_KEYWorkspace key. Omit for free sandbox mode.
ZERODROP_BASE_URLhttps://zerodrop.devSelf-hosted instance URL
{
  "mcpServers": {
    "zerodrop": {
      "command": "npx",
      "args": ["-y", "zerodrop-mcp"],
      "env": { "ZERODROP_API_KEY": "your-key" }
    }
  }
}

Writing tests instead?

If you're generating test code rather than driving flows live, use the SDKs directly:

npm · PyPI · Go · RubyGems · Packagist · JitPack · GitHub Action

AI coding assistant context: docs.zerodrop.dev/ai-coding

Security

  • The server makes requests only to ZERODROP_BASE_URL (zerodrop.dev by default) — nothing else
  • Inbox generation is fully local
  • Two runtime dependencies: the official MCP SDK and zod
  • Report issues: founder@zerodrop.dev

License

MIT — zerodrop.dev

Reviews

No reviews yet

Be the first to review this server!