AI agents have no email
Everything a human has online — now callable from one API. DKIM-signed email. AES-256-GCM vault. MCP-native.
create identity
$ loomal platform create \
--name "sales-agent" \
--email sales
✓ Identity created
IDidt_x8k2m
Emailsales@agent.mailgent.dev
Keyloid-9f4c2b••••
Scopesmail:send, mail:read, vault:*
The problem
Today, agents operate with borrowed identities & hardcoded secrets.
01 still common
No email
Agents use your Gmail or dump messages to a queue. No real address, no threading, no DKIM.
from = "you@gmail.com" // your identity, not agent's
02 still common
No credentials
API keys in .env files. No rotation, no 2FA, no vault. One leaked key breaks everything.
STRIPE_KEY=sk_live_•••• // committed to .env
03 still common
No accountability
No delegation chain. No way to trace an agent's action back to the human who authorized it.
authorized_by = null // who sent this?
The identity stack · Human → Agent
Agents are the new users. They need identity.
Humans need an email, a password manager, and a phone for 2FA to do anything meaningful online. AI agents need the same primitives — plus delegation chains and audit trails that trace every action back to the human who authorized it.
Human
3 primitives
- Email address
- Password manager
- Phone for 2FA
becomes
Agent (Loomal)
5 primitives
- Inbox
- Vault
- TOTP
- Delegation chain
- Audit trail
What you get
The Agent Identity Stack.
One identity, infinite possibilities — attach the capabilities your agent needs.
LiveInbox
- Real email. Send, receive, thread. Per-agent address with DKIM signing.
- DKIM signed < 200ms Threaded.
→inbox.send({ to, subject })
✓msg_a7f3q · delivered
LiveVault
- Encrypted credential storage for API keys, OAuth tokens, and passwords.
- AES-256-GCM Scoped Audited.
→vault.store({ label: "stripe" })
✓stored · 1 audit entry
LiveTOTP
- Generate 2FA codes from stored seeds. Pair with inbox for fully autonomous auth.
- 30s window Email 2FA Seed-encrypted.
→vault.totp("gh-deploy")
✓742198 · 23s left
Use cases Real-world
What agents build with Loomal.
Every use case combines email, vault, and 2FA — the Agent Identity Stack.
Fully autonomous
Customer Onboarding
Agent signs up on platforms, verifies email, stores credentials, confirms setup.
→agent.onboard("figma.com")
✓session stored · 0 retries
No back-and-forth
Meeting Scheduling
Agent reads incoming requests, checks availability, sends invites, confirms replies.
→inbox.parse → calendar.book
✓12 booked · 0 conflicts
End-to-end
Document Processing
Agent receives documents, logs into platforms, uploads files, sends results back.
→inbox.attach → vault.upload
✓8 docs · all replied
~Seconds per link
Payment Link Delivery
Agent generates Stripe payment links using stored API keys and emails them to clients.
→stripe.link → inbox.send
✓$4,900 invoice delivered
Never misses
Compliance Monitoring
Agent tracks regulatory deadlines, logs into portals to check status, alerts on lapse.
→portal.check_all()
✓2 alerts sent · 0 missed
Delegation chain
Every action traces back to the human who authorized it.
Human > Org > Agent > Action. Cryptographically verifiable via DKIM. Revoke the human and every agent stops. No orphaned access. No cleanup scripts.
DKIM-signed identity
Every outbound email is DKIM-signed with agent identity headers. Recipients and regulators can cryptographically verify who sent it.
Instant revocation
Revoke a human, org, or identity — everything downstream stops instantly. No dangling credentials, no orphaned access.
Built on 40-year-old standards
DKIM, SPF, DMARC, OAuth 2.1, MCP. No proprietary protocol. Email's global PKI is already deployed everywhere.
Compliance-ready audit trails
Every email, credential access, and TOTP code is logged with identity, timestamp, and delegation context. The trail regulators ask for.
Integrations
Works with every framework.
REST API + native MCP server. Framework-agnostic by design.
Get started
30 seconds to first email.
Plug Loomal into your AI client. Ask your agent to send the first email.
Other ways: curl Node SDK Python SDK Full docs →
{
"mcpServers": {
"loomal": {
"command": "npx",
"args": ["-y", "@loomal/mcp"],
"env": {
"LOOMAL_API_KEY": "loid-your-api-key"
}
}
}
}
We’re live on Product Hunt
Loomal gives AI agents an identity — email, credentials, 2FA — all via MCP.