AI agents have no email

Everything a human has online — now callable from one API. DKIM-signed email. AES-256-GCM vault. MCP-native.

Get API Key →

Read Docs

create identity

$ loomal platform create \
  --name "sales-agent" \
  --email sales

✓ Identity created

IDidt_x8k2m

Emailsales@agent.mailgent.dev

Keyloid-9f4c2b••••

Scopesmail:send, mail:read, vault:*  

The problem

Today, agents operate with borrowed identities & hardcoded secrets.

01 still common

No email
Agents use your Gmail or dump messages to a queue. No real address, no threading, no DKIM.

from = "you@gmail.com" // your identity, not agent's  

02 still common

No credentials
API keys in .env files. No rotation, no 2FA, no vault. One leaked key breaks everything.

STRIPE_KEY=sk_live_•••• // committed to .env  

03 still common

No accountability
No delegation chain. No way to trace an agent's action back to the human who authorized it.

authorized_by = null // who sent this?  

The identity stack · Human → Agent

Agents are the new users. They need identity.

Humans need an email, a password manager, and a phone for 2FA to do anything meaningful online. AI agents need the same primitives — plus delegation chains and audit trails that trace every action back to the human who authorized it.

Human

3 primitives

  • Email address
  • Password manager
  • Phone for 2FA

becomes

Agent (Loomal)

5 primitives

  • Inbox
  • Vault
  • TOTP
  • Delegation chain
  • Audit trail

What you get

The Agent Identity Stack.

One identity, infinite possibilities — attach the capabilities your agent needs.

LiveInbox

  • Real email. Send, receive, thread. Per-agent address with DKIM signing.
  • DKIM signed < 200ms Threaded.
→inbox.send({ to, subject })  
✓msg_a7f3q · delivered  

LiveVault

  • Encrypted credential storage for API keys, OAuth tokens, and passwords.
  • AES-256-GCM Scoped Audited.
→vault.store({ label: "stripe" })  
✓stored · 1 audit entry  

LiveTOTP

  • Generate 2FA codes from stored seeds. Pair with inbox for fully autonomous auth.
  • 30s window Email 2FA Seed-encrypted.
→vault.totp("gh-deploy")  
✓742198 · 23s left  

Use cases Real-world

What agents build with Loomal.

Every use case combines email, vault, and 2FA — the Agent Identity Stack.

Fully autonomous

Customer Onboarding
Agent signs up on platforms, verifies email, stores credentials, confirms setup.

→agent.onboard("figma.com")  
✓session stored · 0 retries  

No back-and-forth

Meeting Scheduling
Agent reads incoming requests, checks availability, sends invites, confirms replies.

→inbox.parse → calendar.book  
✓12 booked · 0 conflicts  

End-to-end

Document Processing
Agent receives documents, logs into platforms, uploads files, sends results back.

→inbox.attach → vault.upload  
✓8 docs · all replied  

~Seconds per link

Payment Link Delivery
Agent generates Stripe payment links using stored API keys and emails them to clients.

→stripe.link → inbox.send  
✓$4,900 invoice delivered  

Never misses

Compliance Monitoring
Agent tracks regulatory deadlines, logs into portals to check status, alerts on lapse.

→portal.check_all()  
✓2 alerts sent · 0 missed  

Delegation chain

Every action traces back to the human who authorized it.

Human > Org > Agent > Action. Cryptographically verifiable via DKIM. Revoke the human and every agent stops. No orphaned access. No cleanup scripts.

DKIM-signed identity

Every outbound email is DKIM-signed with agent identity headers. Recipients and regulators can cryptographically verify who sent it.

Instant revocation

Revoke a human, org, or identity — everything downstream stops instantly. No dangling credentials, no orphaned access.

Built on 40-year-old standards

DKIM, SPF, DMARC, OAuth 2.1, MCP. No proprietary protocol. Email's global PKI is already deployed everywhere.

Compliance-ready audit trails

Every email, credential access, and TOTP code is logged with identity, timestamp, and delegation context. The trail regulators ask for.

Integrations

Works with every framework.

REST API + native MCP server. Framework-agnostic by design.

Get started

30 seconds to first email.

Plug Loomal into your AI client. Ask your agent to send the first email.

Get API Key →

Other ways: curl Node SDK Python SDK Full docs →

{
  "mcpServers": {
    "loomal": {
      "command": "npx",
      "args": ["-y", "@loomal/mcp"],
      "env": {
        "LOOMAL_API_KEY": "loid-your-api-key"
      }
    }
  }
}

We’re live on Product Hunt

Loomal gives AI agents an identity — email, credentials, 2FA — all via MCP.