Inspiration
Email is one of the web’s most useful coordination layers, but most inboxes were designed only for people clicking through screens. AI agents often need a separate integration, broad account access, or brittle pixel automation.
Mermail starts with a different premise: it is not AI for your email; it is email for your AI. Each agent can have a private inbox while its human keeps a visible, familiar mail interface. WebMCP turns that interface into a native collaboration surface.
What it does
In a WebMCP-enabled browser, Mermail exposes tools that match the active page.
On the public site, an agent can check service status, inspect pricing, and start signup. In an authenticated workspace it can list and open mailboxes. Inside a mailbox it can list and search mail, read one clean-scanned message, open the visible composer, send/reply/forward with human confirmation, change read state, move messages, and confirm trash or permanent deletion.
This lets a person ask an agent to find a thread, inspect a safe message, prepare a reply, or organize an inbox without handing it an invisible, open-ended automation channel.
Why WebMCP fits
Email combines private data, untrusted external content, and consequential actions. Raw browser automation is brittle and risky here. WebMCP gives Mermail a small, typed capability surface tied to the current page and authenticated workspace.
The agent handles search and repetitive navigation; the person stays in the same interface and approves sending or deletion. Public tools appear on the landing page, workspace tools on the mailbox list, and message tools only inside an active mailbox.
How we built it
Mermail uses the standards-track document.modelContext.registerTool() API in Next.js and React. The shared registration layer:
- validates every input with strict Zod JSON schemas
- gates tools with
off,read, andfullrollout modes - aborts tools when the page lifecycle ends
- bounds result sizes and marks email-derived output as untrusted
- uses the authenticated API and current mailbox state
- records registration/execution telemetry without message content
- leaves unsupported browsers unchanged
Read tools request bounded, agent-safe projections. Bodies are returned only for clean-scanned mail and are truncated. Send, reply, forward, trash, and permanent-delete tools reuse visible Mermail confirmation UI. Sends use an idempotency key and an “outcome unknown” recovery path to discourage duplicates after interruption.
What we added during the challenge
Mermail existed before the submission period. We have extended it with WebMCP across the public landing page, authenticated workspace home, and active mailbox. The work added contextual tool catalogs, lifecycle-aware registration, strict validation, bounded outputs, confirmations, telemetry, deployment configuration, and focused browser/security tests.
We verified the live deployment in a WebMCP-enabled in-app browser: public status and pricing tools executed successfully, authenticated mailbox discovery succeeded, and the active mailbox registered its complete 11-tool catalog.
Challenges we faced
The hard part was making every tool safe enough for email. Incoming messages are untrusted, React rerenders can create stale registrations, interrupted sends need special recovery, and destructive actions need stronger confirmation than navigation.
We addressed those cases with strict schemas, bounded projections, clean-scan requirements, lifecycle abort signals, stable catalogs, high-impact action locks, visible confirmations, and cancellation tests.
What we learned
WebMCP works best as a progressive enhancement to a product people already understand. The strongest tools are contextual and narrow, and the safest agent experience combines typed capabilities with visible human checkpoints.
What’s next
We plan to add judge-friendly demo data, richer thread-level tools, clearer indicators of available WebMCP capabilities, and more end-to-end evals for prompt injection and cancellation races.
Built With
- nextjs
- postgresql
- webmcp
Log in or sign up for Devpost to join the conversation.