Agentic Inbox: A Self-Hosted AI Email Client Built on Cloudflare Workers
A self-hosted email client with an AI agent, running entirely on Cloudflare Workers
At a glance
- What is it?
- Agentic Inbox is an open-source email client that runs entirely on a Cloudflare account, with each mailbox isolated in its own Durable Object and SQLite database. An AI agent built on the Cloudflare Agents SDK reads the inbox, searches conversations, and drafts replies, but never sends without explicit confirmation.
- Who is it for?
- Agentic Inbox is best suited to developers who already use Cloudflare and want a programmable email inbox with an embedded AI agent, without setting up a separate email server or relying on a third-party email SaaS. The single Access policy covering all mailboxes is the constraint that matters most for multi-user deployments: anyone who passes the shared policy can reach every mailbox.
- Can I use it commercially?
- Yes. Apache-2.0 is a permissive licence: you can use, modify and sell software built on it, as long as you keep its copyright and licence notices.
- Is it still maintained?
- Yes. The repository last received commits 159 days ago.
- What is it written in?
- Mainly TypeScript, according to GitHub's language statistics.
Answers come from the project's GitHub data, last synced on September 29, 2026, and from our analysis. They are not legal advice.
Editorial analysis
What Agentic Inbox Is and Who It Is For
Agentic Inbox solves two problems at once: it provides a self-hosted email client so developers are not dependent on a third-party email provider, and it embeds an AI agent that can read, search, and draft email responses through a natural language interface.
The project is aimed at developers with a Cloudflare account and a domain with Email Routing enabled. It is not a general-purpose email client for non-technical users. Setting it up requires configuring Cloudflare Access, creating a catch-all Email Routing rule, enabling the Email Service binding, and creating an R2 bucket. The README links to a detailed GitHub issue comment with step-by-step screenshots, acknowledging that the deploy-button flow alone is insufficient.
The underlying storage model is the key design decision. Each mailbox runs in its own Cloudflare Durable Object with a dedicated SQLite database. Attachments land in R2. This means there is no shared database, no centralized email store, and no external email server. The Cloudflare infrastructure IS the email backend.
The Storage and Infrastructure Architecture
The README provides an architecture diagram that shows the data flow:
┌──────────────┐ ┌──────────────────┐ ┌─────────────────┐
│ Browser │────>│ Hono Worker │────>│ MailboxDO │
│ React SPA │ │ (API + SSR) │ │ (SQLite + R2) │
│ Agent Panel │ │ │ └─────────────────┘
└──────┬───────┘ │ /agents/* ──────┼────>┌─────────────────┐
│ │ │ │ EmailAgent DO │
│ WebSocket │ │ │ (AIChatAgent) │
└─────────────┤ │ │ 9 email tools │
│ │────>│ Workers AI │Incoming email arrives via Cloudflare Email Routing. The Hono-based Worker routes API requests and handles SSR. Each mailbox is a separate Durable Object (`MailboxDO`) that holds the email data in SQLite and serves attachments from R2. The AI agent runs in its own Durable Object (`EmailAgent DO`) that holds the chat state and calls Workers AI for model inference.
The AI model in use is `@cf/moonshotai/kimi-k2.5`, accessed through Workers AI. The frontend is built with React 19 and React Router v7, styled with Tailwind CSS, using Zustand for state management and TipTap for the rich text email composer. The WebSocket connection from the browser to the Worker drives the streaming chat interface.
Getting Started with Local Development and Deployment
Local development requires Node.js and a Cloudflare account. Clone the repository and install dependencies:
npm install
npm run devThe `wrangler.jsonc` file at the project root requires a domain to be set before deploying. The README also requires creating an R2 bucket named `agentic-inbox`:
wrangler r2 bucket create agentic-inboxDeploying to Cloudflare runs:
npm run deployThe deploy command runs the React Router build and then deploys via Wrangler. After deployment, the README requires four additional manual steps: configuring Cloudflare Access with `POLICY_AUD` and `TEAM_DOMAIN` secrets, setting up the catch-all Email Routing rule, enabling the Email Service binding for outbound email, and creating at least one mailbox address.
The README is explicit that the deploy button automates only the provisioning of R2, Durable Objects, and Workers AI. The Access configuration and Email Routing setup must be done by hand in the Cloudflare dashboard.
The AI Agent and Its Nine Email Tools
The AI agent appears as a side panel in the email client interface. It has nine email tools for operating on the inbox: reading messages, searching conversations, and drafting and sending replies.
The auto-draft feature is notable. When a new inbound email arrives, the agent automatically reads it and generates a draft reply. The README emphasizes that this draft always requires explicit confirmation before sending. The agent never sends email autonomously.
Each mailbox supports a custom system prompt, which allows the agent's tone and behavior to be configured per mailbox. Chat history is persistent across sessions, and the agent's tool calls are visible in the interface, giving the user transparency into what the agent is doing and why.
The Cloudflare Agents SDK (`AIChatAgent`) manages the agent's state, and the AI SDK v6 provides the abstraction layer for model calls. The MCP server is exposed at `/mcp`. The README notes that external tools like Claude Code or Cursor, when connected via MCP, can operate on any mailbox by passing a `mailboxId` parameter. There is no per-mailbox authorization for MCP clients: the Cloudflare Access policy controls who can connect.
The Single Access Policy Limitation
The most significant architectural constraint is the authorization model. The README states clearly: "Any user who passes the shared Cloudflare Access policy can access all mailboxes in this app by design. There is no per-mailbox authorization; the Cloudflare Access policy is the single trust boundary."
This is a practical limitation for any deployment with more than one user. A shared household, small team, or organization where multiple people have separate mailboxes cannot give each person access to only their own inbox. Everyone who passes the Access policy sees everything.
The MCP server inherits this limitation. An external AI tool connected via MCP and authorized through the Access policy can operate on any mailbox. The application as built assumes the Access policy controls a trusted group that is acceptable to share all mailboxes.
For a personal single-user deployment on a personal Cloudflare account, this constraint is irrelevant. For any multi-user scenario, it is the first thing to evaluate.
Comparison to Hosted Email Clients
Fastmail is a hosted email service with strong privacy credentials and a polished web client. It handles email routing, storage, and a web interface as a paid service. Agentic Inbox is the opposite: zero ongoing cost (beyond Cloudflare's free tier limits), no third-party data custody, but full setup and maintenance responsibility.
The AI agent embedded in Agentic Inbox is the primary feature that has no direct equivalent in standard hosted email clients. Fastmail does not offer an AI agent that reads, drafts, and searches your email through a chat interface on the same infrastructure. Tools that add AI to hosted email, like Gmail's built-in AI features, are controlled by the provider. Agentic Inbox gives the owner full control over which model handles email content, since Workers AI is the inference layer and is part of the same Cloudflare infrastructure the email is stored on.
The trade-off is complexity. Self-hosting requires ongoing attention to Cloudflare infrastructure changes, potential Workers AI model updates, and Email Routing reliability. The repository had its last push on 2026-04-23.
Licensing and Stack Summary
Agentic Inbox is released under the Apache 2.0 licence, which permits commercial use, modification, and redistribution, with requirements to include the licence notice and a NOTICE file. The repository has no GitHub releases.
The dependency list in `package.json` shows a specific version of the AI model reference: `@cf/moonshotai/kimi-k2.5`, accessed through the `workers-ai-provider` package. This is a Cloudflare Workers AI model and is subject to availability in the Workers AI catalog. If Cloudflare deprecates or replaces the model, the `wrangler.jsonc` binding configuration would need to be updated.
The repository structure separates the Workers code in the `workers/` directory, the application code in the `app/` directory, and shared utilities in `shared/`. The Wrangler configuration file is `wrangler.jsonc`, which supports inline comments unlike standard JSON.
Editorial conclusion
Agentic Inbox is best suited to developers who already use Cloudflare and want a programmable email inbox with an embedded AI agent, without setting up a separate email server or relying on a third-party email SaaS. The single Access policy covering all mailboxes is the constraint that matters most for multi-user deployments: anyone who passes the shared policy can reach every mailbox. Verify that constraint is acceptable before deploying. The repository had its last push on 2026-04-23.
Frequently asked questions
What is Agentic Inbox and how does it work?
Agentic Inbox is a self-hosted email client that runs on Cloudflare Workers. Incoming email arrives via Cloudflare Email Routing, each mailbox is stored in its own Durable Object with SQLite, and an AI agent built on the Cloudflare Agents SDK can read, search, and draft replies through a side-panel chat interface.
Does the AI agent in Agentic Inbox send emails automatically?
No. The auto-draft feature generates a draft reply when a new email arrives, but the README explicitly states that explicit confirmation is always required before sending. The agent never sends email without user approval.
Can multiple users have separate mailboxes with different access levels?
No. The README states that any user who passes the shared Cloudflare Access policy can access all mailboxes. There is no per-mailbox authorization. This makes Agentic Inbox suitable for single-user deployments but requires careful evaluation for any scenario with multiple users.
Official sources
Add this badge to your README
If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.
[](https://hysenlabs.com/projects/cloudflare-agentic-inbox)