otpbox

OTPBox / Guides / AI agents

MCP · AI agents

OTP testing for AI agents

An AI agent driving a browser to sign up for a service hits the same wall a human does: "check your email for a code." Unlike a human, it has no inbox to check — unless you give it one. OTPBox's MCP server does exactly that: it hands the agent tools to create a real inbox, wait for mail, and pull out the code or link, all inside the same conversation that's driving the signup.

Why MCP instead of a script

The Playwright/Cypress guides in this series wire a fixed sequence of steps a human wrote in advance. An agent is different: it decides at runtime whether it needs an inbox, when to check it, and what to do with what arrives. MCP tools are built for exactly that — single, well-scoped calls the agent's own reasoning invokes as needed, rather than a script it executes top to bottom. The same OTPBox account and quota back both; MCP is just a second interface onto the same inboxes, messages and identities as the REST API.

1. Connect the server

OTPBox runs a remote (streamable HTTP) MCP server at https://otpbox.io/mcp, authenticated with the same bearer key as the REST API. Add it to an MCP-aware client — Claude, Cursor, or your own agent harness:

{
  "mcpServers": {
    "otpbox": {
      "url": "https://otpbox.io/mcp",
      "headers": { "Authorization": "Bearer <your-key>" }
    }
  }
}

Get a key with no account at all — POST /api/v1/keys/free (see Get a key) — or mint an organization key from the dashboard if several agents or projects should share one pooled quota.

2. The tools an agent has to work with

The server exposes 13 tools total; these are the ones a signup-and-verify task actually uses. Full list and argument details are in the docs.

ToolUse it to…
create_test_inboxGet a fresh disposable address before starting the signup.
wait_for_emailBlock until something arrives, instead of the agent looping on its own.
get_otpRead just the extracted code from the most recent message.
get_verification_linkRead the extracted confirmation/reset/magic-login link instead of a code.
get_latest_emailRead the full message when the agent needs more than the code (subject, body, sender).
create_test_identityGet a name, country and profile alongside the inbox, for a signup form that wants a believable person, not just an email address.
delete_inboxClean up once the task is done.

3. A typical agent task

Prompted with something like "sign up for acme.example.com and confirm the account exists," an agent with the OTPBox tools available and a browser tool (or its own HTTP capability) tends to sequence roughly like this — this is the tool-call pattern, not literal code, since the agent's own model decides the order and any retries:

1. create_test_inbox()
   -> { id: "a1b2c3", address: "bold.quartz844@otpbox.io", expiresAt: ... }

2. (drive the browser) fill the signup form's email field with that address,
   submit

3. wait_for_email({ inboxId: "a1b2c3", timeoutSeconds: 20 })
   -> { timedOut: false, message: { code: "482913", ... } }

   // or, if the agent only wants the code and not the whole message:
   get_otp({ inboxId: "a1b2c3" })
   -> { code: "482913", messageId: "msg_..." }

4. (drive the browser) type "482913" into the OTP field, submit

5. delete_inbox({ inboxId: "a1b2c3" })

Prefer wait_for_email over having the agent call get_otp in a manual retry loop — it's one tool call that blocks server-side (up to 25 seconds) instead of several calls each burning a unit of quota.

4. Bulk and persona-driven testing

An agent tasked with something like "create 10 test accounts with different countries and confirm each one verifies" can reach for create_bulk_test_identities (template plus a count of 1–50) instead of calling create_test_inbox in a loop — each identity comes back with a name, email and country-appropriate profile already attached, backed by its own real inbox. Templates: us_customer, indian_customer, european_customer, business_customer, student, employee.

Limits an agent will run into

Next steps

Ready to wire this into your own agent? Create a free account

← Back to OTPBox