MCP server for SendGrid's v3 API: email marketing, transactional mail, templates, and analytics.
SendGrid MCP Server (io.github.deyikong/sendgrid-mcp)
MCP server for SendGridβs v3 API, exposing functionality for email marketing, transactional email operations, dynamic template management, and detailed analytics. It is an independent project maintained by a SendGrid engineer, not an official SendGrid product. The repository indicates 58 tools to cover email management and performance analysis.
π οΈ Key Features
SendGrid API v3 access
Email marketing operations
Transactional mail operations
Dynamic template management
Detailed analytics
58 tools covering email management and performance analysis
π Use Cases
Automate SendGrid email marketing via MCP
Run transactional email workflows through the API
Manage SendGrid templates dynamically
Retrieve and analyze email performance data
β‘ Developer Benefits
Consolidates SendGrid v3 capabilities into MCP tools
Developer-facing access to email management and analytics
β οΈ Limitations
Not described as an official SendGrid product
The catalog excerpt only references tool coverage (58), without enumerating individual tools or authentication details
A Model Context Protocol (MCP) server that provides comprehensive access to SendGrid's API v3 for email marketing, transactional email operations, dynamic template management, and detailed analytics. Features 154 tools covering all aspects of email management and performance analysis.
Built and maintained by a SendGrid engineer, as an independent project β not an official SendGrid product.
See RELEASES.md for what's changed in the latest release.
Features
Marketing Automations: Create and manage email automation workflows
Single Send Campaigns: Manage one-time email campaigns with detailed performance tracking
Contact Management: Complete CRUD operations for contacts with advanced search and bulk operations
Email Statistics & Analytics: Multi-dimensional performance analysis across browsers, devices, geography, and email providers with 13-month historical data
Dynamic Segment Management: Create, update, and delete contact segments with complex filtering criteria that automatically refresh
Dynamic Template Management: Create, manage, and version HTML email templates with Handlebars support for personalization
Custom Fields Management: Define and manage additional contact data fields for enhanced targeting
Mail Sending: Send transactional emails via SendGrid with full personalization support
Sender Identity Management: Manage verified sender identities with authentication tracking
Suppression Lists: Manage bounces, spam reports, and unsubscribes for deliverability optimization
Account Settings: Access account details and configuration management
Browser Integration: Quick links to SendGrid web interface for visual operations
Read-Only Safety Mode: Secure operation mode prevents accidental data modification while maintaining full analytics access
Supported MCP Clients
β Claude Desktop - Official desktop app
β Claude Code - Official CLI tool
β Claude custom connectors - via Streamable HTTP (see Install the server)
β OpenAI Responses API / Apps SDK - via Streamable HTTP
β MCP Market - Hosted, one-click deploy, no install required (see Install the server)
β Cline - VS Code extension
β Zed Editor - Modern code editor
β Continue - VS Code autopilot
β Codex CLI - via Streamable HTTP
β Any MCP-compatible client
Getting Started
Follow these steps in order β by the end you'll have the server installed (or deployed), your SendGrid API key set, and your MCP client connected.
This is the actual request path, whichever client you end up using β some
launch the server locally over stdio, others reach it over the network via
Streamable HTTP (MCP Market, self-hosted), which adds a choice of client
auth on top:
SENDGRID_API_KEY is required no matter which path you take. READ_ONLY=true
(the default) is a further gate inside the MCP Server box β it blocks
create/update/delete/send tools once a request is already in, regardless of
which branch it arrived on. See Environment Variables
for the full list of what you can configure.
1. Install the server
Install it locally if your client launches it itself, or go remote if it connects over the network instead.
Local (stdio) β for Claude Desktop, Claude Code, Cline, Zed, Continue, or any client that runs the server as a subprocess:
bash
npm install -g sendgrid-mcp
This installs the sendgrid-mcp command globally, which your MCP client will launch as a subprocess. Requires Node.js 20+.
Remote (HTTP) β nothing to install locally; pick one:
MCP Market (hosted, no install required)
MCP Market deploys and hosts this server for you β nothing to install locally and no environment variables to manage on your machine. You still need a SendGrid API key; you'll enter it into MCP Market instead of your own shell/config.
From MCP Market's MCP Servers page, deploy a custom MCP from either source:
GitHub β select the GitHub source, choose Public or Private repo, paste
the repo URL (https://github.com/deyikong/sendgrid-mcp), and pick a
server name.
npm β select the npm source, enter the package name (sendgrid-mcp),
and pick a server name.
Either way, MCP Market builds and runs it for you; it shows up under
MCP Servers with a Running status once ready. Continue to
Configure your MCP client to set your
credentials and connect.
Self-hosted (Streamable HTTP)
Run the server yourself and expose it over Streamable HTTP instead of letting
a client launch it locally β for Claude custom connectors, OpenAI's Responses
API mcp tool / Apps SDK, or any other remote client.
The MCP endpoint is POST /mcp; GET /health returns a status document for
load balancers. Requests are handled statelessly (no session id required),
which is what hosted clients expect.
none/token/oauth below are not alternate ways to connect β they're
three different locks on the one new door (HTTP), as shown in the
request-flow diagram above.
OAuth mode makes this server an OAuth 2.1 resource server. It does not
issue or store credentials β it verifies access tokens minted by your existing
identity provider (Auth0, Okta, Entra ID, Google, Stytch, β¦) against that
provider's published JWKS.
SENDGRID_API_KEY (see the diagram in Getting Started)
is still required alongside these β OAuth only controls who can reach the server, not what the server
uses to talk to SendGrid.
The server publishes RFC 9728
Protected Resource Metadata at /.well-known/oauth-protected-resource, so
clients discover your authorization server automatically: an unauthenticated
request gets a 401 whose WWW-Authenticate header points at that document,
the client reads it, sends the user to your IdP to log in, and retries with the
resulting token.
Tokens are rejected (401) if expired, wrongly signed, or issued for a
different issuer or audience; a valid token missing a required scope gets 403.
Setting up your identity provider
Whichever provider you use, you're configuring the same three things: an
issuer URL, an audience (a stable identifier for this API resource),
and a scope clients will request. A few concrete walkthroughs:
Auth0
Sign in to your Auth0 Dashboard and go to
Applications β APIs β Create API.
Set an Identifier β this is your audience, e.g.
https://mcp.example.com. It doesn't need to resolve to anything; it just
needs to be unique.
Under the API's Permissions tab, add the scopes your server should
require, e.g. sendgrid:read, sendgrid:write.
Your Issuer URL is your tenant domain, shown on the API's Settings
tab: https://YOUR_TENANT.auth0.com/.
Sign in to the Okta Admin Console and go to
Security β API β Authorization Servers.
Use the default authorization server, or create a new one. Its
Issuer URI, shown at the top of the server's settings page, looks like
https://{yourOktaDomain}/oauth2/{authServerId}.
On the same page, the Audience field (default api://default) is what
you'll use for the audience β set it to something specific to this server,
e.g. api://sendgrid-mcp.
Open the Scopes tab and add a scope, e.g. sendgrid:read.
Other providers (Google Identity Platform, Stytch, β¦) follow the same shape:
find the OpenID Connect issuer (usually published at
<issuer>/.well-known/openid-configuration), define an audience/resource
identifier for this server, and create a scope for it.
Whichever provider you use, also set MCP_PUBLIC_URL to the
externally-reachable URL of your server (e.g. https://mcp.example.com) β
clients use it during OAuth discovery.
TRUST_PROXY is off by default because X-Forwarded-* headers are
client-controlled unless a proxy you control overwrites them. TLS 1.2 is the
enforced minimum in in-process mode.
Connecting clients
OpenAI (Responses API):
json
{"model":"gpt-5","tools":[{"type":"mcp","server_label":"sendgrid","server_url":"https://mcp.example.com/mcp","authorization":"ACCESS_TOKEN"}],"input":"List my SendGrid automations"}
Claude (custom connector): add https://mcp.example.com/mcp as a custom
connector. In oauth mode Claude walks the discovery flow and prompts the user
to log in; in token mode supply the bearer token directly.
Security
The server refuses to start on misconfigurations that would quietly expose your
SendGrid account, rather than coming up in a weaker mode than you intended:
Binding to a non-loopback address without either TLS or TRUST_PROXY
MCP_AUTH_MODE=none on anything but a loopback bind
An http://MCP_PUBLIC_URL that is not loopback
A missing or under-length MCP_AUTH_TOKEN, or oauth mode without an issuer
and audience
TLS_KEY_FILE and TLS_CERT_FILE set only one of the pair
Beyond that:
Keep READ_ONLY=true unless you need write and send operations. This is
the single most effective limit on blast radius β it is the difference
between a leaked token exposing analytics and one sending mail from your
domain.
Set MCP_ALLOWED_HOSTS / MCP_ALLOWED_ORIGINS to enable DNS-rebinding
protection, which matters most for locally bound servers reachable from a
browser.
Scope your SendGrid API key to only the permissions this server needs;
the key is the real credential behind every request.
Choose "Full Access" or select specific permissions
Copy the generated key (starts with SG.)
3. Configure your MCP client
MCP Market
Once your server is deployed (see Install the server),
set your credentials and connect a client.
Set your environment variables
Open your deployed server β the Variables tab β My Credentials, and
fill in:
Variable
Required
Description
SENDGRID_API_KEY
β
Your SendGrid API key (starts with SG.)
MCP_SERVER_NAME
β
Server name for identification
MCP_SERVER_VERSION
β
Server version
LOG_LEVEL
β
Logging level (debug, info, warn, error)
REQUEST_TIMEOUT
β
API request timeout in milliseconds
READ_ONLY
β
Enable read-only mode (true/false)
Each field saves independently β only SENDGRID_API_KEY is required.
Connect a client
Click + Connect on your server's page. MCP Market shows one-click
install options for Claude Desktop, Claude Code, Codex CLI, Cursor, VS Code,
Windsurf, Cline, JetBrains, Gemini CLI, Amazon Q, Goose, and Continue β pick
yours and follow its prompt.
For any other client, use the Connection URL option instead, which gives
you a Streamable HTTP endpoint unique to your deployment. The examples below
use deyikong/sendgrid-mcp for illustration β yours will have your own
username and server name:
Wire it up the same way as any other self-hosted
endpoint, e.g.:
bash
# Claude Code
claude mcp add --transport http sendgrid https://link.mcpmarket.com/<your-username>/<your-server-name>/mcp
# Codex CLI
codex mcp add sendgrid --url https://link.mcpmarket.com/<your-username>/<your-server-name>/mcp
MCP Market manages hosting, TLS, and availability for the deployed server; for account, billing, or deployment questions, refer to MCP Market directly rather than this repository.
Claude Desktop
The official Claude desktop application with native MCP support.
The server is configured entirely through environment variables. SENDGRID_API_KEY is the only required one.
Variable
Required
Description
Default
SENDGRID_API_KEY
β
Your SendGrid API key (starts with SG.)
-
READ_ONLY
β
Enable read-only mode (true/false)
true
MCP_SERVER_NAME
β
Server name for identification
sendgrid-mcp
MCP_SERVER_VERSION
β
Server version
1.0.0
LOG_LEVEL
β
Logging level (debug, info, warn, error)
info
REQUEST_TIMEOUT
β
API request timeout in milliseconds
30000
READ_ONLY defaults to true. In this mode every tool is registered and visible, but operations that create, update, delete, or send are blocked at runtime with a clear error message β only list/get/search/browser-link tools actually run. This is the safest default while you're getting set up. See Read-Only Mode for the full breakdown of what's blocked, and set READ_ONLY=false once you're ready to allow write and send operations.
These variables are set inside your MCP client's configuration (as an env block) β see Configure your MCP client. Self-hosted HTTP mode has its own set of variables (transport, auth, TLS) β see Install the server.
Read-Only Mode
Read-Only Mode
By default, the SendGrid MCP server runs in read-only mode (READ_ONLY=true) for safety. All tools are registered and available, but mutable operations are blocked at runtime with helpful error messages.
How Read-Only Mode Works
When READ_ONLY=true (default):
All tools are registered and visible to the AI assistant
Non-mutating operations work normally (list, get, search, open browser links)
Mutating operations are blocked with a clear error message:
code
β Operation blocked: Server is running in READ_ONLY mode. Set READ_ONLY=false in your environment to enable write operations.
Read-Only Safe Operations
These 32 operations work normally when READ_ONLY=true:
This will allow all mutating operations to execute normally while maintaining all read operations.
β οΈ Security Note: Only disable read-only mode if you need write access and trust the environment where the server is running.
Available Tools
The server exposes 154 tools grouped into 22 categories. Every tool is registered regardless of READ_ONLY mode β see Read-Only Mode for which ones are blocked by default.
π For natural-language prompts you can say directly to Claude, see EXAMPLE_PROMPTS.md. The examples below show the underlying JSON tool calls.
API Keys, Alerts, Teammates, and Dedicated IPs are deliberately read-only in this server, and SSO/certificate management isn't exposed at all β see Intentionally Unsupported Operations for why.
Marketing Automations
list_automations - List all marketing automations with metadata
get_automation - Get detailed information about a specific automation
list_templates - List all dynamic and legacy templates
get_template - Get details of a specific template including all versions
create_template - Create a new dynamic template
update_template - Update template name and settings
delete_template - Delete a template and all its versions
create_template_version - Create a new version with HTML content and settings
get_template_version - Get details of a specific template version
update_template_version - Update version content, subject, and settings
delete_template_version - Delete a specific template version
create_html_template - Create complete template with HTML content in one step (perfect for AI agents)
open_template_editor - Open SendGrid's visual template editor in browser
Templates support Handlebars syntax for dynamic content ({{variable}}, {{#each}}, {{#if}}), responsive HTML with inline CSS, up to 300 versions per template, test-data previews, and automatic plain-text generation.
Examples
Example β create a complete template in one step (best for AI agents):
json
{"tool":"create_html_template","arguments":{"template_name":"Welcome Email","version_name":"Version 1.0","subject":"Welcome to {{companyName}}, {{firstName}}!","html_content":"<!DOCTYPE html><html><head><meta charset=\"utf-8\"><title>Welcome</title></head><body style=\"font-family: Arial, sans-serif; max-width: 600px; margin: 0 auto;\"><h1 style=\"color: #333;\">Welcome {{firstName}}!</h1><p>Thank you for joining {{companyName}}. We're excited to have you on board.</p></body></html>","test_data":"{\"firstName\":\"John\",\"companyName\":\"Acme Corp\"}"}}
{"tool":"send_mail","arguments":{"personalizations":[{"to":[{"email":"recipient@example.com","name":"John Doe"}],"subject":"Hello from SendGrid MCP!"}],"from":{"email":"sender@yourdomain.com","name":"Your Name"},"content":[{"type":"text/plain","value":"Hello! This email was sent via SendGrid MCP server."}]}}
get_scopes - Get available API permission scopes (no arguments)
Suppressions
list_suppression_groups - List all unsubscribe (suppression) groups on the account
create_suppression_group - Create a new unsubscribe (suppression) group
get_suppression_group - Get details about a specific unsubscribe (suppression) group
update_suppression_group - Update the name, description, or default status of an existing suppression group
delete_suppression_group - Permanently delete an unsubscribe (suppression) group. This action cannot be undone.
list_group_suppressions - List all email addresses that are unsubscribed from a specific suppression group
add_group_suppressions - Add one or more email addresses to a specific suppression group's unsubscribe list
remove_group_suppression - Remove a single email address from a specific suppression group's unsubscribe list. This only re-permits mail assigned to this group's category -- it is not a global resubscribe.
list_global_suppressions - List email addresses on the account-wide global unsubscribe list, optionally filtered by a time range
add_global_suppression - Add recipients to the account-wide global unsubscribe list -- they will stop receiving all non-transactional mail from this account
get_global_suppression - Check whether a specific email address is on the account-wide global unsubscribe list
delete_global_suppression - Remove an email address from the account-wide global suppression list, effectively resubscribing them to non-transactional mail
list_bounces - List all email addresses that have bounced, optionally filtered by a time range
get_bounce - Get bounce event(s) recorded for a specific email address
delete_bounce - Remove a bounce record for an email address so this address can receive mail again
list_blocks - List all email addresses currently on the blocks list, optionally filtered by a time range
delete_block - Remove an email address from the blocks list so this address can receive mail again
list_spam_reports - List all email addresses that have reported mail as spam, optionally filtered by a time range
delete_spam_report - Remove an email address from the spam reports list so this address can receive mail again
list_invalid_emails - List all email addresses that have been marked invalid, optionally filtered by a time range
delete_invalid_email - Remove an email address from the invalid emails list so this address can receive mail again
Domain Authentication & Link Branding
list_authenticated_domains - List all authenticated (whitelabel) domains configured for sending mail
get_authenticated_domain - Get detailed information about a specific authenticated domain, including its DNS records
create_authenticated_domain - Set up domain authentication (SPF/DKIM) for sending mail from a custom domain
update_authenticated_domain - Update the custom SPF or default settings of an existing authenticated domain
delete_authenticated_domain - Permanently delete an authenticated domain. This action cannot be undone.
validate_authenticated_domain - Check whether the domain's DNS records are correctly configured for authentication
get_default_authenticated_domain - Get the authenticated domain currently set as the default for sending mail
list_branded_links - List all branded links (link whitelabels) configured for click tracking
get_branded_link - Get detailed information about a specific branded link, including its DNS records
create_branded_link - Set up branded link tracking (click tracking through the sender's own domain instead of sendgrid.net)
update_branded_link - Update the default setting of an existing branded link
delete_branded_link - Permanently delete a branded link. This action cannot be undone.
validate_branded_link - Check whether the branded link's DNS records are correctly configured
Event & Inbound Parse Webhooks
list_event_webhooks - List all configured Event Webhook settings on the account
get_event_webhook - Get the configuration of a specific Event Webhook by ID
create_event_webhook - Creates a new Event Webhook that POSTs email events (delivered, bounced, opened, clicked, etc.) to the given URL
update_event_webhook - Update the configuration of an existing Event Webhook
delete_event_webhook - Permanently delete an Event Webhook configuration. This action cannot be undone.
test_event_webhook - Sends a test event payload to the given webhook URL to verify it's reachable and correctly configured
list_inbound_parse_settings - List all configured Inbound Parse webhook settings on the account
get_inbound_parse_setting - Get the Inbound Parse webhook configuration for a specific hostname
create_inbound_parse_setting - Configures inbound email parsing so mail sent to the given hostname is POSTed to the given URL
update_inbound_parse_setting - Update the Inbound Parse webhook configuration for a specific hostname
delete_inbound_parse_setting - Permanently delete an Inbound Parse webhook configuration for a hostname. This action cannot be undone.
get_inbound_parse_stats - Get statistics on the number of inbound emails parsed over a given date range
Tracking Settings
get_tracking_settings - Retrieve all tracking settings (click, open, subscription, Google Analytics) in one call
get_click_tracking_settings - Retrieve the current click tracking setting
update_click_tracking_settings - Enable or disable click tracking on links within emails
get_google_analytics_settings - Retrieve the current Google Analytics tracking settings
update_google_analytics_settings - Update Google Analytics tracking settings, including UTM campaign, content, medium, source, and term values
get_open_tracking_settings - Retrieve the current open tracking setting
update_open_tracking_settings - Enable or disable open tracking, which inserts an invisible pixel to record when an email is opened
get_subscription_tracking_settings - Retrieve the current subscription tracking settings
update_subscription_tracking_settings - Update subscription tracking settings, including the unsubscribe link content, landing page, URL, and replacement tag
Mail Settings
get_all_mail_settings - Retrieve all mail settings (address whitelist, bounce purge, footer, forward bounce, forward spam, etc.) in one call
get_address_whitelist_settings - Retrieve the current address whitelist mail setting, which controls which email addresses or domains bypass all suppression lists
update_address_whitelist_settings - Update the address whitelist setting that controls which email addresses or domains bypass all suppression lists
get_bounce_purge_settings - Retrieve the current bounce purge mail setting, which automatically purges old bounce records after a configured number of days
update_bounce_purge_settings - Update the bounce purge setting that automatically purges old bounce records after a configured number of days
get_footer_settings - Retrieve the current footer mail setting, which appends a footer to every outgoing email
update_footer_settings - Update the footer setting that appends a footer to every outgoing email
get_forward_bounce_settings - Retrieve the current forward bounce mail setting, which forwards bounce notifications to a given email address
update_forward_bounce_settings - Update the forward bounce setting that forwards bounce notifications to a given email address
get_forward_spam_settings - Retrieve the current forward spam mail setting, which forwards spam report notifications to a given email address
update_forward_spam_settings - Update the forward spam setting that forwards spam report notifications to a given email address
API Keys (read-only)
list_api_keys - List all API keys on the account (names and IDs only, not the secret key values)
get_api_key - Get details for a specific API key, including its scopes
Alerts (read-only)
list_alerts - List all usage/stats alerts configured on the account
get_alert - Get details for a specific alert
Teammates (read-only)
list_teammates - List all teammates (users) on the account
get_teammate - Get details for a specific teammate, including their permission scopes
list_pending_teammates - List pending teammate invitations that haven't been accepted yet
Dedicated IPs (read-only)
list_ip_addresses - List all IP addresses assigned to the account
get_ip_address - Get details for a specific IP address, including its warmup status and assigned subusers
list_assigned_ips - List all IP addresses that are currently assigned to a subuser
list_ip_pools - List all IP pools on the account
get_ip_pool - Get details for a specific IP pool, including the IP addresses it contains
get_remaining_ips - Get the count and cost of additional dedicated IP addresses available for purchase
list_ip_warmups - List all IP addresses currently in the warmup process
get_ip_warmup_status - Get the warmup status for a specific IP address
list_allowed_ips - List IP addresses allowed to access the account via the API/UI (the access allowlist)
get_allowed_ip - Get details for a specific entry in the access allowlist
list_access_activity - List recent account access attempts (successful and blocked logins/API calls)
Design Library
list_designs - List all custom email designs in the Design Library
create_design - Create a new custom email design in the Design Library from raw HTML
get_design - Get details for a specific design in the Design Library
update_design - Update the content or metadata of an existing design in the Design Library
delete_design - Permanently delete a custom design from the Design Library. This action cannot be undone.
duplicate_design - Create a copy of an existing design in the Design Library
list_prebuilt_designs - List SendGrid's built-in pre-made design templates
get_prebuilt_design - Get details for one of SendGrid's built-in pre-made designs
duplicate_prebuilt_design - Create an editable copy of one of SendGrid's built-in pre-made designs
Email Address Validation
validate_email - Check whether an email address is valid and likely to be deliverable, using SendGrid's Email Address Validation API (consumes a billed validation credit per call)
Message Search
search_email_activity - Search sent message activity using SendGrid's SGQL filter syntax (e.g. by recipient, status, or subject) -- useful for troubleshooting why a specific email wasn't delivered
get_message_details - Get full delivery event history and details for a single sent message by its message ID
Available Resources
sendgrid://automations - Marketing automations data
sendgrid://singlesends - Single send campaigns data
sendgrid://stats - Global email statistics and performance metrics (30-day overview)
sendgrid://stats/browsers - Email statistics by browser type (7-day data)
sendgrid://stats/devices - Email statistics by device type (7-day data)
sendgrid://stats/geography - Email statistics by geographic location (7-day data)
sendgrid://stats/providers - Email statistics by mailbox provider (7-day data)
Available Prompts
sendgrid_automation_help - Get help with marketing automations
sendgrid_campaign_help - Get help with single send campaigns
sendgrid_contacts_help - Get help with comprehensive contact management
sendgrid_list_management_help - Get help with email list CRUD operations
sendgrid_update_list_help - Get help with updating/renaming email lists
sendgrid_contact_crud_help - Get help with contact create/read/update/delete operations
sendgrid_custom_fields_help - Get help with custom field definitions management
sendgrid_segment_management_help - Get help with managing dynamic contact segments
sendgrid_sender_management_help - Get help with sender identity management
sendgrid_templates_help - Get help with creating and managing dynamic email templates
sendgrid_suppressions_help - Get help with suppression lists
sendgrid_settings_help - Get help with account settings
sendgrid_mail_send_help - Get help with sending emails
sendgrid_stats_help - Get help with analyzing email performance and statistics
Development & Contributing
This section is for developers who want to modify the server or contribute to development.
Development setup, project structure, and contribution guide
Prerequisites
Node.js 20+ and npm
SendGrid account with API key
Git
Development Setup
bash
# Clone the repository
git clone https://github.com/deyikong/sendgrid-mcp.git
cd sendgrid-mcp
# Install dependencies
npm install
# Build the project
npm run build
# Link for local development
npm link# Test the local build
sendgrid-mcp
Using a local build in an MCP client (instead of the npm-installed binary):
Add tool definition to appropriate file in src/tools/
Follow the existing pattern with config and handler
Export from src/tools/index.ts
Update README.md with new tool documentation
Run npm run build to compile
Available Scripts
npm run build - Compile TypeScript to JavaScript
npm start - Run the compiled server
npm test - Build and run the test suite
Testing Your Changes
bash
# Build the project
npm run build
# Test with environment variables
SENDGRID_API_KEY="SG.your_key" READ_ONLY="true" node build/index.js
For manually verifying a real client can connect over each HTTP auth mode
(token, none, TLS, OAuth) rather than just the automated suite, see
TESTING.md.
Creating a Release
For maintainers only:
Update version in package.json:
bash
npm version patch # or minor, major
Push changes and tags:
bash
git push && git push --tags
Create GitHub release - this triggers automatic npm publishing via GitHub Actions
Publishing Process
Automated: GitHub Actions publishes to npm on release creation
Provenance: All packages include provenance attestation for security
This will provide detailed information about API requests and responses.
Security
Found a vulnerability? Please report it privately rather than opening a
public issue β see SECURITY.md.
Intentionally Unsupported Operations
A handful of SendGrid API capabilities are deliberately left out of this server, on top of whatever READ_ONLY mode blocks at runtime. These aren't gaps to be filled later β they're excluded because letting an LLM call them autonomously carries account-wide blast radius that a READ_ONLY toggle alone doesn't mitigate (an operator running with READ_ONLY=false for legitimate marketing-automation writes shouldn't also be one prompt-injected tool call away from losing account access or api budget):
API key creation/rotation/deletion β only list_api_keys/get_api_key are exposed. Minting or deleting API keys is a classic prompt-injection target: a malicious webpage or email an agent processes could try to trick it into creating a new key and exfiltrating it.
Teammate invites, permission changes, and removal β only list_teammates/get_teammate/list_pending_teammates are exposed. Adding, removing, or re-permissioning teammates is account access control with the same injection risk as API keys.
Dedicated IP purchases, warmup control, and access-allowlist changes β only read/list tools are exposed. Dedicated IPs cost real money and affect deliverability infrastructure account-wide; access-allowlist mistakes can lock out legitimate API access entirely.
SSO and certificate management β not exposed at all, in any form. Misconfiguring SSO can lock an entire organization out of login, and there's essentially no legitimate reason for a chat assistant to be managing it.
If you need any of these for a specific automation, use the SendGrid dashboard or API directly rather than requesting this server add them β that's a deliberate design boundary, not an oversight.
I work at SendGrid and maintain this project. Feedback, bug reports, and feature requests are always welcome β please open an issue or start a discussion on the repository.
Install
Configuration
Environment variables
SENDGRID_API_KEYrequiredsecret
Your SendGrid API key (must start with 'SG.').
READ_ONLYdefault true
When true (the default), blocks all write/delete operations at runtime while keeping every tool registered and visible.