Scoped API keys
Every key carries a role. Minting one and being allowed to send are two separate permissions, deliberately not one.
API and agents
Two different readers, deliberately kept apart: your own software, which does exactly what you programmed, and an AI agent, which does something reasonable that you did not specify. They get separate doors, separate keys, and different powers.
A REST API for your own systems, an MCP server so an AI agent can work your inbox, and scoped keys that can never do more than the person who made them.
Every key carries a role. Minting one and being allowed to send are two separate permissions, deliberately not one.
Post a message or a file, create and update contacts, import a list. Same rules as the panel, same delivery receipts.
Point Claude or your own agent at Birsend and it can read conversations, message people and pause a campaign, within its role.
Connect a model you pay for and let an auto-reply rule ask it what to say. Your key, your provider, your bill.
The MCP tools let an agent pause a campaign but never resume one. Undoing a deliberate human stop is not a thing to hand to a sentence.
Each automatic reply records what it did, or why it did not — cooling down, no model connected, refused by the filter.
A key carries the role its maker chose for it, and what it may do is the overlap between that role and the maker’s own permissions. Two things follow, and both matter: nobody can mint a key more capable than themselves, and a key stops growing when the person behind it is demoted.
The MCP tools are chosen so an agent can act usefully and cannot escalate. It can pause a campaign that is going out; it cannot resume one. Widening is a human decision, because resuming puts thousands of messages back in motion off a single sentence.
Birsend does not resell AI. You connect a provider and a model with your own key, and an automatic reply rule can ask it to write the answer, with per-rule instructions so one connection can handle a price question and a complaint differently.
The honest list. We would rather you found this here than three weeks into a trial.
Any provider with an OpenAI-style chat endpoint over HTTPS. You choose the model and hold the key, so the running cost is between you and them.
It is scoped by a role you pick, it cannot exceed your own permissions, and every message it sends passes the same guardrails as one you type. Pausing is available to it; resuming is not.
Fourteen days free, no credit card. Connect a number, send one campaign, and judge the reports for yourself.