Resend email inbox
Agentbot can receive inbound emails through a Resend webhook. Emails from approved senders are processed and forwarded to your agent for handling.How it works
- A user sends an email to your Resend inbox address
- Resend forwards the email to
POST /api/webhooks/resend - Agentbot verifies the webhook signature, checks the sender against an allowlist, and applies rate limiting
- Approved emails are processed and made available to your agent
Setup
1
Create a Resend webhook
2
Configure environment variables
Add the following environment variables to your deployment:
3
Test the integration
Send an email from one of the allowed sender addresses to your Resend inbox. Check the agent logs to confirm it was received and processed.
Webhook endpoint
Headers
Signature verification
The endpoint verifies the webhook payload using the Resend SDK’s built-in signature verification. Requests with invalid or missing signatures are acknowledged with200 to prevent Resend from retrying.
Handled event types
Response
The endpoint always returns200 to prevent Resend from retrying delivery.
Security
Sender allowlist
Only emails from addresses listed in theALLOWED_SENDERS environment variable are processed. All other emails are rejected and logged for audit. This is a strict allowlist — there is no wildcard or domain-level matching.
Rate limiting
Each allowed sender is limited to 10 emails per hour. Emails that exceed this limit are acknowledged but not processed.Content sanitization
Email bodies are sanitized before processing:- Script tags and HTML markup are stripped
- Body text is truncated to 5,000 characters
Troubleshooting
Webhook returns 500
Webhook returns 500
Verify that the
RESEND_WEBHOOK_SECRET environment variable is set. The endpoint cannot verify signatures without it.Emails are rejected
Emails are rejected
Check that the sender’s email address is included in
ALLOWED_SENDERS. Addresses are matched in a case-insensitive manner.Emails are rate limited
Emails are rate limited
The limit is 10 emails per sender per hour. Wait for the rate limit window to reset or adjust the sending frequency.