# Misralo — Announcer > Announcer is transactional email for applications. It sends a product's > password resets, receipts and alerts from the customer's own domain and > DKIM-signs every message, so mailbox providers can verify the sender. > Misralo is the company; the product is Misralo Announcer. An emerging convention (llms.txt) for assistants and AI crawlers that would otherwise have to infer all of this from marketing copy. Keep it short, keep it true, and keep it in step with the pages themselves -- everything below is a claim the site already makes. ## What it does - Sending is one HTTPS request. No SDK required, no SMTP credentials to rotate. - Official SDKs: Node.js (npm install announcer-sdk), Python (pip install announcer-sdk), Go (go get github.com/ZeldaIV/announcer-go) and .NET (dotnet add package Announcer). Install and usage: https://misralo.com/docs.html#sdks - A domain is registered through the API, which returns the DNS record to publish. - Errors are RFC 9457 problem documents. - Webhooks are signed twice: HMAC-SHA256 over the body with the endpoint's secret, and an RFC 9421 HTTP message signature per Web Bot Auth, verifiable with the public key at https://misralo.com/.well-known/http-message-signatures-directory. ## Plans - Free: EUR 0/month, 100 messages a day, two domains. No card. Does not expire. - Pro: EUR 19/month, 10,000 messages a month included, then EUR 1.00 per 1,000. Ten domains, 90 days of message history. Open for purchase. - Scale: EUR 99/month, 100,000 messages a month included, then EUR 0.80 per 1,000. A hundred domains, priority support. Priced but NOT open: it is waiting on a dedicated sending IP. /v1/plans reports it as available: false and checkout refuses it; the useful thing to do with it is POST /v1/plans/interest. - Paid plans carry a 99.5% monthly uptime commitment on the sending API, with service credits of 10% of the month's fee per 0.5% missed, capped at that month. The terms are at https://misralo.com/terms.html#availability. - Messages are counted when accepted, not when delivered. Going past the included allowance is billed, never refused; each paid plan also has a hard monthly ceiling above its allowance so a leaked key cannot run up an unbounded bill. - Prices exclude VAT, which is calculated at checkout from the billing address. - Paid plans are sold through Link (a Stripe company) as merchant of record: Link takes the payment, issues the invoice, and handles VAT. ## Endpoints - API base: https://mail.misralo.com - POST /v1/domains — register a sending domain - POST /v1/emails — send a message - GET /healthz — unauthenticated health check The full surface is specified in OpenAPI 3.1 at https://misralo.com/openapi.json and discoverable per RFC 9727 at https://misralo.com/.well-known/api-catalog, which names the description, the documentation and the health endpoint. ## Getting a credential - https://misralo.com/auth.md — the procedure, written for agents. Also served at https://mail.misralo.com/auth.md, for a client that holds the API base URL and nothing else. - The short way is the RFC 8628 device grant: POST /v1/auth/device, show the person the code it returns, poll POST /v1/auth/device/token until it answers with a key. No password passes through the agent and no mailbox is needed. Both endpoints are in openapi.json under the `Device` tag. - Falling back: sign up, verify the address, log in, issue a key. Only for an agent with no human to ask and a mailbox of its own. - Discovery starts at any 401: the `WWW-Authenticate` header names https://mail.misralo.com/.well-known/oauth-protected-resource (RFC 9728), which names the authorization server, whose metadata (RFC 8414) is at /.well-known/oauth-authorization-server and carries an `agent_auth` block. Both are copied to https://misralo.com/ for clients that start at the brand. - One grant type: the device code. No authorization endpoint, no dynamic client registration, no JWKS, no ID-JAG or claim ceremony. Credentials are API keys, scoped `send` or `full`, issued by the account that pays for what is sent. - One human step is irreducible: publishing the DKIM record for a sending domain. auth.md says where it falls. ## MCP - https://mail.misralo.com/mcp — an MCP server over this same API, Streamable HTTP, protocol revision 2026-07-28. Nine tools: sending, message history, delivery events, usage, suppressions and sending domains. - The card is at https://misralo.com/.well-known/mcp/server-card.json (and on mail.misralo.com, and at .../server-cards.json, which is where SEP-1649 is moving the name). - It takes the same API key as everything else, as a bearer token, and grants nothing the key does not already grant. Which tools it offers depends on the key's scope. Key issuance, domain deletion, billing and account closure are deliberately not exposed as tools. - An unauthenticated call answers 401 with the `WWW-Authenticate` header that starts the discovery chain above. ## A2A - https://mail.misralo.com/a2a — the same skills for agent-to-agent delegation, A2A 1.0 over HTTP+JSON. Card at https://misralo.com/.well-known/agent-card.json. - This agent runs no model and interprets no prose. Send a data part shaped {"skill": "", "arguments": {...}} and it returns a completed task carrying what the API answered; each skill's `examples` in the card shows the exact shape. A message of plain text comes back as a rejected task saying so. - Same API key, same scope gating, same nine skills as MCP. It streams nothing and pushes nothing, which the card declares. ## Skills - https://misralo.com/.well-known/agent-skills/index.json — three procedures written for agents, per the Agent Skills Discovery RFC, each with a SHA-256 digest of itself: - send-transactional-email — what must be true before sending, how to send, and what each refusal means - verify-a-sending-domain — register, publish the DKIM record, verify, and where the human with DNS access comes in - diagnose-a-delivery — what happened to a message somebody says never arrived, before resending anything ## Pages Every page below answers in markdown as well as HTML. Send `Accept: text/markdown` and you get the prose without the layout, with the rough token count in the `x-markdown-tokens` response header; or ask for the same file by name, swapping `.html` for `.md` (the home page is `/index.md`). - https://misralo.com/ — what the product is, and the developer quickstart - https://misralo.com/pricing.html — plans and limits - https://misralo.com/docs.html — the API: auth, sending, webhooks, errors, limits - https://misralo.com/privacy.html — what is stored, why, and for how long - https://misralo.com/terms.html — acceptable use and suspension - https://misralo.com/dpa.html — the data processing agreement ## Contact - hello@misralo.com — general - privacy@misralo.com — data protection - abuse@misralo.com — abuse reports