Winnr

app.winnrv0.6.1更新于 Oct 7, 2026

Cold email infrastructure: buy domains, create SMTP mailboxes, set DNS, run warming, read mail.

概览

AI 生成的概览

让助手管理冷邮件基础设施:购买域名、创建 SMTP 邮箱、配置 DNS、运行预热,以及读取或发送邮件。

功能
Winnr 将 Winnr 冷邮件基础设施 API 封装为 55 个工具(其中 26 个只读),另有 8 个资源和 5 个提示词剧本。助手可以列出并查看域名、邮箱、收件箱邮件、预热指标、预热市场列表、任务和 webhook;创建或删除域名与邮箱;发送邮件;并执行 DNS 配置与验证。有四个工具会产生扣款:购买域名、两个购买预热域名的工具,以及启用预热。
适用场景
当助手需要端到端操作冷邮件配置时使用:配置域名和邮箱、检查 DNS 与预热健康度、分拣回复,或购买预热域名。只读令牌适合做报告和回复分拣,不具备任何写入或消费能力。
运行要求
远程端点 OAuth 2.1 + PKCE 登录;或通过 uvx winnr-mcp(或 pip install winnr-mcp)以 stdio 在本地运行。本地使用需要 uv 和 WINNR_API_TOKEN 中的 Winnr API 令牌;可选 WINNR_API_URL、WINNR_TIMEOUT、WINNR_READ_ONLY、WINNR_NO_PURCHASES、WINNR_CONFIRM_SECRET。需要访问 Winnr API 的网络。
安装前请注意
purchase 权限的工具会花钱:winnr_purchase_domains、winnr_purchase_prewarmed、winnr_purchase_prewarmed_batch 和 winnr_enable_warming 会扣款,但每个都会先返回报价和确认令牌。写入类工具会创建、修改、发送和删除数据,包括 winnr_delete_domain、winnr_delete_email_user、winnr_delete_message 和 winnr_cancel_prewarmed。winnr_export_email_users 通过 15 分钟有效的链接返回邮箱凭据 CSV,winnr_get_webhook_secret 会暴露签名密钥。API 令牌(WINNR_API_TOKEN)拥有账户完整权限;可在控制台撤销以立即切断助手访问。

安装

在 SourceWeft 中

  1. 打开 控制台中的 Winnr,将其添加到工作区。
  2. 为需要使用其工具的对话启用该服务。

Web executable,通过 Streamable HTTP。 远程服务在工作区中配置后即可从网页运行时运行。

其他 MCP 客户端

把它添加到你客户端的 mcpServers 配置中。

{
  "mcpServers": {
    "winnr": {
      "type": "http",
      "url": "https://mcp.winnr.app/mcp"
    }
  }
}

README

winnr-mcp

MCP server for the Winnr cold-email infrastructure API.

Lets Claude (web, mobile and desktop), ChatGPT, Claude Code, Cursor, Windsurf, VS Code (Copilot) and any other MCP client manage your domains, mailboxes, warming, inbox, pre-warmed marketplace and webhooks through natural language.

55 tools, 26 of them read-only, plus 8 resources and 5 prompt playbooks.

Two ways to run it:

Hosted (recommended)Local
Endpointhttps://mcp.winnr.app/mcpuvx winnr-mcp over stdio
AuthSign in with Winnr (OAuth 2.1 + PKCE)API token in the config file
Installnoneuv, plus a config file per app
Works withclaude.ai web/mobile, ChatGPT, and every desktop clientdesktop clients only

Setup either way: app.winnr.app/mcp.


Hosted server

Add https://mcp.winnr.app/mcp as a custom connector / remote MCP server. The client registers itself (RFC 7591), sends you to Winnr to sign in, and you choose what it may do:

ScopeGrants
readList and inspect everything. Always granted.
writeCreate, change, send, delete.
purchaseSpend money: buy domains, buy pre-warmed domains, enable warming.

Scopes imply each other (purchase ⊃ write ⊃ read), and a session only ever sees the tools its scopes allow. Each grant is backed by a normal API token named MCP · <client>, so it appears on the dashboard's API page and revoking it there cuts the assistant off.

bash
# Claude Code, hostedclaude mcp add --scope user --transport http winnr https://mcp.winnr.app/mcp

Quick start (local)

1. Get a token

app.winnr.app/mcp (or API → Create Token). Tokens start with wnr_. Pick read-only if you only want reports and reply triage: every tool that creates, sends, buys or deletes is then hidden from the assistant. Add WINNR_NO_PURCHASES=true (or --no-purchases) to keep full write access while hiding the four tools that charge the card.

2. Install uv

The server runs with uvx, so uv must be installed once:

bash
# macOS / Linuxcurl -LsSf https://astral.sh/uv/install.sh | sh      # or: brew install uv# Windows (PowerShell)powershell -ExecutionPolicy ByPass -c "irm https://astral.sh/uv/install.ps1 | iex"

No uv? pip install winnr-mcp and use "command": "winnr-mcp" with no args instead.

3. Add the server to your client

Claude Desktop

Settings → Developer → Edit Config, then paste (macOS ~/Library/Application Support/Claude/claude_desktop_config.json, Windows %APPDATA%\Claude\claude_desktop_config.json). Fully quit and reopen Claude.

json
{  "mcpServers": {    "winnr": {      "command": "uvx",      "args": ["winnr-mcp"],      "env": { "WINNR_API_TOKEN": "wnr_your_token_here" }    }  }}
Claude Code
bash
claude mcp add --scope user winnr -e WINNR_API_TOKEN=wnr_your_token_here -- uvx winnr-mcp

Then /mcp inside Claude Code shows Winnr as connected. Optional guided workflows (/winnr setup, /winnr health, /winnr export) come from winnr-claude-skills:

bash
curl -sL https://raw.githubusercontent.com/winnr-app/winnr-claude-skills/main/install.sh | bash
Cursor

~/.cursor/mcp.json (global) or .cursor/mcp.json (project) — same JSON as Claude Desktop. Settings → MCP shows Winnr with a green dot when it is up.

Windsurf

~/.codeium/windsurf/mcp_config.json — same JSON. Refresh in Settings → Cascade → MCP Servers.

VS Code (Copilot agent mode)

.vscode/mcp.json:

json
{  "servers": {    "winnr": {      "type": "stdio",      "command": "uvx",      "args": ["winnr-mcp"],      "env": { "WINNR_API_TOKEN": "wnr_your_token_here" }    }  }}

4. Try it

What's in my Winnr account, and how much capacity do I have left?

The assistant calls winnr_get_account and winnr_get_usage. The app.winnr.app/mcp page flips to Connected once the token has been used.

Configuration

SourceVariable / flagDescription
Env varWINNR_API_TOKENRequired. Your Winnr API token (wnr_*)
Env varWINNR_API_URLAPI base URL (default https://api.winnr.app; resellers use their own host)
Env varWINNR_TIMEOUTHTTP timeout in seconds (default 30; purchases use 60)
Env varWINNR_READ_ONLYtrue to register read tools only, even with a read/write token
Env varWINNR_NO_PURCHASEStrue to keep write access but hide the four money tools
Env varWINNR_CONFIRM_SECRETHMAC key for purchase confirmation tokens (set automatically on the hosted server)
CLI--token, --api-url, --timeout, --read-only, --no-purchases, --versionOverride the env vars

CLI args take precedence over environment variables.

At startup the server calls GET /v1/account. An invalid token exits immediately with a clear message (a server that starts and then fails every call is worse). If the token is read-only, write tools are hidden automatically — no flag needed.

Spending money is always two steps

The four tools that charge the card — winnr_purchase_domains, winnr_purchase_prewarmed, winnr_purchase_prewarmed_batch, winnr_enable_warming — never charge on the first call. They return a live quote (availability re-checked, exact prices, monthly total) plus a confirmation_token valid for 10 minutes. The assistant shows the quote, gets an explicit yes, and calls again with the token. The quote is recomputed at that moment and the token is an HMAC over it, so if a price moved or a domain sold, the purchase is refused with a fresh quote instead of a surprise charge.

How the assistant is guided

The server ships instructions to the client (most hosts put them in the system prompt), and every tool carries MCP annotations (readOnlyHint, destructiveHint, idempotentHint) so hosts can ask for confirmation at the right moments. The instructions cover:

  • IDs and async jobs (job_id → poll winnr_get_job)
  • The four tools that charge the card (domain purchase, pre-warmed purchase ×2, warming enable) and the rule to get an explicit yes with the exact price first. Domain purchases re-check availability and price right before ordering and refuse the order if anything changed, so the confirmed total is the charged total
  • Never retrying a purchase after a timeout without checking winnr_list_jobs
  • Domain-name hygiene (brand-like names; no outreach/blast/bulk words)
  • Cold-email ratios (2–5 mailboxes per domain, warm 2–3 weeks, modest daily sends)

It also ships resources (read-only records the host can attach to a conversation: winnr://account, winnr://usage, winnr://domains, winnr://domains/{id}, winnr://domains/{id}/dns-records, winnr://domains/{id}/dns-status, winnr://warming/overview, winnr://jobs/{id}) and prompts — parameterised playbooks: winnr_setup_infrastructure, winnr_health_check, winnr_reply_triage, winnr_connect_own_domain, winnr_scale_up.

Tools

Permission is the token scope the tool needs. Read tools are visible to every token.

Account, jobs, export

ToolDescriptionPermission
winnr_get_accountAccount, plan, limits, and the calling token's scoperead
winnr_get_usageDomains / email users / pre-warmed addresses vs limitsread
winnr_list_jobsRecent async jobs (status / type filters)read
winnr_get_jobOne job's status, progress, result, errorread
winnr_wait_for_jobBlock until a job finishes, streaming progress notificationsread
winnr_list_export_formatsSupported CSV formatsread
winnr_export_email_usersCSV of credentials (15-minute link), 22 sequencer formatswrite

Domains

ToolDescriptionPermission
winnr_list_domainsList domains (paginated, optional status filter: complete, pending, …)read
winnr_get_domainOne domain with DNS status and live healthread
winnr_search_domainsAvailability + price for one nameread
winnr_search_domains_bulkAvailability + price for up to 100 namesread
winnr_get_dns_statusProvisioning/propagation state (MX, SPF, DKIM, DMARC)read
winnr_get_dns_recordsRecords to add for manual-DNS domainsread
winnr_check_dns_providerWhere a domain's DNS is hosted today (≤20 per call)read
winnr_purchase_domainsBuy + set up domains (quote → confirm, charges card)purchase
winnr_setup_domainRe-run DNS/mail provisioning, add mailboxes/redirectwrite
winnr_connect_domainsBring your own domains (nameserver, manual DNS, or Cloudflare token)write
winnr_check_nameserversVerify NS change; auto-queues provisioningwrite
winnr_verify_dnsLive-verify manual-DNS recordswrite
winnr_tag_domainsAdd/remove/set tags on up to 50 domainswrite
winnr_delete_domainDelete a domain and its mailboxes (destructive)write

Mailboxes (email users)

ToolDescriptionPermission
winnr_list_email_usersList mailboxes, filterable by domainread
winnr_get_email_userOne mailbox with IMAP/SMTP detailsread
winnr_create_email_userCreate one mailbox (async job)write
winnr_bulk_create_email_usersCreate up to 100 mailboxes on one domainwrite
winnr_update_email_userRename or set passwordwrite
winnr_delete_email_userDelete a mailbox (destructive)write

Inbox

ToolDescriptionPermission
winnr_list_inboxMessages across all mailboxes; warm-up hidden by defaultread
winnr_get_message_bodyFull body by uid + mailbox (truncated at 10k chars)read
winnr_send_emailSend from a mailbox, with threading headerswrite
winnr_refresh_inboxTrigger a syncwrite
winnr_delete_messageDelete one message (destructive)write

Warming

ToolDescriptionPermission
winnr_list_warmingEvery warming mailbox with health/inbox rateread
winnr_get_warming_overviewAggregate stats + estimated monthly costread
winnr_get_warming_metricsDaily series for one mailboxread
winnr_enable_warmingEnable, emails_per_day 1–20, rampup_speed (quote → confirm, $0.60/mailbox/mo)purchase
winnr_disable_warmingDisable and stop billingwrite
winnr_pause_warming / winnr_resume_warmingTemporary stop / restartwrite
winnr_update_warming_settingsemails_per_day, rampup_enabled, rampup_speedwrite

Pre-warmed marketplace

ToolDescriptionPermission
winnr_browse_prewarmedAvailable aged, warmed domainsread
winnr_get_prewarmed_domainPer-address health for one listingread
winnr_check_prewarmed_blocklistLive blocklist check (9 lists)read
winnr_list_my_prewarmedPurchased pre-warmed domainsread
winnr_purchase_prewarmedBuy one domain, $3/address/mo (quote → confirm, charges card)purchase
winnr_purchase_prewarmed_batchBuy up to 25 domains as one charge (quote → confirm, charges card)purchase
winnr_cancel_prewarmedCancel and return the domain (destructive)write

Webhooks

ToolDescriptionPermission
winnr_list_webhooksEndpoints with status and healthread
winnr_get_webhook_deliveriesRecent delivery attemptsread
winnr_create_webhookCreate (response includes signing secret)write
winnr_update_webhookChange URL/events/description/statuswrite
winnr_test_webhookSend a test.pingwrite
winnr_rotate_webhook_secretRotate secret (old valid 24 h)write
winnr_get_webhook_secretRead the signing secret (sensitive; hidden from read-only tokens)write
winnr_delete_webhookDelete (destructive)write

Errors

Every tool returns JSON. Failures look like:

json
{ "error": { "message": "Payment required: …", "status_code": 402, "code": "payment_method_required" } }

so an agent can branch on code. Read-only 403s explain that the token lacks write scope; 429s on reads are retried once automatically.

Security

  • Token-scoped. Everything runs as one account, with the token's permissions. Revoke it in the dashboard and the assistant is cut off instantly.
  • Passwords never appear in tool output. Credentials leave only through winnr_export_email_users, a 15-minute presigned CSV link that needs a read/write token.
  • Nothing is logged. The token is sent as a bearer header and never printed; the server writes one startup line to stderr.
  • Rate limits are the API's (300 req/min Startup, 500 Enterprise). The server warns when fewer than 10 requests remain in the window.

Development

bash
git clone https://github.com/winnr-app/winnr-mcp.gitcd winnr-mcppython3 -m venv .venv && source .venv/bin/activatepip install -e ".[dev]"pytest          # 124 tests, all HTTP mocked (incl. the full OAuth flow)ruff check src testsWINNR_API_TOKEN=wnr_xxx python -m winnr_mcp   # run locally over stdio
# the hosted server, locallypip install -e ".[remote]"uvicorn --factory winnr_mcp.remote.app:create_app --port 8000

Deploying the hosted server

python scripts/deploy_remote.py provisions everything in AWS (DynamoDB table for OAuth state, SSM secret, arm64 Lambda + layer, HTTP API, ACM certificate, mcp.winnr.app domain and Route53 alias) and verifies the deployment.

License

MIT

来源:README.md,提交 7bcaf26

工具

0
工具元数据尚未被收录。

版本历史

1
  1. v0.6.1最新Oct 7, 2026