
Winnr
app.winnrv0.6.1更新於 Oct 7, 2026
Cold email infrastructure: buy domains, create SMTP mailboxes, set DNS, run warming, read mail.
概覽
讓助理管理冷郵件基礎設施:購買網域、建立 SMTP 信箱、設定 DNS、執行暖機,以及讀取或寄送郵件。
- 功能
- Winnr 將 Winnr 冷郵件基礎設施 API 包裝成 55 個工具(其中 26 個為唯讀),另有 8 個資源與 5 個提示詞劇本。助理可以列出並檢視網域、信箱、收件匣郵件、暖機指標、預熱市場清單、任務與 webhook;建立或刪除網域與信箱;寄送郵件;並執行 DNS 佈建與驗證。有四個工具會產生扣款:購買網域、兩個購買預熱網域的工具,以及啟用暖機。
- 適用情境
- 當助理需要端到端操作冷郵件設定時使用:佈建網域與信箱、檢查 DNS 與暖機健康度、分揀回覆,或購買預熱網域。唯讀權杖適合做報表與回覆分揀,不具備任何寫入或消費能力。
- 執行需求
- 遠端端點 OAuth 2.1 + PKCE 登入;或透過 uvx winnr-mcp(或 pip install winnr-mcp)以 stdio 在本機執行。本機使用需要 uv 與 WINNR_API_TOKEN 中的 Winnr API 權杖;可選 WINNR_API_URL、WINNR_TIMEOUT、WINNR_READ_ONLY、WINNR_NO_PURCHASES、WINNR_CONFIRM_SECRET。需要連線至 Winnr API 的網路。
安裝
在 SourceWeft 中
- 開啟 儀表板中的 Winnr,將其新增到工作區。
- 為需要使用其工具的對話啟用該服務。
Web executable,透過 Streamable HTTP。 遠端服務在工作區中設定後即可從網頁執行環境執行。
其他 MCP 客戶端
把它新增到你客戶端的 mcpServers 設定中。
{
"mcpServers": {
"winnr": {
"type": "http",
"url": "https://mcp.winnr.app/mcp"
}
}
}README
winnr-mcp
MCP server for the Winnr cold-email infrastructure API.
Lets Claude (web, mobile and desktop), ChatGPT, Claude Code, Cursor, Windsurf, VS Code (Copilot) and any other MCP client manage your domains, mailboxes, warming, inbox, pre-warmed marketplace and webhooks through natural language.
55 tools, 26 of them read-only, plus 8 resources and 5 prompt playbooks.
Two ways to run it:
Setup either way: app.winnr.app/mcp.
Hosted server
Add https://mcp.winnr.app/mcp as a custom connector / remote MCP server. The client
registers itself (RFC 7591), sends you to Winnr to sign in, and you choose what it may do:
Scopes imply each other (purchase ⊃ write ⊃ read), and a session only ever sees
the tools its scopes allow. Each grant is backed by a normal API token named
MCP · <client>, so it appears on the dashboard's API page and revoking it there cuts
the assistant off.
Quick start (local)
1. Get a token
app.winnr.app/mcp (or API → Create Token). Tokens start with
wnr_. Pick read-only if you only want reports and reply triage: every tool that
creates, sends, buys or deletes is then hidden from the assistant. Add
WINNR_NO_PURCHASES=true (or --no-purchases) to keep full write access while hiding the
four tools that charge the card.
2. Install uv
The server runs with uvx, so uv must be installed once:
No uv? pip install winnr-mcp and use "command": "winnr-mcp" with no args instead.
3. Add the server to your client
Claude Desktop
Settings → Developer → Edit Config, then paste (macOS
~/Library/Application Support/Claude/claude_desktop_config.json, Windows
%APPDATA%\Claude\claude_desktop_config.json). Fully quit and reopen Claude.
Claude Code
Then /mcp inside Claude Code shows Winnr as connected. Optional guided workflows
(/winnr setup, /winnr health, /winnr export) come from
winnr-claude-skills:
Cursor
~/.cursor/mcp.json (global) or .cursor/mcp.json (project) — same JSON as Claude
Desktop. Settings → MCP shows Winnr with a green dot when it is up.
Windsurf
~/.codeium/windsurf/mcp_config.json — same JSON. Refresh in Settings → Cascade → MCP Servers.
VS Code (Copilot agent mode)
.vscode/mcp.json:
4. Try it
What's in my Winnr account, and how much capacity do I have left?
The assistant calls winnr_get_account and winnr_get_usage. The
app.winnr.app/mcp page flips to Connected once the
token has been used.
Configuration
CLI args take precedence over environment variables.
At startup the server calls GET /v1/account. An invalid token exits immediately with
a clear message (a server that starts and then fails every call is worse). If the token
is read-only, write tools are hidden automatically — no flag needed.
Spending money is always two steps
The four tools that charge the card — winnr_purchase_domains,
winnr_purchase_prewarmed, winnr_purchase_prewarmed_batch, winnr_enable_warming —
never charge on the first call. They return a live quote (availability re-checked,
exact prices, monthly total) plus a confirmation_token valid for 10 minutes. The
assistant shows the quote, gets an explicit yes, and calls again with the token. The
quote is recomputed at that moment and the token is an HMAC over it, so if a price moved
or a domain sold, the purchase is refused with a fresh quote instead of a surprise charge.
How the assistant is guided
The server ships instructions to the client (most hosts put them in the system
prompt), and every tool carries MCP annotations (readOnlyHint, destructiveHint,
idempotentHint) so hosts can ask for confirmation at the right moments. The
instructions cover:
- IDs and async jobs (
job_id→ pollwinnr_get_job) - The four tools that charge the card (domain purchase, pre-warmed purchase ×2, warming enable) and the rule to get an explicit yes with the exact price first. Domain purchases re-check availability and price right before ordering and refuse the order if anything changed, so the confirmed total is the charged total
- Never retrying a purchase after a timeout without checking
winnr_list_jobs - Domain-name hygiene (brand-like names; no outreach/blast/bulk words)
- Cold-email ratios (2–5 mailboxes per domain, warm 2–3 weeks, modest daily sends)
It also ships resources (read-only records the host can attach to a conversation:
winnr://account, winnr://usage, winnr://domains, winnr://domains/{id},
winnr://domains/{id}/dns-records, winnr://domains/{id}/dns-status,
winnr://warming/overview, winnr://jobs/{id}) and prompts — parameterised
playbooks: winnr_setup_infrastructure, winnr_health_check, winnr_reply_triage,
winnr_connect_own_domain, winnr_scale_up.
Tools
Permission is the token scope the tool needs. Read tools are visible to every token.
Account, jobs, export
Domains
Mailboxes (email users)
Inbox
Warming
Pre-warmed marketplace
Webhooks
Errors
Every tool returns JSON. Failures look like:
so an agent can branch on code. Read-only 403s explain that the token lacks write
scope; 429s on reads are retried once automatically.
Security
- Token-scoped. Everything runs as one account, with the token's permissions. Revoke it in the dashboard and the assistant is cut off instantly.
- Passwords never appear in tool output. Credentials leave only through
winnr_export_email_users, a 15-minute presigned CSV link that needs a read/write token. - Nothing is logged. The token is sent as a bearer header and never printed; the server writes one startup line to stderr.
- Rate limits are the API's (300 req/min Startup, 500 Enterprise). The server warns when fewer than 10 requests remain in the window.
Development
Deploying the hosted server
python scripts/deploy_remote.py provisions everything in AWS (DynamoDB table for OAuth
state, SSM secret, arm64 Lambda + layer, HTTP API, ACM certificate, mcp.winnr.app
domain and Route53 alias) and verifies the deployment.
License
MIT
來源:README.md,提交 7bcaf26
工具
0版本歷史
1- v0.6.1最新Oct 7, 2026
