@inbin/cloudflare
v0.1.0
Published
Forward Cloudflare email (Email Workers / Agents SDK onEmail) to Inbin: raw RFC-822 in, schema-validated JSON with per-field trust labels out.
Maintainers
Readme
@inbin/cloudflare
Forward Cloudflare email to Inbin. Raw RFC-822 in, schema-validated JSON out, with a hallucination guard and per-field trust labels, before your agent acts on any of it.
Cloudflare's Email Service gives your Worker or agent an inbox. It also
hands you raw email, the one input format written by strangers that
agents read as instructions. This package is the missing layer: one
call sends the message through Inbin's live pipeline (extraction
against your schema, guard-verified values, field_trust labels,
webhook delivery, MCP availability).
Install
npm install @inbin/cloudflareFrom an Email Worker
Route an address (or a catch-all) to a Worker under Email Routing, then:
import { forwardToInbin } from "@inbin/cloudflare";
export default {
async email(message, env) {
await forwardToInbin(message, {
apiKey: env.INBIN_API_KEY, // wrangler secret put INBIN_API_KEY
inbox: env.INBIN_INBOX, // your inbox slug, e.g. "a3f2c8"
});
},
};From the Agents SDK (onEmail)
import { forwardToInbin } from "@inbin/cloudflare";
async onEmail(email) {
const { event_id } = await forwardToInbin(email, {
apiKey: this.env.INBIN_API_KEY,
inbox: this.env.INBIN_INBOX,
});
// Read back typed, guarded fields instead of parsing raw email:
const event = await fetch(
"https://api.inbin.dev/v1/events/" + event_id,
{ headers: { authorization: "Bearer " + this.env.INBIN_API_KEY } },
).then((r) => r.json());
// event.extracted -> your schema's fields, verbatim-verified
// event.field_trust -> "typed" vs "untrusted_text", per field
// event.sender_auth -> SPF/DKIM/DMARC from the transport's own header
}Behavior
- Idempotent. Re-forwarding the same message (same
Message-Id) returns the original event withdeduped: true, so retries from the email runtime are safe. - Live. Events are dated by receipt and fire your webhook. For
importing archives use
POST /v1/backfillinstead (dated by the originalDate:header, never fires the live webhook). - Auth verdicts. SPF/DKIM/DMARC are parsed server-side from the
message's own
Authentication-Resultsheader (Cloudflare stamps one); they surface on the event assender_auth. - Failures throw. Non-2xx responses raise
InbinIngestError(status + body). In an Email Worker, an uncaught throw makes Cloudflare report a delivery failure to the sender; catch it if you prefer to swallow failures. - Limits. Raw messages up to 10MB.
Full walkthrough: inbin.dev/guides/cloudflare-email-agents API docs: inbin.dev/docs
MIT © Inbin
