How can an AI agent read an email verification code without writing a regex? Agentboxd released an email verification API that lets AI agents extract sign-up codes and confirmation links without regex, using a server-side pattern matcher plus an AI classifier that returns a confidence score. The endpoint GET /v1/inboxes/:id/verification (SDK waitForVerification, MCP get_verification_code) holds a request open for up to 60 seconds until a verification email newer than a supplied timestamp arrives, avoiding polling loops and stale codes. Pattern matching alone caps confidence at 0.7, while the classifier raises it to 0.95 on a clear verification email and drops it to 0.2 on a clear negative. Sign-up forms stop agents with “we sent you a code”. The obvious fix, a six-digit regex over the inbox, works in a demo and breaks on real mail. Here is why, and the one call that replaces it. TL;DR Give the agent its own inbox, note the time, trigger the email, then call GET /v1/inboxes/:id/verification SDK waitForVerification , MCP get verification code . It waits up to 60 seconds and returns the code or link with a confidence score. The extraction runs on our server the moment the email arrives, and an AI check confirms it is really a verification email. Because verification emails are full of other numbers. Order numbers, dates, prices, phone numbers, copyright years and ticket IDs all look like codes to \d{6} . And many codes don’t look like six digits at all: some are four or eight digits, some are letters and digits, some are split by a space or a hyphen. js // The usual first attempt const code = message.text.match /\b\d{6}\b/ ?. 0 ; // What it finds in real sign-up emails: // "Order 482913 confirmed" → 482913 an order number // "© 2026 Example Inc." → no match, but "2026" at 4 digits would be // "Call +1 415 555 0199" → no match, or part of a phone number // "Your code: KQ7-M2X" → no match letters and a hyphen // "G-583920 is your Google code" → 583920, luckily Links are worse. A sign-up email has a confirm button, but also “log in”, “manage preferences”, “unsubscribe”, tracking pixels and a privacy policy. Taking the first link can unsubscribe the agent instead of confirming it. And an agent that polls the inbox in a loop either waits too long or reads the previous code. Every inbound email is checked for a code or link the moment it is stored, before your agent asks. The rules favour precision, because a wrong code is worse than none: the agent can always read the message itself. 482 913 → 482913 , KQ7-M2X → KQ7M2X , G-583920 → 583920 . On top of the pattern match, an AI classifier reads the email and answers one question: is this a login, one-time-code or confirm-your-email message? Pattern matching alone is capped at a confidence of 0.7. A clear yes from the classifier raises it to 0.95; a clear no drops it to 0.2. The classifier’s own answer is returned too, as jev probability . How the classifier works is in How we classify every email an AI agent receives https://agentboxd.com/blog/classifying-inbound-email-for-ai-agents-jev?utm source=devto&utm medium=social&utm campaign=xpost-email-verification-codes . Three steps: note the time, trigger the email, wait. The wait endpoint holds the request open until a verification email newer than since arrives, up to 60 seconds, and returns the newest one, since the latest code is the valid one. No polling loop, no sleep. js import { Agentboxd } from 'agentboxd'; const mr = new Agentboxd { apiKey: process.env.AGENTBOXD API KEY } ; // 1. Note the time BEFORE triggering the email, so an older code can't be picked up. const since = new Date .toISOString ; // 2. Trigger the sign-up browser automation, an API call, whatever your agent does . await signUpOnTheSite { email: inbox.address } ; // 3. Wait up to 60 seconds for the code or link to arrive. const v = await mr.messages.waitForVerification inbox.id, { since, timeout: 60, from: 'example.com' } ; if v throw new Error 'no verification email within 60 s' ; if v.confidence < 0.9 console.warn 'low confidence: read the message', v.message id ; await enterCode v.code ?? undefined ; // or open v.link python from datetime import datetime, timezone from agentboxd import Agentboxd mr = Agentboxd reads AGENTBOXD API KEY since = datetime.now timezone.utc .isoformat sign up on the site email=inbox "address" v = mr.messages.wait for verification inbox "id" , timeout=60, since=since, from ="example.com" if v is None: raise TimeoutError "no verification email within 60 s" print v "code" or v "link" , v "confidence" curl -s "https://api.agentboxd.com/v1/inboxes/$INBOX ID/verification?timeout=60&since=2026-09-29T10:00:00Z&from=example.com" \ -H "Authorization: Bearer $AGENTBOXD API KEY" { "data": { "code": "583920", "link": null, "confidence": 0.95, "jev probability": 0.97, "message id": "0b3e8f4c-…", "from": "Example