Resend agents that watch deliverability and read replies
Paste one Resend API key. Qoren registers the webhook, wakes an agent when an email bounces, is opened, gets a complaint or arrives at a receiving address, and lets it check what was sent.
Integrations is in early access: Qoren is turning it on account by account. Already have access? Open Integrations
How do I connect Resend to an AI agent?
Create a full access API key in Resend, because Resend only lets full access keys manage webhooks, and paste it in Qoren. Pick an event such as Email bounced or Email received, and grant an agent access. Agents can check sent emails and their status. Sending an email through Resend always waits for a person's approval.
What agents do with Resend
Example jobs, each built only from the events and tools listed further down. Write the agent's rules in plain words; these are starting points, not presets.
For agencies running it for clients
Bounce and complaint watch for a client's domain
When an email bounces or is marked as spam, the agent checks what was sent and to whom, and reports the pattern before it hurts the client's sender reputation.
- Wakes on
- Email bounced
- Marked as spam
- Uses
- Check an email
- List recent emails
Replies routed to the right person
When an email arrives at one of the client's receiving addresses, Qoren reads the message for the agent, which sorts it and drafts the answer. Sending it waits for approval.
- Wakes on
- Email received
- Uses
- Send an email
For founders running it for themselves
Know when an important email did not land
When delivery is delayed or fails, the agent checks the email's status and tells you which customers did not get it.
- Wakes on
- Delivery delayed
- Email failed
- Uses
- Check an email
The path one event takes
9 Resend events that can wake an agent
Pick one on an agent's Triggers tab. Each event can arrive on its own, as a digest, or as the latest state of a record, and events that do not match your conditions are logged as Filtered, with no turn and no charge.
| Event | When it fires |
|---|---|
| Email sent | Resend accepted an email and handed it to the recipient's mail server. |
| Email delivered | The recipient's mail server accepted the email. |
| Delivery delayed | Delivery is delayed for now (a full inbox, a busy server). Resend keeps trying. |
| Email bounced | The recipient's server refused the email for good. Resend stops sending to that address. |
| Marked as spam | The recipient marked the email as spam. |
| Email failed | Resend could not send the email at all, for example because of a quota or a domain problem. |
| Email opened | The recipient opened the email. Only when open tracking is on for the domain. |
| Link clicked | The recipient clicked a link in the email. Only when click tracking is on for the domain. |
| Email received | An email arrived at one of your receiving addresses. Only for domains with receiving turned on in Resend. Qoren reads the message for the agent. |
3 tools agents can use
Curated Resend tools, not a raw API: each returns only the fields the job needs. A read only grant never gets a write tool, and tools marked Always asks wait for a person's approval whatever the agent's autonomy setting.
| Tool | What it does | Access | Approval |
|---|---|---|---|
| Check an email | Read one sent email's status: recipients, subject, when it was sent and its last event (delivered, bounced, opened...). | Read | None |
| List recent emails | List the most recent sent emails, newest first, at most 20: recipients, subject, time and last event. | Read | None |
| Send an email | Send one plain-text email through Resend to one recipient. Always asks a person to approve first. | Write | Always asks |
How connecting Resend works
- 01Make a Resend key with the least access it needs, following the guide below. Only the account owner can connect a tool.
- 02Paste it in Qoren. Qoren checks it before saving: which account it belongs to, what it can do and, where Resend says, when it expires.
- 03Give an agent access, read only or read and write. An agent cannot use a tool it was not given.
- 04Pick the events that should wake the agent. Qoren registers the Resend webhook itself, so there is no URL or signing secret to copy.
Making the Resend key
- 1
Create an API key
In Resend, open API Keys and choose Create API key. Name it Qoren.
Qoren's connect dialog links straight to this page in Resend.
- 2
Choose Full access
Set Permission to Full access. Resend only lets full access keys manage webhooks, which is how Qoren sets up triggers. A sending access key is refused.
- 3
Paste the key here
Copy the key and paste it here. Resend shows it once. Never send it by email or chat.
Connecting a client's account? Send a link
An agency does not need its client's key. Send a connect link instead: it shows your agency's name and the exact permissions to tick, works once, expires after 7 days and can be revoked. The client pastes the key on that page, Qoren encrypts it on arrival, and you only ever see its last four characters. A client's connection is used only by that client's agents. Connect links come with Clients, on the Ultimate, Business and Enterprise plans.
Client connect linksSecurity in plain words
Keys never reach the agent's machine
The Resend key is encrypted at rest with AES-256-GCM and used only inside Qoren's own calls to Resend. It is never written to the agent's environment, and after you connect only its last four characters are shown.
Read only until you say otherwise
Each agent gets read only or read and write access, granted one agent at a time. The Resend key itself can be limited too, and the guide asks for the least it needs.
Risky actions always ask
In Resend, these always wait for a person's approval, whatever the agent's autonomy setting: send an email.
Capped reads and a full audit log
By default an agent reads at most 500 records an hour from one connection. Every call, read or write, lands in the audit log with the agent, the tool and the record ids.
Event data is treated as data
Events reach the agent fenced off as data, with a warning not to follow instructions inside them. For 30 minutes after an agent reads connected data, a Qoren tool that would send it outside your account waits for your approval.
Stored events expire
Qoren keeps event bodies for 7 days on Starter, 30 on Pro, 90 on Ultimate and 180 on Business, then removes them and keeps only the metadata.
Resend limits worth knowing
When you disconnect, Qoren cannot revoke the key at Resend, so it tells you where to delete it. In Resend, open API Keys and delete the key.
- Resend only lets full access keys manage webhooks. A sending access key is refused at connect.
- Resend disables an endpoint after about a day of failed deliveries. Qoren's daily check turns it back on and replays failed events from up to 3 days back.
- Opens and clicks only arrive when open or click tracking is on for the domain.
Frequently asked questions
Why does Resend need a full access key?
Resend only lets full access keys manage webhooks, and a webhook is how Qoren wakes an agent. Qoren's tools stay read only unless you grant read and write, and sending always asks.
Can the agent read emails people send to us?
Yes, for domains with receiving turned on in Resend. When an email arrives, Qoren reads the message and hands the agent its text, attachment names and authentication results.
Does my agent ever see the Resend key?
No. Qoren encrypts the key as soon as it arrives and uses it only inside its own calls to Resend. The key never reaches the agent's machine, is never shown again after you connect, and the agent only gets the results of the tools you allowed.
Can an agent send an email without asking?
No. In Resend, these tools always wait for a person's approval, whatever the agent's autonomy setting: send an email. The approval shows the exact details the agent wants to send.
ApprovalsWhat happens when I disconnect Resend?
Qoren deletes the webhooks it registered, deletes the stored key, pauses the triggers that used it and removes stored event bodies. It cannot revoke a key at Resend, so it shows you where to delete it: In Resend, open API Keys and delete the key.
What does the Resend integration cost?
Connecting tools comes with every Qoren plan, with no limit on connections, once Integrations is on for your account. It is in early access for now, turned on account by account. An event that wakes an agent uses credits like any other agent turn, and each trigger has an hourly cap.
Qoren pricingConnect Resend once. Let agents handle the rest.
Integrations is in early access, turned on account by account. Request it and tell us how your agents should use Resend.