SendGrid agents that catch deliverability problems early

Paste one SendGrid restricted key. Qoren registers the signed event webhook, wakes an agent on bounces, drops, spam reports and unsubscribes, and lets it check why an address gets no mail.

Request early accessSee pricing

Integrations is in early access: Qoren is turning it on account by account. Already have access? Open Integrations

How do I connect SendGrid to an AI agent?

Create a restricted API key in SendGrid with full access to Event Webhook and read access to what agents should see, such as Stats and Suppressions. Paste it in Qoren, which reads the key's exact permissions and registers a signed event webhook. Removing a suppression or sending an email always waits for a person's approval.

What agents do with SendGrid

Example jobs, each built only from the events and tools listed further down. Write the agent's rules in plain words; these are starting points, not presets.

For agencies running it for clients

  • Deliverability watch for each client

    When an email bounces, is dropped or is marked as spam, the agent checks the address's suppressions and reports what is going wrong while it is still one address, not a campaign.

    Wakes on
    Email bounced or blocked
    Email dropped
    Marked as spam
    Uses
    Check an address's suppressions
  • Unsubscribes reach the CRM

    When someone unsubscribes, the agent records it where the client's team will see it before the next campaign.

    Wakes on
    Unsubscribed
    Unsubscribed from a group

For founders running it for themselves

  • "I never got the email"

    When a customer says an email never arrived, the agent checks the address's suppressions and recent activity and tells you why. Taking it off a suppression list waits for your approval.

    Uses
    Check an address's suppressions
    Check email activity
    Remove a suppression

The path one event takes

10 SendGrid events that can wake an agent

Pick one on an agent's Triggers tab. Each event can arrive on its own, as a digest, or as the latest state of a record, and events that do not match your conditions are logged as Filtered, with no turn and no charge.

EventWhen it fires
Email acceptedSendGrid accepted a message and queued it for delivery.
Email deliveredThe recipient's mail server accepted the email.
Delivery deferredThe recipient's server asked SendGrid to try again later. SendGrid keeps trying for up to 72 hours.
Email bounced or blockedThe recipient's server refused the email: a bounce (the address is bad) or a block (for now).
Email droppedSendGrid did not send the email, for example because the address bounced or unsubscribed before.
Email openedThe recipient opened the email. Only with open tracking on, and mail apps may open it on their own.
Link clickedThe recipient clicked a tracked link.
Marked as spamThe recipient marked the email as spam. SendGrid stops sending to them.
UnsubscribedThe recipient unsubscribed from all of your email.
Unsubscribed from a groupThe recipient unsubscribed from one unsubscribe group.

4 tools agents can use

Curated SendGrid tools, not a raw API: each returns only the fields the job needs. A read only grant never gets a write tool, and tools marked Always asks wait for a person's approval whatever the agent's autonomy setting.

ToolWhat it doesAccessApproval
Check email activityLook up recent emails to one address, or one message by id: subject, status, opens and clicks. Needs SendGrid's Email Activity history add-on.ReadNone
Check an address's suppressionsShow why SendGrid will not send to one address: bounces, blocks, spam reports, invalid address or a global unsubscribe.ReadNone
Remove a suppressionTake one address off one SendGrid suppression list so email can reach it again. Always asks a person to approve first.WriteAlways asks
Send an emailSend one plain-text email through SendGrid to one recipient. Always asks a person to approve first.WriteAlways asks

How connecting SendGrid works

  1. 01Make a SendGrid key with the least access it needs, following the guide below. Only the account owner can connect a tool.
  2. 02Paste it in Qoren. Qoren checks it before saving: which account it belongs to, what it can do and, where SendGrid says, when it expires.
  3. 03Give an agent access, read only or read and write. An agent cannot use a tool it was not given.
  4. 04Pick the events that should wake the agent. Qoren registers the SendGrid webhook itself, so there is no URL or signing secret to copy.

Making the SendGrid key

  1. 1

    Create a restricted key

    In SendGrid, open Settings > API Keys, choose Create API Key, name it Qoren and pick Restricted Access.

    Qoren's connect dialog links straight to this page in SendGrid.

  2. 2

    Tick the least permissions

    Give Event Webhook full access so Qoren can set up triggers, and read access to what your agents should see, such as Stats and Suppressions. Give Mail Send only if agents should send email. Leave everything else at No Access.

  3. 3

    Paste the key here

    Copy the key and paste it here. SendGrid shows it once. Never send it by email or chat.

SendGrid setup guide, with screenshots

Connecting a client's account? Send a link

An agency does not need its client's key. Send a connect link instead: it shows your agency's name and the exact permissions to tick, works once, expires after 7 days and can be revoked. The client pastes the key on that page, Qoren encrypts it on arrival, and you only ever see its last four characters. A client's connection is used only by that client's agents. Connect links come with Clients, on the Ultimate, Business and Enterprise plans.

Client connect links

Security in plain words

  • Keys never reach the agent's machine

    The SendGrid key is encrypted at rest with AES-256-GCM and used only inside Qoren's own calls to SendGrid. It is never written to the agent's environment, and after you connect only its last four characters are shown.

  • Read only until you say otherwise

    Each agent gets read only or read and write access, granted one agent at a time. The SendGrid key itself can be limited too, and the guide asks for the least it needs.

  • Risky actions always ask

    In SendGrid, these always wait for a person's approval, whatever the agent's autonomy setting: remove a suppression and send an email.

  • Capped reads and a full audit log

    By default an agent reads at most 500 records an hour from one connection. Every call, read or write, lands in the audit log with the agent, the tool and the record ids.

  • Event data is treated as data

    Events reach the agent fenced off as data, with a warning not to follow instructions inside them. For 30 minutes after an agent reads connected data, a Qoren tool that would send it outside your account waits for your approval.

  • Stored events expire

    Qoren keeps event bodies for 7 days on Starter, 30 on Pro, 90 on Ultimate and 180 on Business, then removes them and keeps only the metadata.

SendGrid limits worth knowing

When you disconnect, Qoren cannot revoke the key at SendGrid, so it tells you where to delete it. In SendGrid, open Settings > API Keys and delete the key.

  • SendGrid caps event webhooks per account by plan. Qoren reads your cap, uses one webhook per connection and checks there is room first.
  • The email activity tool needs SendGrid's paid Email Activity history add-on.
  • SendGrid sends events in batches. Qoren splits them, so each event goes through your trigger's rules on its own.

Frequently asked questions

Why does the email activity lookup fail?

SendGrid only serves email activity to accounts with its Email Activity history add-on. Without it the agent says so plainly, and the suppressions check still works.

How many SendGrid webhooks does Qoren use?

One per connection, signed with SendGrid's own key. Qoren receives every event on it and wakes only the agents whose triggers match.

Does my agent ever see the SendGrid key?

No. Qoren encrypts the key as soon as it arrives and uses it only inside its own calls to SendGrid. The key never reaches the agent's machine, is never shown again after you connect, and the agent only gets the results of the tools you allowed.

Can an agent remove a suppression without asking?

No. In SendGrid, these tools always wait for a person's approval, whatever the agent's autonomy setting: remove a suppression and send an email. The approval shows the exact details the agent wants to send.

Approvals
What happens when I disconnect SendGrid?

Qoren deletes the webhooks it registered, deletes the stored key, pauses the triggers that used it and removes stored event bodies. It cannot revoke a key at SendGrid, so it shows you where to delete it: In SendGrid, open Settings > API Keys and delete the key.

What does the SendGrid integration cost?

Connecting tools comes with every Qoren plan, with no limit on connections, once Integrations is on for your account. It is in early access for now, turned on account by account. An event that wakes an agent uses credits like any other agent turn, and each trigger has an hourly cap.

Qoren pricing

Connect SendGrid once. Let agents handle the rest.

Integrations is in early access, turned on account by account. Request it and tell us how your agents should use SendGrid.