All storiesProduct

Know which app you are connecting

Clearer application identity on the consent page and more useful activity details for Sendar agent connections.

Sendar2 min read

Published 4 October 2026

Connecting an agent to email is a decision about access. The application name should be easy to recognize, the permissions should be understandable, and the connection should be easy to inspect later. We have made a focused update to Sendar’s OAuth consent page and Agent connections screen to help with those decisions.

See the application identity before connecting

The consent page now gives unverified applications a prominent label and shows the hostname to which authorization returns. You can expand the full callback address when you need to inspect it. An application’s chosen name is supplied by its developer; it is not a verification or endorsement from Sendar.

Start a connection from an application you trust, then check the requesting app, callback hostname and selected workspace before approving. The existing permission explanation remains visible. Read access includes message content and delivery status, domains and templates. Sending still requires a separate choice, a verified sending domain and the existing sending limits.

Inspect a connection afterward

In Agent connections, expand Connection details to see its creation date, client identifier and the name of the approving account when available. The identifier helps distinguish applications that choose the same display name. Account names are useful context, not proof of a publisher’s identity.

The last-used timestamp now records authenticated agent requests through both REST and MCP. Activity writes are limited to once per minute, so this is a recent-use indicator rather than a complete request log. A connection with no recorded activity is labelled accordingly. Historical REST activity that was not previously recorded cannot be reconstructed by this update.

Keep control without changing your integration

If you no longer recognize or need a connection, use Revoke access. Revocation stops subsequent authorized requests; it cannot undo messages already submitted. The existing sending quota, recipient restrictions and suppression rules continue to apply.

This update keeps open client registration, current scopes, token exchange and existing grants intact. It does not introduce a new approval process for developers, require clients to register again, or claim that dynamically registered applications have been verified. The consent page also blocks scripts while preserving its normal sign-in and authorization flow. See the agent documentation for connection setup and the permissions involved.

Keep building

S.
Sendar

Tools and practical advice for application email.