Hushmail's public API is a single documented POST that emails a secure form, and keys go only to approved integration partners via Customer Care. No developer portal, no way to read form responses or mail by API, no webhooks. Mail is reachable over IMAP and SMTP.
Hushmail scores F on Supergood's API Report Card. Hushmail's public API is a single documented POST that emails a secure form, and keys go only to approved integration partners via Customer Care. No developer portal, no way to read form responses or mail by API, no webhooks. Mail is reachable over IMAP and SMTP.
Without a usable official API, teams fall back on manual exports, file drops, or one-off vendor integrations. The other option is an unofficial API layer like Supergood that automates the authenticated web app directly. Site terms may apply to any integration approach, and how they apply is a determination each team makes for itself.
Hushmail is an encrypted email, secure web form and e-signature service sold to healthcare practices (its largest segment), law firms, small businesses and individuals.
Healthcare; solo therapists, counselors, psychologists, dietitians, optometrists, dentists and chiropractors, plus small group practices. A therapist sends encrypted email and attachments to clients who read them in a passphrase-protected message center, publishes intake, consent and appointment-request forms as links or embeds them on the practice website, receives completed forms and e-signatures as encrypted messages in the Hushmail inbox, and archives everything under the BAA.
Hushmail is a long-running niche vendor.
Encrypted client correspondence, completed intake and assessment forms, consent agreements with legally binding e-signatures and timestamped activity records, secure file transfers, client contact details and the practice's message archive kept for HIPAA retention.
Founded 1998 with a 1999 launch; the stack is server-side OpenPGP key generation with RSA 2048 keys, webmail, an iOS app launched in 2016, and standard IMAP, POP and SMTP access. The public API path is /api/v1 and the marketing site runs on HubSpot.
A former user reported an unauthorized $49.95 charge, and another said the cost stopped making sense once their EHR handled compliant email. Recipients must remember a passphrase to open messages, and a forgotten passphrase means the original email is lost and must be resent. Full sourced list under Sources below.
Common alternatives include Paubox, Proton Mail, Virtru, Spruce, IntakeQ, Jotform. Graded alternatives appear under "More from the report card" below.
Supergood's grades measure one thing: can a customer's engineering team get their own data out programmatically? Supergood checks six things (whether a real API exists, how access is gated, data coverage, auth quality, docs and developer experience, and stability) and rolls them into a letter grade. Supergood re-verifies grades, and they only move on evidence.
Not that we could find. There is no official Hushmail MCP server in any public registry, and no maintained community server we're aware of. We re-verify this periodically — report an inaccuracy below if we missed one.
Not natively. Hushmail doesn't publish an MCP server, so MCP clients like Claude, Cursor, and Codex have nothing to connect to out of the box. If that changes, this page will reflect it.