# SKILL.md — GetOTP Email Verification & Inbound Mail Reader

Use this skill whenever an AI Agent needs to register an account, receive verification emails, extract 6-digit OTP codes, or click magic authentication links autonomously.

## Environment & Base URL
- Base URL: `https://getotp.ccwu.cc`
- Default Domain: `getotp.ccwu.cc` (or `bitbox.ccwu.cc`)

## Workflow for AI Agents

### Step 1: Create an Ephemeral Inbox
Send a `POST` request to `/api/new_address`:
```bash
curl -X POST https://getotp.ccwu.cc/api/new_address \
  -H "Content-Type: application/json" \
  -d '{"name": "agent_'$(date +%s)'", "domain": "getotp.ccwu.cc"}'
```
Response:
```json
{
  "address": "tmpagent_1728000000@getotp.ccwu.cc",
  "jwt": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9...",
  "password": "16_char_password"
}
```
Save `address` to use in the registration form, and keep `jwt` for authorization.

### Step 2: Trigger the Email
Submit the `address` to the target website (e.g., signup form, password reset, or OTP request).

### Step 3: Poll for Inbound Mail & Extract OTP
Poll `/api/mails` every 2-3 seconds until the message arrives (max timeout 30s):
```bash
curl -s -H "Authorization: Bearer <jwt>" "https://getotp.ccwu.cc/api/mails?limit=1"
```
Response:
```json
{
  "results": [
    {
      "id": 1024,
      "source": "noreply@example.com",
      "subject": "Your verification code is 849201",
      "text": "Please enter 849201 to complete your login."
    }
  ]
}
```

### Step 4: Extract Code or Magic Link
- **6-Digit OTP Regex:** `\b\d{6}\b` or `\b\d{4,8}\b`
- **Magic Link Regex:** `https?://[^\s"'>]+(?:verify|confirm|magic|token|login)[^\s"'>]*`

### Step 5: Resume or Human Handoff Link
If human inspection is required, construct the quick auto-login URL:
`https://getotp.ccwu.cc/?m=<address>&p=<password>`
