the landline

An assistant wants to buy from you. Here is how it reaches you.

Short answer

Tunnel gives your business an address AI agents can message — over Model Context Protocol or plain HTTP — and relays what they send to an inbox in your dashboard. You reply there and the agent reads it on the same conversation. Your phone number and email are never exposed. Only registered agents can write, under per-agent quotas and burst limits, with an alarm on anyone messaging many merchants at once.

agent → your inbox
example
A customer is asking whether you can deliver 30 portions to Botanica this Friday evening, and what that would cost.
Yes — Friday 19:00 works. 30 portions is 2 400 MDL delivered. Shall I hold it?
Relayed through tunnel — rate-limited, spam-filtered, your number stays private

A phone number for AI agents

Being named in an answer is half of it. The other half is what happens when someone wants to actually buy — and an assistant has no way to reach you.

MCP and REST, both open

Any assistant or custom agent can open a conversation with your business. No integration on your side.

One inbox, in your dashboard

Every agent conversation lands in the same place. You reply like you would to an email.

Abuse handled for you

Per-agent quotas, burst limits and a fan-out alarm stop one bot farming a hundred merchants.

What happens, end to end

Five steps. Four of them are ours; the last one is a person reading a message.

[01]

The agent finds your record

Through the knowledge-base search, the MCP server, or a direct link. Your record carries the messaging address as a field, so the agent does not have to guess.

[02]

It opens a conversation

One MCP tool call, or one HTTP POST. No integration, no SDK and no negotiation on your side — the endpoint is the same for every business on the platform.

[03]

We check the caller

The agent must be registered and hold a token. We check its quota, its burst rate, and how many other merchants it has contacted recently before anything reaches you.

[04]

It lands in your inbox

Every agent conversation appears in one place in your dashboard, threaded, with the agent identified.

[05]

You reply, and the agent reads it

You answer the way you would an email. The reply goes back on the same conversation, so the agent can carry it into the answer it is writing for its user.

Why this is not a spam pipe

Opening an inbox to anything that can make an HTTP request is only a good idea if the abuse case was designed first.

Registered agents only

Reading is open to anyone. Writing requires a registered agent identity and a token, so every message has something attached to it that can be rate-limited and revoked.

Per-agent quotas and burst limits

A single agent cannot flood one merchant, and cannot make its volume look reasonable by spreading it thin over time.

A fan-out alarm

One agent contacting many merchants in a short window is the signature of harvesting rather than buying. It trips an alarm regardless of whether each individual merchant is under quota.

Your contact details stay yours

The relay address is ours. Your phone number and email are not in the record an agent reads and are not revealed by messaging you.

What it does not do

  • It does not place orders or take payment. It is a conversation channel; the transaction happens the way it already does.

  • It does not answer for you. There is no bot writing replies in your voice, and we will not add one without saying so loudly.

  • It does not oblige any assistant to use it. Consumer ChatGPT will not spontaneously message your bakery today. Most agent traffic right now is developer-built, and this is infrastructure for when that changes — cheap to have and impossible to retrofit in a hurry.

  • It does not guarantee the message is genuine. A registered agent is an accountable one, not a vetted one. Treat an agent enquiry the way you would treat an email from a new customer.

The technical specification

Endpoints, tool schemas, authentication, rate limits and the dispute process are documented for the developer building the agent rather than for the merchant receiving the message.

Read the agent documentation

Questions people ask about this

Which assistants can message my business?

Any of them, in principle: the MCP server and the REST endpoint are open to any registered agent, and there is nothing vendor-specific about either. In practice, whether a given consumer assistant chooses to use it is that vendor’s decision, not ours. Today the realistic caller is a custom or developer-built agent.

Do I need to integrate anything?

No. The endpoint is part of your listing from the moment it exists. You read and answer messages in the dashboard inbox.

Will my phone number be published?

No. Agents message a relay address that belongs to us. Your number and email are not fields an agent can read, and answering a message does not reveal them.

What stops one bot from farming every business on the platform?

Three things: writing requires a registered agent identity, each agent has a quota and a burst limit, and contacting a large number of merchants in a short window trips a fan-out alarm even when each individual merchant is within quota.

What happens if I never reply?

Nothing bad happens to your record — an unanswered conversation is not a penalty. But the agent gets no answer, and whatever it was asking about goes elsewhere. The inbox exists to be read.

free scan

Find out what AI says about your business

We ask six assistants what they say about your business, and send you the answers they gave — including the parts that are wrong. Free, and yours to keep.

Free AI visibility scan (no credit card required)
Setup in under 5 minutes
See the actual answers each assistant gave, per query
Free tier with no time limit — the trial is the product

Get your free AI visibility scan

By submitting, you agree to our Terms of Service and Privacy Policy