惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

C
Check Point Blog
罗磊的独立博客
博客园 - 叶小钗
Google DeepMind News
Google DeepMind News
Hugging Face - Blog
Hugging Face - Blog
人人都是产品经理
人人都是产品经理
J
Java Code Geeks
WordPress大学
WordPress大学
大猫的无限游戏
大猫的无限游戏
Blog — PlanetScale
Blog — PlanetScale
F
Fortinet All Blogs
小众软件
小众软件
M
MIT News - Artificial intelligence
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
酷 壳 – CoolShell
酷 壳 – CoolShell
The GitHub Blog
The GitHub Blog
A
About on SuperTechFans
Y
Y Combinator Blog
Recorded Future
Recorded Future
量子位
美团技术团队
S
Security @ Cisco Blogs
G
Google Developers Blog
Cyberwarzone
Cyberwarzone
C
Cybersecurity and Infrastructure Security Agency CISA
博客园 - 三生石上(FineUI控件)
博客园 - 司徒正美
D
Docker
S
Schneier on Security
T
Tor Project blog
阮一峰的网络日志
阮一峰的网络日志
T
Threatpost
P
Privacy & Cybersecurity Law Blog
C
Cisco Blogs
L
Lohrmann on Cybersecurity
NISL@THU
NISL@THU
Microsoft Azure Blog
Microsoft Azure Blog
博客园 - 聂微东
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
T
The Exploit Database - CXSecurity.com
A
Arctic Wolf
I
Intezer
Latest news
Latest news
Martin Fowler
Martin Fowler
G
GRAHAM CLULEY
B
Blog
V
Vulnerabilities – Threatpost
The Register - Security
The Register - Security
S
Securelist
T
Tenable Blog

DEV Community

Authentication Security Deep Dive: From Brute Force to Salted Hashing (With Java Examples) Why AI Systems Don’t Fail — They Drift Spilling beans for how i learn for exam😁"Reinforcement Learning Cheat Sheet" I Replaced Chrome with Safari for AI Browser Automation. Here's What Broke (and What Finally Worked) How Python Borrows Other People's Work The $40 Architecture: Processing 1 Billion API Requests with 99.99% Uptime Vibe Coding: A Workflow Guide (From Zero to SaaS) Most webhook security guides protect the wrong side. The scary part is delivery. Headless CMS for TanStack Start: Build a Blog with Cosmic EU Age Verification App "Hacked in 2 Minutes" — What Actually Happened Comfy Cloud’s delete function does not actually remove files Running AI Models on GPU Cloud Servers: A Beginner Guide Event-driven media intelligence with AWS Step Functions and Bedrock I scored 500 AI prompts across 8 quality dimensions — here's what broke How to Call Google Gemini API from Next.js (Free Tier, No Backend Needed) The Portal Protocol: Reclaiming Human Connection in the Age of AI How to Fix Your Team's Scattered Knowledge Problem With a Self-Hosted Forum Intro to tc Cloud Functors: A Graph-First Mental Model for the Modern Cloud Designing Multi-Tenant Backends With Both Ownership and Team Access I Built a Neumorphic CSS Library with 77+ Components — Here's What I Learned PostgreSQL Performance Optimization: Why Connection Pooling Is Critical at Scale Cómo construí un SaaS multi-rubro para gestionar expensas en Argentina con FastAPI + Vue 3 🚀 I Built an Ethical Hacking Scanner Tool – Open Source Project I Replaced /usage and /context in Claude Code With a Single Statusline A Pythonic Way to Handle Emails (IMAP/SMTP) with Auto-Discovery and AI-Ready Design I Collected 8.9 Million Polymarket Price Points — Here's What I Found About How Markets Really Move EcoTrack AI — Carbon Footprint Tracker & Dashboard Everyone's Using AI. No One Agrees How. 5 self-hosted ebook managers worth trying in 2026 Building Your First AI Agent with LangChain: From Chatbot to Autonomous Assistant Common SOC 2 Failures (Real World) Stop Vibe-Checking Your AI App: A Practical Guide to Evals How to Use SonarQube and SonarScanner Locally to Level Up Your Code Quality Your Next To-Do App Is Dead — I Replaced Mine with an OpenClaw AI Sign a Nostr event in 60 lines of Python using coincurve — no nostr-sdk, no nbxplorer, no rust toolchain ITGC Audit Explained Like You’re in Big 4 Patch Tuesday abril 2026: Microsoft parcha 163 vulnerabilidades y un zero-day en SharePoint Stop scraping everything: a better way to track competitor price changes Listing on MCPize + the Official MCP Registry while routing payments OUTSIDE the marketplace — how I kept 100% of my x402 revenue Building an AI-Powered Risk Intelligence System Using Serverless Architecture Why We Ripped Function Overloading Out of Our AI Toolchain Testing AI-Generated Code: How to Actually Know If It Works SaaS Churn Is Killing Your Business. Here Is What to Do About It (Without a Support Team) The Speed of AI Is No Longer Linear - And Self-Improving Models Are Why How to Implement RBAC for MCP Tools: A Practical Guide for Engineering Teams From Standard Quote to Persuasive Proposal: AI Automation for Arborists I built a CLI that scaffolds complete multi-tenant SaaS apps Axios CVE-2025–62718: The Silent SSRF Bug That Could Be Hiding in Your Node.js App Right Now The dashboard that ended our friendship Data Pipelines Explained Simply (and How to Build Them with Python) The Hidden Cost of AI Systems Nobody Talks About. undefined vs undeclared, and how typeof behaves Switching from file-based jobs to NATS/Kafka in Rust without changing code io_uring Adventures: Rust Servers That Love Syscalls Why Agentic AI is Killing the Traditional Database The POUR principles of web accessibility for developers and designers Quantum Neural Network 3D — A Deep Dive into Interactive WebGL Visualization How To Install Caveman In Codex On macOS And Windows Automation Pipeline Reliability: Why Your Workflow Breaks When Nobody Is Watching I Built an 'Open World' AI Coding Agent — It Works From ANY Folder From Freelancing to Product: A Tech Service Company's SaaS Transformation China's AI Giants: Adding Tencent Hunyuan & ByteDance Doubao to AI University (74 Providers) On the Vibe Coders and Their Lies clerk: Auto-Summarize Your Claude Code Sessions AI Weekly — 2026/04/10–04/17 | The Model Lockdown Is Here, but the Toolchain Is the Real Battleground AI 週報 — 2026/04/10–2026/04/17 模型封鎖潮來了,但工具鏈才是真戰場 Maybe this is how Open-Source apps are born... 🚀 Fine-Tune LLMs with LoRA and QLoRA: 2026 Guide tRPC v11 + Next.js App Router: End-to-End Type Safety Without the Boilerplate ShadCN UI in 2026: Why I Stopped Installing Component Libraries and Started Owning My Components SaaS Billing in React Server Components: Stripe + Supabase Without a Single `useEffect` Join our DEV Weekend Challenge — $1,000 in Prizes Across TEN winners! Submissions Due April 20 at 6:59 AM UTC. Implementing FSRS Spaced Repetition in Flutter + Supabase — Adding Memory Science to an AI Learning App "I Texted My Localhost From the Train — Claude Code Fixed the Bug Before I Got Home" I Built a Sales Prep AI and It Went Deeper Than Expected Design to Code #2: One JSON, Eleven Outputs Solving the 100M-Row Problem: A Summary Table Pattern for High-Volume Push Notification Logs Flutter Web With Wasm: What Actually Changes For Developers I Built 50 Royalty-Free Soundtracks for My Side Project in a Weekend Using AI Music Generation The Vibe Coding Security Checklist: 7 Things to Check Before You Ship Stop Letting Googlebot Guess Fix Your React App's SEO Right Desconstruindo o Streaming do LinkedIn: Como Criar um Engine de Extração de Vídeo de Alta Performance com HLS e FFmpeg (EDA Part-1) EDA (Exploratory Data Analysis) Explained With Real Life — Why Looking at Your Data Is the Most Important Step in Machine Learning Brand Relationship Management at Scale: Our 4-Touch Outreach System for 200+ Brands Why String.fromEnvironment() Might Return an Empty String in Dart JGuardrails 1.0.0 — Hardening Java LLM Apps Against Jailbreaks, Toxicity, and Prompt Injection Plan and Schedule a Full Week of Threads Content From One Claude Conversation Coding Cat Oran Ep3, Five Tables Changed Everything Updated: BFF Pattern I'm done watching freelancers get buried by 200 proposals. So I'm building the alternative. This is my first post BFS Algorithm in Java Step by Step Tutorial with Examples Tracking LLM Pricing Monthly: An Open Dataset for 22 AI Models How We Measure Content ROI on a Comparison Site: Revenue Attribution Without Perfect Data Introducing Nova AI Ops: The AI-Native Operating System for SRE Teams I built a free desktop video downloader for Windows — Grabbit How Talkie OCR Helps Vision-Impaired & Dyslexic Users Read the World Around Them VRCFaceTracking安装和iPhone面捕配置教程,有bug Even CrowdStrike Can't See Your Agents The Automation Gold Rush: What n8n Workflows and Claude Are Opening Up for Developers Right Now
I found the dumbest way to burn 500 LLM calls a day: polling an inbox every 5 minutes
Lars Winstan · 2026-05-02 · via DEV Community

If your OpenClaw agent checks an email inbox every 5 minutes, you’re probably paying for idle paranoia.

That’s not a theoretical complaint. In an r/openclaw thread about triggering jobs from email, one user described an MS365 setup like this:

"At the moment, I have Openclaw job where agent checks its ms365 mailbox every 5 minutes... Wasted calls to LLM (nearly 500 calls to LLM per day)"

That is such a painfully real failure mode.

The demo works. The cron job looks harmless. Then a month later your agent is re-checking old mail, occasionally double-processing messages, and quietly spending model calls on nothing.

If you’re building always-on agents, this is exactly the kind of bug that turns “cool automation” into “why is this thing flaky and expensive?”

The pattern everyone starts with

Usually it looks like this:

  1. Connect OpenClaw to a mailbox
  2. Poll every 5 minutes with IMAP or Microsoft Graph
  3. If there’s a new message, send it to GPT-5.4, Claude Opus 4.6, or whatever model you’re using
  4. Try not to process the same email twice

For a proof of concept, that’s fine.

If it’s one internal mailbox, low volume, and you have a tiny dedupe store in SQLite, polling can be good enough.

But once the workflow matters, polling starts failing in boring and expensive ways:

  • you keep checking when nothing changed
  • you burn LLM calls on already-seen messages
  • you introduce delays by design
  • you get duplicate processing when scans overlap
  • you miss messages when state gets out of sync

Another user in that same r/openclaw discussion put it even more bluntly:

"I abandoned the interval based scanning... if the scan got out of sync I had repeated responses (more wasted calls) or ignored mails. I failed to get it to be reliable."

That’s the actual problem.

Polling doesn’t just waste money. It makes the agent feel unreliable.

And unreliable is worse than expensive.

Microsoft and Google are both telling you to stop polling

This part is worth emphasizing: the anti-polling advice is not just random architecture purism.

Microsoft Graph supports change notifications so apps can react to mailbox changes instead of hammering the API on a timer.

Gmail push notifications exist for the same reason. Google says push eliminates the extra network and compute cost of polling resources to see if they changed.

If both mailbox providers are nudging you toward push, that’s a clue.

What production intake should look like

There are a few sane ways to do inbound email for agents:

  • Gmail API watch + Google Cloud Pub/Sub
  • Microsoft Graph change notifications
  • Twilio SendGrid Inbound Parse Webhook
  • an email-native service like AgentMail

The common idea is simple:

The provider tells your system that mail arrived.

Your system does not keep asking if anything changed.

Gmail: watch the inbox instead of polling it

For Gmail, the production path is Gmail API watch on the inbox, then Pub/Sub delivers notifications to your webhook.

Example request:

POST https://gmail.googleapis.com/gmail/v1/users/me/watch
Content-Type: application/json
Authorization: Bearer <access_token>

{
  "topicName": "projects/myproject/topics/mytopic",
  "labelIds": ["INBOX"],
  "labelFilterBehavior": "INCLUDE"
}

Enter fullscreen mode Exit fullscreen mode

Google returns a history ID and an expiration time.

That means two things:

  1. you need to process changes based on history
  2. you need to renew the watch before it expires

This is cleaner than polling, but it is not zero-maintenance.

You still need:

  • a Pub/Sub topic
  • a subscription
  • IAM configured correctly
  • watch renewal logic

If you skip the lifecycle work, your “event-driven” setup becomes a very fancy outage.

Microsoft 365: use Graph change notifications

For Microsoft 365, use Microsoft Graph subscriptions for Outlook messages.

Example subscription:

POST https://graph.microsoft.com/v1.0/subscriptions
Content-Type: application/json
Authorization: Bearer <access_token>

{
  "changeType": "created",
  "notificationUrl": "https://your-app.example.com/webhooks/graph",
  "resource": "/me/mailFolders('Inbox')/messages",
  "expirationDateTime": "2026-05-03T00:00:00Z",
  "clientState": "openclaw-mailbox-prod"
}

Enter fullscreen mode Exit fullscreen mode

You need to handle:

  • webhook validation
  • subscription renewal
  • clientState verification
  • dedupe after notification delivery

Again: more setup than polling, much better behavior in production.

SendGrid is the cleanest mental model

If you want the simplest model for inbound email to HTTP, SendGrid Inbound Parse is hard to beat.

Email arrives.

SendGrid parses it.

SendGrid POSTs the content to your endpoint.

Minimal example in Node:

import express from "express";

const app = express();
app.use(express.urlencoded({ extended: true }));
app.use(express.json());

app.post("/inbound-email", async (req, res) => {
  const messageId = req.body.headers?.match(/Message-ID: (.+)/i)?.[1] || req.body.message_id;
  const from = req.body.from;
  const subject = req.body.subject;
  const text = req.body.text;

  // 1. dedupe check
  // 2. persist event
  // 3. enqueue background processing

  console.log({ messageId, from, subject, text });

  res.status(200).send("ok");
});

app.listen(3000, () => {
  console.log("Listening on :3000");
});

Enter fullscreen mode Exit fullscreen mode

The nice part is the delivery contract.

If your endpoint returns 5XX, SendGrid retries.
If your endpoint returns 2XX, retries stop.

That is a much sharper failure model than “cron ran, maybe.”

There are constraints:

  • total message size limit
  • dedicated receiving subdomain setup
  • MX record configuration

Still better than burning cycles forever because polling was easier on day one.

n8n helps, but it does not magically fix polling

This comes up a lot: “Can’t I just use n8n?”

You can absolutely use n8n to improve the workflow.

But if you use the n8n Email Trigger over IMAP, you are still doing mailbox-checking infrastructure. It’s just nicer mailbox-checking infrastructure.

That matters.

n8n gives you useful features like:

  • mailbox selection
  • mark as read
  • attachment handling
  • custom search rules
  • reconnect controls

That is a lot better than a hand-rolled cron script.

But it does not change the trigger model.

If the source of truth is still “go ask the mailbox if anything happened,” you still have polling-shaped failure modes.

Polling vs push

Here’s the tradeoff in plain English:

Approach What you’re really signing up for
Poll mailbox with IMAP or cron Easy setup, delayed reactions, duplicate checks, wasted model calls, awkward dedupe logic
n8n Email Trigger (IMAP) Better operational ergonomics, but still polling underneath
Gmail watch / Graph notifications / SendGrid webhook More setup, much lower idle waste, faster reactions, better delivery semantics

This is not really “simple vs advanced.”

It’s demo-friendly vs production-friendly.

What your OpenClaw email pipeline should actually do

If I were building this today, I’d split it into two layers.

Layer 1: intake

Pick one:

  • SendGrid Inbound Parse if you want email -> HTTP
  • Gmail watch + Pub/Sub if you’re on Google Workspace
  • Microsoft Graph notifications if you’re on Microsoft 365
  • n8n IMAP only for a fast proof of concept

Layer 2: idempotent processing

No matter how the event arrives, your OpenClaw job should:

  1. extract a stable message ID
  2. check a dedupe store before calling any model
  3. persist processing state
  4. acknowledge receipt quickly
  5. do the expensive work asynchronously

That last point is where people get into trouble.

Do not do all processing inside the webhook request.

Accept the event.
Store it.
Deduplicate it.
Then hand it off.

That’s how you survive retries without duplicate replies.

A minimal queue-based pattern

Here’s a practical shape for the service:

email-webhook -> postgres(inbox_events) -> job queue -> OpenClaw worker -> reply/send action

Enter fullscreen mode Exit fullscreen mode

Pseudo-schema:

create table inbox_events (
  id bigserial primary key,
  provider text not null,
  external_message_id text not null,
  received_at timestamptz not null default now(),
  payload jsonb not null,
  processing_status text not null default 'pending',
  unique(provider, external_message_id)
);

Enter fullscreen mode Exit fullscreen mode

Worker logic:

async function processInboxEvent(event) {
  const existing = await db.findByProviderAndMessageId(
    event.provider,
    event.external_message_id
  );

  if (!existing) {
    throw new Error("missing event");
  }

  if (existing.processing_status === "done") {
    return;
  }

  await db.markProcessing(existing.id);

  const result = await runOpenClawAgent({
    email: existing.payload
  });

  await db.saveResult(existing.id, result);
  await db.markDone(existing.id);
}

Enter fullscreen mode Exit fullscreen mode

That is much less exciting than prompt tricks.

It is also the difference between a system that feels solid and one that occasionally replies twice at 3 AM.

The cost side gets ugly fast

If your agent is always on, wasted checks become real money or real usage pressure.

This is where pricing model matters.

Per-token billing makes polling bugs feel worse because every pointless re-check and duplicate pass looks like another tiny leak. You start optimizing prompts and reducing context not because it improves quality, but because you’re trying to contain operational sloppiness.

That’s backwards.

If you’re running OpenClaw agents continuously, predictable flat-rate compute is a much better fit than watching token spend all day. Standard Compute is built for exactly that: OpenAI-compatible API access for OpenClaw agents, flat monthly pricing, and dynamic routing across models like GPT-5.4, Claude Opus 4.6, and Grok 4.20.

So yes, fix the architecture first.

But also: if your agents run 24/7, stop pairing always-on automation with pricing that punishes every extra call.

When polling is still okay

Polling is not always wrong.

Use it when:

  • you have one internal mailbox
  • volume is low
  • a few minutes of delay is fine
  • you have dedupe in SQLite or Postgres
  • nobody will care if you rebuild it later

That is a proof of concept.

Just be honest that it is a proof of concept.

The mistake is pretending that a polling loop is production architecture for a customer-facing or always-on agent.

It isn’t.

The actual line between toy and production

The interesting distinction is not whether OpenClaw can read email.

Of course it can.

The distinction is:

  • how the email arrives
  • whether processing is idempotent after it arrives

A toy automation asks the mailbox every few minutes if anything happened.

A production agent gets an event, validates it, records it once, and processes it once.

That sounds boring.

It’s also the difference between “works in a demo” and “still works three months later.”

If your OpenClaw workflow still polls an inbox every 5 minutes, I wouldn’t call it broken.

I’d call it unfinished.

And once you’ve seen nearly 500 LLM calls per day wasted on mailbox checks, it’s hard to unsee.