API v1
REST + JSON. Long-poll waiting, webhook pushes, automatic verification-code extraction. Create keys in your dashboard.
Send your key in the X-Api-Key header. Keys are stored hashed; the dashboard shows only a prefix. Sandbox keys (tmp_test_…) can seed fake mail via POST /v1/sandbox/deliver.
curl -s https://your-domain/api/v1/me -H "X-Api-Key: tmp_live_…"
# 1. create a mailbox
curl -X POST https://your-domain/api/v1/mailboxes \
-H "X-Api-Key: $KEY" -H "Idempotency-Key: $(uuidgen)" \
-d '{"domain":"thefatburnshift.online"}'
# 2. wait for the verification mail (blocks up to 45s)
curl -s "https://your-domain/api/v1/mailboxes/u9x2k@example.com/messages/wait?timeout=45&match=github" \
-H "X-Api-Key: $KEY"
# 3. the response contains codes: ["482913"] — type it into the signup form. Done.Endpoints
/v1/meanyKey info, plan, live limits and usage — use it for backoff.
/v1/domainsdomains:readDomains pickable by your tier. Premium domains included only for pro.
/v1/domains/{name}/availability?local_part=domains:readCheck whether a username is free; suggests an alternative when taken.
/v1/mailboxesmailboxes:writeCreate a mailbox: {domain?, local_part?, password?}. 409 when taken. Idempotency-Key supported.
/v1/mailbox-authnoneAddress + mailbox password → a 1-hour read-only token. No API key needed — see "Read a mailbox with just its password".
/v1/mailboxesmailboxes:readList your mailboxes (cursor pagination: ?limit=&cursor=).
/v1/mailboxes/{address}mailboxes:readMailbox details with message and unread counts.
/v1/mailboxes/{address}mailboxes:write{password?} · {extend:true} · {recovery_email?}.
/v1/mailboxes/{address}mailboxes:writeDelete the mailbox and every message in it.
/v1/mailboxes/bulkbulk:writePro only. {count ≤50, domain?, prefix?} → 207 with per-item failures.
/v1/mailboxes/{address}/messagesmessages:readList messages: ?since=
/v1/mailboxes/{address}/messages/waitmessages:readLong-poll up to ?timeout= (30s free / 60s pro), optional ?match= substring. 204 on timeout.
/v1/messages/{id}messages:readFull message incl. text, codes[], links[], attachments[].
/v1/messages/{id}messages:read{is_read: true|false}.
/v1/messages/{id}messages:deleteDelete a message.
/v1/messages/{id}/sourcemessages:readOriginal .eml download.
/v1/webhookswebhooks:writeSubscribe: {url, events[], secret?}. Secret auto-generated, shown once.
/v1/webhookswebhooks:writeList your webhooks with delivery health.
/v1/webhooks/{id}/testwebhooks:writeSend a signed test event.
/v1/webhooks/{id}/deliverieswebhooks:writeDelivery log: status, attempts, next retry.
/v1/webhooks/{id}webhooks:writeUnsubscribe.
/v1/sandbox/delivermailboxes:writeSandbox keys only: deliver a synthetic mail to a sandbox mailbox.
Exchange an address + its password for a short-lived token, then read that mailbox's messages
(messages, messages/wait, messages/{id},
/source, /attachments/*) with the
X-Mailbox-Token header instead of the key. Tokens last 1 hour, are read-only,
stop working the moment the password changes, and can't touch any other mailbox.
# 1. swap password for a token (rate-limited — 15 tries / 15 min per IP)
curl -X POST https://your-domain/api/v1/mailbox-auth \
-d '{"address":"ramen@codetohealth.online","password":"hunter22"}'
# → {"data":{"token":"tmp_mb_…","expires_in":3600,"mailbox":{…}}}
# 2. read the inbox with the token alone
curl -s https://your-domain/api/v1/mailboxes/ramen@codetohealth.online/messages \
-H "X-Mailbox-Token: tmp_mb_…"Every delivery carries X-TMP-Timestamp and X-TMP-Signature. Reject timestamps older than 5 minutes.
expected = "sha256=" + HMAC_SHA256(secret, timestamp + "." + raw_body)
if !constant_time_equals(expected, header["X-TMP-Signature"]) { abort(403) }
Free keys: 60 req/min, 10 mailboxes/hour. Pro: 600 req/min, 120/hour.
Every response carries X-RateLimit-Limit / -Remaining / -Reset; 429 adds Retry-After.
Errors use one envelope: {"error":{"code","message","errors"?}} —
codes: bad_request · unauthorized · forbidden · not_found · conflict · validation_failed · rate_limited.