Skip to main content

Authentication

Key scopes

Keys are created with optional scope:
  • Org key (default) — sees everything in the org, minus permission gates.
  • POST /v0/projects/:project_id/api-keys — project-scoped.
  • POST /v0/emails/inboxes/:inbox_id/api-keys — inbox-scoped.
Scoped keys 404 on anything outside their scope. Delete a key with DELETE /v0/api-keys/:api_key_id (or the scoped equivalents).

Permissions

POST /v0/api-keys accepts { "name": "…", "permissions": { "message_send": false } }. Every permission defaults to allow; set one to false to deny. Gates include inbox_*, message_*, draft_*, webhook_*, domain_*, list_*, label_spam_read, label_blocked_read, label_unauthenticated_read, label_trash_read, metric_read, event_read, pod_*, api_key_*, org_read. Denied reads on gated labels behave as 404 (nothing leaks); denied writes are 403 missing_permission.