Skip to main content

Access tokens

Every request to /api/v1 needs an access token in the X-API-KEY header:
  • Generate tokens in your dashboard under API keys, or with the API keys endpoints. A token is shown once: the engine only stores its SHA-256 hash.
  • Revoke a token in the same place. It stops working at once.
  • Give each app or environment its own token, so you can revoke one without affecting the others.
  • Tokens go in the header only. A token in the query string is ignored.
A missing, wrong or revoked token gets:
401 Unauthorized

DSN

Your DSN is your workspace’s API address, shown on your dashboard, for example https://mail-api.example.com. All API paths start with /api/v1:

API keys

You can also manage access tokens through the API. Each key has a pk_… id.

Create a key

string
required
Your name for the key, up to 100 characters.
Response
key is the access token. It’s in this response only, so store it safely.

List and revoke keys

Each key in the list has these fields:

Public endpoints

A few paths are reached by your users’ browsers, so they don’t take an access token. Each is protected in its own way:
Keep access tokens on your server. Never put them in a browser or mobile app: anyone with a token can read every connected mailbox.