API reference
Mailbox auth & security
Operations for mailbox auth & security.
These endpoints take a mailbox token, not an organization API key — they act as one mailbox holder. See Authentication.
- GETThe mailbox holder's security state
/api/v1/mailbox/security - POSTSign in to the webmail with mailbox credentials
/api/v1/mailbox-auth/login - POSTEnd the current webmail session
/api/v1/mailbox-auth/logout - GETWhere this mailbox is signed in
/api/v1/mailbox/security/sessions - POSTChange this mailbox's password
/api/v1/mailbox/security/password - POSTStart two-factor enrolment
/api/v1/mailbox/security/2fa/begin - POSTConfirm two-factor enrolment with a code
/api/v1/mailbox/security/2fa/confirm - POSTTurn two-factor off
/api/v1/mailbox/security/2fa/disable - DELETESign out another device
/api/v1/mailbox/security/sessions/{session_id}