List messages in a sandbox inbox

GET/api/v1/sandbox/inboxes/{id}/messages
Requires anorganization API keywith the scopesandbox:read

Newest first. An inbox keeps its newest 50 messages for 30 days; older ones are deleted automatically.

Parameters

NameInTypeDescription
idrequiredpathstringThe id identifier.
qquerystringMatches subject, From or To (contains).
limitqueryintegerPage size, at most 100.
offsetqueryintegerRows to skip.

Request

GET/api/v1/sandbox/inboxes/{id}/messages
curl -X GET 'https://app.mailyte.com/api/v1/sandbox/inboxes/01JBT8XQ2M9WYC3K4F6R7S8T9V/messages' \
  -H 'Authorization: Bearer mk_live_YOUR_API_KEY'
The key names its own organization, so no X-Organization-ID header is needed.

Response

Success.

  • dataobject
    • itemsarray<object>
      • idstring

        ULID of the stored message.

      • inbox_idstring
      • subjectstring
      • header_fromstring

        The From header, as written.

      • header_toarray<string>

        The To header addresses.

      • envelope_rcptsarray<string>

        Every address the message was sent to, INCLUDING Bcc: blind recipients are in the envelope, never in the headers, so this is the only place they show.

      • size_bytesinteger
      • attachment_countinteger
      • sourcestringsmtp | api | inbound

        `api` for a test-mode API key send; `inbound` for mail sent to the inbox's `inbound_address`.

      • simulated_outcomestringdelivered | bounce | softbounce | complaint | suppressed

        The outcome simulated for this message (a `@sim.mailyte.com` address or an `X-Mailyte-Simulate` header). Null means the default: accepted, then delivered.

      • spam_scorenumber

        Null until the message has been scored; scoring runs after it arrives.

      • read_atstring

        When it was marked read. Null means unread.

      • received_atstring

        When the sandbox accepted it.

    • totalinteger

      Matching rows in all, not just this page.

Returned inside the standard envelope.

Errors

StatusWhen
401The API key is missing, unknown, revoked or expired. All four answer identically, on purpose: distinguishing them would confirm which keys exist.
403The key is valid but may not do this: it lacks the required scope, its IP allowlist does not include you, or this endpoint does not accept API keys.
404No such resource in this organization.
422The request was understood but the values were not acceptable.
429Too many requests, or the organization has spent its sending allowance. `Retry-After` says how long to wait.

Every status, with what causes it and what to do, is on the error reference.