Get a sandbox inbox's public link and access code

GET/api/v1/sandbox/inboxes/{id}/share
Requires anorganization API keywith the scopesandbox:write

Every sandbox inbox has a public link that opens a read-only view of it -- no Mailyte account needed -- so a teammate, a tester or a client can see what your app sent. By default the link asks for a 6-digit access code first. Visitors see the messages (HTML, text, headers, attachments, spam and client checks); they never see the SMTP credentials, webhooks, or anything they could change. The link and code are always viewable here. Needs sandbox:write, because the code opens the inbox to whoever you give it to.

Parameters

NameInTypeDescription
idrequiredpathstringThe id identifier.

Request

GET/api/v1/sandbox/inboxes/{id}/share
curl -X GET 'https://app.mailyte.com/api/v1/sandbox/inboxes/01JBT8XQ2M9WYC3K4F6R7S8T9V/share' \
  -H 'Authorization: Bearer mk_live_YOUR_API_KEY'
The key names its own organization, so no X-Organization-ID header is needed.

Response

Success.

  • dataobject
    • enabledboolean

      The public link opens the inbox. When false the link answers "not available".

    • code_requiredboolean

      Visitors must enter `code` before they see anything.

    • codestring

      The 6-digit access code.

    • tokenstring

      The secret part of the link (24 characters).

    • urlstring

      The public link to share, e.g. `https://mailyte.com/sandbox/<token>`.

    • updated_atstring

      When the link or code last changed. Every change signs all visitors out.

Returned inside the standard envelope.

Errors

StatusWhen
401The API key is missing, unknown, revoked or expired. All four answer identically, on purpose: distinguishing them would confirm which keys exist.
403The key is valid but may not do this: it lacks the required scope, its IP allowlist does not include you, or this endpoint does not accept API keys.
404No such resource in this organization.
422The request was understood but the values were not acceptable.
429Too many requests, or the organization has spent its sending allowance. `Retry-After` says how long to wait.

Every status, with what causes it and what to do, is on the error reference.