Create a sandbox inbox

POST/api/v1/sandbox/inboxes
Requires anorganization API keywith the scopesandbox:write

Returns the inbox with its SMTP secret. Sandbox credentials stay viewable: read them again any time with GET /sandbox/inboxes/{id}/credentials. Your first inbox becomes the default, which is where test-mode API sends land. An organization may have 3 inboxes. Owners and admins only.

Request body

  • namestringrequired

Request

POST/api/v1/sandbox/inboxes
curl -X POST 'https://app.mailyte.com/api/v1/sandbox/inboxes' \
  -H 'Authorization: Bearer mk_live_YOUR_API_KEY' \
  -H 'Content-Type: application/json' \
  -d '{
    "name": "<string>"
  }'
The key names its own organization, so no X-Organization-ID header is needed.

Response

Success.

  • dataobject
    • idstring

      ULID, issued by the mail server (uppercase).

    • organization_idstring
    • namestring

      Your label, e.g. "Staging" or "CI".

    • usernamestring

      The SMTP username for this inbox (`sbx_…`). Authenticate with it on `smtp_host`.

    • smtp_hoststring

      The sandbox SMTP host, `sandbox.smtp.mailyte.com`.

    • smtp_portsarray<integer>

      2525 (STARTTLS) and 2465 (implicit TLS). The production ports 587/465 do not accept sandbox credentials.

    • max_messagesinteger

      How many messages the inbox keeps. The oldest is deleted when a new one would exceed it.

    • retention_daysinteger

      Messages older than this are deleted.

    • inbound_addressstring

      An address anyone can send to from anywhere (no SMTP login), which lands in this inbox: point a third-party service's notification address at it. Null when this deployment has no inbound sandbox domain.

    • is_defaultboolean

      Test-mode API sends land in the default inbox. The first inbox you create is the default.

    • message_countinteger
    • unread_countinteger
    • last_message_atstring

      When the newest message arrived. Null means the inbox has never received one.

    • created_atstring

      When the inbox was created.

    • secretstring

      The SMTP password (`mlt_sbx_…`), on the call that creates the inbox only. Read it again any time with `GET /sandbox/inboxes/{id}/credentials`.

200application/json
{
  "name": "Staging"
}

Returned inside the standard envelope.

Errors

StatusWhen
401The API key is missing, unknown, revoked or expired. All four answer identically, on purpose: distinguishing them would confirm which keys exist.
403The key is valid but may not do this: it lacks the required scope, its IP allowlist does not include you, or this endpoint does not accept API keys.
404No such resource in this organization.
422The request was understood but the values were not acceptable.
429Too many requests, or the organization has spent its sending allowance. `Retry-After` says how long to wait.

Every status, with what causes it and what to do, is on the error reference.