Create a sandbox webhook

POST/api/v1/sandbox/webhooks
Requires anorganization API keywith the scopesandbox:write

Returns the signing secret once. Omit inbox_id to receive events for every inbox. Addresses on private, loopback or internal networks are refused. Send to a simulator address (bounce@sim.mailyte.com, softbounce@, complaint@, suppressed@) to fire the failure events. Owners and admins only.

Request body

  • urlstringrequired
  • eventsarray<string>required
  • inbox_idstring

Request

POST/api/v1/sandbox/webhooks
curl -X POST 'https://app.mailyte.com/api/v1/sandbox/webhooks' \
  -H 'Authorization: Bearer mk_live_YOUR_API_KEY' \
  -H 'Content-Type: application/json' \
  -d '{
    "url": "<string>",
    "events": [],
    "inbox_id": "<string>"
  }'
The key names its own organization, so no X-Organization-ID header is needed.

Response

Success.

  • dataobject
    • idstring
    • organization_idstring
    • inbox_idstring

      The inbox whose messages fire it. Null means every inbox in the organization.

    • urlstring
    • eventsarray<string>
    • statusstringactive | disabled
    • created_atstring

      When it was created.

    • updated_atstring

      When it was last changed.

    • secretstring

      The signing secret. Returned ONCE, on create. Its own secret, never a live webhook's, so a receiver can tell sandbox from live by signature alone. Every sandbox delivery also carries `environment: "sandbox"` and an `X-Webhook-Environment: sandbox` header.

200application/json
{
  "url": "https://example.com/hooks/mailyte",
  "events": [
    "email.delivered",
    "email.bounced"
  ]
}

Returned inside the standard envelope.

Errors

StatusWhen
401The API key is missing, unknown, revoked or expired. All four answer identically, on purpose: distinguishing them would confirm which keys exist.
403The key is valid but may not do this: it lacks the required scope, its IP allowlist does not include you, or this endpoint does not accept API keys.
404No such resource in this organization.
422The request was understood but the values were not acceptable.
429Too many requests, or the organization has spent its sending allowance. `Retry-After` says how long to wait.

Every status, with what causes it and what to do, is on the error reference.