Create a sandbox webhook
/api/v1/sandbox/webhooksReturns the signing secret once. Omit inbox_id to receive events for every inbox. Addresses on private, loopback or internal networks are refused. Send to a simulator address (bounce@sim.mailyte.com, softbounce@, complaint@, suppressed@) to fire the failure events. Owners and admins only.
Request body
urlstringrequiredeventsarray<string>requiredinbox_idstring
Request
/api/v1/sandbox/webhookscurl -X POST 'https://app.mailyte.com/api/v1/sandbox/webhooks' \
-H 'Authorization: Bearer mk_live_YOUR_API_KEY' \
-H 'Content-Type: application/json' \
-d '{
"url": "<string>",
"events": [],
"inbox_id": "<string>"
}'const response = await fetch('https://app.mailyte.com/api/v1/sandbox/webhooks', {
method: 'POST',
headers: {
Authorization: 'Bearer mk_live_YOUR_API_KEY',
'Content-Type': 'application/json',
},
body: JSON.stringify({
"url": "<string>",
"events": [],
"inbox_id": "<string>"
}),
});
const { data } = await response.json();import requests
response = requests.post(
"https://app.mailyte.com/api/v1/sandbox/webhooks",
headers={"Authorization": "Bearer mk_live_YOUR_API_KEY"},
json={
"url": "<string>",
"events": [],
"inbox_id": "<string>"
},
)
data = response.json()["data"]<?php
$response = Http::withToken('mk_live_YOUR_API_KEY')
->post('https://app.mailyte.com/api/v1/sandbox/webhooks', [
'url' => '<string>',
'events' => [],
'inbox_id' => '<string>',
]);
$data = $response->json('data');require "net/http"
require "json"
uri = URI("https://app.mailyte.com/api/v1/sandbox/webhooks")
request = Net::HTTP::Post.new(uri)
request["Authorization"] = "Bearer mk_live_YOUR_API_KEY"
request["Content-Type"] = "application/json"
request.body = {
"url": "<string>",
"events": [],
"inbox_id": "<string>"
}.to_json
response = Net::HTTP.start(uri.hostname, uri.port, use_ssl: true) { |http| http.request(request) }Response
Success.
dataobjectidstringorganization_idstringinbox_idstringThe inbox whose messages fire it. Null means every inbox in the organization.
urlstringeventsarray<string>statusstringactive | disabledcreated_atstringWhen it was created.
updated_atstringWhen it was last changed.
secretstringThe signing secret. Returned ONCE, on create. Its own secret, never a live webhook's, so a receiver can tell sandbox from live by signature alone. Every sandbox delivery also carries `environment: "sandbox"` and an `X-Webhook-Environment: sandbox` header.
application/json{
"url": "https://example.com/hooks/mailyte",
"events": [
"email.delivered",
"email.bounced"
]
}Returned inside the standard envelope.
Errors
| Status | When |
|---|---|
401 | The API key is missing, unknown, revoked or expired. All four answer identically, on purpose: distinguishing them would confirm which keys exist. |
403 | The key is valid but may not do this: it lacks the required scope, its IP allowlist does not include you, or this endpoint does not accept API keys. |
404 | No such resource in this organization. |
422 | The request was understood but the values were not acceptable. |
429 | Too many requests, or the organization has spent its sending allowance. `Retry-After` says how long to wait. |
Every status, with what causes it and what to do, is on the error reference.