تخطَّ إلى المستندات
API

مفاتيح API

كل عملية في هذه المجموعة: ما تقبله وما تُرجعه والأخطاء التي قد تردّ بها.

العمليات

The keys of the workspace, their request log and their activity: the Settings, API keys page of the app. Reading needs keys:read; creating, changing, rotating, switching, revoking and deleting need keys:manage, a scope no key holds unless somebody gave it one. Step-up verification, which the app asks for before it mints or rotates a key, cannot apply to a call made with a key, so treat keys:manage as a credential that can make credentials: give it only to automation that provisions keys, narrow that key to the send scope and role it needs, and give it an expiry. A key never makes or reaches a key wider than itself.

GET/keys

List API keys

الصلاحياتkeys:readيقرأ

Every key in the workspace, newest first, a page at a time, with its status, scopes, role, send scope, when it was last used and who made and last changed it. Revoked and expired keys stay listed until somebody deletes them. No secret is ever returned here.

A key never makes or reaches a key wider than itself. What it creates, changes, rotates, switches, revokes or deletes has to sit inside it on every axis: scopes the caller holds (after its own role has narrowed them), the same role when the caller has one, an expiry no later than the caller's when the caller expires, the caller's mode, and a send scope inside the caller's own, where holding one address never covers its whole domain. A key narrowed to some domains or addresses also only SEES the keys whose send scope sits inside its own; any other is a 404. Over OAuth only the workspace owner reaches these calls, and a member's token is refused with owner_only.

Requires the keys:read scope.

معلمات الاستعلام

limitinteger

Rows per page, 1 to 100.

على الأقل 1على الأكثر 100الافتراضي25
cursorstring

The previous page's nextCursor, passed back as it came. It is opaque: it holds where the last row sat in this list's order, so a row deleted or edited between pages never breaks the walk, and the next page starts at the first row that sorts after it. A value this list did not hand out is a 400 invalid_cursor.

يُرجع

A page of keys.

الأخطاء

الأخطاء التي يمكن أن تُرجعها أي عملية400401403404422500دليل الأخطاء

متاح أيضًا في

SDK
keys.list()keys.listAll()keys.iterate()
CLI
openemail keys list
MCP
listApiKeys

POST/keys

Create an API key

الصلاحياتkeys:manageيغيّر البيانات

Mints a live key and returns its secret in token, once. Nothing recovers it afterwards, so store it before doing anything else.

Left out, scopes is emails:send, the role is the caller's own (or none), the send scope is the caller's own (or none, which means every address the workspace owns), and the expiry is the caller's (or none). The workspace cap on live keys applies, as a 422 workspace_limit_reached. The new key is attributed to the key that made it in the activity log, and it can make keys of its own only if it was given keys:manage.

A key never makes or reaches a key wider than itself. What it creates, changes, rotates, switches, revokes or deletes has to sit inside it on every axis: scopes the caller holds (after its own role has narrowed them), the same role when the caller has one, an expiry no later than the caller's when the caller expires, the caller's mode, and a send scope inside the caller's own, where holding one address never covers its whole domain. A key narrowed to some domains or addresses also only SEES the keys whose send scope sits inside its own; any other is a 404. Over OAuth only the workspace owner reaches these calls, and a member's token is refused with owner_only.

Requires the keys:manage scope.

متن الطلب

namestringمطلوب

A name, 1 to 60 characters.

من 1 إلى 60 من الأحرف
scopesstring[]

The scopes the key holds. Left out, emails:send. Each one has to be held by the caller.

عنصر واحد على الأقلأحد"emails:send""emails:read""drafts:read""drafts:write""threads:read""threads:write""files:read""files:write""labels:read""labels:write""contacts:read""contacts:write""audiences:read""audiences:write""calendar:read""calendar:write""templates:read""templates:write""domains:read""domains:write""webhooks:read""webhooks:write""rules:read""rules:write""connections:read""members:read""members:write""roles:read""roles:write""settings:read""settings:write""keys:write""keys:read""keys:manage""forms:read""forms:write""billing:read""billing:write""account:read""account:write"الافتراضي["emails:send"]
roleIdstring

A role to cap the key. Left out, the caller's own role, or none. A caller with a role can only give its own.

يمكن أن يكون nullمن 1 إلى 64 من الأحرف
addressAllowliststring[]

Single addresses the key may send as. Left out together with domainAllowlist, the caller's own send scope.

حتى 50 من العناصر
domainAllowliststring[]

Whole domains the key may send as, including addresses added to them later.

حتى 25 من العناصر
expiresInMinutesinteger

Minutes until the key expires, 5 to 5,256,000 (ten years). Left out, the caller's own expiry, or none.

على الأقل 5على الأكثر 5256000

يُرجع

201object

The key, with its secret.

objectstring
أحد"api_key"
idstring

24 hex characters, the part of the token after oe_live_.

namestring
modestring
أحد"live""test"
maskedKeystring

Enough of the token to tell two keys apart, such as oe_live_4c1b…kX7a.

keyLast4string
statusstring
أحد"revoked""expired""inactive""active"
scopesstring[]
أحد"emails:send""emails:read""drafts:read""drafts:write""threads:read""threads:write""files:read""files:write""labels:read""labels:write""contacts:read""contacts:write""audiences:read""audiences:write""calendar:read""calendar:write""templates:read""templates:write""domains:read""domains:write""webhooks:read""webhooks:write""rules:read""rules:write""connections:read""members:read""members:write""roles:read""roles:write""settings:read""settings:write""keys:write""keys:read""keys:manage""forms:read""forms:write""billing:read""billing:write""account:read""account:write"
roleIdstring

The role that caps the key, if any.

يمكن أن يكون null
roleNamestring
يمكن أن يكون null
addressAllowliststring[]
يمكن أن يكون null
domainAllowliststring[]
يمكن أن يكون null
expiresAtstring
يمكن أن يكون nullالتنسيقdate-time
lastUsedAtstring
يمكن أن يكون nullالتنسيقdate-time
totalUsesinteger

Calls the key has made, leaving out the ones refused before it authenticated.

rotatedAtstring
يمكن أن يكون nullالتنسيقdate-time
rotationCountinteger
deactivatedAtstring
يمكن أن يكون nullالتنسيقdate-time
revokedAtstring
يمكن أن يكون nullالتنسيقdate-time
revokedReasonstring
يمكن أن يكون null
createdAtstring
التنسيقdate-time
createdByAuditActor
updatedAtstring
التنسيقdate-time
updatedByAuditActor
lastChangeAtstring
يمكن أن يكون nullالتنسيقdate-time
lastChangeTypestring
يمكن أن يكون null
tokenstring

The whole secret, oe_live_…, shown this once.

الأخطاء

403

insufficient_scope: the caller lacks keys:manage. beyond_caller_authority: the key asked for would be wider than the caller, and param names the axis (scopes, roleId, mode, expiresInMinutes or addressAllowlist). owner_only: a member's OAuth token.

422

invalid_parameter or unknown_parameter on a field, role_not_found on roleId, a domain or address the workspace does not own, or workspace_limit_reached.

الأخطاء التي يمكن أن تُرجعها أي عملية400401404500دليل الأخطاء

متاح أيضًا في

SDK
keys.create()
CLI
openemail keys create

GET/keys/requests

List the request log

الصلاحياتkeys:readيقرأ

Every authenticated call the workspace's keys made, newest first, the Requests tab of the app: method, path, status, error code, duration, IP and user agent, never a body or a query string. Calls refused before a key could be identified are not in it, and neither are calls made with an OAuth access token. Nothing is pruned. keyIds, failedOnly, since and until are the filters the app offers.

A narrowed key reads only the log of the keys it can see.

Requires the keys:read scope.

معلمات الاستعلام

keyIdsstring

Comma-separated key ids, at most 50. Left out, every key in the workspace.

failedOnlyboolean

Only calls answered with a status of 400 or more.

الافتراضيfalse
sincestring

Only rows at or after this instant, ISO 8601. One that does not parse is a 400 invalid_parameter.

التنسيقdate-time
untilstring

Only rows before this instant. It has to be later than since.

التنسيقdate-time
limitinteger

Rows per page, 1 to 100.

على الأقل 1على الأكثر 100الافتراضي25
cursorstring

The previous page's nextCursor, passed back as it came. It is opaque: it holds where the last row sat in this list's order, so a row deleted or edited between pages never breaks the walk, and the next page starts at the first row that sorts after it. A value this list did not hand out is a 400 invalid_cursor.

يُرجع

A page of calls, newest first.

الأخطاء

الأخطاء التي يمكن أن تُرجعها أي عملية400401403404422500دليل الأخطاء

متاح أيضًا في

SDK
keys.listWorkspaceRequests()keys.listAllWorkspaceRequests()keys.iterateWorkspaceRequests()
CLI
openemail keys list-workspace-requests
MCP
listApiKeyRequests

GET/keys/activity

List API key activity

الصلاحياتkeys:readيقرأ

What happened to the workspace's keys, newest first, the Activity tab of the app: created, updated, rotated, deactivated, reactivated, revoked, deleted, and every attempt to authenticate with a key that was refused. actor says who, a person as @username or a key as API key <name>, and detail.source where from. A deleted key keeps its history. keyIds, since and until narrow it.

A narrowed key reads only the activity of the keys it can see.

Requires the keys:read scope.

معلمات الاستعلام

keyIdsstring

Comma-separated key ids, at most 50. Left out, every key in the workspace.

sincestring

Only rows at or after this instant, ISO 8601. One that does not parse is a 400 invalid_parameter.

التنسيقdate-time
untilstring

Only rows before this instant. It has to be later than since.

التنسيقdate-time
limitinteger

Rows per page, 1 to 100.

على الأقل 1على الأكثر 100الافتراضي25
cursorstring

The previous page's nextCursor, passed back as it came. It is opaque: it holds where the last row sat in this list's order, so a row deleted or edited between pages never breaks the walk, and the next page starts at the first row that sorts after it. A value this list did not hand out is a 400 invalid_cursor.

يُرجع

A page of changes, newest first.

الأخطاء

الأخطاء التي يمكن أن تُرجعها أي عملية400401403404422500دليل الأخطاء

متاح أيضًا في

SDK
keys.listWorkspaceActivity()keys.listAllWorkspaceActivity()keys.iterateWorkspaceActivity()
CLI
openemail keys list-workspace-activity
MCP
listApiKeyActivity

GET/keys/{id}

Retrieve an API key

الصلاحياتkeys:readيقرأ

One key, without its secret. A key the caller cannot see is a 404.

Requires the keys:read scope.

معلمات المسار

idstringمطلوب

The key id, 24 hex characters.

يُرجع

The key.

الأخطاء

الأخطاء التي يمكن أن تُرجعها أي عملية400401403404422500دليل الأخطاء

متاح أيضًا في

SDK
keys.get()
CLI
openemail keys get
MCP
listApiKeys

PATCH/keys/{id}

Update an API key

الصلاحياتkeys:manageيغيّر البيانات

Renames a key, replaces its scopes or its send scope, or switches it off and on with enabled. A switched-off key is refused on every call with inactive_api_key and keeps everything it had, so switching it back on restores it exactly; that is the reversible alternative to revoking. scopes, addressAllowlist and domainAllowlist REPLACE what the key had, and a list left out stays as it was. A revoked key cannot be changed.

A key never makes or reaches a key wider than itself. What it creates, changes, rotates, switches, revokes or deletes has to sit inside it on every axis: scopes the caller holds (after its own role has narrowed them), the same role when the caller has one, an expiry no later than the caller's when the caller expires, the caller's mode, and a send scope inside the caller's own, where holding one address never covers its whole domain. A key narrowed to some domains or addresses also only SEES the keys whose send scope sits inside its own; any other is a 404. Over OAuth only the workspace owner reaches these calls, and a member's token is refused with owner_only. A key changing itself may only narrow itself.

Requires the keys:manage scope.

معلمات المسار

idstringمطلوب

The key id, 24 hex characters.

متن الطلب

namestring

A new name, 1 to 60 characters.

من 1 إلى 60 من الأحرف
scopesstring[]

The whole new list of scopes, at least one.

عنصر واحد على الأقلأحد"emails:send""emails:read""drafts:read""drafts:write""threads:read""threads:write""files:read""files:write""labels:read""labels:write""contacts:read""contacts:write""audiences:read""audiences:write""calendar:read""calendar:write""templates:read""templates:write""domains:read""domains:write""webhooks:read""webhooks:write""rules:read""rules:write""connections:read""members:read""members:write""roles:read""roles:write""settings:read""settings:write""keys:write""keys:read""keys:manage""forms:read""forms:write""billing:read""billing:write""account:read""account:write"
addressAllowliststring[]

The whole new list of single addresses.

حتى 50 من العناصر
domainAllowliststring[]

The whole new list of whole domains.

حتى 25 من العناصر
enabledboolean

False switches the key off, true switches it back on. Reversible, unlike revoking.

يُرجع

The key as it now stands.

الأخطاء

409

revoked: a revoked key cannot be changed.

الأخطاء التي يمكن أن تُرجعها أي عملية400401404422500دليل الأخطاء

متاح أيضًا في

SDK
keys.update()
CLI
openemail keys update
MCP
setApiKeyEnabledsetApiKeySendScope

DELETE/keys/{id}

Delete an API key

الصلاحياتkeys:manageيحذف

Removes a revoked key from the list. Its request log and its activity stay, under Deleted key. A key that has not been revoked is refused, so nothing still calling with it can lose its credential without somebody deciding to first.

Requires the keys:manage scope.

معلمات المسار

idstringمطلوب

The key id, 24 hex characters.

يُرجع

200

{ object: "api_key", id, deleted: true }.

الأخطاء

409

not_revoked: revoke the key first.

الأخطاء التي يمكن أن تُرجعها أي عملية400401403404422500دليل الأخطاء

متاح أيضًا في

SDK
keys.delete()
CLI
openemail keys delete

POST/keys/{id}/rotate

Rotate an API key

الصلاحياتkeys:manageيحذف

Gives a key a new secret and returns it in token, once. The id, name, scopes, role, send scope, expiry and request history all carry on, and the old secret stops working the instant this returns, with no overlap window. Rotating the calling key itself follows POST /keys/self/rotate and is allowed with keys:write as well as keys:manage. A revoked or expired key cannot be rotated.

A key never makes or reaches a key wider than itself. What it creates, changes, rotates, switches, revokes or deletes has to sit inside it on every axis: scopes the caller holds (after its own role has narrowed them), the same role when the caller has one, an expiry no later than the caller's when the caller expires, the caller's mode, and a send scope inside the caller's own, where holding one address never covers its whole domain. A key narrowed to some domains or addresses also only SEES the keys whose send scope sits inside its own; any other is a 404. Over OAuth only the workspace owner reaches these calls, and a member's token is refused with owner_only. Rotation hands the caller a working secret for the key, which is why a key that is wider than the caller in any way is refused.

Requires the keys:manage scope.

معلمات المسار

idstringمطلوب

The key id, 24 hex characters.

يُرجع

200object

The key, with its new secret.

objectstring
أحد"api_key"
idstring

24 hex characters, the part of the token after oe_live_.

namestring
modestring
أحد"live""test"
maskedKeystring

Enough of the token to tell two keys apart, such as oe_live_4c1b…kX7a.

keyLast4string
statusstring
أحد"revoked""expired""inactive""active"
scopesstring[]
أحد"emails:send""emails:read""drafts:read""drafts:write""threads:read""threads:write""files:read""files:write""labels:read""labels:write""contacts:read""contacts:write""audiences:read""audiences:write""calendar:read""calendar:write""templates:read""templates:write""domains:read""domains:write""webhooks:read""webhooks:write""rules:read""rules:write""connections:read""members:read""members:write""roles:read""roles:write""settings:read""settings:write""keys:write""keys:read""keys:manage""forms:read""forms:write""billing:read""billing:write""account:read""account:write"
roleIdstring

The role that caps the key, if any.

يمكن أن يكون null
roleNamestring
يمكن أن يكون null
addressAllowliststring[]
يمكن أن يكون null
domainAllowliststring[]
يمكن أن يكون null
expiresAtstring
يمكن أن يكون nullالتنسيقdate-time
lastUsedAtstring
يمكن أن يكون nullالتنسيقdate-time
totalUsesinteger

Calls the key has made, leaving out the ones refused before it authenticated.

rotatedAtstring
التنسيقdate-time
rotationCountinteger
deactivatedAtstring
يمكن أن يكون nullالتنسيقdate-time
revokedAtstring
يمكن أن يكون nullالتنسيقdate-time
revokedReasonstring
يمكن أن يكون null
createdAtstring
التنسيقdate-time
createdByAuditActor
updatedAtstring
التنسيقdate-time
updatedByAuditActor
lastChangeAtstring
يمكن أن يكون nullالتنسيقdate-time
lastChangeTypestring
يمكن أن يكون null
tokenstring

The new secret, shown this once.

الأخطاء

409

revoked or expired: create a new key instead.

الأخطاء التي يمكن أن تُرجعها أي عملية400401404422500دليل الأخطاء

متاح أيضًا في

SDK
keys.rotate()
CLI
openemail keys rotate
MCP
rotateApiKey

POST/keys/{id}/revoke

Revoke an API key

الصلاحياتkeys:manageيحذف

Revokes a key for good: every later call with it is refused with revoked_api_key, and it can never be switched back on, rotated or changed. The body is optional and may carry a reason, kept on the key. Revoking a key that is already revoked changes nothing and answers the same. A key may revoke itself, which is how an integration that suspects its secret has leaked retires it at once.

A key never makes or reaches a key wider than itself. What it creates, changes, rotates, switches, revokes or deletes has to sit inside it on every axis: scopes the caller holds (after its own role has narrowed them), the same role when the caller has one, an expiry no later than the caller's when the caller expires, the caller's mode, and a send scope inside the caller's own, where holding one address never covers its whole domain. A key narrowed to some domains or addresses also only SEES the keys whose send scope sits inside its own; any other is a 404. Over OAuth only the workspace owner reaches these calls, and a member's token is refused with owner_only.

Requires the keys:manage scope.

معلمات المسار

idstringمطلوب

The key id, 24 hex characters.

متن الطلب

reasonstring

Why, at most 200 characters.

حتى 200 من الأحرف

يُرجع

The key, now revoked.

الأخطاء

الأخطاء التي يمكن أن تُرجعها أي عملية400401404422500دليل الأخطاء

متاح أيضًا في

SDK
keys.revoke()
CLI
openemail keys revoke
MCP
revokeApiKey

GET/keys/{id}/requests

List one key's requests

الصلاحياتkeys:readيقرأ

The request log of one key, newest first. A deleted key's log is still readable by a key that is not narrowed.

Requires the keys:read scope.

معلمات المسار

idstringمطلوب

The key id, 24 hex characters.

معلمات الاستعلام

failedOnlyboolean

Only calls answered with a status of 400 or more.

الافتراضيfalse
sincestring

Only rows at or after this instant, ISO 8601. One that does not parse is a 400 invalid_parameter.

التنسيقdate-time
untilstring

Only rows before this instant. It has to be later than since.

التنسيقdate-time
limitinteger

Rows per page, 1 to 100.

على الأقل 1على الأكثر 100الافتراضي25
cursorstring

The previous page's nextCursor, passed back as it came. It is opaque: it holds where the last row sat in this list's order, so a row deleted or edited between pages never breaks the walk, and the next page starts at the first row that sorts after it. A value this list did not hand out is a 400 invalid_cursor.

يُرجع

A page of calls, newest first.

الأخطاء

الأخطاء التي يمكن أن تُرجعها أي عملية400401403404422500دليل الأخطاء

متاح أيضًا في

SDK
keys.listRequests()keys.listAllRequests()keys.iterateRequests()
CLI
openemail keys list-requests
MCP
listApiKeyRequests

GET/keys/{id}/activity

List one key's activity

الصلاحياتkeys:readيقرأ

What happened to one key, newest first. A deleted key's history is still readable by a key that is not narrowed.

Requires the keys:read scope.

معلمات المسار

idstringمطلوب

The key id, 24 hex characters.

معلمات الاستعلام

sincestring

Only rows at or after this instant, ISO 8601. One that does not parse is a 400 invalid_parameter.

التنسيقdate-time
untilstring

Only rows before this instant. It has to be later than since.

التنسيقdate-time
limitinteger

Rows per page, 1 to 100.

على الأقل 1على الأكثر 100الافتراضي25
cursorstring

The previous page's nextCursor, passed back as it came. It is opaque: it holds where the last row sat in this list's order, so a row deleted or edited between pages never breaks the walk, and the next page starts at the first row that sorts after it. A value this list did not hand out is a 400 invalid_cursor.

يُرجع

A page of changes, newest first.

الأخطاء

الأخطاء التي يمكن أن تُرجعها أي عملية400401403404422500دليل الأخطاء

متاح أيضًا في

SDK
keys.listActivity()keys.listAllActivity()keys.iterateActivity()
CLI
openemail keys list-activity
MCP
listApiKeyActivity

GET/keys/stats

Read API key stats

الصلاحياتkeys:reademails:readيقرأ

What the keys of the workspace did inside a window, the Analytics tab of the API keys page: the mail they sent and what became of it, the calls refused for a bad or revoked secret, the requests they made and how many failed, the 8 routes they called most with the median time each took, and the status codes they got back. Every key you can see, or the ones keyIds names. A key limited to some addresses sees only the keys whose send scope sits inside its own, and over OAuth only the owner of the workspace reaches it.

Requires the keys:read and emails:read scopes.

معلمات الاستعلام

keyIdsstring

Comma-separated key ids, at most 50. Left out, every key you can see.

sincestring

The start of the window, an ISO 8601 instant. Left out, 30 days before until.

التنسيقdate-time
untilstring

The end of the window, an ISO 8601 instant, not included. Left out, now.

التنسيقdate-time
grainstring

How wide one bucket of the series is. The bucket keys change shape with it: YYYY-MM-DD for a day, YYYY-MM-DDTHH for an hour, YYYY-MM-DDTHH:MM for a minute.

أحد"minute""hour""day"الافتراضي"day"
offsetMinutesinteger

Minutes to add to UTC before cutting the buckets, so a day starts at midnight where the reader is. 120 for UTC+2.

على الأقل -840على الأكثر 840الافتراضي0

يُرجع

The figures for the window.

الأخطاء

الأخطاء التي يمكن أن تُرجعها أي عملية400401403404422500دليل الأخطاء

متاح أيضًا في

SDK
keys.stats()
CLI
openemail keys stats
MCP
getApiKeyStats

الكائنات

ApiKeyobject

An API key without its secret. The secret is returned once, by the call that made or rotated it, and never again.

objectstring
أحد"api_key"
idstring

24 hex characters, the part of the token after oe_live_.

namestring
modestring
أحد"live""test"
maskedKeystring

Enough of the token to tell two keys apart, such as oe_live_4c1b…kX7a.

keyLast4string
statusstring
أحد"revoked""expired""inactive""active"
scopesstring[]
أحد"emails:send""emails:read""drafts:read""drafts:write""threads:read""threads:write""files:read""files:write""labels:read""labels:write""contacts:read""contacts:write""audiences:read""audiences:write""calendar:read""calendar:write""templates:read""templates:write""domains:read""domains:write""webhooks:read""webhooks:write""rules:read""rules:write""connections:read""members:read""members:write""roles:read""roles:write""settings:read""settings:write""keys:write""keys:read""keys:manage""forms:read""forms:write""billing:read""billing:write""account:read""account:write"
roleIdstring

The role that caps the key, if any.

يمكن أن يكون null
roleNamestring
يمكن أن يكون null
addressAllowliststring[]
يمكن أن يكون null
domainAllowliststring[]
يمكن أن يكون null
expiresAtstring
يمكن أن يكون nullالتنسيقdate-time
lastUsedAtstring
يمكن أن يكون nullالتنسيقdate-time
totalUsesinteger

Calls the key has made, leaving out the ones refused before it authenticated.

rotatedAtstring
يمكن أن يكون nullالتنسيقdate-time
rotationCountinteger
deactivatedAtstring
يمكن أن يكون nullالتنسيقdate-time
revokedAtstring
يمكن أن يكون nullالتنسيقdate-time
revokedReasonstring
يمكن أن يكون null
createdAtstring
التنسيقdate-time
createdByAuditActor
updatedAtstring
التنسيقdate-time
updatedByAuditActor
lastChangeAtstring
يمكن أن يكون nullالتنسيقdate-time
lastChangeTypestring
يمكن أن يكون null

ApiKeyActivityEntryobject

objectstring
أحد"api_key_event"
idstring
keyIdstring
keyNamestring

Deleted key once the key itself is gone.

typestring
أحد"created""updated""rotated""revoked""deactivated""reactivated""auth_failed""deleted"
createdAtstring
التنسيقdate-time
detailobject

What changed and where it was changed from (source: console, api, mcp or documentation). A refused authentication carries reason.

ApiKeyActivityListobject

objectstring
أحد"list"
hasMoreboolean

True when another page follows. Pass nextCursor back as cursor to read it.

nextCursorstring

An opaque cursor for the next page, or null on the last page. Pass it back unchanged.

يمكن أن يكون null

ApiKeyListobject

objectstring
أحد"list"
hasMoreboolean

True when another page follows. Pass nextCursor back as cursor to read it.

nextCursorstring

An opaque cursor for the next page, or null on the last page. Pass it back unchanged.

يمكن أن يكون null

ApiKeyRequestobject

One authenticated call a key made. Never a body or a query string.

objectstring
أحد"api_key_request"
idstring
keyIdstring
keyNamestring

Deleted key once the key itself is gone.

requestIdstring

The X-Request-Id the call was answered with.

يمكن أن يكون null
methodstring
pathstring
statusinteger
errorCodestring
يمكن أن يكون null
durationMsinteger
ipstring
يمكن أن يكون null
userAgentstring
يمكن أن يكون null
createdAtstring
التنسيقdate-time

ApiKeyRequestListobject

objectstring
أحد"list"
hasMoreboolean

True when another page follows. Pass nextCursor back as cursor to read it.

nextCursorstring

An opaque cursor for the next page, or null on the last page. Pass it back unchanged.

يمكن أن يكون null

ApiKeyStatsobject

objectstringمطلوب
أحد"api_key_stats"
sincestringمطلوب
التنسيقdate-time
untilstringمطلوب
التنسيقdate-time
grainstringمطلوب
أحد"minute""hour""day"
keyIdsstring[]مطلوب

The keys asked for. Empty means every key you can see.

sendsobjectمطلوب

The mail the keys sent, with what became of it.

daysobject[]
daystring

The bucket, shaped by grain.

sentinteger
deliveredinteger
failedinteger
bouncedinteger
complainedinteger
totalsobject
sendsinteger
testSendsinteger
recipientsinteger
deliveredinteger
failedinteger
bouncedinteger
complainedinteger
uncertaininteger
pendinginteger
statusesobject[]

Sends by status.

labelstring
countinteger
sourcesobject[]

Sends by where they came from.

labelstring
countinteger
sendersobject[]

Sends by the address they went out as.

labelstring
countinteger
suppressedobject[]

Recipients skipped because they were suppressed, by reason.

labelstring
countinteger
rejectedobject[]مطلوب

Calls refused because the secret was wrong, revoked or expired, per bucket.

bucketstring
countinteger
requestsobject[]مطلوب

Requests made and how many of them failed with a 4xx or 5xx, per bucket.

bucketstring
countinteger
failedinteger
routesobject[]مطلوب

The routes called most, with how many failed and the median time in milliseconds.

labelstring
countinteger
failedinteger
medianMsinteger
codesobject[]مطلوب

Requests by the HTTP status they got back.

labelstring
countinteger

AuditActorobject

Who made the change: a person, or a key acting over the API. Null when OpenEmail made it on its own, such as switching a webhook off after 100 failed events in a row, and when the person or key has since been deleted.

يمكن أن يكون null
kindstring
أحد"user""apiKey"
idstring

The account id of the person, or the id of the key.

namestring

The name of the person, or API key <name> for a key.

usernamestring
يمكن أن يكون null
labelstring

What the app shows: @username for a person who has a username, otherwise name.