---
title: "Retrieve the web app address"
description: "The web app address of the workspace, whether people can sign in there, and the CNAME record it needs. With none set, `status` is `none` and `domains` lists the domains one can go under."
url: "https://openemail.uk/docs/api/app-host/get"
area: "API"
category: "Mailbox"
---

# Retrieve the web app address

The web app address of the workspace, whether people can sign in there, and the CNAME record it needs. With none set, `status` is `none` and `domains` lists the domains one can go under.

`GET /app-host`

## GET /app-host

The web app address of the workspace, whether people can sign in there, and the CNAME record it needs. With none set, `status` is `none` and `domains` lists the domains one can go under.

## What the web app address is

**shell**

```
export OE=https://api.openemail.uk
export AUTH="Authorization: Bearer $OPENEMAIL_API_KEY"
```

A workspace on a paid plan can open the web app on a subdomain of one of its verified domains, such as `mailbox.acme.com`, as well as on openemail.uk. It is the address the Branded app tab of the workspace’s Appearance settings sets, and a workspace has at most one.

Only the members of the workspace, the people who sign in with one of its addresses and anyone with a pending invitation can sign in there, and only they get password reset and verification emails sent from it. It looks like openemail.uk until the workspace sets a logo on its Appearance page, then shows the workspace’s logo, mark and name in place of ours. From then on the emails OpenEmail sends them carry the brand, link back to the address, and come from `noreply@` its domain once that domain’s signing records are verified.

It takes one CNAME record, which `record` spells out. The address is `pending` until the record answers and its certificate is issued, and `active` after that. On the free plan it is kept but paused: `paused` is true and nobody can sign in there until the workspace is on a paid plan again.

## Example

Needs `domains:read`.

**curl**

```
curl "$OE/app-host" -H "$AUTH"
```

**Response**

```
{
  "object": "app_host",
  "id": "ahost_3f9c2a71d0b84e56a1c7f2e9",
  "host": "mailbox.acme.com",
  "domainId": "b3e1f0a4-6c2d-4e8a-9f17-2d5c8a0b4e6f",
  "domain": "acme.com",
  "status": "active",
  "active": true,
  "paused": false,
  "target": "cname.openemail.uk",
  "record": {
    "type": "CNAME",
    "name": "mailbox.acme.com",
    "value": "cname.openemail.uk"
  },
  "error": null,
  "checkedAt": "2026-10-01T09:12:30.000Z",
  "verifiedAt": "2026-10-01T09:04:11.000Z",
  "available": true,
  "paidPlan": true,
  "domains": ["acme.com"],
  "suggested": "mailbox.acme.com"
}
```

> Reading it checks the address again when its last check is more than 15 seconds old, so polling this route is how to wait for `active` to turn true.

> `active` is true only when `status` is `active` and the workspace is on a paid plan. `paused` is true when an address is set and the workspace is on the free plan.
