Skip to the documentation
API

Sign in as one address

A password of its own lets somebody sign in to OpenEmail as one address, and read and send only its mail.

GET/domains/{id}/addresses/{addressId}/login

Runs any of 3 calls on your workspace.

GET /domains/{id}/addresses/{addressId}/login

A password of its own lets somebody sign in to OpenEmail as one address, and read and send only its mail.

Read the sign-in

Needs members:write, like setting a password. login is null when the address has no password.

curl
curl "$OE/domains/b3e1f0a4-6c2d-4e8a-9f17-2d5c8a0b4e6f/addresses/5f0c2b7e-8d41-4a6f-b913-7e2a0c4d9b18/login" -H "$AUTH"
Response
{  "object": "address_login",  "addressId": "5f0c2b7e-8d41-4a6f-b913-7e2a0c4d9b18",  "address": "[email protected]",  "login": {    "userId": "W2xR8tLq5nYc3vKp9mBd7fHs1aJe4gZu",    "name": "Invoices",    "createdAt": "2026-09-20T09:30:00.000Z",    "createdBy": "Ana Lima",    "passwordSetAt": "2026-09-28T14:05:00.000Z",    "passwordSetBy": "Ana Lima",    "lastSignedInAt": "2026-10-01T07:58:12.000Z"  }}

A key limited to particular addresses or domains is refused with 422 capability_unsupported, and an app acting for a member reaches only the sign-in of an address that member reaches.

Set the password

Needs members:write. PUT /domains/{id}/addresses/{addressId}/login with { password } gives the address a password, or replaces the one it has. created says whether the sign-in is new.

curl
curl -X PUT "$OE/domains/b3e1f0a4-6c2d-4e8a-9f17-2d5c8a0b4e6f/addresses/5f0c2b7e-8d41-4a6f-b913-7e2a0c4d9b18/login" -H "$AUTH" \  -H "Content-Type: application/json" \  -d '{ "password": "'"$INBOX_PASSWORD"'" }'
Response
{  "object": "address_login",  "addressId": "5f0c2b7e-8d41-4a6f-b913-7e2a0c4d9b18",  "address": "[email protected]",  "login": {    "userId": "W2xR8tLq5nYc3vKp9mBd7fHs1aJe4gZu",    "name": "Invoices",    "createdAt": "2026-09-20T09:30:00.000Z",    "createdBy": "Ana Lima",    "passwordSetAt": "2026-09-28T14:05:00.000Z",    "passwordSetBy": "Ana Lima",    "lastSignedInAt": "2026-10-01T07:58:12.000Z"  },  "created": false}

The password needs at least 8 characters with a lowercase letter, an uppercase letter, a number and a special character, or the call is 422 invalid_parameter on password. OpenEmail sends it to nobody, so hand it over yourself.

Replacing a password signs out everybody who signed in with the old one and removes the forwarding destinations they added.

An address an OpenEmail account already signs in as is refused with 409 account_exists, and an address that is switched off with 409 address_unavailable. The first password on a workspace whose plan has no team access is refused with 403 plan_required.

A key or an app has to hold every scope a sign-in for one address may use, or it is refused with 403 insufficient_authority.

An OAuth access token needs a verification code for this call. Until the app has verified one in the last 60 minutes, the call answers 403 step_up_required and changes nothing. An API key is never asked. The Authentication page shows how to ask for a code and verify it.

Remove the sign-in

Needs members:write. DELETE /domains/{id}/addresses/{addressId}/login takes the password away and signs out everybody who used it. The address and its mail stay.

curl
curl -X DELETE "$OE/domains/b3e1f0a4-6c2d-4e8a-9f17-2d5c8a0b4e6f/addresses/5f0c2b7e-8d41-4a6f-b913-7e2a0c4d9b18/login" -H "$AUTH"
Response
{  "object": "address_login",  "addressId": "5f0c2b7e-8d41-4a6f-b913-7e2a0c4d9b18",  "address": "[email protected]",  "deleted": true}

An address with no password is a 404.

Reference