---
title: "Sign in as one address"
description: "A password of its own lets somebody sign in to OpenEmail as one address, and read and send only its mail."
url: "https://openemail.uk/docs/api/domains/addresses/login"
area: "API"
category: "Mailbox"
---

# Sign in as one address

A password of its own lets somebody sign in to OpenEmail as one address, and read and send only its mail.

`GET /domains/{id}/addresses/{addressId}/login`

**Also documents:** `PUT /domains/{id}/addresses/{addressId}/login`, `DELETE /domains/{id}/addresses/{addressId}/login`

## GET /domains/{id}/addresses/{addressId}/login

A password of its own lets somebody sign in to OpenEmail as one address, and read and send only its mail.

## Read the sign-in

Needs `members:write`, like setting a password. `login` is null when the address has no password.

**curl**

```
curl "$OE/domains/b3e1f0a4-6c2d-4e8a-9f17-2d5c8a0b4e6f/addresses/5f0c2b7e-8d41-4a6f-b913-7e2a0c4d9b18/login" -H "$AUTH"
```

**Response**

```
{
  "object": "address_login",
  "addressId": "5f0c2b7e-8d41-4a6f-b913-7e2a0c4d9b18",
  "address": "billing@acme.com",
  "login": {
    "userId": "W2xR8tLq5nYc3vKp9mBd7fHs1aJe4gZu",
    "name": "Invoices",
    "createdAt": "2026-09-20T09:30:00.000Z",
    "createdBy": "Ana Lima",
    "passwordSetAt": "2026-09-28T14:05:00.000Z",
    "passwordSetBy": "Ana Lima",
    "lastSignedInAt": "2026-10-01T07:58:12.000Z"
  }
}
```

> A key limited to particular addresses or domains is refused with 422 `capability_unsupported`, and an app acting for a member reaches only the sign-in of an address that member reaches.

## Set the password

Needs `members:write`. `PUT /domains/{id}/addresses/{addressId}/login` with `{ password }` gives the address a password, or replaces the one it has. `created` says whether the sign-in is new.

**curl**

```
curl -X PUT "$OE/domains/b3e1f0a4-6c2d-4e8a-9f17-2d5c8a0b4e6f/addresses/5f0c2b7e-8d41-4a6f-b913-7e2a0c4d9b18/login" -H "$AUTH" \
  -H "Content-Type: application/json" \
  -d '{ "password": "'"$INBOX_PASSWORD"'" }'
```

**Response**

```
{
  "object": "address_login",
  "addressId": "5f0c2b7e-8d41-4a6f-b913-7e2a0c4d9b18",
  "address": "billing@acme.com",
  "login": {
    "userId": "W2xR8tLq5nYc3vKp9mBd7fHs1aJe4gZu",
    "name": "Invoices",
    "createdAt": "2026-09-20T09:30:00.000Z",
    "createdBy": "Ana Lima",
    "passwordSetAt": "2026-09-28T14:05:00.000Z",
    "passwordSetBy": "Ana Lima",
    "lastSignedInAt": "2026-10-01T07:58:12.000Z"
  },
  "created": false
}
```

> The password needs at least 8 characters with a lowercase letter, an uppercase letter, a number and a special character, or the call is 422 `invalid_parameter` on `password`. OpenEmail sends it to nobody, so hand it over yourself.

> Replacing a password signs out everybody who signed in with the old one and removes the forwarding destinations they added.

> An address an OpenEmail account already signs in as is refused with 409 `account_exists`, and an address that is switched off with 409 `address_unavailable`. The first password on a workspace whose plan has no team access is refused with 403 `plan_required`.

> A key or an app has to hold every scope a sign-in for one address may use, or it is refused with 403 `insufficient_authority`.

> An OAuth access token needs a verification code for this call. Until the app has verified one in the last 60 minutes, the call answers `403` `step_up_required` and changes nothing. An API key is never asked. The Authentication page shows how to ask for a code and verify it.

## Remove the sign-in

Needs `members:write`. `DELETE /domains/{id}/addresses/{addressId}/login` takes the password away and signs out everybody who used it. The address and its mail stay.

**curl**

```
curl -X DELETE "$OE/domains/b3e1f0a4-6c2d-4e8a-9f17-2d5c8a0b4e6f/addresses/5f0c2b7e-8d41-4a6f-b913-7e2a0c4d9b18/login" -H "$AUTH"
```

**Response**

```
{
  "object": "address_login",
  "addressId": "5f0c2b7e-8d41-4a6f-b913-7e2a0c4d9b18",
  "address": "billing@acme.com",
  "deleted": true
}
```

> An address with no password is a `404`.

## Reference

- [`GET /domains/{id}/addresses/{addressId}/login`](https://openemail.uk/docs/api/reference/domains#get-domains-id-addresses-addressid-login): full reference
- [`PUT /domains/{id}/addresses/{addressId}/login`](https://openemail.uk/docs/api/reference/domains#put-domains-id-addresses-addressid-login): full reference
- [`DELETE /domains/{id}/addresses/{addressId}/login`](https://openemail.uk/docs/api/reference/domains#delete-domains-id-addresses-addressid-login): full reference
