Skip to the documentation
API

Your account

Every operation in this group: what it accepts, what it returns and the errors it can answer with.

Operations

The account of the person behind the key or the app: which email notifications they get, their profile photo and username, the apps they connected and the invitations waiting for them. These calls act on a person, never on a workspace: an API key acts for the workspace owner, and an app for the person who connected it. Reading needs account:read and every change needs account:write. Neither is ever limited by a role, so an app a member connected reaches the member's own account too.

GET/account/notifications

Read your notification settings

Scopesaccount:readReads

Which kinds of email OpenEmail sends the person, as Account, Notifications shows them, and the workspaces whose notifications are muted on their phone. Account and billing email cannot be turned off.

Requires the account:read scope.

Returns

The notification settings.

Errors

The errors every operation can return400401403404422500Error catalog

Also available in

SDK
account.getNotifications()
CLI
openemail account get-notifications
MCP
getNotificationSettings

PUT/account/notifications/email/{category}

Turn a kind of email on or off

Scopesaccount:writeChanges data

enabled: false stops OpenEmail sending the person that kind of email, and true starts it again. account and billing cannot be turned off, and asking to is a 422 invalid_parameter on category.

Requires the account:write scope.

Path parameters

categorystringRequired

The kind of email.

One of"account""billing""activity""product"

Request body

enabledbooleanRequired

True to receive that email, false to stop it.

Returns

The notification settings as they are now.

Errors

The errors every operation can return400401403404422500Error catalog

Also available in

SDK
account.setEmailNotification()
CLI
openemail account set-email-notification
MCP
setEmailNotification

PUT/account/notifications/push/{workspaceId}

Mute a workspace on your phone

Scopesaccount:writeChanges data

muted: true stops the phone app notifying the person about the mail of one workspace, and false lets it notify them again. It applies to every phone they signed in on. A workspace they cannot open is a 404.

Requires the account:write scope.

Path parameters

workspaceIdstringRequired

A workspace from GET /workspaces.

Request body

mutedbooleanRequired

True to mute it, false to let it notify again.

Returns

The notification settings as they are now.

Errors

The errors every operation can return400401403404422500Error catalog

Also available in

SDK
account.setPushMuted()
CLI
openemail account set-push-muted
MCP
setWorkspacePushMuted

PUT/account/photo

Set your profile photo

Scopesaccount:writeChanges data

Uploads the person's profile photo, replacing any there was, as Account, Profile does. Send the image itself as the body, not JSON, with its type in Content-Type: image/png, image/jpeg, image/webp, image/gif. Up to 5 MB goes in. It is fitted into a 512 pixel square and stored as WebP, and an animated image keeps its first frame.

Requires the account:write scope.

Request body

Content typeimage/png, image/jpeg, image/webp, image/gif

binary

Returns

The photo, with its new url.

Errors

422

invalid_image when the body is not an image of an accepted type, is too large or cannot be read.

502

image_not_stored: the image was read but could not be stored. Try again.

503

image_busy: the image service is saturated. Try again shortly.

The errors every operation can return400401403404500Error catalog

Also available in

SDK
account.setPhoto()
CLI
openemail account set-photo
MCP
setProfilePhoto

GET/account/username

Read your username

Scopesaccount:readReads

The username of the person, whether they chose it or it was made for them, and the free address it gives them. A username is made from their name the first time it is read.

Requires the account:read scope.

Returns

The username.

Errors

The errors every operation can return400401403404422500Error catalog

Also available in

SDK
account.getUsername()
CLI
openemail account get-username
MCP
getUsername

PUT/account/username

Choose your username

Scopesaccount:writeChanges data

Sets the username for good, and with it the free address. Once chosen it never changes: a second choice is a 409 username_locked. A username another account has is a 409 username_taken, and one that is too short, too long, reserved or not lowercase letters, numbers and single dots is a 422 invalid_parameter on username. Check one first with GET /account/username/availability.

Requires the account:write scope.

Request body

usernamestringRequired
Up to 60 characters

Returns

The username, now chosen.

Errors

409

username_locked: the username was chosen before and never changes. username_taken: another account has it.

The errors every operation can return400401403404422500Error catalog

Also available in

SDK
account.setUsername()
CLI
openemail account set-username
MCP
chooseUsername

GET/account/username/availability

Check a username

Scopesaccount:readReads

Whether the person could choose a username, without choosing it. The answer says why when they could not.

Requires the account:read scope.

Query parameters

usernamestringRequired

The username to check. It is lowercased and its spaces become dots before it is checked, as the app does.

1 to 60 characters

Returns

The verdict.

Errors

The errors every operation can return400401403404422500Error catalog

Also available in

SDK
account.checkUsername()
CLI
openemail account check-username
MCP
checkUsername

GET/account/connected-apps

List your connected apps

Scopesaccount:readReads

Every app the person connected with OAuth, as Account, Connected apps lists them: what each may reach, until when, how many tokens it holds and whether changes are allowed without a code for it right now. current marks the app making the call. Changing what an app may reach is done in the app, never through an app.

Requires the account:read scope.

Returns

The connected apps.

Errors

The errors every operation can return400401403404422500Error catalog

Also available in

SDK
account.listConnectedApps()
CLI
openemail account list-connected-apps
MCP
listConnectedApps

DELETE/account/connected-apps/{clientId}

Remove a connected app

Scopesaccount:writeDeletes

Deletes every token the app holds and the access the person gave it, so its next call is refused and it has to ask again. Removing the app making the call disconnects it. An app the person never connected is a 404.

Requires the account:write scope.

Path parameters

clientIdstringRequired

The app's clientId from GET /account/connected-apps.

Returns

Errors

The errors every operation can return400401403404422500Error catalog

Also available in

SDK
account.revokeConnectedApp()
CLI
openemail account revoke-connected-app
MCP
revokeConnectedApp

POST/account/invitations/{invitationId}/accept

Accept an invitation

Scopesaccount:writeChanges data

Joins the workspace with the role and the addresses the invitation gives, as accepting it in the app or from its link does. activate: true also makes it the workspace the app opens. A workspace that asks for two-factor sign-in is a 403 two_factor_required until the person turns it on, and an invitation that expired, was withdrawn or went to another address is a 422.

Requires the account:write scope.

Path parameters

invitationIdstringRequired

The invitation id from GET /account/invitations.

Request body

activateboolean

Returns

Errors

403

two_factor_required: the workspace asks everyone in it to sign in with two-factor authentication. mailbox_login: a password sign-in for one address cannot join a workspace.

The errors every operation can return400401404422500Error catalog

Also available in

SDK
account.acceptInvitation()
CLI
openemail account accept-invitation
MCP
acceptInvitation

POST/account/invitations/{invitationId}/decline

Decline an invitation

Scopesaccount:writeDeletes

Turns the invitation down, so its link stops working, and tells whoever sent it. It cannot be taken back: they have to invite the person again. An invitation they already accepted is a 409 invitation_accepted.

Requires the account:write scope.

Path parameters

invitationIdstringRequired

The invitation id from GET /account/invitations.

Returns

Declined.

Errors

The errors every operation can return400401403404422500Error catalog

Also available in

SDK
account.declineInvitation()
CLI
openemail account decline-invitation
MCP
declineInvitation

Objects

AcceptedInvitationobject

objectstringRequired
One of"invitation"
idstringRequired
acceptedbooleanRequired
One oftrue
workspaceIdstringRequired
workspaceNamestringRequired
addressesGrantedintegerRequired
At least 0
domainsGrantedintegerRequired
At least 0
activatedbooleanRequired

Whether the app now opens the workspace, after activate: true.

AccountPhotoobject

objectstringRequired
One of"account_photo"
urlstringRequired
Can be null

ConnectedAppobject

objectstringRequired
One of"connected_app"
clientIdstringRequired
namestringRequired
Can be null
kindstringRequired

cli for a sign-in of the command line tool, app for every other app.

One of"app""cli"
cliDevicestring
Can be null
currentbooleanRequired

Whether it is the app making this call.

registeredByAccountboolean
redirectUrisstring[]
connectedAtstring
Can be nullFormatdate-time
accessUntilstring

When its last token runs out.

Can be nullFormatdate-time
tokenCountintegerRequired
At least 0
statusstringRequired
One of"active""expired""needs-approval""access-lost"
usablePermissionsinteger

How many of the permissions it was given the person still holds.

Can be null
elevatedUntilstring

Until when it may make changes that ask for a verification code without one.

Can be nullFormatdate-time
grantobject

What the person gave it, or null for an app that has to ask again.

Can be null
workspaceIdstringRequired

The one workspace the app acts for.

workspaceNamestringRequired
Can be null
permissionsstring[]Required
addressAllowliststring[]Required
Can be null
domainAllowliststring[]Required
Can be null
expiresAtstringRequired

When the access ends, or null when it lasts until it is removed.

Can be nullFormatdate-time
updatedAtstringRequired
Formatdate-time

DeclinedInvitationobject

objectstringRequired
One of"invitation"
idstringRequired
declinedbooleanRequired
One oftrue

EmailNotificationSettingobject

categorystringRequired
One of"account""billing""activity""product"
labelstringRequired
descriptionstringRequired
requiredbooleanRequired

Whether it can never be turned off.

enabledbooleanRequired

NotificationSettingsobject

objectstringRequired
One of"notification_settings"
emailEmailNotificationSetting[]Required

Every kind of email OpenEmail sends.

mutedWorkspacesstring[]Required

The workspaces whose notifications are muted on the phone.

ReceivedInvitationobject

objectstringRequired
One of"invitation"
idstringRequired
workspaceIdstringRequired
workspaceNamestringRequired
roleNamestringRequired
inviterNamestring
Can be null
addressesintegerRequired

How many addresses and whole domains it gives.

At least 0
expiresAtstringRequired
Formatdate-time
createdAtstringRequired
Formatdate-time

RevokedConnectedAppobject

objectstringRequired
One of"connected_app"
clientIdstringRequired
revokedbooleanRequired
One oftrue
tokensRevokedintegerRequired
At least 0

Usernameobject

objectstringRequired
One of"username"
usernamestringRequired
Can be null
chosenbooleanRequired

Whether the person chose it. A chosen username never changes.

addressstringRequired

The free address the username gives, when this deployment offers one.

Can be null

UsernameAvailabilityobject

objectstringRequired
One of"username_availability"
usernamestringRequired

The username as it was checked.

statusstringRequired

current when it is the username the person already has.

One of"available""current""taken""reserved""invalid""too_short""too_long"
availablebooleanRequired
messagestringRequired