---
title: "client.temp_mail"
description: "Every method in this namespace: its signature, its parameters, what it returns and an example."
url: "https://openemail.uk/docs/ruby/reference/temp-mail"
area: "Ruby"
category: "Reference"
---

# client.temp_mail

Every method in this namespace: its signature, its parameters, what it returns and an example.

## Methods

Short lived inboxes that need no account, authorised by the token they were created with.

### `temp_mail.list_domains`

List the domains a disposable inbox can be created on

```ruby
list_domains(inbox_token: nil) -> Array<Hash>
```

Returns the pool of domains `create` accepts, as a plain Array in the order the operator wrote them in `TEMP_MAIL_DOMAINS`. It takes no credential at all: no API key and no inbox token are sent, even when the client holding this namespace has one.

Nothing checks that a listed domain is verified, so the list is only as good as the operator made it. An empty Array is a normal answer meaning this install offers no disposable domains, and it is exactly the condition under which `create` fails with 503 `not_configured`.

Sends no credential.

**Parameters**

- `inbox_token` (`String`): Accepted for symmetry with the other methods and never sent, because this call is anonymous.

**Returns**

An Array of Hashes, each with `object` set to `temp_domain` and a lowercased `domain` to pass back to `create`.

**Example**

```ruby
temp_mail = OpenEmail.create_temp_mail

domains = temp_mail.list_domains

p domains.map { |entry| entry[:domain] }
```

**Notes**

- The pool is server configuration, so a domain appears when the operator adds it to `TEMP_MAIL_DOMAINS`, not when it is added to a workspace.
- Retried automatically on network failure and retryable statuses, like every GET.

Also available in: API [`GET /temp-mail/domains`](https://openemail.uk/docs/api/reference/temp-mail#get-temp-mail-domains); TypeScript [`tempMail.listDomains()`](https://openemail.uk/docs/sdk/reference/temp-mail#listDomains); Python [`temp_mail.list_domains()`](https://openemail.uk/docs/python/reference/temp-mail#listDomains); CLI [`openemail temp-mail list-domains`](https://openemail.uk/docs/cli/reference/temp-mail#temp-mail-list-domains).

### `temp_mail.create`

Create a disposable inbox and its access token

```ruby
create(body = nil, inbox_token: nil, **fields) -> Hash
```

Mints a disposable address and returns the inbox plus its `token`. It needs no credential, and only this call and `extend` return a token. The token is the lease itself, signed, and nothing about it is stored on the server, so a lost token cannot be recovered, and every other method except `list_domains` needs it. Store it before you show the address to anyone.

The body is optional and so is every field in it. With nothing, you get a 12 character generated local part on the first domain in the pool, leased for 60 minutes. A chosen `localPart` is lowercased and must be up to 64 letters, digits, dots, dashes or underscores, starting and ending with a letter or digit, or it is 422 `invalid_address`, and one longer than 64 characters is 422 `invalid_parameter`. Names such as `postmaster`, `abuse` and `support` are 422 `reserved_address`, and an install with no pooled domain answers 503 `not_configured`.

Nothing is rate limited and nothing reserves an address, so this never answers 429 or 409. A name you choose is issued to anyone who asks for it, and each of you reads the mail that reaches it from the start of your own lease. Leave `localPart:` out when the mail should reach you alone.

Sends no credential.

**Parameters**

- `domain` (`String`): A domain from `list_domains`. Omit it for the first one in the pool. Any other name is 422 `unknown_domain` rather than a silent substitute.
- `localPart` (`String`): The part before the @. Omit it for a generated one, which nobody else is likely to be issued.
- `ttlMinutes` (`Integer`): Lease length from now, a whole number from 1 to 1440. Defaults to 60. Out of range is 422 `invalid_parameter`, not clamped.
- `inbox_token` (`String`): Ignored and never sent. Creating an inbox is anonymous and hands you the token instead.

**Returns**

A Hash with the inbox fields `id`, `address`, `domain`, `createdAt`, `expiresAt`, `extensionsLeft`, `messageCount`, `messageLimit` and `lastMessageAt`, plus the one time `token` beginning `oe_inbox_`.

**Example**

```ruby
temp_mail = OpenEmail.create_temp_mail

inbox = temp_mail.create(ttlMinutes: 120)

puts inbox[:address], inbox[:expiresAt]
puts inbox[:token]
```

**Notes**

- Not retried automatically. A retry would mint a second inbox, and the first would be unreachable because its only token was in the lost response.
- Nothing holds an address back after its lease ends or its inbox is deleted, so it can be issued again at once, to anybody.
- A lease of 1440 minutes reaches the 24 hour ceiling at once, yet the inbox still comes back with `extensionsLeft: 23`, because that counts calls rather than time. None of them can add a minute.
- Unknown body keys are 422 `invalid_parameter`, while a body that is not valid JSON is treated as an empty one.

Also available in: API [`POST /temp-mail/inboxes`](https://openemail.uk/docs/api/reference/temp-mail#post-temp-mail-inboxes); TypeScript [`tempMail.create()`](https://openemail.uk/docs/sdk/reference/temp-mail#create); Python [`temp_mail.create()`](https://openemail.uk/docs/python/reference/temp-mail#create); CLI [`openemail temp-mail create`](https://openemail.uk/docs/cli/reference/temp-mail#temp-mail-create).

### `temp_mail.get`

Read the lease and counters of a disposable inbox

```ruby
get(inbox_id, inbox_token: nil) -> Hash
```

Returns the inbox with its expiry, remaining extensions and message counters, without any messages. To watch an inbox, poll `list_messages` instead: it returns `expires_at` alongside the mail, so one request covers both.

This call is authorised by the inbox token, never by an API key. A workspace key sent in its place is refused with 401 `missing_inbox_token`, and no scope on any key reaches this resource. The token alone decides which inbox is read, and the id in the path is not checked against it.

Once the lease is over the token answers 401 `inbox_expired`, and a token this server did not sign answers 404 `resource_not_found`. Deleting an inbox does not end its lease, so its token still reads it. `messageCount` is counted by reading every page, and is 0 when the install cannot read the mailbox that runs the pool.

Authenticates with an inbox token.

**Parameters**

- `inbox_id` (`String`, required): The `tinb_` id `create` returned. It is not checked against the token, which alone decides the inbox.
- `inbox_token` (`String`): The `oe_inbox_` token `create` returned. Overrides the token given to `OpenEmail.create_temp_mail` for this call, and is required on the `temp_mail` of an `OpenEmail::Client`, which would otherwise send its API key.

**Returns**

A Hash with `id`, `address`, `domain`, `createdAt`, `expiresAt`, `extensionsLeft`, `messageCount`, `messageLimit` and `lastMessageAt`.

**Example**

```ruby
temp_mail = OpenEmail.create_temp_mail

created = temp_mail.create

inbox = temp_mail.get(created[:id], inbox_token: created[:token])

puts inbox[:expiresAt], inbox[:messageCount], inbox[:messageLimit]
```

**Notes**

- A token that does not start with `oe_inbox_` is 401 `missing_inbox_token`, the same as no token at all. One that starts with it but was not signed by this server is 404 `resource_not_found`.
- `messageCount` counts every message the inbox is showing, across every page, and goes down when one is deleted. `messageLimit`, which is 50, is the page size of `list_messages`, not a ceiling: nothing past it is dropped.

Also available in: API [`GET /temp-mail/inboxes/{id}`](https://openemail.uk/docs/api/reference/temp-mail#get-temp-mail-inboxes-id); TypeScript [`tempMail.get()`](https://openemail.uk/docs/sdk/reference/temp-mail#get); Python [`temp_mail.get()`](https://openemail.uk/docs/python/reference/temp-mail#get); CLI [`openemail temp-mail get`](https://openemail.uk/docs/cli/reference/temp-mail#temp-mail-get).

### `temp_mail.extend`

Push the expiry of an inbox an hour further out

```ruby
extend(inbox_id, *modules, inbox_token: nil) -> Hash
```

Adds up to 60 minutes to `expiresAt` and returns the updated inbox and a new `token` that carries the later expiry. There is no body. The old token keeps its old expiry, so use the new one from here on, including in a client built with `OpenEmail.create_temp_mail(inbox_token:)`.

The new expiry is the earlier of one hour past the current expiry and 24 hours after `createdAt`, and a lease allows at most 23 extensions. The last extension can buy less than an hour, and on a lease that already reaches the 24 hours a call still succeeds, spends an extension and buys nothing. `extensionsLeft` counts only the 23 calls, so compare `expiresAt` with `createdAt` before offering more time.

When `extensionsLeft` is 0 this answers 422 `extension_limit` for good, and the only way on is a new inbox. The response reads no mail, so its `messageCount` is 0 and its `lastMessageAt` is nil.

Authenticates with an inbox token.

**Parameters**

- `inbox_id` (`String`, required): The `tinb_` id `create` returned. It is not checked against the token, which alone decides the inbox.
- `inbox_token` (`String`): The `oe_inbox_` token `create` returned. Overrides the token given to `OpenEmail.create_temp_mail` for this call, and is required on the `temp_mail` of an `OpenEmail::Client`, which would otherwise send its API key.

**Returns**

A Hash with the fields of `temp_mail.get`, the new `expiresAt` and the updated `extensionsLeft`, plus the new `token` beginning `oe_inbox_`.

**Example**

```ruby
temp_mail = OpenEmail.create_temp_mail(inbox_token: "oe_inbox_Vb3kT9qLm2Xw7RzN4pYc6HfJ1sGa5Ed8KuQo0iWnS2e")

inbox = temp_mail.extend("tinb_k7m2q9xw4bdp")

puts inbox[:expiresAt], inbox[:extensionsLeft]

renewed = OpenEmail.create_temp_mail(inbox_token: inbox[:token])
puts renewed.get("tinb_k7m2q9xw4bdp")[:expiresAt]
```

**Notes**

- Not retried automatically, because a replay would spend a second extension.
- An inbox created with `ttlMinutes: 1440` still reports `extensionsLeft: 23`, and none of them can add a minute.
- Called with a Module in place of an inbox id, `extend` is Ruby's ordinary `Object#extend`, which mixes the module into the object and sends no request.

Also available in: API [`POST /temp-mail/inboxes/{id}/extend`](https://openemail.uk/docs/api/reference/temp-mail#post-temp-mail-inboxes-id-extend); TypeScript [`tempMail.extend()`](https://openemail.uk/docs/sdk/reference/temp-mail#extend); Python [`temp_mail.extend()`](https://openemail.uk/docs/python/reference/temp-mail#extend); CLI [`openemail temp-mail extend`](https://openemail.uk/docs/cli/reference/temp-mail#temp-mail-extend).

### `temp_mail.delete`

Move the mail in a disposable inbox to the bin now

```ruby
delete(inbox_id, inbox_token: nil) -> Hash
```

Moves every message the inbox shows to the bin of the mailbox that runs the pool, at once. It does not end the lease: nothing about a lease is stored, so there is nothing to revoke, and the token keeps opening the address until its expiry. Mail that arrives afterwards is listed as usual.

Nothing holds the address back either, so it can be issued again at once, to anybody. An install with no key to read the pool answers 503 `not_configured`.

The response is a tombstone rather than an empty body, so a log line can name what went.

Authenticates with an inbox token.

**Parameters**

- `inbox_id` (`String`, required): The `tinb_` id `create` returned. It is not checked against the token, which alone decides the inbox.
- `inbox_token` (`String`): The `oe_inbox_` token `create` returned. Overrides the token given to `OpenEmail.create_temp_mail` for this call, and is required on the `temp_mail` of an `OpenEmail::Client`, which would otherwise send its API key.

**Returns**

A Hash with `object` set to `temp_inbox`, the `id` and `destroyed` set to true.

**Example**

```ruby
temp_mail = OpenEmail.create_temp_mail

inbox = temp_mail.create

result = temp_mail.delete(inbox[:id], inbox_token: inbox[:token])

puts result[:destroyed]
```

**Notes**

- The flag is `destroyed`, not `deleted` as on other tombstones.
- Not retried automatically. Repeating it is harmless: the lease still stands, so a second call answers 200 and moves whatever has arrived since.

Also available in: API [`DELETE /temp-mail/inboxes/{id}`](https://openemail.uk/docs/api/reference/temp-mail#delete-temp-mail-inboxes-id); TypeScript [`tempMail.delete()`](https://openemail.uk/docs/sdk/reference/temp-mail#delete); Python [`temp_mail.delete()`](https://openemail.uk/docs/python/reference/temp-mail#delete); CLI [`openemail temp-mail delete`](https://openemail.uk/docs/cli/reference/temp-mail#temp-mail-delete).

### `temp_mail.list_messages`

List one page of the messages in a disposable inbox

```ruby
list_messages(inbox_id, limit: nil, cursor: nil, inbox_token: nil) -> OpenEmail::TempMessagesPage
```

Returns one page of the messages in the inbox newest first, by the time the server received them, together with the inbox `expires_at`. Rows carry metadata only, and polling this is the way to wait for a confirmation email. Only mail delivered to this address since the lease began is listed.

A page holds up to 50 messages. When more have arrived, `has_more?` is true and `next_cursor` goes back as `cursor:` for the next page, so nothing that reached the inbox is hidden; `list_all_messages` and `iterate_messages` do that walk for you. A page can hold fewer than `limit:` rows, even none, while `has_more?` is true, because mail to other addresses on the pool is read and dropped. `snippet` is plain text capped at 400 characters, which is often enough to read a one time code without opening the message.

`spam` is a flag, never a filing decision. A machine sent confirmation from a sender with no reputation is exactly what a disposable inbox exists to receive, so flagged messages are still listed. `from` is whatever the message claimed and has not been authenticated.

Authenticates with an inbox token.

**Parameters**

- `inbox_id` (`String`, required): The `tinb_` id `create` returned. It is not checked against the token, which alone decides the inbox.
- `limit` (`Integer`): Messages per page, a whole number from 1 to 50, defaulting to 50. Out of range is 422 `invalid_parameter`.
- `cursor` (`String`): The `next_cursor` from the previous page. Never build one yourself.
- `inbox_token` (`String`): The `oe_inbox_` token `create` returned. Overrides the token given to `OpenEmail.create_temp_mail` for this call, and is required on the `temp_mail` of an `OpenEmail::Client`, which would otherwise send its API key.

**Returns**

An `OpenEmail::TempMessagesPage` with `items`, an Array of Hashes each with `id`, `from`, `to`, `subject`, `snippet`, `spam`, `seen`, `attachmentCount`, `sizeBytes` and `receivedAt`, plus `has_more?`, `next_cursor` and the inbox `expires_at`.

**Example**

```ruby
temp_mail = OpenEmail.create_temp_mail

inbox = temp_mail.create

page = temp_mail.list_messages(inbox[:id], inbox_token: inbox[:token], limit: 10)

code = page.items.dig(0, :snippet)&.slice(/\b\d{6}\b/)

puts code, page.expires_at
```

**Notes**

- A message whose `Message-ID` header matches one already in the inbox is not stored twice.
- `to` is the inbox address. A `+tag` the sender added is folded back into the base address.
- Every message the inbox has received is listed, a page at a time. `messageLimit` on the inbox is the size the tool is built for, not a point past which mail is hidden.
- An install with no key to read the pool answers 503 `not_configured`.

Also available in: API [`GET /temp-mail/inboxes/{id}/messages`](https://openemail.uk/docs/api/reference/temp-mail#get-temp-mail-inboxes-id-messages); TypeScript [`tempMail.listMessages()`](https://openemail.uk/docs/sdk/reference/temp-mail#listMessages); Python [`temp_mail.list_messages()`](https://openemail.uk/docs/python/reference/temp-mail#listMessages); CLI [`openemail temp-mail list-messages`](https://openemail.uk/docs/cli/reference/temp-mail#temp-mail-list-messages).

### `temp_mail.list_all_messages`

Collect every message in a disposable inbox into one Array

```ruby
list_all_messages(inbox_id, limit: nil, cursor: nil, inbox_token: nil) -> Array<Hash>
```

Follows `next_cursor` from page to page and returns every message the inbox has received, newest first. Rows carry metadata only, as on `list_messages`.

Authenticates with an inbox token.

**Parameters**

- `inbox_id` (`String`, required): The `tinb_` id `create` returned.
- `limit` (`Integer`): Page size per request, from 1 to 50, defaulting to 50.
- `cursor` (`String`): A cursor from an earlier page to start after.
- `inbox_token` (`String`): The `oe_inbox_` token `create` returned, sent with every page.

**Returns**

An Array of Hashes holding every message across all pages.

**Example**

```ruby
temp_mail = OpenEmail.create_temp_mail

inbox = temp_mail.create

messages = temp_mail.list_all_messages(inbox[:id], inbox_token: inbox[:token])

puts messages.length
```

**Notes**

- A failure on any page fails the whole call, and its error is raised.

Also available in: API [`GET /temp-mail/inboxes/{id}/messages`](https://openemail.uk/docs/api/reference/temp-mail#get-temp-mail-inboxes-id-messages); TypeScript [`tempMail.listAllMessages()`](https://openemail.uk/docs/sdk/reference/temp-mail#listAllMessages); Python [`temp_mail.list_all_messages()`](https://openemail.uk/docs/python/reference/temp-mail#listAllMessages).

### `temp_mail.iterate_messages`

Stream the messages in a disposable inbox one at a time

```ruby
iterate_messages(inbox_id, limit: nil, cursor: nil, inbox_token: nil, &block) -> Enumerator<Hash>
```

Returns an Enumerator that yields the inbox messages individually, newest first, and requests the next page only once the current one is drained. Given a block, it yields each message to the block instead. Breaking out of the loop stops the requests.

Authenticates with an inbox token.

**Parameters**

- `inbox_id` (`String`, required): The `tinb_` id `create` returned.
- `limit` (`Integer`): Page size per request, from 1 to 50, defaulting to 50.
- `cursor` (`String`): A cursor from an earlier page to start after.
- `inbox_token` (`String`): The `oe_inbox_` token `create` returned, sent with every page.

**Returns**

An Enumerator of Hashes, one message per step (or yields each one to a block).

**Example**

```ruby
temp_mail = OpenEmail.create_temp_mail

inbox = temp_mail.create

temp_mail.iterate_messages(inbox[:id], inbox_token: inbox[:token]) do |message|
  code = message[:snippet][/\b\d{6}\b/]

  if code
    puts code
    break
  end
end
```

**Notes**

- The Enumerator fetches a page only when it is consumed, so an abandoned loop costs only the pages you consumed.

Also available in: API [`GET /temp-mail/inboxes/{id}/messages`](https://openemail.uk/docs/api/reference/temp-mail#get-temp-mail-inboxes-id-messages); TypeScript [`tempMail.iterateMessages()`](https://openemail.uk/docs/sdk/reference/temp-mail#iterateMessages); Python [`temp_mail.iterate_messages()`](https://openemail.uk/docs/python/reference/temp-mail#iterateMessages).

### `temp_mail.get_message`

Read one message with its stored body

```ruby
get_message(inbox_id, message_id, inbox_token: nil) -> Hash
```

Returns the list row for one message plus the parsed message as stored. Reading it does not mark it seen: `seen` mirrors the unread state of the message in the mailbox that runs the pool, and nothing on these routes changes it.

Render `decodedBody` from `message`. `body` and `processedHtml` are empty strings for every message that can reach a disposable inbox, so a client reading either shows a blank page. The body is never cut, so `truncated` is always false.

The HTML came from a stranger to an address anyone could name. Render it outside your own origin, for example in a sandboxed iframe.

Authenticates with an inbox token.

**Parameters**

- `inbox_id` (`String`, required): The `tinb_` id `create` returned. It is not checked against the token, which alone decides the inbox.
- `message_id` (`String`, required): An `id` from `list_messages`, such as `thr_` and 24 hex.
- `inbox_token` (`String`): The `oe_inbox_` token `create` returned. Overrides the token given to `OpenEmail.create_temp_mail` for this call, and is required on the `temp_mail` of an `OpenEmail::Client`, which would otherwise send its API key.

**Returns**

A Hash with every field of a `list_messages` row plus `message`, the stored parsed message as a Hash, and `truncated`.

**Example**

```ruby
temp_mail = OpenEmail.create_temp_mail(inbox_token: "oe_inbox_Vb3kT9qLm2Xw7RzN4pYc6HfJ1sGa5Ed8KuQo0iWnS2e")

detail = temp_mail.get_message("tinb_k7m2q9xw4bdp", "thr_9e3b7c1a5f2d8e40b6a9c3f1")

puts detail[:subject], detail[:truncated]
puts detail[:message][:decodedBody]
```

**Notes**

- A message this lease cannot see, deleted ones included, is 404 `resource_not_found`. An expired lease is 401 `inbox_expired`, and an install with no key to read the pool answers 503 `not_configured`.
- `message` is a Hash with no fixed shape, so check that `decodedBody` is a String before rendering it.

Also available in: API [`GET /temp-mail/inboxes/{id}/messages/{messageId}`](https://openemail.uk/docs/api/reference/temp-mail#get-temp-mail-inboxes-id-messages-messageid); TypeScript [`tempMail.getMessage()`](https://openemail.uk/docs/sdk/reference/temp-mail#getMessage); Python [`temp_mail.get_message()`](https://openemail.uk/docs/python/reference/temp-mail#getMessage); CLI [`openemail temp-mail get-message`](https://openemail.uk/docs/cli/reference/temp-mail#temp-mail-get-message).

### `temp_mail.delete_message`

Delete one message from a disposable inbox

```ruby
delete_message(inbox_id, message_id, inbox_token: nil) -> Hash
```

Moves the message, attachments and all, to the bin of the mailbox that runs the pool, and no lease lists or opens it again. Nothing in this SDK restores it.

`messageCount` goes down by one. There is never a slot to free: an inbox keeps every message that reaches it, and `list_messages` pages through all of them.

Authenticates with an inbox token.

**Parameters**

- `inbox_id` (`String`, required): The `tinb_` id `create` returned. It is not checked against the token, which alone decides the inbox.
- `message_id` (`String`, required): An `id` from `list_messages`, such as `thr_` and 24 hex.
- `inbox_token` (`String`): The `oe_inbox_` token `create` returned. Overrides the token given to `OpenEmail.create_temp_mail` for this call, and is required on the `temp_mail` of an `OpenEmail::Client`, which would otherwise send its API key.

**Returns**

A Hash with `object` set to `temp_message`, the message `id` and `deleted` set to true.

**Example**

```ruby
temp_mail = OpenEmail.create_temp_mail(inbox_token: "oe_inbox_Vb3kT9qLm2Xw7RzN4pYc6HfJ1sGa5Ed8KuQo0iWnS2e")

result = temp_mail.delete_message("tinb_k7m2q9xw4bdp", "thr_9e3b7c1a5f2d8e40b6a9c3f1")

puts result[:deleted]
```

**Notes**

- An unknown or already deleted message id is 404 `resource_not_found`, and an install with no key to read the pool answers 503 `not_configured`.
- Not retried automatically. If you repeat it yourself after a lost response, that 404 means the first attempt already worked.

Also available in: API [`DELETE /temp-mail/inboxes/{id}/messages/{messageId}`](https://openemail.uk/docs/api/reference/temp-mail#delete-temp-mail-inboxes-id-messages-messageid); TypeScript [`tempMail.deleteMessage()`](https://openemail.uk/docs/sdk/reference/temp-mail#deleteMessage); Python [`temp_mail.delete_message()`](https://openemail.uk/docs/python/reference/temp-mail#deleteMessage); CLI [`openemail temp-mail delete-message`](https://openemail.uk/docs/cli/reference/temp-mail#temp-mail-delete-message).

### `temp_mail.list_attachments`

List the attachments of a message, metadata only

```ruby
list_attachments(inbox_id, message_id, inbox_token: nil) -> Array<Hash>
```

Returns every attachment on a message as a plain Array of metadata: `attachmentId`, `filename`, `mimeType` and `size` in decoded bytes, with `body` an empty string and `headers` empty. No route on a disposable inbox serves the bytes, and there is no per attachment fetch.

`filename` and `mimeType` are whatever the sender declared, and nothing here is scanned. A message this lease cannot see is 404 `resource_not_found`, and an install with no key to read the pool answers 503 `not_configured`.

Authenticates with an inbox token.

**Parameters**

- `inbox_id` (`String`, required): The `tinb_` id `create` returned. It is not checked against the token, which alone decides the inbox.
- `message_id` (`String`, required): An `id` from `list_messages`, such as `thr_` and 24 hex.
- `inbox_token` (`String`): The `oe_inbox_` token `create` returned. Overrides the token given to `OpenEmail.create_temp_mail` for this call, and is required on the `temp_mail` of an `OpenEmail::Client`, which would otherwise send its API key.

**Returns**

An Array of Hashes, each with `attachmentId`, `filename`, `mimeType`, `size` in decoded bytes, `body` as an empty String and `headers` as an empty Array.

**Example**

```ruby
temp_mail = OpenEmail.create_temp_mail(inbox_token: "oe_inbox_Vb3kT9qLm2Xw7RzN4pYc6HfJ1sGa5Ed8KuQo0iWnS2e")

attachments = temp_mail.list_attachments("tinb_k7m2q9xw4bdp", "thr_9e3b7c1a5f2d8e40b6a9c3f1")

attachments.each { |file| puts "#{file[:filename]} #{file[:size]}" }
```

**Notes**

- Listing attachments does not mark the message seen.
- Check `attachmentCount` from `list_messages` first to skip this call for messages with none.

Also available in: API [`GET /temp-mail/inboxes/{id}/messages/{messageId}/attachments`](https://openemail.uk/docs/api/reference/temp-mail#get-temp-mail-inboxes-id-messages-messageid-attachments); TypeScript [`tempMail.listAttachments()`](https://openemail.uk/docs/sdk/reference/temp-mail#listAttachments); Python [`temp_mail.list_attachments()`](https://openemail.uk/docs/python/reference/temp-mail#listAttachments); CLI [`openemail temp-mail list-attachments`](https://openemail.uk/docs/cli/reference/temp-mail#temp-mail-list-attachments).
