openemail.addresses
Every method in this namespace: its signature, its parameters, what it returns and an example.
Methods
Which addresses and domains the key may send from.
addresses.list()
List the addresses and domains this key may send as
list(options?: ListOptions): Promise<AddressBookPage>Answers the question behind an unexplained 403 from_address_forbidden: which addresses this key may put in from. It returns one page of the addresses created on the workspace's domains, alphabetically, each with a canSend verdict for this key, plus the domains themselves. listAll collects every page into one book and iterate walks the addresses lazily.
unrestricted is true when the key is narrowed by nothing, in which case the API accepts any local-part on the workspace's domains, including ones nobody has created. A key can be narrowed by whole domains, by individual addresses, or by both, and any of those makes unrestricted false. canSend is then true only for an enabled address the key covers, either because its domain is one of the whole domains the key holds or because the address itself is on its address list. A disabled address always reports canSend false.
The SDK reshapes the wire envelope: the server's data array arrives as addresses, so the result is a single object rather than a list.
Parameters
options.limitnumberPage size, from 1 to 100. The server defaults to 25.
options.cursorstringThe
nextCursorof the previous page. Leave it out for the first page.options.signalAbortSignalCancels the request.
options.apiKeystringReports on this key instead of the one the client was built with.
Returns
AddressBookPage with unrestricted, hasMore, nextCursor, addresses (each with address, enabled and canSend) and domains (each with domain, receivingVerified, sendingVerified and catchAll).
Example
const book = await openemail.addresses.listAll() const sendable = book.addresses.filter((entry) => entry.canSend).map((entry) => entry.address) console.log(book.unrestricted, sendable)Notes
It needs
emails:send, not a read scope, because it describes what a send would accept.An app a member connected always reports
unrestricted: false, because its access token is held to what that member reaches: the addresses and domains they were granted, or every domain of the workspace when their role holdsaddresses:all. That is worked out again on every call, so a domain added later appears on the next one.canSendis false when the address is disabled, when the key's allowlists leave it out, or when the domain cannot sign yet.sendingVerifiedon each domain is that last fact on its own, so a domain that is verified for receiving and not yet for sending showsreceivingVerified: true, sendingVerified: false.Only created addresses appear in
addresses. An allowlisted address with no mailbox behind it can still be sent from without ever showing up here, and a key that holds a whole domain can send as any local-part on it, including ones created after the key was.The cursor is opaque and holds where the last row sat in this order, so a row deleted or edited between pages never breaks the walk: the next page starts at the first row that sorts after it. A cursor this list did not hand out is a 400
invalid_cursor.
Also available in
addresses.listAll()
Collect every address this key may see into one book
listAll(options?: ListOptions): Promise<AddressBookResource>Walks every page of list and resolves with one AddressBookResource holding all addresses, alphabetically, with unrestricted and domains as the last page reported them. One request per page.
Parameters
options.limitnumberPage size for each request, from 1 to 100. The server defaults to 25.
options.cursorstringStarts the walk after this cursor instead of the first page.
options.signalAbortSignalCancels the request in flight and the walk with it.
options.apiKeystringReports on this key instead of the one the client was built with.
Returns
AddressBookResource with unrestricted, every address in addresses, and domains.
Example
const book = await openemail.addresses.listAll() console.log(book.addresses.filter((entry) => entry.canSend).length)Notes
If any page fails the promise rejects and the addresses already fetched are discarded.
Also available in
addresses.iterate()
Stream the addresses one at a time
iterate(options?: ListOptions): AsyncGenerator<AddressResource, void, undefined>Returns an async generator that yields addresses individually, alphabetically, each with its canSend verdict for this key, and requests the next page only once the current one is drained. It yields addresses only; read list for unrestricted and domains.
Parameters
options.limitnumberPage size for each request, from 1 to 100. The server defaults to 25.
options.cursorstringStarts the walk after this cursor instead of the first page.
options.signalAbortSignalCancels the request in flight and the walk with it.
options.apiKeystringReports on this key instead of the one the client was built with.
Returns
AsyncGenerator<AddressResource, void, undefined> yielding one address per step.
Example
for await (const entry of openemail.addresses.iterate()) { if (entry.canSend) console.log(entry.address)}Notes
The generator is lazy, so an abandoned loop costs only the pages you consumed.