---
title: "openemail.tempMail"
description: "Every method in this namespace: its signature, its parameters, what it returns and an example."
url: "https://openemail.uk/docs/sdk/reference/temp-mail"
area: "SDK"
category: "Reference"
---

# openemail.tempMail

Every method in this namespace: its signature, its parameters, what it returns and an example.

## Methods

Short lived inboxes that need no account, authorised by the token they were created with.

### `tempMail.listDomains()`

List the domains a disposable inbox can be created on

```ts
listDomains(options?: InboxScope): Promise<Array<TempDomainResource>>
```

Resolves the pool of domains `create` accepts, as a plain array in the order the operator wrote them in `TEMP_MAIL_DOMAINS`. It takes no credential at all: no API key and no inbox token are sent, even when the client holding this namespace has one.

Nothing checks that a listed domain is verified, so the list is only as good as the operator made it. An empty array is a normal answer meaning this install offers no disposable domains, and it is exactly the condition under which `create` fails with 503 `not_configured`.

**Parameters**

- `options.signal` (`AbortSignal`): Cancels the request.
- `options.inboxToken` (`string`): Accepted for symmetry with the other methods and never sent, because this call is anonymous.

**Returns**

`Array<TempDomainResource>`, each with `object` set to `temp_domain` and a lowercased `domain` to pass back to `create`.

**Example**

```ts
const temp = createTempMail()

const domains = await temp.listDomains()

console.log(domains.map((entry) => entry.domain))
```

**Notes**

- The pool is server configuration, so a domain appears when the operator adds it to `TEMP_MAIL_DOMAINS`, not when it is added to a workspace.
- Retried automatically on network failure and retryable statuses, like every GET.

Also available in: API [`GET /temp-mail/domains`](https://openemail.uk/docs/api/reference/temp-mail#get-temp-mail-domains); CLI [`openemail temp-mail list-domains`](https://openemail.uk/docs/cli/reference/temp-mail#temp-mail-list-domains).

### `tempMail.create()`

Create a disposable inbox and its access token

```ts
create(body?: TempInboxCreate, options?: InboxScope): Promise<CreatedTempInboxResource>
```

Mints a disposable address and resolves with the inbox plus its `token`. It needs no credential, and only this call and `extend` return a token. The token is the lease itself, signed, and nothing about it is stored on the server, so a lost token cannot be recovered, and every other method except `listDomains` needs it. Store it before you show the address to anyone.

The body is optional and so is every field in it. With nothing, you get a 12 character generated local part on the first domain in the pool, leased for 60 minutes. A chosen `localPart` is lowercased and must be up to 64 letters, digits, dots, dashes or underscores, starting and ending with a letter or digit, or it is 422 `invalid_address`, and one longer than 64 characters is 422 `invalid_parameter`. Names such as `postmaster`, `abuse` and `support` are 422 `reserved_address`, and an install with no pooled domain answers 503 `not_configured`.

Nothing is rate limited and nothing reserves an address, so this never answers 429 or 409. A name you choose is issued to anyone who asks for it, and each of you reads the mail that reaches it from the start of your own lease. Leave `localPart` out when the mail should reach you alone.

**Parameters**

- `body.domain` (`string`): A domain from `listDomains`. Omit it for the first one in the pool. Any other name is 422 `unknown_domain` rather than a silent substitute.
- `body.localPart` (`string`): The part before the @. Omit it for a generated one, which nobody else is likely to be issued.
- `body.ttlMinutes` (`number`): Lease length from now, a whole number from 1 to 1440. Defaults to 60. Out of range is 422 `invalid_parameter`, not clamped.
- `options.signal` (`AbortSignal`): Cancels the request.
- `options.inboxToken` (`string`): Ignored and never sent. Creating an inbox is anonymous and hands you the token instead.

**Returns**

`CreatedTempInboxResource`: the `TempInboxResource` fields `id`, `address`, `domain`, `createdAt`, `expiresAt`, `extensionsLeft`, `messageCount`, `messageLimit` and `lastMessageAt`, plus the one time `token` beginning `oe_inbox_`.

**Example**

```ts
const temp = createTempMail()

const inbox = await temp.create({ ttlMinutes: 120 })

console.log(inbox.address, inbox.expiresAt)
console.log(inbox.token)
```

**Notes**

- Not retried automatically. A retry would mint a second inbox, and the first would be unreachable because its only token was in the lost response.
- Nothing holds an address back after its lease ends or its inbox is deleted, so it can be issued again at once, to anybody.
- A lease of 1440 minutes reaches the 24 hour ceiling at once, yet the inbox still comes back with `extensionsLeft: 23`, because that counts calls rather than time. None of them can add a minute.
- Unknown body keys are 422 `invalid_parameter`, while a body that is not valid JSON is treated as an empty one.

Also available in: API [`POST /temp-mail/inboxes`](https://openemail.uk/docs/api/reference/temp-mail#post-temp-mail-inboxes); CLI [`openemail temp-mail create`](https://openemail.uk/docs/cli/reference/temp-mail#temp-mail-create).

### `tempMail.get()`

Read the lease and counters of a disposable inbox

```ts
get(inboxId: string, options?: InboxScope): Promise<TempInboxResource>
```

Resolves the inbox with its expiry, remaining extensions and message counters, without any messages. To watch an inbox, poll `listMessages` instead: it returns `expiresAt` alongside the mail, so one request covers both.

This call is authorised by the inbox token, never by an API key. A workspace key sent in its place is refused with 401 `missing_inbox_token`, and no scope on any key reaches this resource. The token alone decides which inbox is read, and the id in the path is not checked against it.

Once the lease is over the token answers 401 `inbox_expired`, and a token this server did not sign answers 404 `resource_not_found`. Deleting an inbox does not end its lease, so its token still reads it. `messageCount` is counted by reading every page, and is 0 when the install cannot read the mailbox that runs the pool.

**Parameters**

- `inboxId` (`string`, required): The `tinb_` id `create` returned. It is not checked against the token, which alone decides the inbox.
- `options.signal` (`AbortSignal`): Cancels the request.
- `options.inboxToken` (`string`): The `oe_inbox_` token `create` returned. Overrides the token given to `createTempMail` for this call, and is required on the `OpenEmail` client, which would otherwise send its API key.

**Returns**

`TempInboxResource` with `id`, `address`, `domain`, `createdAt`, `expiresAt`, `extensionsLeft`, `messageCount`, `messageLimit` and `lastMessageAt`.

**Example**

```ts
const temp = createTempMail()

const created = await temp.create()

const inbox = await temp.get(created.id, { inboxToken: created.token })

console.log(inbox.expiresAt, inbox.messageCount, inbox.messageLimit)
```

**Notes**

- A token that does not start with `oe_inbox_` is 401 `missing_inbox_token`, the same as no token at all. One that starts with it but was not signed by this server is 404 `resource_not_found`.
- `messageCount` counts every message the inbox is showing, across every page, and goes down when one is deleted. `messageLimit`, which is 50, is the page size of `listMessages`, not a ceiling: nothing past it is dropped.

Also available in: API [`GET /temp-mail/inboxes/{id}`](https://openemail.uk/docs/api/reference/temp-mail#get-temp-mail-inboxes-id); CLI [`openemail temp-mail get`](https://openemail.uk/docs/cli/reference/temp-mail#temp-mail-get).

### `tempMail.extend()`

Push the expiry of an inbox an hour further out

```ts
extend(inboxId: string, options?: InboxScope): Promise<ExtendedTempInboxResource>
```

Adds up to 60 minutes to `expiresAt` and resolves with the updated inbox and a new `token` that carries the later expiry. There is no body. The old token keeps its old expiry, so use the new one from here on, including in a client built with `createTempMail({ inboxToken })`.

The new expiry is the earlier of one hour past the current expiry and 24 hours after `createdAt`, and a lease allows at most 23 extensions. The last extension can buy less than an hour, and on a lease that already reaches the 24 hours a call still succeeds, spends an extension and buys nothing. `extensionsLeft` counts only the 23 calls, so compare `expiresAt` with `createdAt` before offering more time.

When `extensionsLeft` is 0 this answers 422 `extension_limit` for good, and the only way on is a new inbox. The response reads no mail, so its `messageCount` is 0 and its `lastMessageAt` is null.

**Parameters**

- `inboxId` (`string`, required): The `tinb_` id `create` returned. It is not checked against the token, which alone decides the inbox.
- `options.signal` (`AbortSignal`): Cancels the request.
- `options.inboxToken` (`string`): The `oe_inbox_` token `create` returned. Overrides the token given to `createTempMail` for this call, and is required on the `OpenEmail` client, which would otherwise send its API key.

**Returns**

`ExtendedTempInboxResource`: the `TempInboxResource` fields with the new `expiresAt` and the updated `extensionsLeft`, plus the new `token` beginning `oe_inbox_`.

**Example**

```ts
const temp = createTempMail({ inboxToken: 'oe_inbox_Vb3kT9qLm2Xw7RzN4pYc6HfJ1sGa5Ed8KuQo0iWnS2e' })

const inbox = await temp.extend('tinb_k7m2q9xw4bdp')

console.log(inbox.expiresAt, inbox.extensionsLeft)

const renewed = createTempMail({ inboxToken: inbox.token })
```

**Notes**

- Not retried automatically, because a replay would spend a second extension.
- An inbox created with `ttlMinutes: 1440` still reports `extensionsLeft: 23`, and none of them can add a minute.

Also available in: API [`POST /temp-mail/inboxes/{id}/extend`](https://openemail.uk/docs/api/reference/temp-mail#post-temp-mail-inboxes-id-extend); CLI [`openemail temp-mail extend`](https://openemail.uk/docs/cli/reference/temp-mail#temp-mail-extend).

### `tempMail.delete()`

Move the mail in a disposable inbox to the bin now

```ts
delete(inboxId: string, options?: InboxScope): Promise<DeletedTempInboxResource>
```

Moves every message the inbox shows to the bin of the mailbox that runs the pool, at once. It does not end the lease: nothing about a lease is stored, so there is nothing to revoke, and the token keeps opening the address until its expiry. Mail that arrives afterwards is listed as usual.

Nothing holds the address back either, so it can be issued again at once, to anybody. An install with no key to read the pool answers 503 `not_configured`.

The response is a tombstone rather than an empty body, so a log line can name what went.

**Parameters**

- `inboxId` (`string`, required): The `tinb_` id `create` returned. It is not checked against the token, which alone decides the inbox.
- `options.signal` (`AbortSignal`): Cancels the request.
- `options.inboxToken` (`string`): The `oe_inbox_` token `create` returned. Overrides the token given to `createTempMail` for this call, and is required on the `OpenEmail` client, which would otherwise send its API key.

**Returns**

`DeletedTempInboxResource` with `object` set to `temp_inbox`, the `id` and `destroyed: true`.

**Example**

```ts
const temp = createTempMail()

const inbox = await temp.create()

const result = await temp.delete(inbox.id, { inboxToken: inbox.token })

console.log(result.destroyed)
```

**Notes**

- The flag is `destroyed`, not `deleted` as on other tombstones.
- Not retried automatically. Repeating it is harmless: the lease still stands, so a second call answers 200 and moves whatever has arrived since.

Also available in: API [`DELETE /temp-mail/inboxes/{id}`](https://openemail.uk/docs/api/reference/temp-mail#delete-temp-mail-inboxes-id); CLI [`openemail temp-mail delete`](https://openemail.uk/docs/cli/reference/temp-mail#temp-mail-delete).

### `tempMail.listMessages()`

List one page of the messages in a disposable inbox

```ts
listMessages(inboxId: string, options?: TempMessageListOptions): Promise<TempMessagesResource>
```

Resolves one page of the messages in the inbox newest first, by the time the server received them, together with the inbox `expiresAt`. Rows carry metadata only, and polling this is the way to wait for a confirmation email. Only mail delivered to this address since the lease began is listed.

A page holds up to 50 messages. When more have arrived, `hasMore` is true and `nextCursor` goes back as `options.cursor` for the next page, so nothing that reached the inbox is hidden; `listAllMessages` and `iterateMessages` do that walk for you. A page can hold fewer than `limit` rows, even none, while `hasMore` is true, because mail to other addresses on the pool is read and dropped. `snippet` is plain text capped at 400 characters, which is often enough to read a one time code without opening the message.

`spam` is a flag, never a filing decision. A machine sent confirmation from a sender with no reputation is exactly what a disposable inbox exists to receive, so flagged messages are still listed. `from` is whatever the message claimed and has not been authenticated.

**Parameters**

- `inboxId` (`string`, required): The `tinb_` id `create` returned. It is not checked against the token, which alone decides the inbox.
- `options.limit` (`number`): Messages per page, a whole number from 1 to 50, defaulting to 50. Out of range is 422 `invalid_parameter`.
- `options.cursor` (`string`): The `nextCursor` from the previous page. Never build one yourself.
- `options.signal` (`AbortSignal`): Cancels the request.
- `options.inboxToken` (`string`): The `oe_inbox_` token `create` returned. Overrides the token given to `createTempMail` for this call, and is required on the `OpenEmail` client, which would otherwise send its API key.

**Returns**

`TempMessagesResource` with `items`, an array of `TempMessageResource` (`id`, `from`, `to`, `subject`, `snippet`, `spam`, `seen`, `attachmentCount`, `sizeBytes`, `receivedAt`), `hasMore`, `nextCursor` and the inbox `expiresAt`.

**Example**

```ts
const temp = createTempMail()

const inbox = await temp.create()

const { items, expiresAt } = await temp.listMessages(inbox.id, { inboxToken: inbox.token, limit: 10 })

const code = items[0]?.snippet.match(/\b\d{6}\b/)?.[0]

console.log(code, expiresAt)
```

**Notes**

- A message whose `Message-ID` header matches one already in the inbox is not stored twice.
- `to` is the inbox address. A `+tag` the sender added is folded back into the base address.
- Every message the inbox has received is listed, a page at a time. `messageLimit` on the inbox is the size the tool is built for, not a point past which mail is hidden.
- An install with no key to read the pool answers 503 `not_configured`.

Also available in: API [`GET /temp-mail/inboxes/{id}/messages`](https://openemail.uk/docs/api/reference/temp-mail#get-temp-mail-inboxes-id-messages); CLI [`openemail temp-mail list-messages`](https://openemail.uk/docs/cli/reference/temp-mail#temp-mail-list-messages).

### `tempMail.listAllMessages()`

Collect every message in a disposable inbox into one array

```ts
listAllMessages(inboxId: string, options?: TempMessageListOptions): Promise<Array<TempMessageResource>>
```

Follows `nextCursor` from page to page and resolves with every message the inbox has received, newest first. Rows carry metadata only, as on `listMessages`.

**Parameters**

- `inboxId` (`string`, required): The `tinb_` id `create` returned.
- `options.limit` (`number`): Page size per request, from 1 to 50, defaulting to 50.
- `options.cursor` (`string`): A cursor from an earlier page to start after.
- `options.signal` (`AbortSignal`): Cancels the request in flight and rejects the whole walk.
- `options.inboxToken` (`string`): The `oe_inbox_` token `create` returned, sent with every page.

**Returns**

`Array<TempMessageResource>` holding every message across all pages.

**Example**

```ts
const temp = createTempMail()

const inbox = await temp.create()

const messages = await temp.listAllMessages(inbox.id, { inboxToken: inbox.token })

console.log(messages.length)
```

**Notes**

- A failure on any page rejects the whole call.

Also available in: API [`GET /temp-mail/inboxes/{id}/messages`](https://openemail.uk/docs/api/reference/temp-mail#get-temp-mail-inboxes-id-messages).

### `tempMail.iterateMessages()`

Stream the messages in a disposable inbox one at a time

```ts
iterateMessages(inboxId: string, options?: TempMessageListOptions): AsyncGenerator<TempMessageResource, void, undefined>
```

Returns an async generator that yields the inbox messages individually, newest first, and requests the next page only once the current one is drained. Breaking out of the loop stops the requests.

**Parameters**

- `inboxId` (`string`, required): The `tinb_` id `create` returned.
- `options.limit` (`number`): Page size per request, from 1 to 50, defaulting to 50.
- `options.cursor` (`string`): A cursor from an earlier page to start after.
- `options.signal` (`AbortSignal`): Cancels the request in flight and rejects the whole walk.
- `options.inboxToken` (`string`): The `oe_inbox_` token `create` returned, sent with every page.

**Returns**

`AsyncGenerator<TempMessageResource, void, undefined>` yielding one message per step.

**Example**

```ts
for await (const message of temp.iterateMessages(inbox.id, { inboxToken: inbox.token })) {
    const code = message.snippet.match(/\b\d{6}\b/)?.[0]

    if (code) {
        console.log(code)
        break
    }
}
```

**Notes**

- The generator is lazy, so an abandoned loop costs only the pages you consumed.

Also available in: API [`GET /temp-mail/inboxes/{id}/messages`](https://openemail.uk/docs/api/reference/temp-mail#get-temp-mail-inboxes-id-messages).

### `tempMail.getMessage()`

Read one message with its stored body

```ts
getMessage(inboxId: string, messageId: string, options?: InboxScope): Promise<TempMessageDetailResource>
```

Resolves the list row for one message plus the parsed message as stored. Reading it does not mark it seen: `seen` mirrors the unread state of the message in the mailbox that runs the pool, and nothing on these routes changes it.

Render `message.decodedBody`. `body` and `processedHtml` are empty strings for every message that can reach a disposable inbox, so a client reading either shows a blank page. The body is never cut, so `truncated` is always false.

The HTML came from a stranger to an address anyone could name. Render it outside your own origin, for example in a sandboxed iframe.

**Parameters**

- `inboxId` (`string`, required): The `tinb_` id `create` returned. It is not checked against the token, which alone decides the inbox.
- `messageId` (`string`, required): An `id` from `listMessages`, such as `thr_` and 24 hex.
- `options.signal` (`AbortSignal`): Cancels the request.
- `options.inboxToken` (`string`): The `oe_inbox_` token `create` returned. Overrides the token given to `createTempMail` for this call, and is required on the `OpenEmail` client, which would otherwise send its API key.

**Returns**

`TempMessageDetailResource`: every `TempMessageResource` field plus `message`, the stored parsed message, and `truncated`.

**Example**

```ts
const temp = createTempMail({ inboxToken: 'oe_inbox_Vb3kT9qLm2Xw7RzN4pYc6HfJ1sGa5Ed8KuQo0iWnS2e' })

const detail = await temp.getMessage('tinb_k7m2q9xw4bdp', 'thr_9e3b7c1a5f2d8e40b6a9c3f1')

console.log(detail.subject, detail.truncated)
console.log(detail.message.decodedBody)
```

**Notes**

- A message this lease cannot see, deleted ones included, is 404 `resource_not_found`. An expired lease is 401 `inbox_expired`, and an install with no key to read the pool answers 503 `not_configured`.
- `message` is typed as a loose record, so narrow `decodedBody` to a string before rendering it.

Also available in: API [`GET /temp-mail/inboxes/{id}/messages/{messageId}`](https://openemail.uk/docs/api/reference/temp-mail#get-temp-mail-inboxes-id-messages-messageid); CLI [`openemail temp-mail get-message`](https://openemail.uk/docs/cli/reference/temp-mail#temp-mail-get-message).

### `tempMail.deleteMessage()`

Delete one message from a disposable inbox

```ts
deleteMessage(inboxId: string, messageId: string, options?: InboxScope): Promise<DeletedTempMessageResource>
```

Moves the message, attachments and all, to the bin of the mailbox that runs the pool, and no lease lists or opens it again. Nothing in this SDK restores it.

`messageCount` goes down by one. There is never a slot to free: an inbox keeps every message that reaches it, and `listMessages` pages through all of them.

**Parameters**

- `inboxId` (`string`, required): The `tinb_` id `create` returned. It is not checked against the token, which alone decides the inbox.
- `messageId` (`string`, required): An `id` from `listMessages`, such as `thr_` and 24 hex.
- `options.signal` (`AbortSignal`): Cancels the request.
- `options.inboxToken` (`string`): The `oe_inbox_` token `create` returned. Overrides the token given to `createTempMail` for this call, and is required on the `OpenEmail` client, which would otherwise send its API key.

**Returns**

`DeletedTempMessageResource` with `object` set to `temp_message`, the message `id` and `deleted: true`.

**Example**

```ts
const temp = createTempMail()

const inbox = await temp.create()

const { items } = await temp.listMessages(inbox.id, { inboxToken: inbox.token })

for (const message of items.filter((row) => row.spam)) {
    await temp.deleteMessage(inbox.id, message.id, { inboxToken: inbox.token })
}
```

**Notes**

- An unknown or already deleted message id is 404 `resource_not_found`, and an install with no key to read the pool answers 503 `not_configured`.
- Not retried automatically. If you repeat it yourself after a lost response, that 404 means the first attempt already worked.

Also available in: API [`DELETE /temp-mail/inboxes/{id}/messages/{messageId}`](https://openemail.uk/docs/api/reference/temp-mail#delete-temp-mail-inboxes-id-messages-messageid); CLI [`openemail temp-mail delete-message`](https://openemail.uk/docs/cli/reference/temp-mail#temp-mail-delete-message).

### `tempMail.listAttachments()`

List the attachments of a message, metadata only

```ts
listAttachments(inboxId: string, messageId: string, options?: InboxScope): Promise<Array<TempAttachmentResource>>
```

Resolves every attachment on a message as a plain array of metadata: `attachmentId`, `filename`, `mimeType` and `size` in decoded bytes, with `body` an empty string and `headers` empty. No route on a disposable inbox serves the bytes, and there is no per attachment fetch.

`filename` and `mimeType` are whatever the sender declared, and nothing here is scanned. A message this lease cannot see is 404 `resource_not_found`, and an install with no key to read the pool answers 503 `not_configured`.

**Parameters**

- `inboxId` (`string`, required): The `tinb_` id `create` returned. It is not checked against the token, which alone decides the inbox.
- `messageId` (`string`, required): An `id` from `listMessages`, such as `thr_` and 24 hex.
- `options.signal` (`AbortSignal`): Cancels the request.
- `options.inboxToken` (`string`): The `oe_inbox_` token `create` returned. Overrides the token given to `createTempMail` for this call, and is required on the `OpenEmail` client, which would otherwise send its API key.

**Returns**

`Array<TempAttachmentResource>`, each with `attachmentId`, `filename`, `mimeType`, `size` in decoded bytes, `body` as an empty string and `headers` as an empty array.

**Example**

```ts
const temp = createTempMail({ inboxToken: 'oe_inbox_Vb3kT9qLm2Xw7RzN4pYc6HfJ1sGa5Ed8KuQo0iWnS2e' })

const attachments = await temp.listAttachments('tinb_k7m2q9xw4bdp', 'thr_9e3b7c1a5f2d8e40b6a9c3f1')

for (const file of attachments) console.log(file.filename, file.size)
```

**Notes**

- Listing attachments does not mark the message seen.
- Check `attachmentCount` from `listMessages` first to skip this call for messages with none.

Also available in: API [`GET /temp-mail/inboxes/{id}/messages/{messageId}/attachments`](https://openemail.uk/docs/api/reference/temp-mail#get-temp-mail-inboxes-id-messages-messageid-attachments); CLI [`openemail temp-mail list-attachments`](https://openemail.uk/docs/cli/reference/temp-mail#temp-mail-list-attachments).
