Provisioning API
List mailboxes for a sender
const url = 'https://live-api.customers.ac/v1/senders/snd_a1b2c3d4-e5f6-7890-abcd-ef1234567890/mailboxes?page%5Bsize%5D=25&filter%5Bstatus%5D=pending&include=credentials';const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request GET \ --url 'https://live-api.customers.ac/v1/senders/snd_a1b2c3d4-e5f6-7890-abcd-ef1234567890/mailboxes?page%5Bsize%5D=25&filter%5Bstatus%5D=pending&include=credentials' \ --header 'Authorization: Bearer <token>'Returns all mailboxes belonging to a sender. By default, credentials are not included. Pass include=credentials to include IMAP and SMTP credentials in the response.
Security note: Only request credentials when you need them. Credential responses are logged separately for audit purposes.
Authorizations
Section titled “Authorizations”Parameters
Section titled “Parameters”Path Parameters
Section titled “Path Parameters”Example
snd_a1b2c3d4-e5f6-7890-abcd-ef1234567890The unique identifier of the sender.
Query Parameters
Section titled “Query Parameters”Maximum number of records to return. Default: 25, maximum: 100.
Opaque cursor returned by a previous list response. Pass this to fetch the next page.
The current lifecycle status of a mailbox.
Return only mailboxes with this status.
Return only mailboxes on this domain.
Comma-separated list of related resources to include. Supported values: credentials.
Responses
Section titled “Responses”A paginated list of mailboxes.
object
object
Unique identifier for the mailbox.
The domain this mailbox belongs to.
The sender this mailbox belongs to (denormalized for convenience).
The full email address of this mailbox.
The display name configured on this mailbox.
The current lifecycle status of a mailbox.
IMAP and SMTP credentials. Only included when ?include=credentials is passed. Omitted by default for security.
object
object
IMAP server hostname.
IMAP server port.
IMAP login username (typically the email address).
IMAP login password.
Connection encryption method.
object
SMTP server hostname.
SMTP server port.
SMTP login username (typically the email address).
SMTP login password.
Connection encryption method.
Cursor-based pagination metadata.
object
true if there are more records after this page.
Pass this value as page[after] to fetch the next page. null when there are no more records.
Example
{ "data": [ { "id": "mbx_f6a7b8c9-d0e1-2345-f678-901234567890", "domain_id": "dom_d4e5f6a7-b8c9-0123-def4-567890123456", "sender_id": "snd_a1b2c3d4-e5f6-7890-abcd-ef1234567890", "email": "jane@outbound.acme.com", "display_name": "Jane Doe", "status": "pending", "credentials": { "mailbox_id": "mbx_f6a7b8c9-d0e1-2345-f678-901234567890", "email": "jane@outbound.acme.com", "imap": { "host": "outlook.office365.com", "port": 993, "username": "jane@outbound.acme.com", "password": "xK9#mP2$vL5nQ8wR", "encryption": "SSL/TLS" }, "smtp": { "host": "smtp.office365.com", "port": 587, "username": "jane@outbound.acme.com", "password": "xK9#mP2$vL5nQ8wR", "encryption": "SSL/TLS" } }, "created_at": "2026-03-21T14:30:00Z", "updated_at": "2026-03-21T14:35:00Z" } ], "pagination": { "next_cursor": "eyJpZCI6InVzcl96OXk4eDd3NiJ9" }}Authentication failed. The API key is missing or invalid.
object
object
A machine-readable error code.
A human-readable explanation of the error.
A link to the documentation page for this error code.
For validation errors, a list of individual field-level problems.
object
The field that caused the error, in dot notation.
A machine-readable code for this specific validation issue.
A human-readable explanation.
Examples
No API key provided
{ "error": { "code": "auth.missing_key", "message": "No API key was provided. Include your key in the Authorization header: Bearer sac_live_xxxxx.", "doc_url": "https://docs.sending.ac/errors/auth-missing-key" }}Invalid API key
{ "error": { "code": "auth.invalid_key", "message": "The API key provided is invalid or has been revoked.", "doc_url": "https://docs.sending.ac/errors/auth-invalid-key" }}The API key does not have the required scope for this operation.
object
object
A machine-readable error code.
A human-readable explanation of the error.
A link to the documentation page for this error code.
For validation errors, a list of individual field-level problems.
object
The field that caused the error, in dot notation.
A machine-readable code for this specific validation issue.
A human-readable explanation.
Example
{ "error": { "code": "auth.insufficient_scope", "message": "Your API key does not have the 'senders:write' scope required for this operation.", "doc_url": "https://docs.sending.ac/errors/auth-insufficient-scope" }}The requested resource does not exist.
object
object
A machine-readable error code.
A human-readable explanation of the error.
A link to the documentation page for this error code.
For validation errors, a list of individual field-level problems.
object
The field that caused the error, in dot notation.
A machine-readable code for this specific validation issue.
A human-readable explanation.
Example
{ "error": { "code": "resource.not_found", "message": "No sender found with ID snd_a1b2c3d4-e5f6-7890-abcd-ef1234567890.", "doc_url": "https://docs.sending.ac/errors/resource-not-found" }}You have exceeded the rate limit. Wait and retry.
object
object
A machine-readable error code.
A human-readable explanation of the error.
A link to the documentation page for this error code.
For validation errors, a list of individual field-level problems.
object
The field that caused the error, in dot notation.
A machine-readable code for this specific validation issue.
A human-readable explanation.
Example
{ "error": { "code": "rate.quota_exceeded", "message": "Rate limit exceeded. You may make 120 requests per minute. Retry after 30 seconds.", "doc_url": "https://docs.sending.ac/errors/rate-quota-exceeded" }}Headers
Section titled “Headers”Example
30Number of seconds to wait before retrying.
Example
120The maximum number of requests allowed per minute.
Example
0The number of requests remaining in the current window.
Example
1711267260Unix timestamp when the rate limit window resets.