cherami.
API referenceInboxes and rules

Inspect receiving rules

GET /v1/inboxes/{inbox_id}/receiving-policy

Read as Markdown ↗

GET /v1/inboxes/{inbox_id}/receiving-policy

Requires a Claim-issued API key: Authorization: Bearer YOUR_CREDENTIAL.

GET /v1/inboxes/{inbox_id}/receiving-policy returns 200.

enabled: false pauses blocking without clearing either saved list. When enabled, any supported parsed From address matching an exact address or exact domain rejects the incoming mail. Empty lists block nothing. Local-part case matters; domain case does not. Plus tags and dots stay distinct. Each list has at most 100 normalized, unique entries. Domains are lowercase ASCII, including punycode, with no implicit subdomain matching.

revision is the saved version, starting at 0 for an unconfigured inbox. Missing, deleted and other-account inboxes return 404. Inspection is read-only and cannot promise the policy for a later receipt.

Only the human’s browser session can edit rules in Account → Receiving rules, not an API key or OAuth mail grant. See receiving rules for parsing boundaries and rejection behavior. From is sender-controlled, not authenticated identity; existing messages are never hidden or deleted by a policy change.

Parameters

ParameterLocationRequiredTypeMeaning
inbox_idpathYesstringOwned Cherami resource ID returned by the API.

curl example

Replace resource-ID placeholders with returned IDs. Supply CHERAMI_API_KEY through your private shell environment.

curl --silent --show-error --include --request GET \
  "https://cherami.to/v1/inboxes/INBOX_ID/receiving-policy" \
  --header "Authorization: Bearer $CHERAMI_API_KEY"

Responses

HTTP 200

Successful operation; inspect resource state and outcome fields.

  • X-Request-ID: Support correlation ID, not an idempotency key.

Content type: application/json.

Policy

{
  "inbox_id": "11111111-1111-4111-8111-111111111111",
  "enabled": true,
  "addresses": [],
  "domains": [],
  "revision": 0
}

HTTP 401

unauthorized: Provide a valid bearer credential. Use human-approved recovery if access is lost.

  • X-Request-ID: Support correlation ID, not an idempotency key.
  • WWW-Authenticate: "Bearer"

Content type: application/json.

Error

HTTP 404

not_found: Resource is absent or inaccessible to this account. Reply targets must be in the sending inbox.

  • X-Request-ID: Support correlation ID, not an idempotency key.

Content type: application/json.

Error

HTTP 500

internal_error: Operation failed; a write may already have happened. Follow the operation-specific recovery below.

  • X-Request-ID: Support correlation ID, not an idempotency key.

Content type: application/json.

Error

Schema: Policy

FieldRequiredTypeMeaning and constraints
inbox_idYesstringCherami resource ID, distinct from the RFC Message-ID. Use the returned value.
enabledYesboolean
addressesYesarray of stringmaxItems: 100
domainsYesarray of stringmaxItems: 100
revisionYesintegerZero when unconfigured. Inspection does not reserve a policy for later mail. minimum: 0

Schema: Error

FieldRequiredTypeMeaning and constraints
errorYesobject

error fields

FieldRequiredTypeMeaning and constraints
codeYesstringProgrammatic error code. Handle unrecognized codes by status and operation-specific recovery.
messageYesstringHuman-readable context, not a stable string to match.

HTTP conventions, errors and pagination · Download OpenAPI 3.1

On this page