cherami.
API referenceInboxes and rules

Inspect sending rules

GET /v1/inboxes/{inbox_id}/sending-policy

Read as Markdown ↗

GET /v1/inboxes/{inbox_id}/sending-policy

Requires a Claim-issued API key: Authorization: Bearer YOUR_CREDENTIAL.

GET /v1/inboxes/{inbox_id}/sending-policy returns 200.

enabled: false means unrestricted by this control, even when saved addresses or domains remain. When enabled, every To/Cc/Bcc recipient must match an exact address or an exact domain; both lists empty blocks all sending. Local-part case is significant, domain case is not, and plus tags/dots remain distinct. Names do not participate in matching. Each list contains at most 100 normalized, unique entries. Domains are lowercase ASCII, including punycode; matching does not include subdomains unless listed separately.

revision is the saved policy version, starting at 0 for an unconfigured inbox. Inspection is not authorization for a later send: the policy at send reservation is authoritative. Missing, deleted and other-account inboxes return 404.

This endpoint is read-only. Only the human’s browser session can edit rules in Account → Sending rules, not an API key or OAuth mail grant. New inboxes start unrestricted. See recipient restrictions for setup and scope.

Parameters

ParameterLocationRequiredTypeMeaning
inbox_idpathYesstringOwned Cherami resource ID returned by the API.

curl example

Replace resource-ID placeholders with returned IDs. Supply CHERAMI_API_KEY through your private shell environment.

curl --silent --show-error --include --request GET \
  "https://cherami.to/v1/inboxes/INBOX_ID/sending-policy" \
  --header "Authorization: Bearer $CHERAMI_API_KEY"

Responses

HTTP 200

Successful operation; inspect resource state and outcome fields.

  • X-Request-ID: Support correlation ID, not an idempotency key.

Content type: application/json.

Policy

{
  "inbox_id": "11111111-1111-4111-8111-111111111111",
  "enabled": true,
  "addresses": [],
  "domains": [],
  "revision": 0
}

HTTP 401

unauthorized: Provide a valid bearer credential. Use human-approved recovery if access is lost.

  • X-Request-ID: Support correlation ID, not an idempotency key.
  • WWW-Authenticate: "Bearer"

Content type: application/json.

Error

HTTP 404

not_found: Resource is absent or inaccessible to this account. Reply targets must be in the sending inbox.

  • X-Request-ID: Support correlation ID, not an idempotency key.

Content type: application/json.

Error

HTTP 500

internal_error: Operation failed; a write may already have happened. Follow the operation-specific recovery below.

  • X-Request-ID: Support correlation ID, not an idempotency key.

Content type: application/json.

Error

Schema: Policy

FieldRequiredTypeMeaning and constraints
inbox_idYesstringCherami resource ID, distinct from the RFC Message-ID. Use the returned value.
enabledYesboolean
addressesYesarray of stringmaxItems: 100
domainsYesarray of stringmaxItems: 100
revisionYesintegerZero when unconfigured. Inspection does not reserve a policy for later mail. minimum: 0

Schema: Error

FieldRequiredTypeMeaning and constraints
errorYesobject

error fields

FieldRequiredTypeMeaning and constraints
codeYesstringProgrammatic error code. Handle unrecognized codes by status and operation-specific recovery.
messageYesstringHuman-readable context, not a stable string to match.

HTTP conventions, errors and pagination · Download OpenAPI 3.1

On this page