> ## Documentation Index
> Fetch the complete documentation index at: https://inbound.new/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Authenticate a mailbox



## OpenAPI

````yaml https://inbound.new/openapi.json post /api/e2/mailboxes/authenticate
openapi: 3.1.0
info:
  title: Inbound Email API
  description: >+

    # Inbound API


    The Inbound API allows you to manage email infrastructure programmatically -
    domains, email addresses, webhooks, and more.


    ## Authentication


    All API requests require a Bearer token in the Authorization header:


    ```bash

    curl -H "Authorization: Bearer YOUR_API_KEY" \
      https://inbound.new/api/e2/domains
    ```


    ## Base URL


    ```

    https://inbound.new/api/e2

    ```


    ## Quick Start


    1. **Create a domain** - Register your domain with Inbound

    2. **Configure DNS** - Add the provided DNS records to your domain

    3. **Create an email address** - Set up addresses to receive emails

    4. **Create an endpoint** - Configure where emails are delivered (webhook,
    forwarding, etc.)

  version: 2.0.0
servers:
  - url: https://inbound.new
    description: Production API server
security:
  - bearerAuth: []
tags:
  - name: Webhooks
    description: Webhooks sent by Inbound to your configured endpoints when events occur.
  - name: Emails
    description: >-
      Send, list, and manage emails. Supports immediate sending, scheduling,
      replies, and retry functionality.
  - name: Mail
    description: >-
      Inbox and thread views for received emails. Filter by domain, address, or
      search.
  - name: Domains
    description: >-
      Manage domains for sending and receiving emails. Domains must be verified
      via DNS before use.
  - name: Endpoints
    description: >-
      Configure where incoming emails are delivered - webhooks, email
      forwarding, or custom handlers.
  - name: Email Addresses
    description: Create and manage email addresses on your verified domains.
  - name: Attachments
    description: Download email attachments using authenticated requests.
paths:
  /api/e2/mailboxes/authenticate:
    post:
      tags:
        - Mailboxes
      summary: Authenticate a mailbox
      operationId: postApiE2MailboxesAuthenticate
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                loginAddress:
                  minLength: 3
                  maxLength: 255
                  type: string
                password:
                  minLength: 1
                  maxLength: 1024
                  type: string
              required:
                - loginAddress
                - password
          application/x-www-form-urlencoded:
            schema:
              type: object
              properties:
                loginAddress:
                  minLength: 3
                  maxLength: 255
                  type: string
                password:
                  minLength: 1
                  maxLength: 1024
                  type: string
              required:
                - loginAddress
                - password
          multipart/form-data:
            schema:
              type: object
              properties:
                loginAddress:
                  minLength: 3
                  maxLength: 255
                  type: string
                password:
                  minLength: 1
                  maxLength: 1024
                  type: string
              required:
                - loginAddress
                - password
      responses:
        '200':
          description: Response for status 200
          content:
            application/json:
              schema:
                type: object
                properties:
                  credentialId:
                    type: string
                  userId:
                    type: string
                  loginAddress:
                    type: string
                  type:
                    const: mailbox
                    type: string
                  sendingMode:
                    type: string
                    enum:
                      - identity
                      - scoped_domains
                  sendingName:
                    nullable: true
                    anyOf:
                      - type: string
                      - type: 'null'
                  sendingAddress:
                    nullable: true
                    anyOf:
                      - type: string
                      - type: 'null'
                  accessMode:
                    type: string
                    enum:
                      - read
                      - read_write
                  scopes:
                    type: array
                    items:
                      type: object
                      properties:
                        id:
                          type: string
                        type:
                          type: string
                          enum:
                            - domain
                            - address
                        domainId:
                          type: string
                        domain:
                          type: string
                        address:
                          nullable: true
                          anyOf:
                            - type: string
                            - type: 'null'
                      required:
                        - id
                        - type
                        - domainId
                        - domain
                        - address
                required:
                  - credentialId
                  - userId
                  - loginAddress
                  - type
                  - sendingMode
                  - sendingName
                  - sendingAddress
                  - accessMode
                  - scopes
        '400':
          description: Response for status 400
          content:
            application/json:
              schema:
                type: object
                properties:
                  error:
                    type: string
                required:
                  - error
        '401':
          description: Response for status 401
          content:
            application/json:
              schema:
                type: object
                properties:
                  error:
                    type: string
                required:
                  - error
        '403':
          description: Response for status 403
          content:
            application/json:
              schema:
                type: object
                properties:
                  error:
                    type: string
                required:
                  - error
        '429':
          description: Response for status 429
          content:
            application/json:
              schema:
                type: object
                properties:
                  error:
                    type: string
                required:
                  - error
        '500':
          description: Response for status 500
          content:
            application/json:
              schema:
                type: object
                properties:
                  error:
                    type: string
                required:
                  - error
        '503':
          description: Response for status 503
          content:
            application/json:
              schema:
                type: object
                properties:
                  error:
                    type: string
                required:
                  - error
components:
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      bearerFormat: API Key
      description: >-
        Your Inbound API key. Include it in the Authorization header as: Bearer
        <your-api-key>

````