Reference

API overview

The REST API: base URL, authentication, conventions, and the 17 operations shared by every client.

Base URL

https://api.goshenemail.com

All paths below are relative to it and versioned under /v1. The OpenAPI 3.1 document is served at /openapi.json and is the source the CLI schemas and MCP tool schemas are generated from.

Authentication

Every request carries Authorization: Bearer <key>, where the key is an account key (bze_) or a mailbox key (gme_). Each operation requires one scope, listed on its page. See Authentication.

Conventions

Operations

Inboxes

OperationMethod and pathScope
List inboxesGET /v1/inboxesinboxes:read
Create an inboxPOST /v1/inboxesinboxes:write
Get an inboxGET /v1/inboxes/{inboxId}inboxes:read
Update an inboxPATCH /v1/inboxes/{inboxId}inboxes:write
Delete an inboxDELETE /v1/inboxes/{inboxId}inboxes:write
Finish inbox setupPOST /v1/inboxes/{inboxId}/setupinboxes:write

Messages

OperationMethod and pathScope
List messagesGET /v1/inboxes/{inboxId}/messagesmessages:read
Search messagesGET /v1/inboxes/{inboxId}/messages/searchmessages:read
Get a messageGET /v1/inboxes/{inboxId}/messages/{messageId}messages:read
Send a messagePOST /v1/inboxes/{inboxId}/messages/sendmessages:send
Reply to a messagePOST /v1/inboxes/{inboxId}/messages/{messageId}/replymessages:send
Update message labelsPATCH /v1/inboxes/{inboxId}/messages/{messageId}/labelsmessages:write
Get an attachmentGET /v1/inboxes/{inboxId}/messages/{messageId}/attachments/{attachmentId}messages:read

Threads

OperationMethod and pathScope
List threadsGET /v1/inboxes/{inboxId}/threadsmessages:read
Get a threadGET /v1/inboxes/{inboxId}/threads/{threadId}messages:read
Update thread labelsPATCH /v1/inboxes/{inboxId}/threads/{threadId}/labelsmessages:write

Account

OperationMethod and pathScope
Get usageGET /v1/usageinboxes:read

Validation

The OpenAPI schemas describe most constraints. The server also enforces a few that JSON Schema cannot express: a body (text or html) is required on sends, text plus html must fit in 512 KiB, attachments must fit in 2 MiB combined, and to plus cc plus bcc is capped at 50. Requests that fail validation return invalid_argument (422) with a message naming the field.

Other endpoints

The /inbox-rpc/* and /rpc/* paths serve older clients and platform integrations and are not covered here.