Developer documentationAPI
Once Email API
Public developer documentation for automated email testing: authentication, quotas, errors, and safe-use rules.
Send Authorization: Bearer oe_live_… with every request. A key is shown once; keep it in a secrets manager and never place it in browser code, logs, or Git.
Authorization: Bearer oe_live_your_key- Proceed only with explicitly authorized API access and already issued, valid credentials with the minimum necessary permissions. Store them in a process secret facility; without this access, stop at reviewing the documentation and downloads. Create a temporary inbox and retain its inbox ID.
- Ask your test system to send mail to that address.
- Poll the message list with backoff; avoid rapid empty polling.
- Read the target message, complete assertions, then delete the inbox.
Private Beta endpoints
POST /v1/inboxesGET /v1/inboxes/{inboxId}/messagesGET /v1/inboxes/{inboxId}/messages/{uid}GET /v1/inboxes/{inboxId}/messages/{uid}/attachments/{cid}DELETE /v1/inboxes/{inboxId}Status codes
400Invalid request
401Missing or invalid key
403Plan or resource denied
404Resource not found
413Response or attachment too large
429Rate or monthly quota reached
503Temporary service failure
Open-source prerelease candidates are available for TypeScript, Python, Java, Go, .NET, PHP, and Ruby. Native CI passed on Linux, macOS, and Windows; language registry releases are not available yet.
The Developer plan uses a monthly Stripe subscription and monthly API allowance. Stored-value recharge is not offered. Live checkout remains closed until payment and refund gates pass.
Use the API only on systems you are authorized to test. Spam, policy evasion, account abuse, monitoring other people’s communications, and long-term personal-data storage are prohibited. Message bodies and attachments do not enter account history.
API Demo
Cross-platform safe example
For owned or authorized test systems; runs on Windows, Linux, and macOS with Node.js 20+.
node demos/api/authorized-workflow.mjs
ONCE_EMAIL_API_KEY <- process secret facility
create inbox -> list messages -> finally delete inboxOpen full demoComplete usage guide
Download the versioned local bundle
Use only an application you own or are explicitly authorized to test. Once Email receives mail only; it does not send mail or automate third-party registrations.
Open SHA256SUMS before extracting the file.
Exact local starting point
node demos/api/authorized-workflow.mjsFrom download to a clean first run
- Confirm ownership or explicit authorization; use local, test, or staging only.
- Proceed only with explicitly authorized API access and already issued, valid credentials with the minimum necessary permissions. Store them in a process secret facility; without this access, stop at reviewing the documentation and downloads.
- Download, verify, extract, and read README.md plus LOCAL-USAGE.md.
- Run the Node.js 20+ demo, then trigger one uniquely marked email from the authorized system.
- Poll with bounded backoff and one deadline; read only the unique match.
- Delete the inbox in finally and report cleanup failure separately.
Failure and recovery
Keep 400, 401, 403, 404, 413, 429, and 503 distinct. Timeout, ambiguity, extraction, assertion, and cleanup are also different failures. Retry only within one deadline and never turn a dependency failure into an empty inbox.