Postilio docs

Authentication and API keys

Every request to the API carries an API key as a bearer token:

curl https://api.postilio.eu/v1/domains \
  -H "Authorization: Bearer $POSTILIO_KEY"

SMTP uses the same keys: user name apikey, the key as the password (see Sending email).

Keys

A key belongs to one project and works only on that project's domains, messages, suppressions and webhooks. Create keys in the portal under Keys & SMTP: Owners and Admins of the organization in every project, Developers in the projects they have access to.

Live and test keys

WhatLive key pk_live_…Test key pk_test_…
Checks (sender domain, restrictions, suppression list, validation)yesthe same
Delivers mailyesnever: every message gets simulated events at once
Sandbox limitsyes, while the organization is in the sandboxno
Counts as usageyesno
Scopesanyemails:send and emails:read at most

Test and live messages are kept apart: a test key finds only test messages and a live key only live ones; the other kind answers 404. Webhook endpoints have a mode too: a test endpoint gets the events of test messages only. The simulator addresses are in Suppressions and test mode.

Scopes

A key has one or more scopes. A call outside them answers 403 with {"error": "insufficient_scope"}.

ScopeAllows
emails:sendPOST /v1/emails, and SMTP submission
emails:readGET /v1/emails/{id}
domains:manageGET /v1/domains, POST /v1/domains, GET /v1/domains/{id}, DELETE /v1/domains/{id}, POST /v1/domains/{id}/check
suppressions:manageGET /v1/suppressions, POST /v1/suppressions, DELETE /v1/suppressions/{id}
webhooks:manageeverything under /v1/webhooks

Give each key only what it needs: the key on a web server that sends sign-in codes needs emails:send, nothing more.

Restrictions

Two optional limits per key, set when you create it (at most 20 entries each):

Without restrictions a key sends from every verified domain of the project, from anywhere.

Errors

StatuserrorWhy
401invalid_api_keyno Authorization: Bearer pk_… header, or a key that does not exist or was revoked
403insufficient_scopethe key lacks the scope this call needs
403client_ip_not_allowedthe key is restricted to networks this request does not come from

A key of an organization that is being deleted stops working too, until the deletion is cancelled.