> ## Documentation Index
> Fetch the complete documentation index at: https://aisa.one/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# List And Create Inbox API Keys

> Retrieve a list of API keys for a specific inbox or create a new API key with optional permissions and name.



## OpenAPI

````yaml openapi/agentmail.json GET /apis/v1/agentmail/inboxes/{inbox_id}/api-keys
openapi: 3.1.0
info:
  description: ''
  title: AgentMail API
  version: '1'
  x-aisa-capabilities:
    idempotency: Idempotency-Key
    max_price: X-AISA-Max-Price-USD
    quote:
      header: X-AISA-Cost-Mode
      value: quote
  x-aisa-configured-paths:
    - /apis/v1/agentmail/api-keys
    - /apis/v1/agentmail/api-keys/{api_key_id}
    - /apis/v1/agentmail/domains
    - /apis/v1/agentmail/domains/{domain_id}
    - /apis/v1/agentmail/domains/{domain_id}/verify
    - /apis/v1/agentmail/domains/{domain_id}/zone-file
    - /apis/v1/agentmail/drafts
    - /apis/v1/agentmail/drafts/{draft_id}
    - /apis/v1/agentmail/drafts/{draft_id}/attachments/{attachment_id}
    - /apis/v1/agentmail/inboxes
    - /apis/v1/agentmail/inboxes/{inbox_id}
    - /apis/v1/agentmail/inboxes/{inbox_id}/api-keys
    - /apis/v1/agentmail/inboxes/{inbox_id}/api-keys/{api_key_id}
    - /apis/v1/agentmail/inboxes/{inbox_id}/drafts
    - /apis/v1/agentmail/inboxes/{inbox_id}/drafts/{draft_id}
    - >-
      /apis/v1/agentmail/inboxes/{inbox_id}/drafts/{draft_id}/attachments/{attachment_id}
    - /apis/v1/agentmail/inboxes/{inbox_id}/drafts/{draft_id}/send
    - /apis/v1/agentmail/inboxes/{inbox_id}/events
    - /apis/v1/agentmail/inboxes/{inbox_id}/lists/{direction}/{type}
    - /apis/v1/agentmail/inboxes/{inbox_id}/lists/{direction}/{type}/{entry}
    - /apis/v1/agentmail/inboxes/{inbox_id}/messages
    - /apis/v1/agentmail/inboxes/{inbox_id}/messages/send
    - /apis/v1/agentmail/inboxes/{inbox_id}/messages/{message_id}
    - >-
      /apis/v1/agentmail/inboxes/{inbox_id}/messages/{message_id}/attachments/{attachment_id}
    - /apis/v1/agentmail/inboxes/{inbox_id}/messages/{message_id}/forward
    - /apis/v1/agentmail/inboxes/{inbox_id}/messages/{message_id}/raw
    - /apis/v1/agentmail/inboxes/{inbox_id}/messages/{message_id}/reply
    - /apis/v1/agentmail/inboxes/{inbox_id}/messages/{message_id}/reply-all
    - /apis/v1/agentmail/inboxes/{inbox_id}/metrics
    - /apis/v1/agentmail/inboxes/{inbox_id}/threads
    - /apis/v1/agentmail/inboxes/{inbox_id}/threads/{thread_id}
    - >-
      /apis/v1/agentmail/inboxes/{inbox_id}/threads/{thread_id}/attachments/{attachment_id}
    - /apis/v1/agentmail/lists/{direction}/{type}
    - /apis/v1/agentmail/lists/{direction}/{type}/{entry}
    - /apis/v1/agentmail/metrics
    - /apis/v1/agentmail/threads
    - /apis/v1/agentmail/threads/{thread_id}
    - /apis/v1/agentmail/threads/{thread_id}/attachments/{attachment_id}
  x-aisa-document:
    facts_hash: 9255366d22784f8aaa8fdf77c4a8ba89a12379e2b6b68f21bfcf09360afd4e63
    generator_version: '2'
    protocol_version: '1'
    schema_version: '1'
    composer_version: '13'
    response_pending: []
    document_hash: sha256:964edddd7b367f2a812e1f909bbc3cb3afa07afdcbeb867c833fcb8ec9cd7905
  x-aisa-plans:
    builder: 1
    display_plan: payg
    payg: 1
    similarweb_payg: 1
    team: 1
    version: e70a0959cd1b93b84ae16dffd7a538273ddb9c1d46277b82823c37ff1b6bc0fb
  x-aisa-provider: agentmail
  x-aisa-catalogs:
    agentmail:
      title: AgentMail API
      description: ''
      x-aisa-document:
        facts_hash: 9255366d22784f8aaa8fdf77c4a8ba89a12379e2b6b68f21bfcf09360afd4e63
        generator_version: '2'
        protocol_version: '1'
        schema_version: '1'
      x-aisa-plans:
        builder: 1
        display_plan: payg
        payg: 1
        similarweb_payg: 1
        team: 1
        version: e70a0959cd1b93b84ae16dffd7a538273ddb9c1d46277b82823c37ff1b6bc0fb
      x-aisa-capabilities:
        idempotency: Idempotency-Key
        max_price: X-AISA-Max-Price-USD
        quote:
          header: X-AISA-Cost-Mode
          value: quote
servers:
  - url: https://api.aisa.one
security:
  - bearerAuth: []
paths:
  /apis/v1/agentmail/inboxes/{inbox_id}/api-keys:
    get:
      tags:
        - default
      summary: List And Create Inbox API Keys
      description: >-
        Retrieve a list of API keys for a specific inbox or create a new API key
        with optional permissions and name.
      operationId: get_any_agentmail_apis_v1_agentmail_inboxes_inbox_81bd1e
      parameters:
        - name: inbox_id
          in: path
          required: true
          schema:
            type: string
            description: The ID of the inbox.
            title: InboxId
        - name: limit
          in: query
          required: false
          schema:
            type: integer
            description: Limit of number of items returned.
            title: Limit
        - name: page_token
          in: query
          required: false
          schema:
            type: string
            description: Page token for pagination.
            title: PageToken
      responses:
        '200':
          description: Response with status 200
          content:
            application/json:
              schema:
                $ref: >-
                  #/components/schemas/ResponseD09F9471A0E8_apiKeys_ListApiKeysResponse
        default:
          content:
            application/json:
              schema: {}
          description: >-
            Error response; upstream passthrough responses may use provider
            formats
components:
  schemas:
    ResponseD09F9471A0E8_apiKeys_ListApiKeysResponse:
      type: object
      properties:
        count:
          $ref: '#/components/schemas/ResponseD09F9471A0E8_Count'
        next_page_token:
          $ref: '#/components/schemas/ResponseD09F9471A0E8_PageToken'
        api_keys:
          type: array
          items:
            $ref: '#/components/schemas/ResponseD09F9471A0E8_apiKeys_ApiKey'
          description: |-
            Every credential family, ordered by `created_at`. `type` restricts
            to one family.
      required:
        - count
        - api_keys
      title: ListApiKeysResponse
    ResponseD09F9471A0E8_Count:
      type: integer
      description: Number of items returned.
      title: Count
    ResponseD09F9471A0E8_PageToken:
      type: string
      description: Page token for pagination.
      title: PageToken
    ResponseD09F9471A0E8_apiKeys_ApiKey:
      oneOf:
        - $ref: '#/components/schemas/ResponseD09F9471A0E8_apiKeys_BearerApiKey'
        - $ref: >-
            #/components/schemas/ResponseD09F9471A0E8_apiKeys_PublicKeyCredential
      description: |-
        One credential of any family. `type` is `bearer` or `public_key`. A
        public key carrying `status` is a sign-in key; one without it is a
        registered signing key.
      title: ApiKey
    ResponseD09F9471A0E8_apiKeys_BearerApiKey:
      type: object
      properties:
        type:
          type: string
          enum:
            - bearer
        api_key_id:
          $ref: '#/components/schemas/ResponseD09F9471A0E8_apiKeys_ApiKeyId'
        prefix:
          $ref: '#/components/schemas/ResponseD09F9471A0E8_apiKeys_Prefix'
        name:
          $ref: '#/components/schemas/ResponseD09F9471A0E8_apiKeys_Name'
        pod_id:
          $ref: '#/components/schemas/ResponseD09F9471A0E8_apiKeys_PodScopeId'
        inbox_id:
          $ref: '#/components/schemas/ResponseD09F9471A0E8_apiKeys_InboxScopeId'
        used_at:
          $ref: '#/components/schemas/ResponseD09F9471A0E8_apiKeys_UsedAt'
        permissions:
          $ref: '#/components/schemas/ResponseD09F9471A0E8_apiKeys_ApiKeyPermissions'
        created_at:
          $ref: '#/components/schemas/ResponseD09F9471A0E8_apiKeys_CreatedAt'
        updated_at:
          $ref: '#/components/schemas/ResponseD09F9471A0E8_apiKeys_UpdatedAt'
        expires_at:
          $ref: '#/components/schemas/ResponseD09F9471A0E8_apiKeys_ExpiresAt'
      required:
        - type
        - api_key_id
        - prefix
        - name
        - created_at
        - updated_at
      description: An API key presented as a bearer token in the `Authorization` header.
      title: BearerApiKey
    ResponseD09F9471A0E8_apiKeys_PublicKeyCredential:
      type: object
      properties:
        type:
          type: string
          enum:
            - public_key
        api_key_id:
          $ref: '#/components/schemas/ResponseD09F9471A0E8_apiKeys_ApiKeyId'
        client_id:
          $ref: '#/components/schemas/ResponseD09F9471A0E8_apiKeys_PublicKeyClientId'
        name:
          $ref: '#/components/schemas/ResponseD09F9471A0E8_apiKeys_Name'
        public_key:
          $ref: '#/components/schemas/ResponseD09F9471A0E8_apiKeys_PublicKeyMaterial'
        pod_id:
          $ref: '#/components/schemas/ResponseD09F9471A0E8_apiKeys_PodScopeId'
        inbox_id:
          $ref: '#/components/schemas/ResponseD09F9471A0E8_apiKeys_InboxScopeId'
        status:
          $ref: '#/components/schemas/ResponseD09F9471A0E8_apiKeys_PublicKeyStatus'
        used_at:
          $ref: '#/components/schemas/ResponseD09F9471A0E8_apiKeys_UsedAt'
        permissions:
          $ref: '#/components/schemas/ResponseD09F9471A0E8_apiKeys_ApiKeyPermissions'
        created_by:
          $ref: '#/components/schemas/ResponseD09F9471A0E8_apiKeys_ApiKeyCreator'
        created_at:
          $ref: '#/components/schemas/ResponseD09F9471A0E8_apiKeys_CreatedAt'
        updated_at:
          $ref: '#/components/schemas/ResponseD09F9471A0E8_apiKeys_UpdatedAt'
        expires_at:
          $ref: '#/components/schemas/ResponseD09F9471A0E8_apiKeys_ExpiresAt'
      required:
        - type
        - api_key_id
        - name
        - permissions
        - created_by
        - created_at
        - updated_at
      description: |-
        An AgentID sign-in credential, scoped like a bearer key; `api_key_id` is
        the JWS `kid`. A sign-in key carries `status`, gains `public_key` once
        the client has proved it, expires 30 days after
        activation, and carries exactly `app_connect` and
        `app_share_owner`, snapshotted from the bearer key that created it
        and enforced from the key itself.
      title: PublicKeyCredential
    ResponseD09F9471A0E8_apiKeys_ApiKeyId:
      type: string
      description: ID of api key.
      title: ApiKeyId
    ResponseD09F9471A0E8_apiKeys_Prefix:
      type: string
      description: Prefix of api key.
      title: Prefix
    ResponseD09F9471A0E8_apiKeys_Name:
      type: string
      description: Name of api key.
      title: Name
    ResponseD09F9471A0E8_apiKeys_PodScopeId:
      type: string
      description: >-
        Pod ID the api key is scoped to. If set, the key can only access
        resources within this pod.
      title: PodScopeId
    ResponseD09F9471A0E8_apiKeys_InboxScopeId:
      type: string
      description: >-
        Inbox ID the api key is scoped to. If set, the key can only access
        resources within this inbox.
      title: InboxScopeId
    ResponseD09F9471A0E8_apiKeys_UsedAt:
      type: string
      format: date-time
      description: Time at which api key was last used.
      title: UsedAt
    ResponseD09F9471A0E8_apiKeys_ApiKeyPermissions:
      type: object
      properties:
        inbox_read:
          type: boolean
          description: Read inbox details.
        inbox_create:
          type: boolean
          description: Create new inboxes.
        inbox_update:
          type: boolean
          description: Update inbox settings.
        inbox_delete:
          type: boolean
          description: Delete inboxes.
        message_read:
          type: boolean
          description: Read messages. Also required to read threads.
        message_reply:
          type: boolean
          description: >-
            Reply and reply-all when the request is signed with a registered
            public key. Bearer keys reply with `message_send`.
        message_send:
          type: boolean
          description: Send messages.
        message_update:
          type: boolean
          description: Update message labels. Also required to update threads.
        message_delete:
          type: boolean
          description: Delete messages. Also required to delete threads.
        label_spam_read:
          type: boolean
          description: Access messages labeled spam.
        label_blocked_read:
          type: boolean
          description: Access messages labeled blocked.
        label_unauthenticated_read:
          type: boolean
          description: Access messages labeled unauthenticated.
        label_trash_read:
          type: boolean
          description: Access messages labeled trash.
        draft_read:
          type: boolean
          description: Read drafts.
        draft_create:
          type: boolean
          description: Create drafts.
        draft_update:
          type: boolean
          description: Update drafts.
        draft_delete:
          type: boolean
          description: Delete drafts.
        draft_send:
          type: boolean
          description: Send drafts.
        webhook_read:
          type: boolean
          description: Read webhook configurations.
        webhook_create:
          type: boolean
          description: Create webhooks.
        webhook_update:
          type: boolean
          description: Update webhooks.
        webhook_delete:
          type: boolean
          description: Delete webhooks.
        domain_read:
          type: boolean
          description: Read domain details.
        domain_create:
          type: boolean
          description: Create domains.
        domain_update:
          type: boolean
          description: Update domains.
        domain_delete:
          type: boolean
          description: Delete domains.
        list_entry_read:
          type: boolean
          description: Read list entries.
        list_entry_create:
          type: boolean
          description: Create list entries.
        list_entry_delete:
          type: boolean
          description: Delete list entries.
        metrics_read:
          type: boolean
          description: Read metrics.
        api_key_read:
          type: boolean
          description: Read API keys.
        api_key_create:
          type: boolean
          description: Create API keys.
        api_key_update:
          type: boolean
          description: Update API keys.
        api_key_delete:
          type: boolean
          description: Delete API keys.
        app_connect:
          type: boolean
          description: >-
            Sign in to apps as an inbox: connect an app, authorize an inbox, and
            mint the

            sign-in keys. Omitted on a new bearer key means false, whatever else
            the key holds.
        app_share_owner:
          type: boolean
          description: >-
            Share the organization owner's name and email with apps at sign-in.
            One permission

            for both values.
        account_update:
          type: boolean
          description: >-
            Update accounts: disable or re-enable an inbox's sign-in at an app.
            Reading accounts

            needs only `inbox_read`.
        pod_read:
          type: boolean
          description: Read pods.
        pod_create:
          type: boolean
          description: Create pods.
        pod_update:
          type: boolean
          description: Update pods.
        pod_delete:
          type: boolean
          description: Delete pods.
        calendar_read:
          type: boolean
          description: Read inbox calendar settings.
        calendar_update:
          type: boolean
          description: Update inbox calendar settings.
        calendar_event_read:
          type: boolean
          description: >-
            Read calendar events, and receive `calendar.event.*` webhook and
            WebSocket events.
        calendar_event_create:
          type: boolean
          description: Create calendar events.
        calendar_event_update:
          type: boolean
          description: Update calendar events and respond to invitations.
        calendar_event_delete:
          type: boolean
          description: Delete calendar events.
      description: >-
        Granular permissions for the API key. When ommitted all permissions are
        granted. Otherwise, only permissions set to true are granted.
      title: ApiKeyPermissions
    ResponseD09F9471A0E8_apiKeys_CreatedAt:
      type: string
      format: date-time
      description: Time at which api key was created.
      title: CreatedAt
    ResponseD09F9471A0E8_apiKeys_UpdatedAt:
      type: string
      format: date-time
      description: Time at which api key was last updated.
      title: UpdatedAt
    ResponseD09F9471A0E8_apiKeys_ExpiresAt:
      type: string
      format: date-time
      description: Time at which api key expires. Omitted when it does not expire.
      title: ExpiresAt
    ResponseD09F9471A0E8_apiKeys_PublicKeyClientId:
      type: string
      description: >-
        Caller-chosen alias for a public key, unique within the organization and

        reusable after deletion. Accepted in place of `api_key_id` on get,
        update,

        and delete. Registration is idempotent on it: the same alias returns the

        existing key, a conflicting one returns `409`. URL-safe; no slash or
        `@`.
      title: PublicKeyClientId
    ResponseD09F9471A0E8_apiKeys_PublicKeyMaterial:
      type: object
      properties:
        jwk:
          $ref: '#/components/schemas/ResponseD09F9471A0E8_apiKeys_PublicJwk'
        fingerprint:
          type: string
          pattern: ^[A-Za-z0-9_-]{43}$
          minLength: 43
          maxLength: 43
          description: RFC 7638 SHA-256 JWK thumbprint encoded as unpadded base64url.
      required:
        - jwk
        - fingerprint
      description: >-
        Registered public key material and its server-computed RFC 7638
        thumbprint.
      title: PublicKeyMaterial
    ResponseD09F9471A0E8_apiKeys_PublicKeyStatus:
      type: string
      enum:
        - pending
        - active
      description: |-
        Lifecycle of a sign-in key: `pending` until the client finishes
        creating it on the AgentID page, `active` once it can sign in as the
        inbox. Absent on a registered key.
      title: PublicKeyStatus
    ResponseD09F9471A0E8_apiKeys_ApiKeyCreator:
      type: object
      properties:
        api_key_id:
          $ref: '#/components/schemas/ResponseD09F9471A0E8_apiKeys_ApiKeyId'
      required:
        - api_key_id
      description: >-
        The bearer API key that created the credential. Provenance only; the
        credential outlives it.
      title: ApiKeyCreator
    ResponseD09F9471A0E8_apiKeys_PublicJwk:
      type: object
      properties:
        kty:
          type: string
          enum:
            - EC
        crv:
          type: string
          enum:
            - P-256
        x:
          $ref: >-
            #/components/schemas/ResponseD09F9471A0E8_apiKeys_PublicJwkCoordinate
        'y':
          $ref: >-
            #/components/schemas/ResponseD09F9471A0E8_apiKeys_PublicJwkCoordinate
      required:
        - kty
        - crv
        - x
        - 'y'
      description: >-
        A public P-256 JWK. The object accepts exactly `kty`, `crv`, `x`, and
        `y`.

        Private key material such as `d`, embedded key IDs, and all other
        members

        are rejected. The server also rejects coordinates that are not a point
        on

        P-256.
      title: PublicJwk
    ResponseD09F9471A0E8_apiKeys_PublicJwkCoordinate:
      type: string
      pattern: ^[A-Za-z0-9_-]{43}$
      minLength: 43
      maxLength: 43
      description: A 32-byte P-256 coordinate encoded as unpadded base64url.
      title: PublicJwkCoordinate
  securitySchemes:
    bearerAuth:
      scheme: bearer
      type: http

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.