Overview
The sending-integration API exposes TenantCore-defined operations for provider accounts already linked to your TenantCore account. The authorization chain remains:API key → TenantCore account UUID → TenantCore-owned integration/mailbox → provider action
The public API never accepts an arbitrary Microsoft tenant, arbitrary external mailbox, or raw provider mailbox identifier as authority to perform work.
Current public providers:
- Instantly
- PlusVibe
- Smartlead
- ManyReach
/v1 until their vendor-supported onboarding/OAuth access is available to TenantCore.
Provider credentials are submitted only when creating a TenantCore integration. TenantCore encrypts and stores them server-side. They are never returned by
/v1 list/detail endpoints.Create an integration
workspace_id:
PlusVibe workspace selection
If a PlusVibe key can access more than one workspace and noworkspace_id is supplied, TenantCore returns 400 plusvibe_workspace_required with a safe list of workspace IDs/names. Resubmit the create request with the selected workspace_id and a new idempotency key.
List integrations
Get one integration
404 integration_not_found shape as a nonexistent UUID.
Test provider connectivity
List eligible TenantCore mailboxes
Start Microsoft authorization for a mailbox
Use the TenantCore mailbox UUID returned from the mailbox API/integration mailbox list:integration_idmust belong to the authenticated TenantCore account.mailbox_idmust be a TenantCore mailbox UUID.- The mailbox’s parent tenant must be owned by the same account.
- The mailbox must have been provisioned by TenantCore.
- A mailbox already connected/pending on another sending platform is rejected.
auth_url in an interactive browser/popup. Do not attempt to parse or synthesize the URL/state yourself.
Check Microsoft authorization status
pendingconnectedfailedexpired
failed or expired, start a new authorization session with a new Idempotency-Key.
Reconcile provider state
Disconnect a mailbox
Delete an integration
One sending platform per mailbox
TenantCore enforces one active/pending sending-platform connection per mailbox. If a mailbox is already connected or connecting through another integration, a new connection attempt returns409 mailbox_already_connected_elsewhere.
Disconnect/switch the existing connection first.
Rate limiting and idempotency
Provider-backed integration writes are classified as Microsoft/provider-heavy operations. The current default is 12 operations per 10 minutes per TenantCore account, with a separate concurrency ceiling. Every integrationPOST or DELETE request requires Idempotency-Key.
OAuth status reads are also provider-heavy because checking status may call the provider. Ordinary list/detail reads remain in the normal read bucket.
Security boundaries
The public sending-integration API does not expose:- raw provider API passthrough
- encrypted provider credentials
- stored provider API keys
- mailbox passwords
- TOTP/OATH seeds or current MFA codes
- arbitrary external mailbox connection by email address
- arbitrary Microsoft tenant connection by tenant GUID
- managed-tenant provisioning or CSP operations