Overview
Mailbox API operations are resource-bound. TenantCore does not accept an arbitrary Microsoft mailbox, domain, or tenant and then operate on it. The authorization chain is:tenant_resource_id— TenantCore tenant-row UUIDdomain_id— TenantCore domain-row UUIDmailbox_id— TenantCore mailbox-row UUID
Idempotency-Key. Microsoft/Exchange-heavy mailbox operations use the public API’s expensive-operation rate-limit bucket.
List tenant mailboxes
Returns every mailbox already registered to an owned TenantCore tenant.tenant_resource_id where possible. The existing Microsoft tenant GUID remains accepted only because TenantCore resolves it against the authenticated account before returning data.
List domain mailboxes
Returns mailboxes through an owned TenantCore domain UUID.404 domain_not_found shape as a nonexistent UUID.
Get one mailbox
Returns one mailbox strictly from its TenantCore mailbox UUID.security object is status-only. It never contains a password, external vault secret ID, TOTP seed, or current MFA code. sending_connection is null when TenantCore has no persisted sending-tool connection for the mailbox. Raw provider errors are never exposed; use has_error plus the integration/retry workflow instead.
Create mailboxes
Creates one or more mailboxes through an existing TenantCore domain UUID.domain string is retired. TenantCore now resolves the domain resource first, proves that its parent tenant belongs to the authenticated account, and only then calls Microsoft.
The domain name is not supplied separately. The path
domain_id is the authorization anchor.
Example response:
Mailbox creation errors
Retired free-form provisioning contract
POST /v1/domains/{domain_id}/mailboxes instead.
Reset mailbox password
Resets the Microsoft password for a TenantCore-created mailbox.
The older tenant-scoped reset route remains available for compatibility, but new integrations should use the mailbox UUID route above.
Get mailbox usage
Returns current stored daily usage and effective mailbox cap information.Delete mailbox
Permanently removes a TenantCore-created mailbox from Microsoft and TenantCore.request_id when support needs to trace the underlying operation.
Direct mailbox update remains retired
Send-limit enforcement
Sending limits are Exchange-enforced policies. Tenant-wide policy needs only an owned tenant. A domain override now requires a TenantCoredomain_id, not a free-form domain name.
Set enforcement
domain_id must belong to the same authenticated TenantCore tenant. A domain from another TenantCore account or another owned tenant cannot be used as the scope.
The old domain_scope: "mail.acmecorp.com" request field returns 410 domain_name_scope_retired so an old request cannot silently become tenant-wide enforcement.
Get enforcement policy
Tenant-wide:domain_id and readable domain_name. When no policy exists, daily_send_limit is null; that is a normal 200 response.
List enforcement scopes
domain_id as well as the readable domain name.
List effective mailbox policies
mailbox_id, so subsequent API actions do not need to use an email address as the resource identifier.
Remove enforcement
Tenant-wide:not_found result rather than treating that state as an API failure.
Public API security boundary
The mailbox API intentionally does not expose:- arbitrary Microsoft tenant or mailbox lookup
- mailbox password reveal
- external vault record IDs
- TOTP seed reveal
- current MFA-code generation
- raw Microsoft/Exchange responses
- generic Microsoft command passthrough
- arbitrary provider calls