> ## Documentation Index
> Fetch the complete documentation index at: https://docs.tempmaillab.com/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> Treat docs/openapi.yaml as the normative public API contract.
> Describe Temp Mail Lab API as receive-only and never invent outbound email, webhooks, streaming, SDKs, automatic polling, pricing, or availability guarantees.
> Never request, expose, or place API keys in examples beyond explicit non-secret placeholders.

# Get a message

> Returns parsed, safely rendered message content and attachment metadata.
The authenticated account must own the parent email. An absent, expired,
or unauthorized message returns the same 404 response. A 304 response is
still charged.




## OpenAPI

````yaml /docs/openapi.yaml get /v1/messages/{message_id}
openapi: 3.1.0
info:
  title: Temp Mail Lab API
  version: 0.1.0-draft
  summary: Receive-only temporary email API for Temp Mail Lab Premium customers.
  description: |
    Create isolated temporary email addresses and retrieve messages, raw RFC 822
    source, and attachments. This contract is a pre-launch draft.

    The API never sends email and never performs automatic polling. A client
    decides when to make each request, and every processed request follows the
    documented usage policy.
  contact:
    name: Temp Mail Lab
    url: https://tempmaillab.com
  license:
    name: Temp Mail Lab Terms of Service
    url: https://tempmaillab.com/terms
servers:
  - url: https://api.tempmaillab.com
    description: Production (available only after the approved public launch)
security:
  - bearerAuth: []
tags:
  - name: Domains
    description: Discover domains that can create and receive API email.
  - name: Emails
    description: Create and inspect isolated temporary email reservations.
  - name: Messages
    description: List and retrieve received messages and their private content.
  - name: Usage
    description: Inspect the authenticated account's current request allowance.
paths:
  /v1/messages/{message_id}:
    get:
      tags:
        - Messages
      summary: Get a message
      description: |
        Returns parsed, safely rendered message content and attachment metadata.
        The authenticated account must own the parent email. An absent, expired,
        or unauthorized message returns the same 404 response. A 304 response is
        still charged.
      operationId: getMessage
      parameters:
        - $ref: '#/components/parameters/MessageId'
        - $ref: '#/components/parameters/IfNoneMatch'
      responses:
        '200':
          description: Parsed message.
          headers:
            X-Request-Id:
              $ref: '#/components/headers/RequestId'
            RateLimit-Limit:
              $ref: '#/components/headers/RateLimitLimit'
            RateLimit-Remaining:
              $ref: '#/components/headers/RateLimitRemaining'
            RateLimit-Reset:
              $ref: '#/components/headers/RateLimitReset'
            ETag:
              $ref: '#/components/headers/ETag'
            Cache-Control:
              $ref: '#/components/headers/PrivateNoStore'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/MessageResponse'
        '304':
          $ref: '#/components/responses/NotModifiedCharged'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '404':
          $ref: '#/components/responses/NotFoundCharged'
        '429':
          $ref: '#/components/responses/RateLimited'
        '500':
          $ref: '#/components/responses/ServerError'
        '503':
          $ref: '#/components/responses/ServiceUnavailable'
components:
  parameters:
    MessageId:
      name: message_id
      in: path
      required: true
      description: Opaque message identifier.
      schema:
        $ref: '#/components/schemas/MessageId'
    IfNoneMatch:
      name: If-None-Match
      in: header
      required: false
      description: Return 304 when the current representation matches this entity tag.
      schema:
        type: string
  headers:
    RequestId:
      description: Opaque request identifier for support and audit correlation.
      required: true
      schema:
        type: string
        pattern: ^req_[A-Za-z0-9_-]{16,80}$
    RateLimitLimit:
      description: >-
        Current authoritative request allowance visible to this key. Separate
        short-window safety limits may reject bursts with 429.
      required: true
      schema:
        type: integer
        minimum: 0
    RateLimitRemaining:
      description: Requests remaining in the current authoritative allowance window.
      required: true
      schema:
        type: integer
        minimum: 0
    RateLimitReset:
      description: >-
        UTC Unix timestamp when the current authoritative allowance window
        resets.
      required: true
      schema:
        type: integer
        minimum: 0
    ETag:
      description: Entity tag for a conditional one-shot read.
      required: true
      schema:
        type: string
    PrivateNoStore:
      description: Sensitive API responses must not be stored by shared or browser caches.
      required: true
      schema:
        type: string
        const: private, no-store
    RetryAfter:
      description: Seconds until the client may retry.
      required: true
      schema:
        type: integer
        minimum: 1
  schemas:
    MessageResponse:
      type: object
      additionalProperties: false
      required:
        - data
      properties:
        data:
          $ref: '#/components/schemas/Message'
    MessageId:
      type: string
      pattern: ^msg_[A-Za-z0-9_-]{10,64}$
      examples:
        - msg_7c2m9v4k8q
    Message:
      type: object
      additionalProperties: false
      required:
        - id
        - email_id
        - from
        - to
        - subject
        - received_at
        - expires_at
        - size_bytes
        - attachment_count
        - text
        - html
        - attachments
        - source_path
      properties:
        id:
          $ref: '#/components/schemas/MessageId'
        email_id:
          $ref: '#/components/schemas/EmailId'
        from:
          type: string
          description: Sanitized sender header value.
        to:
          type: array
          items:
            type: string
        subject:
          type: string
          description: Sanitized subject header value.
        received_at:
          type: string
          format: date-time
        expires_at:
          type: string
          format: date-time
          description: >-
            Message, raw source, and attachments expire 15 minutes after
            arrival.
        size_bytes:
          type: integer
          minimum: 0
        attachment_count:
          type: integer
          minimum: 0
        text:
          type:
            - string
            - 'null'
        html:
          type:
            - string
            - 'null'
          description: >-
            Sanitized HTML. Clients must still render untrusted mail in an
            isolated context.
        attachments:
          type: array
          items:
            $ref: '#/components/schemas/Attachment'
        source_path:
          type: string
          description: Authenticated relative API path for raw source.
          example: /v1/messages/msg_7c2m9v4k8q/source
    ErrorResponse:
      type: object
      additionalProperties: false
      required:
        - error
      properties:
        error:
          $ref: '#/components/schemas/ErrorObject'
    EmailId:
      type: string
      pattern: ^eml_[A-Za-z0-9_-]{10,64}$
      examples:
        - eml_4p9g2t7n8w
    Attachment:
      type: object
      additionalProperties: false
      required:
        - id
        - filename
        - content_type
        - size_bytes
        - expires_at
        - download_path
      properties:
        id:
          $ref: '#/components/schemas/AttachmentId'
        filename:
          type: string
          description: Sanitized display filename; never a storage key.
        content_type:
          type: string
        size_bytes:
          type: integer
          minimum: 0
        expires_at:
          type: string
          format: date-time
        download_path:
          type: string
          description: Authenticated relative API path, not a public R2 URL.
          example: /v1/messages/msg_7c2m9v4k8q/attachments/att_6w3n8p2x9r
    ErrorObject:
      type: object
      additionalProperties: false
      required:
        - code
        - message
        - request_id
      properties:
        code:
          type: string
          pattern: ^[a-z][a-z0-9_]{2,63}$
        message:
          type: string
        request_id:
          type: string
        details:
          type: array
          items:
            $ref: '#/components/schemas/ErrorDetail'
    AttachmentId:
      type: string
      pattern: ^att_[A-Za-z0-9_-]{10,64}$
      examples:
        - att_6w3n8p2x9r
    ErrorDetail:
      type: object
      additionalProperties: false
      required:
        - reason
      properties:
        field:
          type: string
        reason:
          type: string
  responses:
    NotModifiedCharged:
      description: Representation has not changed. This authenticated request is charged.
      headers:
        X-Request-Id:
          $ref: '#/components/headers/RequestId'
        RateLimit-Limit:
          $ref: '#/components/headers/RateLimitLimit'
        RateLimit-Remaining:
          $ref: '#/components/headers/RateLimitRemaining'
        RateLimit-Reset:
          $ref: '#/components/headers/RateLimitReset'
        ETag:
          $ref: '#/components/headers/ETag'
        Cache-Control:
          $ref: '#/components/headers/PrivateNoStore'
    Unauthorized:
      description: >-
        Missing, malformed, revoked, or environment-invalid API key. Not
        charged.
      headers:
        X-Request-Id:
          $ref: '#/components/headers/RequestId'
        Cache-Control:
          $ref: '#/components/headers/PrivateNoStore'
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
          examples:
            invalidKey:
              value:
                error:
                  code: invalid_api_key
                  message: A valid API key is required.
                  request_id: req_a1b2c3d4e5f6g7h8
    Forbidden:
      description: >-
        Authenticated account is not entitled to the requested operation. Not
        charged.
      headers:
        X-Request-Id:
          $ref: '#/components/headers/RequestId'
        Cache-Control:
          $ref: '#/components/headers/PrivateNoStore'
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
    NotFoundCharged:
      description: >-
        Resource is absent, expired, or not owned by the authenticated account.
        Charged.
      headers:
        X-Request-Id:
          $ref: '#/components/headers/RequestId'
        RateLimit-Limit:
          $ref: '#/components/headers/RateLimitLimit'
        RateLimit-Remaining:
          $ref: '#/components/headers/RateLimitRemaining'
        RateLimit-Reset:
          $ref: '#/components/headers/RateLimitReset'
        Cache-Control:
          $ref: '#/components/headers/PrivateNoStore'
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
          examples:
            notFound:
              value:
                error:
                  code: resource_not_found
                  message: The requested resource was not found.
                  request_id: req_a1b2c3d4e5f6g7h8
    RateLimited:
      description: >-
        A short-window safety or authoritative quota limit was reached. Not
        charged.
      headers:
        X-Request-Id:
          $ref: '#/components/headers/RequestId'
        RateLimit-Limit:
          $ref: '#/components/headers/RateLimitLimit'
        RateLimit-Remaining:
          $ref: '#/components/headers/RateLimitRemaining'
        RateLimit-Reset:
          $ref: '#/components/headers/RateLimitReset'
        Retry-After:
          $ref: '#/components/headers/RetryAfter'
        Cache-Control:
          $ref: '#/components/headers/PrivateNoStore'
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
          examples:
            rateLimited:
              value:
                error:
                  code: rate_limit_exceeded
                  message: Too many requests. Retry after the indicated delay.
                  request_id: req_a1b2c3d4e5f6g7h8
    ServerError:
      description: >-
        The service failed before completing the operation. Not charged; never
        represented as an empty success.
      headers:
        X-Request-Id:
          $ref: '#/components/headers/RequestId'
        Cache-Control:
          $ref: '#/components/headers/PrivateNoStore'
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
    ServiceUnavailable:
      description: >-
        A required isolated API dependency is temporarily unavailable. Not
        charged.
      headers:
        X-Request-Id:
          $ref: '#/components/headers/RequestId'
        Retry-After:
          $ref: '#/components/headers/RetryAfter'
        Cache-Control:
          $ref: '#/components/headers/PrivateNoStore'
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      bearerFormat: tml_live_...
      description: >
        Send a live API key in the Authorization header. Keys in query strings
        are

        rejected. A staging key never authenticates against production.

````