Skip to main content

API keys

  • Call the API from a backend, CI job, or test runner.
  • Give each key only the scopes its integration needs.
  • Never include a key or Authorization header in URLs, logs, analytics, or support messages.
  • Rotate a key if it may have been exposed.

Email content

Treat sender names, addresses, subjects, HTML, filenames, raw source, and attachments as untrusted input. Escape values before inserting them into HTML, SQL, shell commands, or templates. Render HTML in an isolated sandbox and validate or scan attachments according to your application’s risk. The API checks account ownership on every private read. Missing, expired, and non-owned private resources use the same 404 response.
Last modified on August 15, 2026