Developer Friendly

Reseller API

Manage white-label sub-tenant lifecycle and issue scoped canonical tenant API credentials.

✨Fully White-Labeled — Resellers can offer these APIs under their own brand→

Authentication & Scopes

The reseller API lives inside your Mailbux billing account. Every route requires a Passport OAuth bearer token carrying the reseller scope. Tenant GET routes also require reseller.read. Requests are rate-limited to 60/minute, and every resource is owner-scoped — a cross-owner service, pool, brand, operation, tenant, or resource id returns 404, never 403.

Header: Authorization: Bearer <passport_token>

Canonical base URL: https://dash.mailbux.com/api/v1/reseller. The /api/v1/mailbux/reseller path is a compatibility alias for existing integrations.

Scopes

Scopes are cumulative — grant a token only what the integration needs.

reseller
Required on every reseller route; identifies and confines access to your owned reseller resources.
reseller.read
Required with reseller for tenant GET routes, including tenant list, detail, status, and credential metadata.
reseller.write
Create/recheck/rearm/suspend/resume brands; create sub-tenants and issue or revoke canonical credentials
reseller.settings
Link pools; change allocations, branding, and hostnames; retry settings operations
reseller.uploads
Upload private Android build configuration and retry upload operations
reseller.lifecycle
Suspend, unsuspend, or delete a sub-tenant through its supported lifecycle

Services, pools & brands

The white-label side: your reseller add-ons, the mail pools they draw capacity from, and the brands provisioned against them.

GEThttps://dash.mailbux.com/api/v1/reseller/services

Owned reseller add-on services and quantity-aware brand usage.

GEThttps://dash.mailbux.com/api/v1/reseller/services/{service}/pools

Linked and eligible pools, with reserved, used, and free capacity.

PUThttps://dash.mailbux.com/api/v1/reseller/services/{service}/pools/{pool}

Reserve explicit capacity from an owned, active Mailbux pool.

DELETEhttps://dash.mailbux.com/api/v1/reseller/services/{service}/pools/{link}

Remove an unused pool link.

GETPOSThttps://dash.mailbux.com/api/v1/reseller/services/{service}/brands

Paginated, filterable brand list, and create a brand within your addon entitlement.

GEThttps://dash.mailbux.com/api/v1/reseller/brands/{brand}

Lifecycle, pool source, sync state, and recovery details for one brand.

GEThttps://dash.mailbux.com/api/v1/reseller/brands/{brand}/operations

Paginated, filterable external-operation and dead-letter history.

GEThttps://dash.mailbux.com/api/v1/reseller/brands/{brand}/audit

Paginated, filterable safe lifecycle audit trail.

POSThttps://dash.mailbux.com/api/v1/reseller/brands/{brand}/{recheck|rearm|suspend|unsuspend}

Lifecycle actions on one brand.

PATCHhttps://dash.mailbux.com/api/v1/reseller/brands/{brand}/allocations

Non-destructive quota changes within the existing reservation.

PATCHhttps://dash.mailbux.com/api/v1/reseller/brands/{brand}/settings

Validated branding/provisioning settings operation.

PATCHhttps://dash.mailbux.com/api/v1/reseller/brands/{brand}/endpoints

Validated hostname/certificate operation.

DELETEhttps://dash.mailbux.com/api/v1/reseller/brands/{brand}

Ordered, idempotent termination attempt.

GEThttps://dash.mailbux.com/api/v1/reseller/openapi

The full scope, endpoint, filter, and blocked-capability contract — the authoritative source this page is generated from.

Sub-tenants

GETPOSThttps://dash.mailbux.com/api/v1/reseller/services/{service}/tenants

List your sub-tenants, or create one from capacity in this reseller service. Creating a child does not create mailboxes or publish DNS records.

Show Example
curl -X POST "https://dash.mailbux.com/api/v1/reseller/services/123/tenants" \
  -H "Authorization: Bearer <passport_token>" \
  -H "Content-Type: application/json" \
  -d '{"name": "Acme Corp", "hostname": "mail.acme.example"}'
GEThttps://dash.mailbux.com/api/v1/reseller/tenants/{tenant}

Show one sub-tenant.

PATCHhttps://dash.mailbux.com/api/v1/reseller/tenants/{tenant}

Update sub-tenant metadata.

GEThttps://dash.mailbux.com/api/v1/reseller/tenants/{tenant}/status

Sub-tenant lifecycle status.

POSThttps://dash.mailbux.com/api/v1/reseller/tenants/{tenant}/{suspend|unsuspend}

Audited sub-tenant lifecycle action. Requires reseller.lifecycle and an Idempotency-Key.

DELETEhttps://dash.mailbux.com/api/v1/reseller/tenants/{tenant}

Delete an owned sub-tenant through the supported lifecycle.

Canonical tenant API credentials

GETPOSThttps://dash.mailbux.com/api/v1/reseller/tenants/{tenant}/credentials

List safe metadata for canonical credentials, or issue one one-time-visible proxy-only credential bound to this owned child.

DELETEhttps://dash.mailbux.com/api/v1/reseller/tenants/{tenant}/credentials/{credential}

Revoke one exact canonical credential for this owned child.

Documented but not yet available
Child mail resources remain exclusively in the canonical Mailbux tenant API at /api/v1. Reseller routes issue only a brand-bound proxy credential; they never proxy mail resources or mint mail:native. GET https://dash.mailbux.com/api/v1/reseller/openapi is the live, authoritative lifecycle contract.

Ready to Host Your Business Email for Free?

Set up professional email on your own domain in minutes. Free business email hosting, powered by Mailbux.