Authentication & Scopes
The reseller API lives inside your Mailbux billing account. Every route requires a Passport OAuth bearer token carrying the reseller scope. Tenant GET routes also require reseller.read. Requests are rate-limited to 60/minute, and every resource is owner-scoped — a cross-owner service, pool, brand, operation, tenant, or resource id returns 404, never 403.
Authorization: Bearer <passport_token>Canonical base URL: https://dash.mailbux.com/api/v1/reseller. The /api/v1/mailbux/reseller path is a compatibility alias for existing integrations.
Scopes
Scopes are cumulative — grant a token only what the integration needs.
Required on every reseller route; identifies and confines access to your owned reseller resources.Required with reseller for tenant GET routes, including tenant list, detail, status, and credential metadata.Create/recheck/rearm/suspend/resume brands; create sub-tenants and issue or revoke canonical credentialsLink pools; change allocations, branding, and hostnames; retry settings operationsUpload private Android build configuration and retry upload operationsSuspend, unsuspend, or delete a sub-tenant through its supported lifecycleServices, pools & brands
The white-label side: your reseller add-ons, the mail pools they draw capacity from, and the brands provisioned against them.
https://dash.mailbux.com/api/v1/reseller/servicesOwned reseller add-on services and quantity-aware brand usage.
https://dash.mailbux.com/api/v1/reseller/services/{service}/poolsLinked and eligible pools, with reserved, used, and free capacity.
https://dash.mailbux.com/api/v1/reseller/services/{service}/pools/{pool}Reserve explicit capacity from an owned, active Mailbux pool.
https://dash.mailbux.com/api/v1/reseller/services/{service}/pools/{link}Remove an unused pool link.
https://dash.mailbux.com/api/v1/reseller/services/{service}/brandsPaginated, filterable brand list, and create a brand within your addon entitlement.
https://dash.mailbux.com/api/v1/reseller/brands/{brand}Lifecycle, pool source, sync state, and recovery details for one brand.
https://dash.mailbux.com/api/v1/reseller/brands/{brand}/operationsPaginated, filterable external-operation and dead-letter history.
https://dash.mailbux.com/api/v1/reseller/brands/{brand}/auditPaginated, filterable safe lifecycle audit trail.
https://dash.mailbux.com/api/v1/reseller/brands/{brand}/{recheck|rearm|suspend|unsuspend}Lifecycle actions on one brand.
https://dash.mailbux.com/api/v1/reseller/brands/{brand}/allocationsNon-destructive quota changes within the existing reservation.
https://dash.mailbux.com/api/v1/reseller/brands/{brand}/settingsValidated branding/provisioning settings operation.
https://dash.mailbux.com/api/v1/reseller/brands/{brand}/endpointsValidated hostname/certificate operation.
https://dash.mailbux.com/api/v1/reseller/brands/{brand}Ordered, idempotent termination attempt.
https://dash.mailbux.com/api/v1/reseller/openapiThe full scope, endpoint, filter, and blocked-capability contract — the authoritative source this page is generated from.
Sub-tenants
https://dash.mailbux.com/api/v1/reseller/services/{service}/tenantsList your sub-tenants, or create one from capacity in this reseller service. Creating a child does not create mailboxes or publish DNS records.
Show Example
curl -X POST "https://dash.mailbux.com/api/v1/reseller/services/123/tenants" \
-H "Authorization: Bearer <passport_token>" \
-H "Content-Type: application/json" \
-d '{"name": "Acme Corp", "hostname": "mail.acme.example"}'https://dash.mailbux.com/api/v1/reseller/tenants/{tenant}Show one sub-tenant.
https://dash.mailbux.com/api/v1/reseller/tenants/{tenant}Update sub-tenant metadata.
https://dash.mailbux.com/api/v1/reseller/tenants/{tenant}/statusSub-tenant lifecycle status.
https://dash.mailbux.com/api/v1/reseller/tenants/{tenant}/{suspend|unsuspend}Audited sub-tenant lifecycle action. Requires reseller.lifecycle and an Idempotency-Key.
https://dash.mailbux.com/api/v1/reseller/tenants/{tenant}Delete an owned sub-tenant through the supported lifecycle.
Canonical tenant API credentials
https://dash.mailbux.com/api/v1/reseller/tenants/{tenant}/credentialsList safe metadata for canonical credentials, or issue one one-time-visible proxy-only credential bound to this owned child.
https://dash.mailbux.com/api/v1/reseller/tenants/{tenant}/credentials/{credential}Revoke one exact canonical credential for this owned child.
Ready to Host Your Business Email for Free?
Set up professional email on your own domain in minutes. Free business email hosting, powered by Mailbux.
