Receive email as JSON on your webhook
Forward your mailbox to IotaBot and every email arrives on your server as clean JSON — sender, recipients, subject, text, safe and raw HTML, threading headers and attachments.
- ✓ Parsed JSON, not MIME
- ✓ Safe HTML and raw HTML
- ✓ Threading headers
- ✓ Signed, retried webhooks
Subscribe to inbound email
Full reference →curl -X POST "https://api.iotabot.com/v1/webhook-endpoints" \
-H "Authorization: Bearer $IOTABOT_API_KEY" \
-H "Content-Type: application/json" \
-d '{
"url": "https://crm.acme.com/iotabot",
"channels": [
"email"
],
"events": [
"message.received"
]
}'{
"data": {
"id": "6a4bb0…",
"object": "webhook_endpoint",
"url": "https://crm.acme.com/iotabot",
"status": "active",
"secret": "whsec_…",
"verification": {
"verified": true,
"reason": null
}
}
}- JSON
- every email parsed for you
- 2 HTML versions
- sanitised to render, raw to archive
- 3 days
- of retries if your server is down
- In order
- per conversation, de-duplicated by event id
Get started with the Inbound Email API in three steps
- 1
Forward your mailbox
Set your mail provider to forward support@ (or any address) to IotaBot.
- 2
Add a webhook endpoint
In Developers → Webhooks, add your HTTPS URL for the email channel and message.received.
- 3
Handle the JSON
Check the IotaBot-Signature header, answer 2xx, and process the email in your system.
What you can build with the Inbound Email API
Everything parsed
from, to, cc, subject, text, in_reply_to and references — no MIME parsing on your side.
See how →Safe HTML and raw HTML
html is sanitised and safe to show in a browser; html_raw is exactly what arrived, for archiving or your own processing.
See how →Attachments by link
Attachments arrive as signed download links valid for an hour — never inline in the payload.
See how →Signed and retried
Every request carries an HMAC signature; failures are retried for 3 days, in order per conversation.
See how →Metadata-only mode
For regulated data, an endpoint can receive ids and status without the email content, and fetch content through the API.
See how →Reply in the thread
Answer with POST /v1/messages and the conversation_id — the reply threads onto the customer's email.
See how →Inbound Email API use cases
Emails into tickets
Open a ticket in your helpdesk for every email, with the thread kept together.
Leads from email
Create a lead in your CRM when someone writes to sales@.
Orders and forms by email
Read structured requests out of emails and act on them.
Archive and compliance
Keep the raw HTML of every email in your own storage.
Inbound Email API: frequently asked questions
What is an inbound email API?
It receives emails for you and delivers them to your application as structured data. IotaBot parses every email sent to your forwarded mailbox and POSTs it to your webhook as JSON.
Which fields do I get?
The message (text, sanitised html, html_raw, attachments) and an email block with subject, from, to, cc, message id, in_reply_to and references, plus the conversation it belongs to.
How do I set it up?
Forward your mailbox to IotaBot, then add a webhook endpoint for the email channel with the message.received event — in the portal or with POST /v1/webhook-endpoints.
How are attachments delivered?
As signed links valid for an hour, so large files never bloat the webhook payload.
Is the webhook secure?
Yes. Each request is signed with HMAC-SHA256 using your endpoint's secret in the IotaBot-Signature header; verify it and reject old timestamps.
Can I reply to the email?
Yes. POST /v1/messages with the conversation_id replies in the same thread, from the address the customer wrote to.
One API for every channel
The same endpoints, webhooks and errors on WhatsApp, Instagram, email and website chat.
Start building with the Inbound Email API
Create a key, send your first request, and try everything in test mode before it goes live.
