Inbound email API

Receive email as JSON on your webhook

Forward your mailbox to IotaBot and every email arrives on your server as clean JSON — sender, recipients, subject, text, safe and raw HTML, threading headers and attachments.

  • ✓ Parsed JSON, not MIME
  • ✓ Safe HTML and raw HTML
  • ✓ Threading headers
  • ✓ Signed, retried webhooks

Subscribe to inbound email

Full reference →
Request
curl -X POST "https://api.iotabot.com/v1/webhook-endpoints" \
  -H "Authorization: Bearer $IOTABOT_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
  "url": "https://crm.acme.com/iotabot",
  "channels": [
    "email"
  ],
  "events": [
    "message.received"
  ]
}'
Response · 201
{
  "data": {
    "id": "6a4bb0…",
    "object": "webhook_endpoint",
    "url": "https://crm.acme.com/iotabot",
    "status": "active",
    "secret": "whsec_…",
    "verification": {
      "verified": true,
      "reason": null
    }
  }
}
JSON
every email parsed for you
2 HTML versions
sanitised to render, raw to archive
3 days
of retries if your server is down
In order
per conversation, de-duplicated by event id
How it works

Get started with the Inbound Email API in three steps

  1. 1

    Forward your mailbox

    Set your mail provider to forward support@ (or any address) to IotaBot.

  2. 2

    Add a webhook endpoint

    In Developers → Webhooks, add your HTTPS URL for the email channel and message.received.

  3. 3

    Handle the JSON

    Check the IotaBot-Signature header, answer 2xx, and process the email in your system.

Use cases

Inbound Email API use cases

Emails into tickets

Open a ticket in your helpdesk for every email, with the thread kept together.

Leads from email

Create a lead in your CRM when someone writes to sales@.

Orders and forms by email

Read structured requests out of emails and act on them.

Archive and compliance

Keep the raw HTML of every email in your own storage.

FAQ

Inbound Email API: frequently asked questions

What is an inbound email API?

It receives emails for you and delivers them to your application as structured data. IotaBot parses every email sent to your forwarded mailbox and POSTs it to your webhook as JSON.

Which fields do I get?

The message (text, sanitised html, html_raw, attachments) and an email block with subject, from, to, cc, message id, in_reply_to and references, plus the conversation it belongs to.

How do I set it up?

Forward your mailbox to IotaBot, then add a webhook endpoint for the email channel with the message.received event — in the portal or with POST /v1/webhook-endpoints.

How are attachments delivered?

As signed links valid for an hour, so large files never bloat the webhook payload.

Is the webhook secure?

Yes. Each request is signed with HMAC-SHA256 using your endpoint's secret in the IotaBot-Signature header; verify it and reject old timestamps.

Can I reply to the email?

Yes. POST /v1/messages with the conversation_id replies in the same thread, from the address the customer wrote to.

Start building with the Inbound Email API

Create a key, send your first request, and try everything in test mode before it goes live.