September 2026 OpenAPI spec + message search/filter
A machine-readable OpenAPI 3.1 contract (/docs/openapi.yaml) validated in CI, plus shared message filtering — has_otp, subject_contains and from — across the REST API and the dashboard.
Changelog
What we have shipped, newest first.
A machine-readable OpenAPI 3.1 contract (/docs/openapi.yaml) validated in CI, plus shared message filtering — has_otp, subject_contains and from — across the REST API and the dashboard.
API-key minting is now bounded: a maximum of 20 active keys per account, with an hourly create rate limit, so leaked-key hygiene stays manageable.
The public quickstart and this reference set, plus a copy-paste Playwright example (examples/playwright/otp-signup.spec.ts) that awaits an OTP over the wait endpoint.
Post-signup activation: a first inbox and welcome message are provisioned automatically, with a one-click API key and ready-to-run code snippets on the dashboard.
The landing page now leads with the OTP wedge: "Wait for the OTP. One API call.", with a live curl and Python sample for the wait endpoint.
Bearer-authenticated REST API: inboxes, message listing and retrieval, cursor pagination, per-key rate limits, and the wait-for-OTP/magic-link long-poll primitive.
DB-backed webhooks with SSRF-pinned HTTPS delivery and per-webhook HMAC signatures.
The no-loss inbound path: Postfix accepts and durably stores mail, then a bounded parser extracts OTPs and magic links. Mail is deferred, never lost, when the app is down.