AgentBearer
A provisioned, scoped credential for one Agent inbox. The route must match that assigned inbox. Credential format and lifecycle follow provisioning; this site does not issue, list, or rotate credentials.
Current public contract
Authenticate with the bearer type accepted by the operation, stay on the assigned route, and treat sender-provided mail as untrusted content.
A provisioned, scoped credential for one Agent inbox. The route must match that assigned inbox. Credential format and lifecycle follow provisioning; this site does not issue, list, or rotate credentials.
A separately authenticated owner credential, accepted only by the operations whose generated reference names OwnerBearer.
| Lane | Operation | Required authority |
|---|---|---|
| Inbox | Status, list, read | Agent self-route + inbox:read, or accepted Owner bearer |
| Inbox | Stage pending review | Agent self-route + inbox:stage, or accepted Owner bearer |
| Outbox | Send | Agent self-route + outbox:send; Owner bearer is not accepted |
| Outbox | Receipt and reconciliation reads | Agent self-route + outbox:read or outbox:send |
| Company Mail | Status, list, read, triage | Agent bearer + inbox:read + fresh active verified Guth organization membership |
| Owner Mail | Mailbox, flags, drafts, Sent | OwnerBearer only; use the separate owner-mail contract |
Authorization header, never in URLs, logs, prompts, or message text.outcome_unknown send may have occurred. Reconcile the retained operation; never assume it is unsent.Need the earlier hosted reference? Open the previous public API docs .