/api/v1/health
Status check. Confirms the service is online, whether Firebase is connected, returns current Lagos time, lifetime request count, and links to every available endpoint.
Query temporary inboxes, read messages, and delete them from your apps, bots, or scripts. No signup, no API key, no cost. Rate limited to 30 requests / minute per IP with a 5-minute blacklist on excess.
Hit any endpoint directly from your terminal. No setup, no key.
| jq for pretty output. Every response is valid JSON.
ZMAIL Drop is a thin, cached proxy over public @maildrop.cc inboxes. Every request is rate limited, throttled, and cached to protect the upstream server — but from your side, it's just clean JSON over HTTPS 💡.
All responses are JSON objects with a top-level ok boolean.
Success responses include data and meta.
Errors include error and meta.
/api/v1/health
Status check. Confirms the service is online, whether Firebase is connected, returns current Lagos time, lifetime request count, and links to every available endpoint.
/api/v1/inbox?mailbox=:name
Lists all messages in a mailbox. Results are cached for 3 seconds to protect the upstream. Second calls within the window return instantly from cache.
/api/v1/message?mailbox=:name&id=:id
Reads a single message by ID. Returns the sanitized HTML body, the raw MIME source,
a pre-built cid_map for inline images, and a has_attachments flag.
/api/v1/message?mailbox=:name&id=:id
Permanently removes a message from the mailbox. Invalidates any cached views of that mailbox and message. Deletion is final — ZMail Drop has no trash recovery policy or endpoint.
Lightweight object returned by /inbox.
Detailed object returned by /message.
Every response carries standard rate-limit headers. Your client should back off
automatically when it sees a 429.
| Code | Status | Meaning |
|---|---|---|
MISSING_MAILBOX | 400 | The mailbox query parameter was omitted. |
MISSING_ID | 400 | The id query parameter was omitted. |
INVALID_MAILBOX | 400 | Mailbox name failed validation (a-z0-9._-, max 64 chars). |
INVALID_ID | 400 | Message ID failed validation. |
MESSAGE_NOT_FOUND | 404 | Message doesn't exist, or it expired. |
METHOD_NOT_ALLOWED | 405 | Wrong HTTP verb for this endpoint. |
RATE_LIMITED | 429 | You've hit 30 requests in 60 seconds. |
IP_BLACKLISTED | 429 | Your IP is temporarily blocked for 5 minutes. |
UPSTREAM_BUSY | 503 | Server queued too many concurrent upstream calls. |
UPSTREAM_ERROR | 502 | ZMail Drop Server itself returned an error. |
CLEANUP_FAILED | 500 | Only on /cleanup. Firestore write failure. |
UNAUTHORIZED | 401 | Only on /cleanup. Missing or invalid CRON_SECRET. |
Open any mailbox name on the main site, then use it with the API. All inboxes are public and free forever.