POST
/sending/identitiesPOST /sending/identities
Create a sender identity. The first one in a workspace becomes its default automatically.
Request
curl -X POST 'https://api.sendheron.com/api/v1/sending/identities' \
-H 'Authorization: Bearer <YOUR_API_KEY>' \
-H 'Content-Type: application/json'Required scopes
The key must carry these:
- sending:write
Body parameters
| Name | Type | Required | Description |
|---|---|---|---|
| label | string | Yes | Human label shown when picking a sender, e.g. Acme Billing. |
| fromEmail | string | Yes | The From address, e.g. [email protected]. Accepted whatever its domain, and reported as unsendable until that domain is authenticated in this workspace, so an identity can be prepared before the DNS is in place. |
| fromName | string | No | Display name recipients see beside the address. |
| replyToEmail | string | No | Where replies go, when that differs from the From address. Its domain does not have to be authenticated. |
Responses
Returns 201 on success.
- 400
- The payload failed validation, or the request is not valid for the current state. The body's `description` names the field and says what was wrong with it in words, e.g. "domain: domain must be a bare hostname such as acme.com, with no scheme, path, or port". The `error` code is stable and safe to branch on; `description` is for the human reading the log.
- 401
- Missing or invalid API key.
- 403
- Valid key, but it does not carry the required scope. The `error` code is `apiKeys.insufficientScopes` and the `description` names both halves of the problem: "Missing required scope(s): X. This key holds: Y." Neither is a secret, since the required scopes are on this page and the held ones are your own credential, and a bare "Forbidden" costs a debugging pass to work out which of the two it was.
- 404
- No such record in this workspace. An id belonging to a different workspace returns this too, never a 403, because the API will not confirm that a record exists outside the workspace your key was issued in. Read it as "not yours or not there" rather than as "definitely gone".
- 409
- A duplicate, or an idempotency key reused with a different payload.
- 429
- Either rate-limit ceiling was exceeded.
Rate limits
100/min per key, counted against the organization's WRITE ceiling (400/min). Both windows are one minute. There is no hourly or daily quota.