support
POST /v1/webhooks/inbound-email
Ingest a customer's support reply from the mail edge.
Πισtoποίηση
Αυτό το τελικό σημείο είναι δημόσιο. Δεν απαιτεί διαπιστευτήρια ούτε οργανισμό — είναι αυτό που διαβάζουν ο δικός μας ιστότοπος μάρκετινγκ και οι μηχανές απαντήσεων τεχνητής νοημοσύνης.
Αυτό το τελικό σημείο δεν δέχεται αναγνωριστικό οργανισμού. Το κλειδί σας προσδιορίζει ήδη τον οργανισμό στον οποίο ανήκει, και η απάντηση περιορίζεται σε αυτόν.
Δοκιμάστε το
Ατικatastήstε ό,τι βρίskεtai μέσα σe γώniaδeς μe τis δikές sas timές, kai to placeholder klεidioύ μe éna klεidi apó ton pinaka ελέgchou sas.
curl -X POST https://api.zinndigital.com/v1/webhooks/inbound-email \
-H "Content-Type: application/json" \
-d '{ "from": <string>, "message_id": <string> }'Συνδεθήκατε; Η κονσόλα API στον πίνακα ελέγχου σας συμπληρώνει το πραγματικό αναγνωριστικό του οργανισμού σας και το δικό σας κλειδί, και εκτελεί το αίτημα στο ζωντανό API, ώστε να μπορείτε να δείτε την πραγματική απόκριση. Ανοίξτε αυτό το τελικό σημείο στην κονσόλα API
Λεπτομέρειες
**Unauthenticated by design** — the caller is a Cloudflare Email Routing Worker with no Zinn® credential, so an HMAC over `"<timestamp>\n<body>"` in `X-Zinn-Signature` *is* the authentication. The timestamp is inside the signed material and its skew is bounded, so a captured request cannot be replayed later. This is the inbound half of support email. Before it existed the platform sent notifications from an address that accepted mail and discarded it: a customer replied, nothing happened, and neither they nor the waiting staff member was told. The ticket is resolved from a **signed token inside the `Message-ID`** we set on the outbound notification — nothing in the body, the `From` address or any other header selects a tenant, because all of those are chosen by whoever sent the mail. Redelivery is the normal case, not the exception: email is at-least-once and a lost response guarantees a retry, so a message already filed answers `200` with `duplicate: true` rather than appending a second copy. ⛔ Unlike the gateway webhooks, a message that **cannot be routed is answered `422`**, not `200`. A 2xx tells the Worker to accept the mail, and an accepted message that reaches no ticket is the exact defect this endpoint exists to remove; `422` makes the Worker reject it so the sender's own mail server bounces it back to the customer.
Παράμετροι
| Όνομα | Τύpος | Υποχρεωτικό | Τι είναι |
|---|---|---|---|
X-Zinn-Timestamp (header) | string | Ναι | Unix seconds. Inside the signed material; skew-bounded to five minutes. |
X-Zinn-Signature (header) | string | Ναι | `sha256=<hex>` HMAC over `"<timestamp>\n<body>"`. |
Σώμα αίτησης
| Όνομα | Τύpος | Υποχρεωτικό | Τι είναι |
|---|---|---|---|
from | string | Ναι | The envelope sender. Forgeable, and treated as such — it is checked against the ticket's org and the answer becomes a flag, never a permission. |
to | string | Όχι | — |
message_id | string | Ναι | The message's own `Message-ID`. Stored, and unique, so a redelivery cannot append twice. |
in_reply_to | string | Όχι | Carries the signed ticket token when the customer replied to one of our notifications. |
references | string | Όχι | The full thread chain. Searched as well as `in_reply_to`, because a reply to the third message in a thread puts our id here and not there. |
subject | string | Όχι | — |
text | string | Όχι | The message body. Quoted history is trimmed engine-side and the result is length-bounded. |
Απάντηση
| Όνομα | Τύpος | Υποχρεωτικό | Τι είναι |
|---|---|---|---|
ticket_id | string | Ναι | — |
duplicate | boolean | Ναι | This exact message had already been filed — a success, not an error. |
sender_verified | boolean | Ναι | Whether the sender is a known address on the ticket's org. `false` still files the message, flagged for staff. |
reopened | boolean | Ναι | Whether filing it moved a `solved` ticket back to `open`. |
Σφάλματα που μπορεί να επιστρέψει αυτό το τελικό σημείο
400 · 422 · 503