---
# @generated by sylphx-gen 0.1.0 from contracts@f43687e14b51721de401af0b4dfdca44ad768a0c80ebc87a5f5fd6b3ff19f7d7. Do not edit.
title: "Create a mailbox connect link"
description: "`notify.mailbox_connect_links.create` (POST /v1/{parent}/mailbox_connect_links): Mints a mailbox connect link for one end user; the response carries its `url`, which no later call returns."
type: reference
product: email
summary: "Mints a mailbox connect link for one end user; the response carries its `url`, which no later call returns."
updated: 2026-09-28
nav: false
---

Mints a mailbox connect link for one end user; the response carries its `url`, which no later call returns.

- **Path** `POST https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/mailbox_connect_links`
- **Scope** `notify:write`
- **Effect** `write` — a successful call changes state.
- **Collection** [mailbox_connect_links](/docs/api/mailbox_connect_links)
- **Query** `mailbox_connect_link_id`, `validate_only`

## Request

| Field | Type | What it is |
| --- | --- | --- |
| `parent` | `string` | The parent to create in. Required. |
| `mailbox_connect_link_id` | `string` | The mailbox connect link id, the final name segment; the server assigns one when empty. |
| `mailbox_connect_link` | `MailboxConnectLink` | The mailbox connect link to create; only caller-writable fields are read. Required. |
| `validate_only` | `bool` | Validate and return the result without writing anything. |

### MailboxConnectLink

| Field | Type | What it is |
| --- | --- | --- |
| `name` | `string` | `orgs/{org}/projects/{project}/envs/{env}/mailbox_connect_links/{mailbox_connect_link}`. |
| `meta` | `ResourceMeta` | Resource metadata; labels may carry the customer's own end-user id. |
| `provider` | `MailboxOauthProvider` | The provider whose consent the page opens; the environment needs that provider's Mailbox OAuth App. Required. One of `google`, `microsoft`. |
| `mailbox` | `string` | The mailbox to reconnect, keeping its id and feed; it must be signed in as the same address. Empty creates a new connected mailbox. |
| `mailbox_id` | `string` | The id of the new mailbox; the server assigns one when empty. |
| `display_name` | `string` | The From display name of the new mailbox. |
| `backfill_start_time` | `timestamp` | The new mailbox reads mail received on or after this day on its first poll. |
| `login_hint` | `string` | The address to suggest on the consent screen (`login_hint`); the mailbox takes the address the provider confirms, whatever this says. |
| `return_url` | `string` | Where the end user lands when done, HTTPS, with `connect_link={id}` and `result=connected` or `result=failed` added to the query. The query proves nothing: read the link back with your key for the outcome. Required. |
| `refresh_url` | `string` | Where a claimed or expired link sends the end user, HTTPS; your server mints a new link there. Empty shows a page saying the link has expired. |
| `ttl` | `duration` | How long the link stays open; default 1 hour, at most 7 days. |

### ResourceMeta

| Field | Type | What it is |
| --- | --- | --- |
| `labels` | `map<string, string>` | Caller-writable, indexed labels (AIP-122 label rules). |
| `annotations` | `map<string, string>` | Caller-writable, unindexed annotations. |
| `display_name` | `string` | Caller-writable human-readable name. |

## Response

| Field | Type | What it is |
| --- | --- | --- |
| `name` | `string` | `orgs/{org}/projects/{project}/envs/{env}/mailbox_connect_links/{mailbox_connect_link}`. |
| `uid` | `string` | `mcl_<cell><ulid>`; never reused. Output only. |
| `meta` | `ResourceMeta` | Resource metadata; labels may carry the customer's own end-user id. |
| `provider` | `MailboxOauthProvider` | The provider whose consent the page opens; the environment needs that provider's Mailbox OAuth App. Required. One of `google`, `microsoft`. |
| `mailbox` | `string` | The mailbox to reconnect, keeping its id and feed; it must be signed in as the same address. Empty creates a new connected mailbox. |
| `mailbox_id` | `string` | The id of the new mailbox; the server assigns one when empty. |
| `display_name` | `string` | The From display name of the new mailbox. |
| `backfill_start_time` | `timestamp` | The new mailbox reads mail received on or after this day on its first poll. |
| `login_hint` | `string` | The address to suggest on the consent screen (`login_hint`); the mailbox takes the address the provider confirms, whatever this says. |
| `return_url` | `string` | Where the end user lands when done, HTTPS, with `connect_link={id}` and `result=connected` or `result=failed` added to the query. The query proves nothing: read the link back with your key for the outcome. Required. |
| `refresh_url` | `string` | Where a claimed or expired link sends the end user, HTTPS; your server mints a new link there. Empty shows a page saying the link has expired. |
| `ttl` | `duration` | How long the link stays open; default 1 hour, at most 7 days. |
| `url` | `string` | The link to hand the end user. It is a bearer secret: only the create call returns it, and only its hash is stored. Output only. Never returned again. |
| `state` | `MailboxConnectLinkState` | The lifecycle state. Output only. One of `pending`, `claimed`, `connected`, `failed`, `expired`. |
| `expire_time` | `timestamp` | When it expires. Output only. |
| `complete_time` | `timestamp` | When the end user finished, connected or failed. Output only. |
| `connected_mailbox` | `string` | The mailbox it connected or reconnected. Output only. |
| `address` | `string` | The address the provider confirmed. Output only. |
| `error_code` | `string` | Why it failed: `consent_denied`, `scope_missing` (the end user unticked a scope), `address_mismatch` (a reconnect signed in as another address), `address_in_use` (another mailbox of the environment has the address), `plan_limit_reached`, or `provider_error`. Output only. |

### ResourceMeta

| Field | Type | What it is |
| --- | --- | --- |
| `generation` | `int64` | Increases by one on every change to `spec`. Output only. |
| `etag` | `string` | Strong ETag (AIP-154): changes on any change to spec, status, or metadata. Send it back as `If-Match` or `etag` to make Update and Delete conditional; a mismatch fails with ABORTED / 409 `ETAG_MISMATCH`. Output only. |
| `create_time` | `timestamp` | When the Resource was created. Output only. |
| `update_time` | `timestamp` | When the Resource last changed. Output only. |
| `delete_time` | `timestamp` | Set while the Resource is being deleted. Output only. |
| `labels` | `map<string, string>` | Caller-writable, indexed labels (AIP-122 label rules). |
| `annotations` | `map<string, string>` | Caller-writable, unindexed annotations. |
| `display_name` | `string` | Caller-writable human-readable name. |
| `creator` | `string` | The principal that created the Resource. Output only. |

## Errors

- [`UNAUTHENTICATED`](/docs/api/errors/UNAUTHENTICATED) — No valid key or token was presented.
- [`PERMISSION_DENIED`](/docs/api/errors/PERMISSION_DENIED) — The key lacks the method's permission.
- [`UNKNOWN_FIELD`](/docs/api/errors/UNKNOWN_FIELD) — The request has a field the schema does not know.
- [`INVALID_FIELD`](/docs/api/errors/INVALID_FIELD) — A field failed validation.
- [`RESOURCE_NOT_FOUND`](/docs/api/errors/RESOURCE_NOT_FOUND) — The named Resource does not exist or is not visible.
- [`RESOURCE_ALREADY_EXISTS`](/docs/api/errors/RESOURCE_ALREADY_EXISTS) — A Resource with this name exists.
- [`INVALID_STATE`](/docs/api/errors/INVALID_STATE) — The Resource is in a state that forbids the call.
- [`IDEMPOTENCY_KEY_REUSED`](/docs/api/errors/IDEMPOTENCY_KEY_REUSED) — An Idempotency-Key was reused with another body.
- [`IDEMPOTENCY_IN_PROGRESS`](/docs/api/errors/IDEMPOTENCY_IN_PROGRESS) — The first call with this Idempotency-Key is still running.

Every error arrives in the body [Errors](/docs/platform/errors) describes.

## Examples

**cURL**

```curl
curl -X POST "https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/mailbox_connect_links" \
  -H "Authorization: Bearer $SYLPHX_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"provider":"google","return_url":"…"}'
```

**TypeScript**

```ts
const response = await sylphx.notify.mailboxConnectLinks.create({ mailboxConnectLink: { provider: 'google', returnUrl: '…' }, parent: 'orgs/acme/projects/shop/envs/production' })
```

**Rust**

```rust
let mut req = sylphx::notify::CreateMailboxConnectLinkRequest::default();
req.mailbox_connect_link = Some(sylphx::notify::MailboxConnectLink {
    provider: sylphx::notify::MailboxOauthProvider::Google,
    return_url: "…".to_string(),
    ..Default::default()
});
req.parent = "orgs/acme/projects/shop/envs/production".to_string();
let response = sx.notify().mailbox_connect_links().create(req).await?;
```

**CLI**

```bash
sylphx notify mailbox-connect-links create --parent orgs/acme/projects/shop/envs/production --provider google --return-url …
```

**MCP**

```json
{ "method_id": "notify.mailbox_connect_links.create", "args": {"mailbox_connect_link":{"provider":"google","return_url":"…"},"parent":"orgs/acme/projects/shop/envs/production"} }
```
