---
# @generated by sylphx-gen 0.1.0 from contracts@f43687e14b51721de401af0b4dfdca44ad768a0c80ebc87a5f5fd6b3ff19f7d7. Do not edit.
title: "Create a mailbox OAUTH app"
description: "`notify.mailbox_oauth_apps.create` (POST /v1/{parent}/mailbox_oauth_apps): Creates a mailbox OAuth app."
type: reference
product: email
summary: "Creates a mailbox OAuth app."
updated: 2026-09-28
nav: false
---

Creates a mailbox OAuth app.

- **Path** `POST https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/mailbox_oauth_apps`
- **Scope** `notify:write`
- **Effect** `write` — a successful call changes state.
- **Collection** [mailbox_oauth_apps](/docs/api/mailbox_oauth_apps)
- **Query** `mailbox_oauth_app_id`, `validate_only`

## Request

| Field | Type | What it is |
| --- | --- | --- |
| `parent` | `string` | The parent to create in. Required. |
| `mailbox_oauth_app_id` | `string` | The mailbox OAuth app id, the final name segment; the server assigns one when empty. |
| `mailbox_oauth_app` | `MailboxOauthApp` | The mailbox OAuth app to create; only caller-writable fields are read. Required. |
| `validate_only` | `bool` | Validate and return the result without writing anything. |

### MailboxOauthApp

| Field | Type | What it is |
| --- | --- | --- |
| `name` | `string` | `orgs/{org}/projects/{project}/envs/{env}/mailbox_oauth_apps/{mailbox_oauth_app}`. |
| `meta` | `ResourceMeta` | Resource metadata. |
| `spec` | `MailboxOauthAppSpec` | Desired state. Required. |

### ResourceMeta

| Field | Type | What it is |
| --- | --- | --- |
| `labels` | `map<string, string>` | Caller-writable, indexed labels (AIP-122 label rules). |
| `annotations` | `map<string, string>` | Caller-writable, unindexed annotations. |
| `display_name` | `string` | Caller-writable human-readable name. |

### MailboxOauthAppSpec

| Field | Type | What it is |
| --- | --- | --- |
| `provider` | `MailboxOauthProvider` | The provider. Required. One of `google`, `microsoft`. |
| `client_id` | `string` | The client id the provider issued. Required. |
| `client_secret` | `string` | The client secret; write-only, sealed at rest, never returned. Never returned again. |
| `tenant` | `string` | Microsoft only: who may consent, `common` (the default: any work, school or personal account), `organizations`, `consumers`, or one tenant id. |

## Response

| Field | Type | What it is |
| --- | --- | --- |
| `name` | `string` | `orgs/{org}/projects/{project}/envs/{env}/mailbox_oauth_apps/{mailbox_oauth_app}`. |
| `uid` | `string` | `moa_<cell><ulid>`; never reused. Output only. |
| `meta` | `ResourceMeta` | Resource metadata. |
| `spec` | `MailboxOauthAppSpec` | Desired state. Required. |
| `status` | `MailboxOauthAppStatus` | Observed state. Output only. |

### ResourceMeta

| Field | Type | What it is |
| --- | --- | --- |
| `generation` | `int64` | Increases by one on every change to `spec`. Output only. |
| `etag` | `string` | Strong ETag (AIP-154): changes on any change to spec, status, or metadata. Send it back as `If-Match` or `etag` to make Update and Delete conditional; a mismatch fails with ABORTED / 409 `ETAG_MISMATCH`. Output only. |
| `create_time` | `timestamp` | When the Resource was created. Output only. |
| `update_time` | `timestamp` | When the Resource last changed. Output only. |
| `delete_time` | `timestamp` | Set while the Resource is being deleted. Output only. |
| `labels` | `map<string, string>` | Caller-writable, indexed labels (AIP-122 label rules). |
| `annotations` | `map<string, string>` | Caller-writable, unindexed annotations. |
| `display_name` | `string` | Caller-writable human-readable name. |
| `creator` | `string` | The principal that created the Resource. Output only. |

### MailboxOauthAppSpec

| Field | Type | What it is |
| --- | --- | --- |
| `provider` | `MailboxOauthProvider` | The provider. Required. One of `google`, `microsoft`. |
| `client_id` | `string` | The client id the provider issued. Required. |
| `client_secret` | `string` | The client secret; write-only, sealed at rest, never returned. Never returned again. |
| `tenant` | `string` | Microsoft only: who may consent, `common` (the default: any work, school or personal account), `organizations`, `consumers`, or one tenant id. |

### MailboxOauthAppStatus

| Field | Type | What it is |
| --- | --- | --- |
| `observed_generation` | `int64` | The generation this status was computed from. Output only. |
| `conditions` | `Condition[]` | Ready, Reconciling, Stalled. Output only. |
| `client_secret_set` | `bool` | Whether a client secret is stored. Output only. |
| `redirect_uri` | `string` | The redirect URI to register on the provider's client. Output only. |
| `scopes` | `string[]` | The scopes a connect link asks for: Google `https://mail.google.com/` (a restricted scope: a public app needs Google's verification), and Microsoft `IMAP.AccessAsUser.All`, `SMTP.Send` and `offline_access`, each with `openid email` to learn the address. Output only. |

### Condition

| Field | Type | What it is |
| --- | --- | --- |
| `type` | `string` | The condition type, for example `Ready`. |
| `status` | `ConditionStatus` | Whether the condition holds. One of `true`, `false`, `unknown`. |
| `observed_generation` | `int64` | The generation this observation was made against. |
| `reason` | `string` | A machine-readable UpperCamelCase reason. |
| `message` | `string` | A customer-safe human-readable message. |
| `severity` | `Severity` | How severe a FALSE condition is. One of `info`, `warning`, `error`. |
| `transition_time` | `timestamp` | When `status` last changed. |

## Errors

- [`UNAUTHENTICATED`](/docs/api/errors/UNAUTHENTICATED) — No valid key or token was presented.
- [`PERMISSION_DENIED`](/docs/api/errors/PERMISSION_DENIED) — The key lacks the method's permission.
- [`UNKNOWN_FIELD`](/docs/api/errors/UNKNOWN_FIELD) — The request has a field the schema does not know.
- [`INVALID_FIELD`](/docs/api/errors/INVALID_FIELD) — A field failed validation.
- [`RESOURCE_ALREADY_EXISTS`](/docs/api/errors/RESOURCE_ALREADY_EXISTS) — A Resource with this name exists.
- [`IDEMPOTENCY_KEY_REUSED`](/docs/api/errors/IDEMPOTENCY_KEY_REUSED) — An Idempotency-Key was reused with another body.
- [`IDEMPOTENCY_IN_PROGRESS`](/docs/api/errors/IDEMPOTENCY_IN_PROGRESS) — The first call with this Idempotency-Key is still running.

Every error arrives in the body [Errors](/docs/platform/errors) describes.

## Examples

**cURL**

```curl
curl -X POST "https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/mailbox_oauth_apps" \
  -H "Authorization: Bearer $SYLPHX_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"spec":{"client_id":"…","provider":"google"}}'
```

**TypeScript**

```ts
const response = await sylphx.notify.mailboxOauthApps.create({ mailboxOauthApp: { spec: { clientId: '…', provider: 'google' } }, parent: 'orgs/acme/projects/shop/envs/production' })
```

**Rust**

```rust
let mut req = sylphx::notify::CreateMailboxOauthAppRequest::default();
req.mailbox_oauth_app = Some(sylphx::notify::MailboxOauthApp {
    spec: Some(sylphx::notify::MailboxOauthAppSpec {
        client_id: "…".to_string(),
        provider: sylphx::notify::MailboxOauthProvider::Google,
        ..Default::default()
    }),
    ..Default::default()
});
req.parent = "orgs/acme/projects/shop/envs/production".to_string();
let response = sx.notify().mailbox_oauth_apps().create(req).await?;
```

**CLI**

```bash
sylphx notify mailbox-oauth-apps create --parent orgs/acme/projects/shop/envs/production --spec.provider google --spec.client-id …
```

**MCP**

```json
{ "method_id": "notify.mailbox_oauth_apps.create", "args": {"mailbox_oauth_app":{"spec":{"client_id":"…","provider":"google"}},"parent":"orgs/acme/projects/shop/envs/production"} }
```
