Skip to content

Start connecting a mailbox

GET
/{provider}/oauth/start
curl --request GET \
--url 'https://api.clearance.rest/emails/gmail/oauth/start?return_url=https%3A%2F%2Fapp.example.com%2Fsettings%2Fmailboxes&client_state=user-42' \
--header 'X-API-Key: <X-API-Key>'

Call this from your backend, not the browser. It returns an authorize_url; redirect the user’s browser there. After the user consents, the provider redirects to the service, which redirects the browser to your return_url with result_token and client_state query parameters. Read the outcome server-to-server with GET /{provider}/oauth/result.

return_url must be an absolute http(s) URL. If your project restricts allowed return origins, only those origins are accepted.

provider
required
string
Allowed values: gmail outlook

Mail provider.

return_url
required
string format: uri

Where the browser is sent after the provider redirect.

client_state
string

Opaque value of your choosing, echoed back unchanged at the end of the flow.

The URL to send the user to.

Media typeapplication/json
object
success
required
boolean
authorize_url
required
string format: uri
Example
{
"success": true,
"authorize_url": "https://accounts.google.com/o/oauth2/v2/auth?client_id=example&state=6f1c1a4e"
}

return_url is not an absolute http(s) URL, or its origin is not allowed.

Media typeapplication/json

Error envelope returned with a non-2xx status.

object
success
required
boolean
error
required

Human-readable error message.

string
Example
{
"success": false,
"error": "geçersiz veya izin verilmeyen return_url"
}

The X-API-Key header is missing or invalid.

Media typeapplication/json

Error envelope returned with a non-2xx status.

object
success
required
boolean
error
required

Human-readable error message.

string
Example
{
"success": false,
"error": "geçersiz API anahtarı"
}