Skip to main content
POST
Allowlist an inbox sender

Authorizations

X-API-Key
string
header
required

User API key authentication. Create a key under Settings → API keys in the Slash dashboard (https://app.slash.com/global-settings/api-keys) and send the x-legal-entity header naming the legal entity to act on with every request. Keys scoped to a legal entity are rejected with 403 user_api_key_required.

Headers

The legal entity to act on. Required on every request; a user API key can act on any legal entity its user has access to.

Pattern: ^le_[a-zA-Z0-9]+$

Body

application/json

Allowlist an email address or a whole domain for the accounts-payable inbox.

type
enum<string>
required

email to allowlist one address, domain to allowlist every address at a domain.

Available options:
email,
domain
value
string
required

The address (billing@vendor.com) or bare domain (vendor.com), matched case-insensitively. Public mail providers such as gmail.com cannot be allowlisted as a domain; add the individual address instead.

Required string length: 1 - 254
Example:

"billing@vendor.com"

Response

The allowlisted sender.

An email address or domain the legal entity has allowlisted for its accounts-payable inbox. Invoices from an allowlisted sender become draft bills even when the sender is not a user, on the company's domain, or a known vendor.

id
string
required

Sender id with the ais_ prefix. Remove the sender with DELETE /v2/bills/inbox/senders/{senderId}.

Example:

"ais_2rj4l7hmrrrcv"

type
enum<string>
required

email matches one address exactly; domain matches every address at that domain.

Available options:
email,
domain
value
string
required

The lowercased address or bare domain.

Example:

"billing@vendor.com"

createdAt
string<date-time>
required

When the sender was allowlisted.