How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

Sublime Security Messages API

The Messages API from Sublime Security — 19 operation(s) for messages.

Sublime Security Messages API is one of 16 APIs that Sublime Security publishes on the APIs.io network, described by a machine-readable OpenAPI specification.

Tagged areas include Message. The published artifact set on APIs.io includes an OpenAPI specification.

This API exposes 19 operations across 19 paths, and defines 75 schemas. It is described by OpenAPI 3.2.0, at version 1.0.

Requests are made against a single base URL, {scheme}://{server}.

19 operations 19 paths 75 schemas 10 GET9 POST

Metadata

The identity and technical contract details declared by the specification.

Specification
OpenAPI 3.2.0
API Version
1.0
Base URL
https://platform.sublime.security
Authentication
HTTP Bearer
Resource Areas
1

Authentication & Security 1

Sublime Security Messages API declares 1 security scheme for authenticating requests. It accepts HTTP bearer tokens (bearerAuth). By default, every request must be authenticated.

Paths & Operations 19

Across 19 paths, the API surfaces 19 operations — 10 GET, 9 POST. Each is listed below with its method, path, parameters, and response codes.

Messages 19
POST
/v0/messages/analyze
Analyze a raw message
analyzeMessage body → 200
POST
/v0/messages/attachment/image
Render image for attachment from the raw base64 encoded bytes
getMessageAttachmentImageRaw body → 200
POST
/v0/messages/attack_score
Evaluate attack score for a raw message
attackScoreForRawMessage body → 200
POST
/v0/messages/create
Create message
createMessage body → 200
GET
/v0/messages/groups/{id}/action-state
Retrieve details about the state of manual actions for a canonical group
getMessageCanonicalGroupActionState 4 params → 200
GET
/v0/messages/{id}
Retrieve message
getMessage 3 params → 200
POST
/v0/messages/{id}/actions
Perform actions on an individual message
actionMessage 1 param body → 202
POST
/v0/messages/{id}/analyze
Analyze a message by ID
analyzeMessageByID 1 param body → 200
GET
/v0/messages/{id}/asa_report
Retrieve ASA report for a message
retrieveASAReport 1 param → 200
GET
/v0/messages/{id}/asa_verdict
Retrieve ASA verdict for a message
retrieveASAVerdict 1 param → 200
GET
/v0/messages/{id}/attachment/{hash}/image
Retrieve image of PDF attachment by md5 hash
getMessageAttachmentImage 2 params → 200
GET
/v0/messages/{id}/attack_score
Evaluate attack score against an existing message
attackScoreForMessage 1 param → 200
GET
/v0/messages/{id}/eml
Retrieve raw EML
getMessageEML 1 param → 200
GET
/v0/messages/{id}/image
Retrieve image of message
getMessageImage 3 params → 200
GET
/v0/messages/{id}/image_link
Retrieve a temporary link to the image of message
getMessageImageLink 5 params → 200
POST
/v0/messages/{id}/justification
Set access justification
SetMessageAccessJustification 1 param body → 200
GET
/v0/messages/{id}/message_data_model
Retrieve the message's Message Data Model
getMessageDataModel 3 params → 200
POST
/v0/messages/{id}/restore
Restore a previously-trashed message
restoreMessage 1 param → 202
POST
/v0/messages/{id}/trash
Trash message
trashMessage 1 param → 202

Schemas 75

The contract defines 75 schemas that model the data the API accepts and returns. The most detailed are Mdm_serviceHeaders (20 properties), HandlersMessage (17 properties), Handler_typesMessage (14 properties), Mdm_serviceURL (12 properties). Each schema is shown below with its type and property counts.

CreateMessageInput
object
10 properties 1 required
Mdm_serviceSPFSummary
object
Summary of the SPF check
4 properties
Mdm_serviceThread
object
The current text thread of the message
4 properties
Mdm_serviceLink
object
6 properties
Mdm_serviceReceivedFrom
object
The 'from' section of the Received header, relating to a server in a prior hop
1 property
Mdm_serviceMessageType
object
Override on message types, defined from the perspective of your organization
3 properties
Mdm_serviceRewriteDetails
object
Information about an original URL that was unfurled from rewrite detection
2 properties 1 required
TypesMessageType
object
The types of the message
3 properties
Handler_typesMessageImageLink
object
2 properties 2 required
Mdm_serviceBanner
object
2 properties
Handler_typesTaskAccepted
object
1 property 1 required
Handler_typesAnalyzeResponseRule
object
6 properties 3 required
Mdm_serviceDomain
object
Domain parsed from X-Authenticated-Domain or X-Authenticated-Sender headers, which represents the domain used for sender authentication, typically the domain o…
7 properties 1 required
Handler_typesAnalyzeResponseQuery
object
6 properties 2 required
Handler_typesQuerySimpleMeta
object
Metadata about the query evaluated against the message
3 properties
Mdm_serviceReceivedVia
object
The 'via' section of the Received header, denoting transport
1 property
Handler_typesMessageImage
object
3 properties
Mdm_serviceHopField
object
3 properties 2 required
Mdm_serviceMessageDataModel
object
Full data model of the message
11 properties 5 required
Mdm_serviceIP
object
X-Originating-IP header, which identifies the originating IP address of the sender client
3 properties 1 required
Mdm_serviceMailbox
object
Organizer mailbox with email and display name
2 properties 1 required
TypesPreview
object
Preview of key details from the message header
5 properties 4 required
Mdm_serviceReceivedFor
object
The 'for' section of the Received header, denoting the destination mailbox
1 property
Handler_typesRuleSimplePublicID
object
Metadata for the rule compared against the message
4 properties 1 required
AnalyzeMessageInput
object
6 properties 1 required
AnalyzeMessageByIDInput
object
5 properties
SetMessageAccessJustificationInput
object
1 property
Handler_typesRecipient
object
1 property 1 required
Mdm_serviceIPTranslation
object
2 properties
HandlersAsaTitleDescriptionPair
object
2 properties
GetMessageAttachmentImageRawInput
object
2 properties 1 required
Mdm_serviceSenderMailbox
object
Sender object
3 properties 1 required
Mdm_serviceThreadRecipients
object
Recipients extracted from thread preamble
3 properties
Mdm_serviceHop
object
6 properties 2 required
Mdm_serviceSignature
object
Details of a message signature. Supported fields include 'DKIM-Signature', 'DomainKey-Signature', 'X-Google-DKIM-Signature' and 'ARC-Message-Signature'
9 properties
HandlersMessage
object
17 properties 7 required
Mdm_serviceReceivedWith
object
The 'with' section of the Received header, denoting the protocol used
1 property
Mdm_serviceExternal
object
Cloud API provider or other external source metadata
6 properties
Actions_typesActionEventCounts
object
6 properties
Mdm_serviceReceivedID
object
The 'id' section of the Received header
1 property
Mdm_servicePlain
object
The body part containing content-type text/plain
4 properties
Mdm_serviceAttachment
object
11 properties
Mdm_serviceDMARC
object
Details of the Domain-based Message Authentication, Reporting & Conformance check
7 properties
Mdm_serviceCompAuth
object
Composite Authentication result, used by Microsoft O365
2 properties 2 required
Mdm_serviceRecipients
object
Recipient objects
3 properties
HandlersAsaVerdictResponseV0
object
1 property
Mdm_serviceReceivedBy
object
The 'by' section of the Received header, denoting the current server
1 property
Handler_typesAttachmentImageContent
object
2 properties
Mdm_serviceAuthResults
object
Results of authentication. Supported fields include 'Authentication-Results', 'X-Original-Authentication-Results', 'X-MS-Exchange-Authentication-Results', 'X-A…
10 properties
Mdm_serviceReceived
object
Details of the Received field
9 properties
Mdm_serviceHeaders
object
The message headers
20 properties 1 required
Mdm_serviceDMARCSummary
object
Summary of the DMARC check
4 properties
Mdm_serviceSubject
object
Subject object
5 properties
Mdm_servicePreviousThread
object
9 properties
Mdm_serviceMailboxExtended
object
The mailbox where the message was found
4 properties 1 required
Mdm_serviceURL
object
URL details when QR code type is url
12 properties 1 required
Handler_typesAnalyzeRawMessageResponse
object
2 properties
Mdm_serviceSPF
object
Details of the Sender Policy Framework check. Supported fields include 'Received-SPF' and 'X-Received-SPF'
6 properties
HandlersGetMessageCanonicalGroupTasksResponse
object
1 property
Mdm_serviceAuthSummary
object
Summary of authentication results for the message
2 properties
Handler_typesMailbox
object
Mailbox that the email bomb was found in
3 properties 2 required
AttackScoreForRawMessageInput
object
1 property 1 required
Handler_typesMessage
object
14 properties 7 required
Mdm_serviceReceivedAdditional
object
The remaining additional clauses of the Received header
1 property
Mdm_serviceBodyHTML
object
The body part containing content-type text/html
6 properties
Mdm_serviceMetadata
object
Metadata
4 properties 2 required
Mdm_serviceBody
object
Body of the email
6 properties
Mdm_serviceEmailAddress
object
Email address object
3 properties
Handler_typesRuleSimple
object
5 properties 1 required
ActionMessageInput
object
3 properties
Handler_typesQuerySimple
object
3 properties 1 required
HandlersAttackScoreSignalResult
object
3 properties
HandlersAttackScoreResponse
object
4 properties
Handler_typesSender
object
Details of the message sender
2 properties 1 required
HandlersAsaReportResponseV0
object
5 properties

Specification

The full machine-readable OpenAPI contract behind this narrative.

Source

sublime-security-messages-api-openapi.yml Raw ↑

Other APIs Sublime Security publishes across the network.

Sublime Security BinExplode API
Sublime Security Email Bombs API
Sublime Security Enrichment API
Sublime Security Events in the audit log API
Sublime Security Hunt Jobs API
Sublime Security Lists API
Sublime Security Live flow API
Sublime Security Mailboxes API
Sublime Security Message Groups API
Sublime Security Organizations API
Sublime Security Roles API
Sublime Security Rules API
Where this information came from

This is an independent, third-party profile of Sublime Security Messages API, published by API Evangelist. We do not operate, host, resell, or support these APIs, and we are not affiliated with or endorsed by the company unless stated above. Everything here is built from publicly available information — the company's own site, developer portal, documentation, public repositories, and the specifications it publishes for public use. Nothing is obtained by breaching a system, defeating an access control, or using credentials.

The Kin Score and Agent Readiness rating are independently calculated assessments of a company's public API artifacts, scored against a published rubric. They are not certifications, endorsements, security assessments, or audits.

Corrections, re-scores, and removal are free — no partnership or purchase required, and you do not need to justify the request. A removed company is recorded as unrated, never scored zero for having asked. Acknowledgement within one business day; removal within two.

info@apievangelist.com · Read the full data-sourcing policy →
On a security or compliance team? Put security in the subject line and you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.