How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

Valimail Partner API

The Valimail Partner API is the reseller/MSP surface for managing customer accounts under a partner account — account lifecycle (create, read, update, delete, and hard-delete under /v2), user lifecycle and invitations, full SSO configuration CRUD, subscription packages, portfolios, and an account senders report. OpenAPI 3.0.0, 12 paths, 21 operations, bearer-JWT secured via the shared POST /auth credential exchange. Overlaps the Account Management API but adds GET /accounts/{slug}/reports/senders and the GET/PUT/DELETE SSO operations. Discovered 2026-08-14 at https://api.valimail.com/docs/partner.yml; it is served from Valimail's own API host, its servers[] are api.valimail.com / api.valimail-staging.com, and info.title is "Partner API" with description "ValiMail Integration API" — but nothing in the Valimail help center links to it.

Valimail Partner API is one of 17 APIs that Valimail publishes on the APIs.io network, described by a machine-readable OpenAPI specification.

Tagged areas include Partner, Account, User, SSO, and Portfolio. The published artifact set on APIs.io includes an OpenAPI specification, an API reference, and API documentation.

This API exposes 21 operations across 12 paths, organized into 6 resource areas, and defines 21 schemas. It is described by OpenAPI 3.0.0, at version 1.0.0.

Requests are made against 3 base URLs: https://api.valimail.com, https://api.valimail-staging.com, http://localhost:7001.

21 operations 12 paths 21 schemas 5 DELETE8 GET5 POST3 PUT

Metadata

The identity and technical contract details declared by the specification.

Specification
OpenAPI 3.0.0
API Version
1.0.0
Base URL
https://api.valimail.com
Authentication
HTTP Bearer
Resource Areas
6

Authentication & Security 1

Valimail Partner API declares 1 security scheme for authenticating requests. It accepts HTTP bearer tokens (JWT) (bearerAuth). By default, every request must be authenticated.

Paths & Operations 21

Across 12 paths, the API surfaces 21 operations — 5 DELETE, 8 GET, 5 POST, 3 PUT. They span 6 resource areas: Authentication, Accounts, Users, SSO, Portfolios, Senders Reports. Each is listed below with its method, path, parameters, and response codes.

Authentication 1
POST
/auth
Authenticates the API user with the credentials (client-id and app-id)
body → 200400422429500
Accounts 7
GET
/accounts/packages
Returns a list of packages available for a partner account.
→ 200400401403422429500
GET
/accounts
Returns accounts and subsidiaries that are linked to the partner account. (If no query parameters are provided, all accounts and subsidiaries linked to the partner account will be returned.)
8 params → 200400401403422429500
POST
/accounts
Creates a new account with the partner account as the parent account and also creates all domains provided in the request body as enabled domains linked to the account that was created.
body → 200400401403422429500
GET
/accounts/{slug}
Returns a single account that are linked to the partner account according to the account slug provided.
1 param → 200400404401403422429500
PUT
/accounts/{slug}
Updates name, limits, and package of authorized accounts according to the slug provided in the path.
1 param body → 200400404401403422429500
DELETE
/accounts/{slug}
Deactivates account by updating the account limits to zero
1 param → 200400401403422429500
DELETE
/accounts/{slug}/v2
Deletes the account according to the account slug provided. Depending on the account's domains, either destroys the account or revokes it by removing its users and domains.
1 param → 200400401403422429500
Users 7
GET
/accounts/{slug}/users
Returns users linked to the account slug provided.
11 params → 200400401403422429500
POST
/accounts/{slug}/users
Creates a new user linked to the account slug provided and sends an invitation email.
1 param body → 200400401403422429500
POST
/accounts/{slug}/users/{user-slug}/invitation
Sends a new invitation email for the existing user and returns the latest activation link.
2 params → 200400401403404422429500
GET
/accounts/{slug}/users/{user-slug}
Returns account user data by account slug and user slug.
2 params → 200400401403404422429500
PUT
/accounts/{slug}/users/{user-slug}
Updates user data by account slug and user slug.
2 params body → 200400401403404422429500
DELETE
/accounts/{slug}/users/{user-slug}
Inactivates a user according to the account slug and user slug provided.
2 params → 200400401403422429500
DELETE
/accounts/{slug}/v2/users/{user-slug}
Inactivates a user according to the account slug and user slug provided.
2 params → 200400401403422429500
SSO 4
GET
/accounts/{slug}/app/sso
Returns the SSO configuration for the account slug provided.
1 param → 200401403404422429500
POST
/accounts/{slug}/app/sso
Creates an SSO configuration for the account slug provided.
1 param body → 200400401403422429500
PUT
/accounts/{slug}/app/sso
Updates the SSO configuration for the account slug provided. Supports partial updates — only the fields provided in the request body will be changed.
1 param body → 200400401403404422429500
DELETE
/accounts/{slug}/app/sso
Deletes the SSO configuration for the account slug provided.
1 param → 200401403404422429500
Portfolios 1
GET
/accounts/{slug}/portfolios
Returns domains connected to portfolios of all linked accounts
1 param → 200400401403422429500
Senders Reports 1
GET
/accounts/{slug}/reports/senders
Returns senders report
7 params → 200429400401403422500

Schemas 21

The contract defines 21 schemas that model the data the API accepts and returns. The most detailed are Account (9 properties), SsoConfig (8 properties), AccountListItem (8 properties), User (8 properties). Each schema is shown below with its type and property counts.

KeyRequest
object
2 properties
KeyResponse
object
2 properties
ErrorResponse
object
5 properties
PortfolioSets
array
User
object
8 properties
InvitedUser
CreateUser
object
4 properties
UserUpdate
object
4 properties
UserDelete
object
2 properties
SsoCreate
object
6 properties
SsoConfig
object
8 properties
AccountListItem
object
Account read response payload. Fields with empty or null values are omitted. Numeric limit fields are serialized as strings.
8 properties
Account
object
Account response payload. Fields with empty or null values are omitted. Numeric limit fields are serialized as strings.
9 properties
UpdateAccount
object
6 properties
Senders
array
Any
ValidationDetail
object
3 properties
ValidationResponse
object
2 properties
DefaultDelegatedAPIErrorResponse
object
4 properties
DelegatedAPIValidationErrorDetail
object
3 properties
DelegatedAPIValidationErrorResponse
object
2 properties

Specification

The full machine-readable OpenAPI contract behind this narrative.

Source

valimail-partner-openapi-original.yml Raw ↑

Other APIs Valimail publishes across the network.

Valimail Reporting Data API
Valimail Accounts API
Valimail Authentication API
Valimail DKIMs by Domain API
Valimail DKIMs by Sender API
Valimail Domains API
Valimail MTA-STS Policy API
Valimail MTA-STS Policy Reports API
Valimail Netblocks API
Valimail Portfolios API
Valimail SCIM API
Valimail Senders API
Where this information came from

This is an independent, third-party profile of Valimail Partner API, published by API Evangelist. We do not operate, host, resell, or support these APIs, and we are not affiliated with or endorsed by the company unless stated above. Everything here is built from publicly available information — the company's own site, developer portal, documentation, public repositories, and the specifications it publishes for public use. Nothing is obtained by breaching a system, defeating an access control, or using credentials.

The Kin Score and Agent Readiness rating are independently calculated assessments of a company's public API artifacts, scored against a published rubric. They are not certifications, endorsements, security assessments, or audits.

Corrections, re-scores, and removal are free — no partnership or purchase required, and you do not need to justify the request. A removed company is recorded as unrated, never scored zero for having asked. Acknowledgement within one business day; removal within two.

info@apievangelist.com · Read the full data-sourcing policy →
On a security or compliance team? Put security in the subject line and you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.