SendMailboxEmail
Send email from an exact owned mailbox through a short-lived DirectAdmin/Roundcube delegated session without requesting its password.
Endpoint: https://sive.host/modules/addons/shapi/sh-api.php
Method: POST using application/x-www-form-urlencoded.
Consequential action: may purchase, delete, replace credentials, or remove data. Access is limited to directly owned records or explicitly assigned Partner-managed client services after both relationships are verified.
Important behavior
- The From address is fixed to the delegated mailbox; arbitrary sender overrides are not accepted.
- The user must explicitly confirm the exact From, To, subject, and body immediately before sending.
- Per-mailbox MCP limits are 20 messages per hour and 100 per day.
Request parameters
| Parameter | Type | Required | Description |
|---|---|---|---|
action | string | Yes | Exact SHAPI action name shown in this article. |
api_key | string | Yes | Client API key generated in the Sive.Host SHAPI page. |
api_secret | string | Yes | Secret paired with the API key. Send it only in the POST body. |
serviceid | positive integer | Yes | Active WHMCS service ID owned by the authenticated client. |
mailbox | email address | Yes | Full mailbox address. |
to | JSON array | Yes | One to ten recipient addresses. |
subject | string | Yes | Message subject, maximum 200 characters. |
text_body | string | No | Plain-text body. |
html_body | string | No | Optional HTML body. |
confirm_send | boolean | Yes | Must be true after confirming exact From, To, subject, and body. |
Example request
Set the four environment variables from the authenticated SHAPI page. Do not put credentials in source control or URLs.
curl --request POST 'https://sive.host/modules/addons/shapi/sh-api.php' \
--user "${SHAPI_HTTP_USER}:${SHAPI_HTTP_PASSWORD}" \
--header 'Accept: application/json' \
--data-urlencode "action=SendMailboxEmail" \
--data-urlencode "api_key=${SHAPI_API_KEY}" \
--data-urlencode "api_secret=${SHAPI_API_SECRET}" \
--data-urlencode "serviceid=12345" \
--data-urlencode "mailbox=user@example.com" \
--data-urlencode "to=[\"recipient@example.net\"]" \
--data-urlencode "subject=Hello" \
--data-urlencode "text_body=Hello from Sive.Host" \
--data-urlencode "confirm_send=true"Response
SHAPI always returns JSON. Check result; panel responses can vary by the server module and DirectAdmin version.
{
"result": "success",
"message": {
"action": "SendMailboxEmail",
"data": "Panel- or action-specific response"
}
}Common errors
Unauthorized access!: source IP or HTTP Basic authentication failed.Invalid API Key or secret.: the customer key is wrong, disabled, or deleted.Unable to retrieve an active service owned by this client.: the service is inactive or belongs to another client.Missing required parameters.: one or more required fields were omitted.
SHAPI documentation version 2.0 — generated from the current endpoint contract.

