Umtapo Wolwazi

ReplyMailboxMessage Print

  • 0

ReplyMailboxMessage

Send a true threaded reply to one existing owned mailbox message through passwordless DirectAdmin/Roundcube delegation.

Endpoint: https://sive.host/modules/addons/shapi/sh-api.php

Method: POST using application/x-www-form-urlencoded.

Consequential action: may purchase, delete, replace credentials, or remove data. Access is limited to directly owned records or explicitly assigned Partner-managed client services after both relationships are verified.

Important behavior

  • Roundcube binds the send to the source UID so Message-ID/References threading and the Answered flag are preserved.
  • The source message is marked read after Roundcube confirms the reply.
  • HTML entities and folded whitespace in the live Roundcube subject are normalized before it is compared with the confirmed subject.
  • Live reply recipients and normalized subject must exactly match the values the user confirmed.

Request parameters

ParameterTypeRequiredDescription
actionstringYesExact SHAPI action name shown in this article.
api_keystringYesClient API key generated in the Sive.Host SHAPI page.
api_secretstringYesSecret paired with the API key. Send it only in the POST body.
serviceidpositive integerYesActive WHMCS service ID owned by the authenticated client.
mailboxemail addressYesFull mailbox address.
folderstringNoMailbox folder containing the source message; defaults to INBOX.
uidpositive integerYesUID returned by ListMailboxMessages.
reply_allbooleanNoUse Roundcube reply-all resolution; defaults to false.
expected_toJSON arrayYesExact To recipients shown to and confirmed by the user.
expected_ccJSON arrayNoExact CC recipients shown to and confirmed by the user.
expected_subjectstringYesExact reply subject shown to and confirmed by the user.
text_bodystringNoPlain-text reply body.
html_bodystringNoOptional HTML reply body.
confirm_sendbooleanYesMust be true after confirming exact From, To, CC, subject, and body.

Example request

Set the four environment variables from the authenticated SHAPI page. Do not put credentials in source control or URLs.

curl --request POST 'https://sive.host/modules/addons/shapi/sh-api.php' \
  --user "${SHAPI_HTTP_USER}:${SHAPI_HTTP_PASSWORD}" \
  --header 'Accept: application/json' \
  --data-urlencode "action=ReplyMailboxMessage" \
  --data-urlencode "api_key=${SHAPI_API_KEY}" \
  --data-urlencode "api_secret=${SHAPI_API_SECRET}" \
  --data-urlencode "serviceid=12345" \
  --data-urlencode "mailbox=user@example.com" \
  --data-urlencode "folder=INBOX" \
  --data-urlencode "uid=123" \
  --data-urlencode "reply_all=false" \
  --data-urlencode "expected_to=[\"sender@example.net\"]" \
  --data-urlencode "expected_cc=[]" \
  --data-urlencode "expected_subject=Re: Hello" \
  --data-urlencode "text_body=Thank you for your message." \
  --data-urlencode "confirm_send=true"

Response

SHAPI always returns JSON. Check result; panel responses can vary by the server module and DirectAdmin version.

{
    "result": "success",
    "message": {
        "action": "ReplyMailboxMessage",
        "data": "Panel- or action-specific response"
    }
}

Common errors

  • Unauthorized access!: source IP or HTTP Basic authentication failed.
  • Invalid API Key or secret.: the customer key is wrong, disabled, or deleted.
  • Unable to retrieve an active service owned by this client.: the service is inactive or belongs to another client.
  • Missing required parameters.: one or more required fields were omitted.

SHAPI documentation version 2.0 — generated from the current endpoint contract.


Ingabe le mpendulo ibe usizo?
Back