Skip to content

Create S/MIME config

POST/smime/config

Email Management API · SMIME

Create S/MIME configuration. Setting smimeEnabled to true requires an internal CA certificate to already exist for the tenant.

Parameters

Name In Type Required Description
X-Tenant-ID header string (uuid) Yes Tenant ID.

Request body

Content type: application/json

Request body fields

smimeEnabledbooleanrequired
Whether S/MIME is enabled for the tenant.
extractCertificateboolean
Whether to extract certificates from incoming messages.
certExpiryNotificationEmailAddressesarray of string (email)
Target email addresses to which certificate expiry notification emails are sent.
Must contain at most 5 items. Each item must be 3–255 characters long.

Request samples

curl -X POST "https://api-<data-region>.central.sophos.com/email/v1/smime/config" -H "Authorization: Bearer <access-token>" -H "X-Tenant-ID: <tenant-id>" -H "Content-Type: application/json" -d "{
  \"smimeEnabled\": true,
  \"extractCertificate\": false,
  \"certExpiryNotificationEmailAddresses\": [
    \"john.doe@sophos.com\"
  ]
}"

import requests

response = requests.post(
    "https://api-<data-region>.central.sophos.com/email/v1/smime/config",
    headers={
        "Authorization": "Bearer <access-token>",
        "X-Tenant-ID": "<tenant-id>",
        "Content-Type": "application/json",
    },
    json={   'smimeEnabled': True,
    'extractCertificate': False,
    'certExpiryNotificationEmailAddresses': ['john.doe@sophos.com']},
)
print(response.json())

$headers = @{
    "Authorization" = "Bearer <access-token>"
    "X-Tenant-ID" = "<tenant-id>"
    "Content-Type" = "application/json"
}
$body = '{
  "smimeEnabled": true,
  "extractCertificate": false,
  "certExpiryNotificationEmailAddresses": [
    "john.doe@sophos.com"
  ]
}'
Invoke-RestMethod -Method POST -Uri "https://api-<data-region>.central.sophos.com/email/v1/smime/config" -Headers $headers -Body $body -ContentType "application/json"

package main

import (
    "fmt"
    "io"
    "net/http"
    "strings"
)

func main() {
    req, err := http.NewRequest("POST", "https://api-<data-region>.central.sophos.com/email/v1/smime/config", strings.NewReader(`{
  "smimeEnabled": true,
  "extractCertificate": false,
  "certExpiryNotificationEmailAddresses": [
    "john.doe@sophos.com"
  ]
}`))
    if err != nil {
        panic(err)
    }
    req.Header.Set("Authorization", "Bearer <access-token>")
    req.Header.Set("X-Tenant-ID", "<tenant-id>")
    req.Header.Set("Content-Type", "application/json")

    resp, err := http.DefaultClient.Do(req)
    if err != nil {
        panic(err)
    }
    defer resp.Body.Close()

    body, _ := io.ReadAll(resp.Body)
    fmt.Println(string(body))
}

const response = await fetch("https://api-<data-region>.central.sophos.com/email/v1/smime/config", {
  method: "POST",
  headers: {
    "Authorization": "Bearer <access-token>",
    "X-Tenant-ID": "<tenant-id>",
    "Content-Type": "application/json",
  },
  body: JSON.stringify({
  "smimeEnabled": true,
  "extractCertificate": false,
  "certExpiryNotificationEmailAddresses": [
    "john.doe@sophos.com"
  ]
}),
});
const data = await response.json();
console.log(data);

Responses

201 — S/MIME configuration created.

Response fields

smimeEnabledbooleanrequired
Whether S/MIME is enabled for the tenant.
extractCertificatebooleanrequired
Whether to extract certificates from incoming messages.
certExpiryNotificationEmailAddressesarray of string (email)required
Target email addresses to which certificate expiry notification emails are sent.
Must contain at most 5 items.
deleteTokenstringrequired
Token required for the DELETE request to remove the S/MIME configuration (use as the path parameter in DELETE /config/{deleteToken}).
Must be exactly 8 characters long.

Errors

Status Meaning
400 Invalid request.
401 Authentication required.
403 Authorization required.
409 Conflict. The configuration already exists, or smimeEnabled was set to true before an internal CA certificate was configured.
500 Internal server error.
503 Server Unavailable.

All error responses share the same shape — see the error response object.

Response examples

201

{
  "smimeEnabled": true,
  "extractCertificate": true,
  "certExpiryNotificationEmailAddresses": [
    "user_bob@sophos.com"
  ],
  "deleteToken": "a1b2c3d4"
}

See the guide for a narrative walkthrough of this API.