> ## Documentation Index
> Fetch the complete documentation index at: https://docs.anycrm.anyreach.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Inbound Email

> Somebody mailed the assistant a meeting link (F23).

The most exposed surface in the feature: it books a paid bot from an
unauthenticated request, so it is the one place where refusing by default
matters most. With no secret configured the endpoint refuses everything —
a fresh environment has no secret, and an inbound booking path must not be
open because a deployment has not been finished.

Vetting is by sender DOMAIN, matched against the org's own domains and then
against the domains of its known contacts. Everything else — the classify,
the live-call lookup, the booking — happens in the RPC, so a redelivery and
two simultaneous senders resolve the same way.



## OpenAPI

````yaml /openapi-generated.json post /meetings/webhooks/inbound-email
openapi: 3.1.0
info:
  title: anycrm-api
  version: 0.0.1
servers: []
security: []
tags:
  - name: Customer Intelligence
    description: >-
      Company research and ICP-fit scoring — create a research run, track its
      progress, and read back scored companies as leads.
  - name: Outreach
    description: >-
      The cold-email management console — domains, mailboxes, and campaigns — as
      a thin control plane over the SalesForge stack.
  - name: AnyCard
    description: >-
      Authenticated CRUD for AnyCard, the org's digital business-card /
      lead-capture product.
  - name: AnyCard Events
    description: >-
      Event-attribution analytics for AnyCard — which captured leads converted,
      broken down by source, owner, and deal.
  - name: AnyCard Share Links
    description: >-
      Unauthenticated endpoints reached by anyone who scans a QR code or opens a
      shared AnyCard link.
  - name: AI
    description: >-
      A streaming (SSE) AI chat endpoint with account-commit actions it can take
      on the caller's behalf.
  - name: Analytics Assistant
    description: >-
      The natural-language analytics assistant — a guarded text-to-SQL loop
      (SSE) that answers ad-hoc questions over the org's CRM data as a
      least-privilege, read-only database role.
  - name: Account Readiness
    description: >-
      Account Readiness Profiles — AI-scored signals on whether an account is
      ready for outreach or expansion, computed via a Temporal workflow.
  - name: Integrations
    description: >-
      Pipedream Connect — issuing connect tokens and managing the org's
      connected third-party accounts.
  - name: Feedback
    description: >-
      User-submitted platform feedback (bug reports, feature requests) — global,
      not scoped to one organization.
  - name: Public Media
    description: >-
      Unauthenticated image reads for publicly-embeddable assets (card photos,
      inline email images) — allowlisted by key shape; everything else in the
      storage bucket stays private.
  - name: Service Health
    description: Service liveness.
paths:
  /meetings/webhooks/inbound-email:
    post:
      tags:
        - Meetings
      summary: Inbound Email
      description: >-
        Somebody mailed the assistant a meeting link (F23).


        The most exposed surface in the feature: it books a paid bot from an

        unauthenticated request, so it is the one place where refusing by
        default

        matters most. With no secret configured the endpoint refuses everything
        —

        a fresh environment has no secret, and an inbound booking path must not
        be

        open because a deployment has not been finished.


        Vetting is by sender DOMAIN, matched against the org's own domains and
        then

        against the domains of its known contacts. Everything else — the
        classify,

        the live-call lookup, the booking — happens in the RPC, so a redelivery
        and

        two simultaneous senders resolve the same way.
      operationId: inbound_email_meetings_webhooks_inbound_email_post
      parameters:
        - name: X-Signature
          in: header
          required: false
          schema:
            anyOf:
              - type: string
              - type: 'null'
            title: X-Signature
      responses:
        '200':
          description: Successful Response
          content:
            application/json:
              schema:
                type: object
                additionalProperties: true
                title: Response Inbound Email Meetings Webhooks Inbound Email Post
        '422':
          description: Validation Error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/HTTPValidationError'
components:
  schemas:
    HTTPValidationError:
      properties:
        detail:
          items:
            $ref: '#/components/schemas/ValidationError'
          type: array
          title: Detail
      type: object
      title: HTTPValidationError
    ValidationError:
      properties:
        loc:
          items:
            anyOf:
              - type: string
              - type: integer
          type: array
          title: Location
        msg:
          type: string
          title: Message
        type:
          type: string
          title: Error Type
      type: object
      required:
        - loc
        - msg
        - type
      title: ValidationError

````