The inbox talks to Relay through these endpoints. They need the session cookie you get by signing in, they act on the workspace you are currently in, and they’re listed here for completeness.
Not a stable public API
Owner endpoints serve Relay’s own inbox and can change between versions. There are no API keys yet; a keyed REST API and webhooks are on the roadmap.
Session#
Sign-in uses Google or an emailed link and is handled by the sign-in page (/login); use that rather than calling the auth endpoints by hand. The session lasts 14 days. Your access comes from the workspaces you belong to: a signed-in person with no workspace gets 403, and a workspace whose subscription has lapsed gets 402 on every endpoint here.