Aqua Mail data API: folders, licenses and push
Aqua Mail is a multi-account Android email client from Aqua Mail Inc. It brings Gmail, Outlook/Office 365, Yahoo, Yandex and generic IMAP or Exchange mailboxes into one fast, secure inbox, and its free, Premium and Pro tiers make it a long-standing choice for users who juggle several accounts.
As a data source, the app exposes the objects behind those screens: the signed-in account returning userId and authToken for a registered deviceID, entitlement records carrying accountType and subscriptions, mail folders with displayName and unreadItemCount, messages flagged by isRead and internetMessageId, out-of-office settings and per-folder push subscriptions marked is_live. Developers build license-aware feature gating, unread-mail dashboards, onboarding auto-configuration and new-mail notification tooling on these fields.
Aqua Mail is a multi-account Android email client from Aqua Mail Inc that unifies Gmail, Outlook/Office 365, Yahoo, Yandex and generic IMAP or Exchange accounts behind one fast, secure inbox, with free, Premium and Pro tiers. Behind the account list, inbox and upgrade screens sits a dataset of account profiles and device identities, license entitlements and Play purchase receipts, mail folder trees with unread counts, message lists, inbox rules, out-of-office settings and push subscription state. Companion apps, dashboards and onboarding tools integrate that data without scraping the UI.
Screenshots
API surface
The endpoints and request/response examples below are reconstructed from the app's interface — illustrative, not a live capture.
Aqua account login
POST
/v2/accounts/signinosintSigns the Aqua Mail account in with a Google, Apple or Facebook credential bound to a deviceID and returns the userId plus authToken that later license and profile calls use.
Auth: Unauthenticated JSON POST. Body is a login object with a social provider id (google_id, apple_id or facebook_id) plus deviceID. Optional encrypted request envelope. The returned authToken is attached to later account calls.
- login
- google_id
- apple_id
- facebook_id
- deviceID
- fetch_user_fields
- userId
- authToken
- name
- avatar
POST /v2/accounts/signin HTTP/1.1 Content-Type: application/json { "login": { "google_id": "118304928176102938475", "deviceID": "a1b2c3d4-e5f6-7890-abcd-ef1234567890", "fetch_user_fields": [] } }{ "userId": "usr_7f3a91c2", "authToken": "aqm_live_9f2c1e8b4d6a", "name": "Alex Rivera", "email": "[email protected]", "avatar": "https://cdn.example.net/avatars/usr_7f3a91c2.png" }reconstructed from the app's account sign-in flowmatches the social-provider login form shown before mailbox setup
Aqua user profile
POST
/v2/accounts/profileosintReads the signed-in Aqua Mail account card — display name, email and avatar — for the license and account screen.
Auth: Signed-in Aqua session. JSON POST with a profile object; the authToken from sign-in rides the request envelope.
- profile
- fields
- name
- avatar
POST /v2/accounts/profile HTTP/1.1 Content-Type: application/json { "profile": { "fields": "name email avatar" } }{ "name": "Alex Rivera", "email": "[email protected]", "avatar": "https://cdn.example.net/avatars/usr_7f3a91c2.png" }reconstructed from the account card on the license and account screen
Create device id
POST
/v2/devices/registeropendataMints the deviceID that every later login, license and logout call attaches, recording platform and handset model.
Auth: Unauthenticated JSON POST during first-run device registration.
- create
- platform
- model
- deviceID
POST /v2/devices/register HTTP/1.1 Content-Type: application/json { "create": { "platform": "android", "model": "Pixel 8" } }{ "deviceID": "a1b2c3d4-e5f6-7890-abcd-ef1234567890", "platform": "android", "model": "Pixel 8" }reconstructed from the first-run device registration
Check device login state
POST
/v2/devices/sessionopendataPolls whether this device still holds a valid Aqua Mail session and, if so, returns a fresh authToken (or errorCode when the device must log in again).
Auth: JSON POST with the social credential and deviceID under login_state. Used to resume a session without a full sign-in.
- login_state
- google_id
- deviceID
- isLoggedIn
- authToken
- errorCode
POST /v2/devices/session HTTP/1.1 Content-Type: application/json { "login_state": { "google_id": "118304928176102938475", "deviceID": "a1b2c3d4-e5f6-7890-abcd-ef1234567890" } }{ "isLoggedIn": true, "authToken": "aqm_live_9f2c1e8b4d6a", "errorCode": 0 }reconstructed from the session-resume check at app launch
Check device product license
POST
/v2/billing/entitlementsopenfinanceReturns the device's Aqua Mail entitlement — free, premium or pro — plus the Play subscription SKUs, and can force a logout when the license is no longer valid.
Auth: Signed-in Aqua session (authToken from sign-in). JSON POST with an empty check_device_license object.
- check_device_license
- accountType
- subscriptions
- isForceLogout
POST /v2/billing/entitlements HTTP/1.1 Content-Type: application/json { "check_device_license": {} }{ "accountType": "premium", "subscriptions": ["pro_plus_yearly", "unlocker_permanent"], "isForceLogout": false }reconstructed from the premium screen's entitlement refresh
Validate Play purchase receipt
POST
/v2/billing/receipts/verifyopenfinanceSends the Google Play purchase JSON to Aqua Mail's billing service so the server can confirm the receipt and flip accountType to a paid plan.
Auth: Signed-in Aqua session. JSON POST wrapping the Play Billing purchase JSON under validate-receipt.
- validate-receipt
- orderId
- packageName
- productId
- purchaseToken
- purchaseState
- accountType
- subscriptions
POST /v2/billing/receipts/verify HTTP/1.1 Content-Type: application/json { "validate-receipt": { "orderId": "GPA.1234-5678-9012-34567", "packageName": "org.kman.AquaMail", "productId": "pro_plus_yearly", "purchaseToken": "opaque-play-token", "purchaseState": 0 } }{ "accountType": "pro", "subscriptions": ["pro_plus_yearly"], "valid": true }reconstructed from the purchase-completion flow after a Play Billing upgrade
Check existing Play purchase
POST
/v2/billing/orders/statusopenfinanceAsks the license cloud whether an existing Play order is still active so restore-purchases and silent entitlement checks can refresh accountType without a new receipt.
Auth: Signed-in Aqua session. JSON POST with a purchase-status token so the server can report whether a prior Play order is still entitled.
- purchase-status
- accountType
- subscriptions
- isForceLogout
POST /v2/billing/orders/status HTTP/1.1 Content-Type: application/json { "purchase-status": "GPA.1234-5678-9012-34567" }{ "accountType": "pro", "subscriptions": ["pro_plus_yearly"], "isForceLogout": false }reconstructed from the restore-purchases flow
Office mail folder tree
GET
/mail/v3/foldersopendataLists the signed-in Microsoft 365 / Outlook mailbox folders, including hidden ones, that populate Aqua Mail's folder pane after Office account setup.
Auth: Authorization: Bearer <OAuth2 access token> from the Office/Hotmail sign-in redirect.
- value
- id
- displayName
- parentFolderId
- childFolderCount
- unreadItemCount
- totalItemCount
- isHidden
- includeHiddenFolders
GET /mail/v3/folders?includeHiddenFolders=true HTTP/1.1 Authorization: Bearer eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiIsIng1dCI6Ik...{ "value": [ { "id": "AAMkAGI2TG93AAA=", "displayName": "Inbox", "parentFolderId": "AAMkAGI2AAAA", "childFolderCount": 3, "unreadItemCount": 12, "totalItemCount": 1840, "isHidden": false } ] }reconstructed from the folder pane that appears after Office account setup
Office child folders
GET
/mail/v3/folders/{id}/childrenopendataExpands a parent mail folder into its children so nested trees under Inbox, Archive and custom folders render in the two-pane UI.
Auth: Authorization: Bearer <OAuth2 access token>.
- value
- id
- displayName
- parentFolderId
- unreadItemCount
- totalItemCount
GET /mail/v3/folders/AAMkAGI2TG93AAA=/children HTTP/1.1 Authorization: Bearer eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiIsIng1dCI6Ik...{ "value": [ { "id": "AAMkAGI2TG93AAB=", "displayName": "Receipts", "parentFolderId": "AAMkAGI2TG93AAA=", "unreadItemCount": 2, "totalItemCount": 56 } ] }reconstructed from nested-folder expansion in the two-pane UI
Office folder messages
GET
/mail/v3/folders/{id}/messagesopendataPages messages inside a mail folder — the inbox list Aqua Mail shows for Office 365 accounts, including read state and internetMessageId.
Auth: Authorization: Bearer <OAuth2 access token>.
- value
- id
- subject
- internetMessageId
- isRead
- receivedDateTime
- hasAttachments
- conversationId
- from
GET /mail/v3/folders/AAMkAGI2TG93AAA=/messages?$top=50&$select=id,subject,internetMessageId,isRead,receivedDateTime,from,hasAttachments HTTP/1.1 Authorization: Bearer eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiIsIng1dCI6Ik...{ "value": [ { "id": "AAMkAGI2AAAoAAA=", "subject": "Q3 close checklist", "internetMessageId": "<[email protected]>", "isRead": false, "receivedDateTime": "2026-09-27T14:22:08Z", "hasAttachments": true, "conversationId": "AAQkAGI2CgBQAAA=", "from": { "emailAddress": {"name": "Jordan Lee", "address": "[email protected]"} } } ] }reconstructed from the message list shown for Office 365 accounts
Inbox message rules
GET
/mail/v3/folders/inbox/rulesopendataReads Outlook inbox rules so Aqua Mail can show and edit server-side filters for Office accounts.
Auth: Authorization: Bearer <OAuth2 access token>.
- value
- id
- displayName
- sequence
- isEnabled
- conditions
- actions
- senderContains
- moveToFolder
- markAsRead
GET /mail/v3/folders/inbox/rules HTTP/1.1 Authorization: Bearer eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiIsIng1dCI6Ik...{ "value": [ { "id": "AQMkAGI2AABhAAAA", "displayName": "File receipts", "sequence": 1, "isEnabled": true, "conditions": {"senderContains": ["[email protected]"]}, "actions": {"moveToFolder": "AAMkAGI2TG93AAB=", "markAsRead": true} } ] }reconstructed from the server-side filter editor
Automatic replies (OOF)
GET
/mail/v3/settings/autoreplyopendataLoads the Outlook out-of-office banner that Aqua Mail's OOF get/set screens display and edit.
Auth: Authorization: Bearer <OAuth2 access token>. PATCH the same resource to update automaticRepliesSetting.
- automaticRepliesSetting
- status
- externalAudience
- internalReplyMessage
- externalReplyMessage
- scheduledStartDateTime
- scheduledEndDateTime
GET /mail/v3/settings/autoreply HTTP/1.1 Authorization: Bearer eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiIsIng1dCI6Ik...{ "automaticRepliesSetting": { "status": "scheduled", "externalAudience": "all", "internalReplyMessage": "I am out of office until Monday.", "externalReplyMessage": "Please contact [email protected].", "scheduledStartDateTime": {"dateTime": "2026-09-26T17:00:00", "timeZone": "Pacific Standard Time"}, "scheduledEndDateTime": {"dateTime": "2026-09-29T08:00:00", "timeZone": "Pacific Standard Time"} } }reconstructed from the out-of-office get/set screens
Register push device
POST
/push/v1/devicesopendataRegisters this handset with Aqua Mail's push broker so Exchange/Office new-mail notifications can be delivered via FCM.
Auth: JSON POST. Body includes push_token and push_tech; auth and nonce are an HMAC signature over the registered device identity.
- push_token
- push_tech
- nonce
- auth
- result
POST /push/v1/devices HTTP/1.1 Content-Type: application/json; charset=UTF-8 { "push_token": "fcm-c3d4e5f6", "push_tech": "fcm", "nonce": "a8f3c1", "auth": "7b2e9c1d0a44" }{ "result": "ok", "device_id": "dev_91ab33" }reconstructed from the new-mail notification setup for Exchange and Office accounts
Change push folder subscriptions
POST
/push/v1/subscriptionsopendataCreates or drops per-folder push subscriptions (inbox, sent, custom) so Aqua Mail only wakes for mailboxes the user actually syncs.
Auth: JSON POST with HMAC auth/nonce over the registered device. create/delete arrays name Exchange folder ids.
- create
- delete
- f_id
- sub_id
- ts
- is_live
- is_dead
- subs
- result
- nonce
- auth
POST /push/v1/subscriptions HTTP/1.1 Content-Type: application/json; charset=UTF-8 { "create": [{"f_id": "AAMkAGI2TG93AAA=", "sub_id": "sub_inbox_1"}], "nonce": "a8f3c1", "auth": "7b2e9c1d0a44" }{ "result": "ok", "subs": [ {"f_id": "AAMkAGI2TG93AAA=", "sub_id": "sub_inbox_1", "ts": 1727539200, "is_live": 1} ] }reconstructed from the per-folder sync toggles
List push subscriptions
POST
/push/v1/subscriptions/listopendataReturns the live folder-subscription set on the push broker so the client can reconcile local sync state before changing subscriptions.
Auth: JSON POST with HMAC auth/nonce over the registered device.
- nonce
- auth
- result
- subs
- f_id
- sub_id
- ts
- is_live
POST /push/v1/subscriptions/list HTTP/1.1 Content-Type: application/json; charset=UTF-8 { "nonce": "a8f3c1", "auth": "7b2e9c1d0a44" }{ "result": "ok", "subs": [ {"f_id": "AAMkAGI2TG93AAA=", "sub_id": "sub_inbox_1", "ts": 1727539200, "is_live": 1} ] }reconstructed from the sync-state reconciliation that runs before subscription changes
MX host lookup
GET
/setup/v1/mx/{domain}osintResolves the mail-exchanger hostname for an email domain during account setup so Aqua Mail can auto-fill IMAP/SMTP or Exchange hosts.
Auth: Static shared Authorization header sent as-is. Used when local DNS MX lookup is empty or slow during account setup.
- HostList
- Host
- Priority
GET /setup/v1/mx/example.com HTTP/1.1 Authorization: <static shared token>{ "HostList": [ {"Host": "aspmx.l.google.com", "Priority": 1}, {"Host": "alt1.aspmx.l.google.com", "Priority": 5} ] }reconstructed from account setup's server auto-fill
Yahoo OAuth token
POST
/oauth/v2/tokenosintExchanges or refreshes a Yahoo Mail OAuth2 token so Aqua Mail can open the Yahoo mailbox over IMAP with XOAUTH2 after the in-app Yahoo sign-in.
Auth: OAuth2 authorization_code or refresh_token grant. The Yahoo mailbox token is stored in the Android account manager and used for IMAP XOAUTH2.
- client_id
- scope
- refresh_token
- grant_type
- access_token
- expires_in
- token_type
POST /oauth/v2/token HTTP/1.1 Content-Type: application/x-www-form-urlencoded client_id=dj0yJmk9ZXhhbXBsZQ&scope=mail-r&refresh_token=AAh.xz1&grant_type=refresh_token{ "access_token": "djE8b2Fr...", "refresh_token": "AAh.xz1", "expires_in": 3600, "token_type": "bearer" }reconstructed from the Yahoo sign-in and mailbox login flow
Exchange autodiscover
POST
/setup/v1/exchange-settingsopendataDiscovers the Exchange Web Services URL for a corporate mailbox during account setup so Aqua Mail can subscribe to push and sync folders without a manual EWS host.
Auth: HTTP Basic or NTLM with the Exchange mailbox credentials. SOAP Autodiscover request schema 2006.
- EMailAddress
- AcceptableResponseSchema
- EwsUrl
- Server
- AccountType
POST /setup/v1/exchange-settings HTTP/1.1 Content-Type: text/xml Authorization: Basic YWxpY2U6c2VjcmV0 <?xml version="1.0" encoding="utf-8" ?> <Autodiscover xmlns="http://schemas.microsoft.com/exchange/autodiscover/outlook/requestschema/2006"> <Request> <EMailAddress>[email protected]</EMailAddress> <AcceptableResponseSchema>http://schemas.microsoft.com/exchange/autodiscover/outlook/responseschema/2006a</AcceptableResponseSchema> </Request> </Autodiscover>{ "EMailAddress": "[email protected]", "EwsUrl": "https://mail.example.net/EWS/Exchange.asmx", "Server": "mail.example.net", "AccountType": "email" }reconstructed from the Exchange account setup flow
Data categories
- account profile
- device identity
- product licenses
- play purchases
- mail folders
- messages
- inbox rules
- out-of-office
- push subscriptions
- mx hosts
- oauth tokens
- exchange autodiscover
Where teams use this data
License-aware feature gating
A companion tool can call the entitlement check with an empty check_device_license object, read accountType and subscriptions, and only enable Pro filters, extra accounts or backup-to-Drive when the Aqua Mail cloud says the device is entitled.
Office mailbox inventory
After the user signs in with Microsoft OAuth, the folder-tree, child-folder and folder-messages calls yield folder displayName, unreadItemCount and per-message internetMessageId/isRead — enough to build an unread dashboard without scraping the UI.
New-mail push reconciliation
Ops can compare local sync state with the subscription-list and subscription-change calls: each sub carries f_id, sub_id, ts and is_live, so a dead Exchange folder subscription can be recreated before notifications stall.
Autodiscover from MX
During onboarding, the MX lookup call returns HostList with Host and Priority so a setup wizard can skip manual IMAP host entry when DNS on the device is blocked; Exchange mailboxes then run the autodiscover request for EwsUrl.
Frequently asked questions
How does Aqua Mail authenticate its own account versus a mailbox?
The Aqua Mail cloud account is a social sign-in (google_id, apple_id or facebook_id plus deviceID) that returns an authToken. Each mailbox is separate: Office 365 uses an OAuth2 Bearer token from the sign-in redirect, Yahoo uses an OAuth2 token exchange, and IMAP or Exchange accounts use the mail server's own credentials. License and billing calls ride the Aqua authToken, not the mailbox token.
Which data exposes mailbox contents?
For Microsoft 365 / Outlook, the folder-tree and child-folder calls return the folder hierarchy (displayName, unreadItemCount, totalItemCount), the folder-messages call pages messages with internetMessageId, isRead and subject, and the inbox-rules call lists server-side filters with their conditions and actions. IMAP and Exchange accounts talk to the user's own mail host rather than the Aqua account cloud.
How are Pro and Premium licenses checked?
Play Billing receipts are sent for server-side validation, and the entitlement check then answers with accountType (free, premium or pro), a subscriptions array of SKUs, and an isForceLogout flag when the entitlement has lapsed. An existing order can be re-checked from its GPA order id so restore-purchases works without a new receipt.
What is the push API for?
Exchange and Office accounts register the handset with push_token and push_tech, then create or delete per-folder subscriptions (f_id, sub_id, is_live) and list them back to reconcile state. That is how Aqua Mail delivers new-mail notifications without holding a persistent IMAP connection.
Apps similar to Email Aqua Mail - Fast, Secure
- K-9 Mail / Thunderbird for Android — Free, open-source Android email client with IMAP/POP3 support, multiple accounts, OpenPGP encryption and a unified inbox; it is being rebranded as Thunderbird for Android under Mozilla.
- FairEmail — Open-source, privacy-focused email client for Android offering unlimited accounts, a unified inbox, PGP and S/MIME encryption and offline use, with no tracking.
- Microsoft Outlook — Microsoft's cross-platform email app with Exchange and Microsoft 365 support, built-in calendar and contacts integration and a unified inbox.
- BlueMail — Free email app that manages unlimited accounts in a unified inbox with smart push notifications and a people-centric view, available on Android, iOS, Windows, Mac and Linux.
- Spark Mail — Freemium email client with a smart inbox, AI-assisted writing, scheduling and snooze, plus team collaboration features across Android, iOS, Mac and Windows.
- Canary Mail — Email client with an AI Copilot for composing and summarizing messages, optional PGP end-to-end encryption, read receipts and a unified inbox on mobile and desktop.
- Proton Mail — Privacy-focused email service from Switzerland whose Android app offers end-to-end and zero-access encryption along with a built-in encrypted calendar.
- Nine — Business-oriented Android email app built around Exchange, with Direct Push sync covering email, calendar, contacts, tasks and notes.
Topics
- aqua mail api
- aqua mail data
- aqua mail license api
- office 365 mail folder api
- aqua mail push notifications
- email mx lookup
- email client data api
Need this app's data API integrated?
We deliver scoped integrations for any named app — from USD 500 with source-code handoff, or hosted access billed per call. Tell us the data you need.
- NDA + SOW on every engagement
- Delivery in 3–7 days
- Payment only after acceptance
- Work scoped to authorized use