Skip to content

Retrieve mail and attachments

Search live Tinbox mail, read complete threads, download attachments safely, inspect inbound source, or take a full account archive.

Tinbox is the mailbox. Cloudflare Email Routing accepts mail, but it does not provide an IMAP or POP mailbox to read later. Use the Tinbox app, API-backed CLI, or agent tools for the current mailbox; use an account archive when you need an offline copy or a deployment-to-deployment move.

Pick the retrieval path

NeedBest surfaceWhat it returns
Browse, preview, or download several filesInbox appRendered conversation, safe previews, individual or bulk downloads
Script a mailbox lookuptinbox CLIJSON thread/message data and attachment bytes
Let an assistant find or summarize mailChat or MCPRead-only search and thread content, subject to the same inbox grants
Take an offline or migration copySettings → Export / ImportD1 account rows plus optional raw .eml and attachment objects

These paths use the deployment API, so they see current state. A git mail archive, when enabled, is useful for broad historical search but can lag and does not contain drafts, read state, or assignments.

Search and download with the CLI

Use a viewer/read token when the job only retrieves data. First verify the live deployment and discover accessible inboxes:

tinbox whoami --json
tinbox inboxes --json

Then search, read the selected thread, and use the attachment id returned in the thread payload:

tinbox search "invoice 4291" --inbox-id ibx_support --json
tinbox thread thr_01K... --json
tinbox attachment get att_01K... --out ./downloads/invoice.pdf --json

tinbox search is an alias of the generated search-emails command. Search results contain a threadId; tinbox thread returns every message in the conversation and lists each attachment's id. Omitting --out writes the server filename into the current directory.

Every read is constrained to inboxes the token can access. Under --json, stdout is one JSON document and the exit code remains meaningful: 2 is an authentication failure, while 3 means the thread or attachment was not found. A blocked attachment also returns 3 because its dangerous bytes were rejected at ingest and never stored.

See the generated command reference for tinbox search, tinbox thread, and tinbox attachment get.

Preview and bulk download in the app

Open a conversation and select an attachment chip. Tinbox previews PDF, raster images, and plain-text formats through the authenticated attachment route. It does not render active SVG or HTML as a preview. Other types download instead.

For a message with several files, choose Download all. Tinbox skips blocked or unavailable entries, avoids overwriting duplicate filenames, and reports partial failures rather than claiming the whole batch succeeded. Browser support determines whether it can use a folder picker or must start downloads one by one.

Inline CID images used by the message body are not duplicated as ordinary attachment chips. They still travel through the same authenticated byte route.

Read with an agent

Tinbox chat and MCP expose the same read-authorized tools used by the CLI:

  • search_emails finds messages by subject, sender, or body and returns thread ids.
  • list_threads browses recent conversations.
  • get_thread reads the conversation before an agent summarizes it or prepares a draft.

The tools return message content for reasoning; they are not a general file download protocol. Use the app or tinbox attachment get when the caller needs the attachment bytes on disk. The public @tinbox/sdk is currently focused on transactional sending rather than mailbox retrieval.

Raw source and complete copies

For inbound mail, the activity detail can show and download the retained raw .eml source. Display and copy are capped at 1,000,000 characters and a truncated preview is marked; Download .eml uses a separate authenticated byte stream and returns the complete retained object. Outbound messages do not currently retain the fully assembled MIME, so their stored text/HTML bodies are available but a sent .eml may not be.

For a bulk copy of retained source objects, create an export with raw messages & attachments enabled. That is the appropriate path for offline custody or moving a deployment. Read Download all your Tinbox data before handling the archive: it can contain active, sensitive account configuration as well as mail.

Bringing mail in instead

Retrieval reads the live Tinbox mailbox. To migrate source data from Gmail, IMAP, mbox, or Mailchimp into it, follow Import existing mail and lists. A Tinbox account archive uses a different, row-preserving restore path described in the export guide.