Retrieve mail and attachments
Search live Tinbox mail, read complete threads, download attachments safely, inspect inbound source, or take a full account archive.
Tinbox is the mailbox. Cloudflare Email Routing accepts mail, but it does not provide an IMAP or POP mailbox to read later. Use the Tinbox app, API-backed CLI, or agent tools for the current mailbox; use an account archive when you need an offline copy or a deployment-to-deployment move.
Pick the retrieval path
| Need | Best surface | What it returns |
|---|---|---|
| Browse, preview, or download several files | Inbox app | Rendered conversation, safe previews, individual or bulk downloads |
| Script a mailbox lookup | tinbox CLI | JSON thread/message data and attachment bytes |
| Let an assistant find or summarize mail | Chat or MCP | Read-only search and thread content, subject to the same inbox grants |
| Take an offline or migration copy | Settings → Export / Import | D1 account rows plus optional raw .eml and attachment objects |
These paths use the deployment API, so they see current state. A git mail archive, when enabled, is useful for broad historical search but can lag and does not contain drafts, read state, or assignments.
Search and download with the CLI
Use a viewer/read token when the job only retrieves data. First verify the live deployment and discover accessible inboxes:
tinbox whoami --json
tinbox inboxes --json
Then search, read the selected thread, and use the attachment id returned in the thread payload:
tinbox search "invoice 4291" --inbox-id ibx_support --json
tinbox thread thr_01K... --json
tinbox attachment get att_01K... --out ./downloads/invoice.pdf --json
tinbox search is an alias of the generated search-emails command. Search
results contain a threadId; tinbox thread returns every message in the
conversation and lists each attachment's id. Omitting --out writes the server
filename into the current directory.
Every read is constrained to inboxes the token can access. Under --json,
stdout is one JSON document and the exit code remains meaningful: 2 is an
authentication failure, while 3 means the thread or attachment was not found.
A blocked attachment also returns 3 because its dangerous bytes were rejected
at ingest and never stored.
See the generated command reference for
tinbox search,
tinbox thread, and
tinbox attachment get.
Preview and bulk download in the app
Open a conversation and select an attachment chip. Tinbox previews PDF, raster images, and plain-text formats through the authenticated attachment route. It does not render active SVG or HTML as a preview. Other types download instead.
For a message with several files, choose Download all. Tinbox skips blocked or unavailable entries, avoids overwriting duplicate filenames, and reports partial failures rather than claiming the whole batch succeeded. Browser support determines whether it can use a folder picker or must start downloads one by one.
Inline CID images used by the message body are not duplicated as ordinary attachment chips. They still travel through the same authenticated byte route.
Read with an agent
Tinbox chat and MCP expose the same read-authorized tools used by the CLI:
search_emailsfinds messages by subject, sender, or body and returns thread ids.list_threadsbrowses recent conversations.get_threadreads the conversation before an agent summarizes it or prepares a draft.
The tools return message content for reasoning; they are not a general file
download protocol. Use the app or tinbox attachment get when the caller needs
the attachment bytes on disk. The public @tinbox/sdk is currently focused on
transactional sending rather than mailbox retrieval.
Raw source and complete copies
For inbound mail, the activity detail can show and download the retained raw
.eml source. Display and copy are capped at 1,000,000 characters and a
truncated preview is marked; Download .eml uses a separate authenticated
byte stream and returns the complete retained object. Outbound messages do not
currently retain the fully assembled MIME, so their stored text/HTML bodies are
available but a sent .eml may not be.
For a bulk copy of retained source objects, create an export with raw messages & attachments enabled. That is the appropriate path for offline custody or moving a deployment. Read Download all your Tinbox data before handling the archive: it can contain active, sensitive account configuration as well as mail.
Bringing mail in instead
Retrieval reads the live Tinbox mailbox. To migrate source data from Gmail, IMAP, mbox, or Mailchimp into it, follow Import existing mail and lists. A Tinbox account archive uses a different, row-preserving restore path described in the export guide.