Enable the API
The API might already be enabled, but let's check that it is enabled before proceeding:
-
Launch the MailStore Server Service Configuration Configuration tool.
-
Go to the Network Settings panel.
-
Enable MailStore Administration API (HTTPS) and note the port.
-
Click Restart Service if you made any changes.
Call the HTTPS API directly
Pick an API client
The Firefox RESTClient extension that I originally used here has long since been retired. Any modern API client will do, but two good open-source options are:
- Bruno — cross-platform desktop app (Windows/macOS/Linux), offline-first, collections stored as plain text files (git-friendly). This is my current recommendation.
- Hoppscotch — runs in the browser (or as a desktop app), so it reuses the browser's certificate trust, which is handy when talking to a server with a self-signed cert.
For reference my server's API is available at https://exchangedc.example.com:8463 but of course you'll need to use appropriate server name or IP address and port information.
Trust the certificate
If you're using a desktop client like Bruno, the easiest path is to enable the per-request Disable SSL verification option (Bruno: cog icon on the request → Settings → SSL Verification: off). Alternatively, import the server's certificate into your OS trust store.
If you're using a browser-based client like Hoppscotch, you'll need the browser itself to trust the certificate first:
-
Visit the web interface at https://exchangedc.example.com:8462
-
Advanced -> Accept the certificate
-
Close the tab when prompted for credentials.
Make a first call to the API
-
Open your API client of choice (Bruno, Hoppscotch, etc.)
-
Switch to Basic Auth (Bruno: Auth tab → Basic Auth; Hoppscotch: Authorization → Basic Auth).
-
Set the admin username/password.
-
Change the Method to Post
-
Call
https://exchangedc.example.com:8463/api/invoke/GetUsers(without the quotes)
My response looks like this:
{
"error": null,
"token": null,
"statusVersion": 2,
"statusCode": "succeeded",
"percentProgress": null,
"statusText": null,
"result": [
{
"userName": "admin",
"fullName": "Administrator",
"distinguishedName": null
},
{
"userName": "frank.clark",
"fullName": "Frank Clark",
"distinguishedName": null
}
],
"logOutput": null
}
Add parameters to apply a filter
Now change the URI to https://exchangedc.example.com:8463/api/invoke/GetUserInfo. If you were to submit now you'd get a response that start like this:
{
"error": {
"message": "Missing API argument userName.",
"details": "System.Exception: Missing API argument userName.\r\n at
Add the body userName=frank.clark and we get a good response again:
{
"error": null,
"token": null,
"statusVersion": 2,
"statusCode": "succeeded",
"percentProgress": null,
"statusText": null,
"result": {
"userName": "frank.clark",
"fullName": "Frank Clark",
"distinguishedName": null,
"authentication": "directoryServices",
"emailAddresses": [
"frank.clark@example.com"
],
"pop3UserNames": [],
"privileges": [
"login"
],
"privilegesOnFolders": [
{
"folder": "frank.clark",
"privileges": [
"read"
]
}
]
},
"logOutput": null
}
You can see the additional user information is now availble, confirming everything is working.
curl
We could do the same from curl, I'll jump straight to the command as a starting point.
curl -X POST -k -H 'Authorization: Basic YWRtaW46UGFzc3cwcmQhIQ==' -i 'https://exchangedc.example.com:8463/api/invoke/GetUserInfo' --data 'userName=frank.clark'
The response is the same as above so I won't repeat.