> ## Documentation Index
> Fetch the complete documentation index at: https://docs.artbucket.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Open an email domain to joining

> With `join`, anyone who signs up or signs in with an address at exactly this domain is offered to join the organization, able to read, once the server's own email has confirmed the address (me.joinable, POST /api/v1/join). Refused for a domain not proved yet, one that gives addresses to the public (gmail.com, orange.fr), one single sign-on covers, and on a server that sends no email of its own.

Scope: `admin`.



## OpenAPI

````yaml /openapi.json patch /api/v1/email-domains/{domain}
openapi: 3.1.0
info:
  title: artbucket
  version: '1'
  description: >-
    Agent-first asset management. The web UI is built on this API and nothing
    else, beside signing in at /api/auth. Send `Authorization: Bearer <key>`: a
    key works in one workspace with one scope, and scopes are a ladder: read <
    propose < write < admin. People signed in to the app carry a session cookie
    instead, and their scope is what their grants add up to: on the
    organization, the workspace, or single collections and assets. A scope shown
    as needed on the workspace is also enough on the one collection or asset a
    route acts on. Agents (MCP at POST /api/v1/mcp) usually get `propose`: what
    they add waits for a human.
servers:
  - url: http://localhost:3000
security:
  - bearer: []
  - session: []
  - {}
paths:
  /api/v1/email-domains/{domain}:
    parameters:
      - name: domain
        in: path
        required: true
        description: e.g. acme.com
        schema:
          type: string
    patch:
      summary: Open an email domain to joining
      description: >-
        With `join`, anyone who signs up or signs in with an address at exactly
        this domain is offered to join the organization, able to read, once the
        server's own email has confirmed the address (me.joinable, POST
        /api/v1/join). Refused for a domain not proved yet, one that gives
        addresses to the public (gmail.com, orange.fr), one single sign-on
        covers, and on a server that sends no email of its own.


        Scope: `admin`.
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                join:
                  type: boolean
                  description: >-
                    Let anyone whose address is at exactly this domain join,
                    able to read. Needs it proved, not free mail, no single
                    sign-on over it, and the server's own email
              required:
                - join
              additionalProperties: false
      responses:
        '200':
          description: The email domain
          content:
            application/json:
              schema:
                type: object
                properties:
                  data:
                    type: object
                    properties:
                      domain:
                        type: string
                      verified:
                        type: boolean
                        description: >-
                          Proved by its TXT record: single sign-on and joining
                          by domain may use it
                      join:
                        type: boolean
                        description: >-
                          Anyone whose address is at exactly this domain may
                          join the organization, able to read
                      sso:
                        type: boolean
                        description: The organization's single sign-on uses it
                      record:
                        type: object
                        properties:
                          type:
                            type: string
                            const: TXT
                          name:
                            type: string
                          value:
                            type: string
                        required:
                          - type
                          - name
                          - value
                        additionalProperties: false
                        description: >-
                          What proves the domain: add this record at your DNS
                          host
                    required:
                      - domain
                      - verified
                      - join
                      - sso
                      - record
                    additionalProperties: false
                required:
                  - data
                additionalProperties: false
        default:
          description: An error
          content:
            application/json:
              schema:
                type: object
                properties:
                  error:
                    type: object
                    properties:
                      code:
                        type: string
                      message:
                        type: string
                      detail: {}
                    required:
                      - code
                      - message
                    additionalProperties: false
                required:
                  - error
                additionalProperties: false
components:
  securitySchemes:
    bearer:
      type: http
      scheme: bearer
      description: 'An API key: ab_...'
    session:
      type: apiKey
      in: cookie
      name: better-auth.session_token
      description: Signed in, at /api/auth

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.