openapi: 3.0.0 info: version: '2017-10-01' x-release: v4 title: 'Amazon WorkMail #X Amz Target=WorkMailService.AssociateDelegateToResource #X Amz Target=WorkMailService.AssociateDelegateToResource #X Amz Target=WorkMailService.CreateOrganization API' description:
WorkMail is a secure, managed business email and calendaring service with support for existing desktop and mobile email clients. You can access your email, contacts, and calendars using Microsoft Outlook, your browser, or other native iOS and Android email applications. You can integrate WorkMail with your existing corporate directory and control both the keys that encrypt your data and the location in which your data is stored.
The WorkMail API is designed for the following scenarios:
Listing and describing organizations
Managing users
Managing groups
Managing resources
All WorkMail API operations are Amazon-authenticated and certificate-signed. They not only require the use of the AWS SDK, but also allow for the exclusive use of AWS Identity and Access Management users and roles to help facilitate access, trust, and permission policies. By creating a role and allowing an IAM user to access the WorkMail site, the IAM user gains full administrative visibility into the entire WorkMail organization (or as set in the IAM policy). This includes, but is not limited to, the ability to create, update, and delete users, groups, and resources. This allows developers to perform the scenarios listed above, as well as give users the ability to grant access on a selective basis using the IAM model.
x-logo: url: https://twitter.com/awscloud/profile_image?size=original backgroundColor: '#FFFFFF' termsOfService: https://aws.amazon.com/service-terms/ contact: name: Mike Ralphson email: mike.ralphson@gmail.com url: https://github.com/mermade/aws2openapi x-twitter: PermittedSoc license: name: Apache 2.0 License url: http://www.apache.org/licenses/ x-providerName: amazonaws.com x-serviceName: workmail x-origin: - contentType: application/json url: https://raw.githubusercontent.com/aws/aws-sdk-js/master/apis/workmail-2017-10-01.normal.json converter: url: https://github.com/mermade/aws2openapi version: 1.0.0 x-apisguru-driver: external x-apiClientRegistration: url: https://portal.aws.amazon.com/gp/aws/developer/registration/index.html?nc2=h_ct x-apisguru-categories: - cloud x-preferred: true servers: - url: http://workmail.{region}.amazonaws.com variables: region: description: The AWS region enum: - us-east-1 - us-east-2 - us-west-1 - us-west-2 - us-gov-west-1 - us-gov-east-1 - ca-central-1 - eu-north-1 - eu-west-1 - eu-west-2 - eu-west-3 - eu-central-1 - eu-south-1 - af-south-1 - ap-northeast-1 - ap-northeast-2 - ap-northeast-3 - ap-southeast-1 - ap-southeast-2 - ap-east-1 - ap-south-1 - sa-east-1 - me-south-1 default: us-east-1 description: The Amazon WorkMail multi-region endpoint - url: https://workmail.{region}.amazonaws.com variables: region: description: The AWS region enum: - us-east-1 - us-east-2 - us-west-1 - us-west-2 - us-gov-west-1 - us-gov-east-1 - ca-central-1 - eu-north-1 - eu-west-1 - eu-west-2 - eu-west-3 - eu-central-1 - eu-south-1 - af-south-1 - ap-northeast-1 - ap-northeast-2 - ap-northeast-3 - ap-southeast-1 - ap-southeast-2 - ap-east-1 - ap-south-1 - sa-east-1 - me-south-1 default: us-east-1 description: The Amazon WorkMail multi-region endpoint - url: http://workmail.{region}.amazonaws.com.cn variables: region: description: The AWS region enum: - cn-north-1 - cn-northwest-1 default: cn-north-1 description: The Amazon WorkMail endpoint for China (Beijing) and China (Ningxia) - url: https://workmail.{region}.amazonaws.com.cn variables: region: description: The AWS region enum: - cn-north-1 - cn-northwest-1 default: cn-north-1 description: The Amazon WorkMail endpoint for China (Beijing) and China (Ningxia) security: - hmac: [] tags: - name: '#X Amz Target=WorkMailService.CreateOrganization' paths: /#X-Amz-Target=WorkMailService.CreateOrganization: parameters: - $ref: '#/components/parameters/X-Amz-Content-Sha256' - $ref: '#/components/parameters/X-Amz-Date' - $ref: '#/components/parameters/X-Amz-Algorithm' - $ref: '#/components/parameters/X-Amz-Credential' - $ref: '#/components/parameters/X-Amz-Security-Token' - $ref: '#/components/parameters/X-Amz-Signature' - $ref: '#/components/parameters/X-Amz-SignedHeaders' post: operationId: CreateOrganization description:Creates a new WorkMail organization. Optionally, you can choose to associate an existing AWS Directory Service directory with your organization. If an AWS Directory Service directory ID is specified, the organization alias must match the directory alias. If you choose not to associate an existing directory with your organization, then we create a new WorkMail directory for you. For more information, see Adding an organization in the WorkMail Administrator Guide.
You can associate multiple email domains with an organization, then choose your default email domain from the WorkMail console. You can also associate a domain that is managed in an Amazon Route 53 public hosted zone. For more information, see Adding a domain and Choosing the default domain in the WorkMail Administrator Guide.
Optionally, you can use a customer managed key from AWS Key Management Service (AWS KMS) to encrypt email for your organization. If you don't associate an AWS KMS key, WorkMail creates a default, AWS managed key for you.
responses: '200': description: Success content: application/json: schema: $ref: '#/components/schemas/CreateOrganizationResponse' '480': description: InvalidParameterException content: application/json: schema: $ref: '#/components/schemas/InvalidParameterException' '481': description: DirectoryInUseException content: application/json: schema: $ref: '#/components/schemas/DirectoryInUseException' '482': description: DirectoryUnavailableException content: application/json: schema: $ref: '#/components/schemas/DirectoryUnavailableException' '483': description: LimitExceededException content: application/json: schema: $ref: '#/components/schemas/LimitExceededException' '484': description: NameAvailabilityException content: application/json: schema: $ref: '#/components/schemas/NameAvailabilityException' requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/CreateOrganizationRequest' parameters: - name: X-Amz-Target in: header required: true schema: type: string enum: - WorkMailService.CreateOrganization summary: Amazon WorkMail Create Organization tags: - '#X Amz Target=WorkMailService.CreateOrganization' components: schemas: NameAvailabilityException: {} CreateOrganizationRequest: type: object required: - Alias title: CreateOrganizationRequest properties: DirectoryId: allOf: - $ref: '#/components/schemas/DirectoryId' - description: The AWS Directory Service directory ID. Alias: allOf: - $ref: '#/components/schemas/OrganizationName' - description: The organization alias. ClientToken: allOf: - $ref: '#/components/schemas/IdempotencyClientToken' - description: The idempotency token associated with the request. Domains: allOf: - $ref: '#/components/schemas/Domains' - description: The email domains to associate with the organization. KmsKeyArn: allOf: - $ref: '#/components/schemas/KmsKeyArn' - description: The Amazon Resource Name (ARN) of a customer managed key from AWS KMS. EnableInteroperability: allOf: - $ref: '#/components/schemas/Boolean' - description: Whentrue, allows organization interoperability between WorkMail and Microsoft Exchange. If true, you must include a AD Connector directory ID in the request.
OrganizationId:
type: string
pattern: ^m-[0-9a-f]{32}$
minLength: 34
maxLength: 34
InvalidParameterException: {}
DirectoryUnavailableException: {}
IdempotencyClientToken:
type: string
pattern: '[\x21-\x7e]+'
minLength: 1
maxLength: 128
LimitExceededException: {}
Boolean:
type: boolean
Domains:
type: array
items:
$ref: '#/components/schemas/Domain'
minItems: 0
maxItems: 5
OrganizationName:
type: string
pattern: ^(?!d-)([\da-zA-Z]+)([-][\da-zA-Z]+)*
minLength: 1
maxLength: 62
DomainName:
type: string
pattern: '[a-zA-Z0-9.-]+\.[a-zA-Z-]{2,}'
minLength: 3
maxLength: 255
HostedZoneId:
type: string
pattern: '[\S\s]*'
minLength: 1
maxLength: 32
Domain:
type: object
properties:
DomainName:
allOf:
- $ref: '#/components/schemas/DomainName'
- description: The fully qualified domain name.
HostedZoneId:
allOf:
- $ref: '#/components/schemas/HostedZoneId'
- description: The hosted zone ID for a domain hosted in Route 53. Required when configuring a domain hosted in Route 53.
description: The domain to associate with an WorkMail organization.
When you configure a domain hosted in Amazon Route 53 (Route 53), all recommended DNS records are added to the organization when you create it. For more information, see Adding a domain in the WorkMail Administrator Guide.
DirectoryId: type: string pattern: ^d-[0-9a-f]{10}$ minLength: 12 maxLength: 12 DirectoryInUseException: {} KmsKeyArn: type: string pattern: arn:aws:kms:[a-z0-9-]*:[a-z0-9-]+:[A-Za-z0-9][A-Za-z0-9:_/+=,@.-]{0,1023} minLength: 20 maxLength: 2048 CreateOrganizationResponse: type: object properties: OrganizationId: allOf: - $ref: '#/components/schemas/OrganizationId' - description: The organization ID. parameters: X-Amz-Credential: name: X-Amz-Credential in: header schema: type: string required: false X-Amz-Date: name: X-Amz-Date in: header schema: type: string required: false X-Amz-Signature: name: X-Amz-Signature in: header schema: type: string required: false X-Amz-Algorithm: name: X-Amz-Algorithm in: header schema: type: string required: false X-Amz-Security-Token: name: X-Amz-Security-Token in: header schema: type: string required: false X-Amz-SignedHeaders: name: X-Amz-SignedHeaders in: header schema: type: string required: false X-Amz-Content-Sha256: name: X-Amz-Content-Sha256 in: header schema: type: string required: false securitySchemes: hmac: type: apiKey name: Authorization in: header description: Amazon Signature authorization v4 x-amazon-apigateway-authtype: awsSigv4 externalDocs: description: Amazon Web Services documentation url: https://docs.aws.amazon.com/workmail/ x-hasEquivalentPaths: true