Skip to main content
POST
Audit an email

Authorizations

Authorization
string
header
default:Bearer brew_your_api_key
required

Send your Brew API key as Authorization: Bearer brew_xxx.

Headers

Idempotency-Key
string

Optional idempotency key for safe retries. Reusing the same key with the same request body returns the original response for 24 hours.

Required string length: 1 - 100
X-Brand-Id
string

The brand this request acts on. REQUIRED for organization-scoped credentials (otherwise 400 BRAND_ID_REQUIRED — there is no default brand); list ids with GET /v1/brands. Brand-scoped credentials may omit it, and sending a different brand returns 403 BRAND_SCOPE_MISMATCH. A brand outside your organization returns 404 BRAND_NOT_FOUND.

Required string length: 1 - 64

Body

application/json
emailHtml
string
required
Minimum string length: 1
subject
string
Maximum string length: 1000
previewText
string
Maximum string length: 1000
sendingPurpose
enum<string>
Available options:
marketing,
transactional

Response

A complete or partial audit. Branch on completion.status; only complete carries a numeric score. A partial response is not cached under its idempotency key and may be retried with the same key.

schemaVersion
enum<number>
required
Available options:
1
rulesetVersion
string
required
Required string length: 1 - 100
auditId
string<uuid>
required
contentHash
string
required
Pattern: ^sha256:[0-9a-f]{64}$
auditedAt
string<date-time>
required
expiresAt
string<date-time>
required
policy
object
required
summary
object
required
checks
object[]
required
Maximum array length: 32
metrics
object
required
findings
object[]
required
Maximum array length: 100
totalFindings
integer
required
Required range: x >= 0
findingsTruncated
boolean
required
completion
object
required