> ## Documentation Index
> Fetch the complete documentation index at: https://openworklabs.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Move an Outlook message to archive, deleted items, or inbox

> Requires Mail.ReadWrite and mailManage. Moves one message to a fixed named folder, never permanently deletes it. Moving to deleteditems also requires confirmTrash: true. Use the returned message id after moving, since Graph can change it. Uses only the calling member's delegated Microsoft 365 connection. Never automatically retry a mutation after a timeout, cancellation, or ambiguous response; inspect current state first.



## OpenAPI

````yaml /openapi.json post /v1/capabilities/microsoft-365/mail-message/{messageId}/move
openapi: 3.1.0
info:
  title: Den API
  description: >-
    OpenAPI spec for the Den control plane API.


    Authentication:

    - Use `Authorization: Bearer <session-token>` for user-authenticated routes
    that require a Den session.

    - Use `x-api-key: <den-api-key>` for organization API-key calls. API keys
    resolve to the issuing user and the organization member they were scoped to
    when created, so they can call ordinary user and organization routes without
    a separate signed-in session.
      Example: `curl https://api.openworklabs.com/v1/me -H "x-api-key: den_..."`.
    - Session-only flows still require a signed-in user session, including
    organization creation, invitation acceptance, active-organization switching,
    and MCP token minting.

    - Public routes like health and documentation do not require authentication.


    Swagger tip: use the security schemes in the Authorize dialog to set either
    `bearerAuth` or `denApiKey` before trying protected endpoints.
  version: 0.18.46
  contact:
    name: OpenWork
    url: https://openworklabs.com
    email: team@openworklabs.com
  license:
    name: OpenWork Enterprise Edition License
    url: https://github.com/different-ai/openwork/blob/dev/ee/LICENSE
servers:
  - url: https://api.openworklabs.com
security:
  - bearerAuth: []
  - denApiKey: []
tags:
  - name: System
    description: >-
      Service health, readiness, API documentation, and desktop version
      metadata.
  - name: Authentication
    description: >-
      Sign-in discovery, administrator bootstrap, OAuth provider connections,
      and MCP token minting.
  - name: OAuth
    description: >-
      OAuth 2.0 / OpenID Connect authorization-server and protected-resource
      metadata and dynamic client registration (RFC 8414, RFC 9728, RFC 7591),
      used by MCP clients.
  - name: SCIM
    description: >-
      SCIM 2.0 provisioning endpoints for identity providers (RFC 7644) and the
      organization SCIM connector management routes.
  - name: SSO
    description: Organization single sign-on connector management routes.
  - name: Bootstrap
    description: Agent-first provisional workspace setup routes.
  - name: Users
    description: Current user and membership routes.
  - name: Organizations
    description: Organization creation, context, brand assets, and install links.
  - name: Invitations
    description: Invitation preview, acceptance, creation, and cancellation routes.
  - name: Members
    description: Organization member management routes.
  - name: Roles
    description: Organization custom role management routes.
  - name: Teams
    description: Organization team management routes.
  - name: API Keys
    description: Organization API key management routes.
  - name: Desktop Policies
    description: Desktop app policies applied to the organization, members, or teams.
  - name: LLM Providers
    description: Organization LLM provider catalog, configuration, and access routes.
  - name: Inference
    description: Organization inference settings.
  - name: Cloud
    description: Organization Cloud instance lifecycle and browser gateway resolution.
  - name: Workers
    description: Worker lifecycle, billing, and runtime routes.
  - name: Worker Runtime
    description: Worker runtime inspection and upgrade routes.
  - name: Worker Activity
    description: Worker heartbeat and activity reporting routes.
  - name: Automations
    description: Scheduled Automations, their runs, and desktop runner presence.
  - name: Workflows
    description: Saved Workflows (Code Mode scripts), their versions, snapshots, and views.
  - name: Workflow Runs
    description: Durable Workflow run history.
  - name: Codemode Runs
    description: Generated Artifact views produced by Code Mode runs.
  - name: Apps
    description: >-
      Saved reusable apps built from Workflows and Artifact views, and their
      sharing.
  - name: Config Objects
    description: >-
      Versioned configuration objects (skills, workflows, and other plugin
      content).
  - name: Plugins
    description: Plugin packages, access grants, and imports.
  - name: Marketplaces
    description: Marketplaces that distribute plugins to members and teams.
  - name: Resources
    description: >-
      Aggregated snapshot of the resources and marketplace capabilities
      available to the caller.
  - name: Dashboards
    description: Shared dashboards and their access grants.
  - name: Capability Sources
    description: >-
      Native provider capabilities (Google Workspace, Microsoft 365) and
      external MCP connections executed as the calling member.
  - name: Direct uploads
    description: Multipart uploads that stream workspace files straight to a provider.
  - name: Connectors
    description: >-
      Connector accounts and instances (GitHub and other sources) and their sync
      state.
  - name: GitHub
    description: >-
      GitHub App installation, repository discovery, and plugin import from
      GitHub.
  - name: Diagnostics
    description: Controlled egress diagnostics for self-hosted deployments.
  - name: Telemetry
    description: Telemetry event ingestion and adoption analytics.
  - name: Webhooks
    description: Signed inbound webhooks from third-party providers.
  - name: Admin
    description: Platform administration routes for allowlisted OpenWork administrators.
  - name: Deprecated
    description: Removed features that answer with 410 or an empty result for old clients.
paths:
  /v1/capabilities/microsoft-365/mail-message/{messageId}/move:
    post:
      tags:
        - Capability Sources
      summary: Move an Outlook message to archive, deleted items, or inbox
      description: >-
        Requires Mail.ReadWrite and mailManage. Moves one message to a fixed
        named folder, never permanently deletes it. Moving to deleteditems also
        requires confirmTrash: true. Use the returned message id after moving,
        since Graph can change it. Uses only the calling member's delegated
        Microsoft 365 connection. Never automatically retry a mutation after a
        timeout, cancellation, or ambiguous response; inspect current state
        first.
      operationId: moveMicrosoft365MailMessage
      parameters:
        - in: path
          name: messageId
          schema:
            type: string
            minLength: 1
            maxLength: 512
          required: true
          description: Microsoft Graph message id.
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/Microsoft365MailMessageMoveBody'
      responses:
        '200':
          description: Microsoft Graph mutation receipt returned.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Microsoft365MailMessageResponse'
        '401':
          description: The caller must be signed in.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/UnauthorizedError'
        '409':
          description: The selected feature or delegated permission is missing.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Microsoft365NeedsConnectionError'
        '413':
          description: Request body exceeds 1 MiB.
          content:
            application/json:
              schema:
                type: object
                properties:
                  error:
                    type: string
                    const: invalid_request
                  message:
                    type: string
                required:
                  - error
                  - message
        '502':
          description: Microsoft Graph rejected the request or the outcome is unknown.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Microsoft365GraphError'
      security:
        - bearerAuth: []
        - denApiKey: []
components:
  schemas:
    Microsoft365MailMessageMoveBody:
      type: object
      properties:
        destination:
          type: string
          enum:
            - archive
            - deleteditems
            - inbox
          description: >-
            Named folder in the caller's mailbox. deleteditems moves to trash,
            never permanently deletes.
        confirmTrash:
          description: >-
            Required when destination is deleteditems. Set true only when the
            user explicitly requested moving this message to trash.
          type: boolean
          const: true
      required:
        - destination
      additionalProperties: false
    Microsoft365MailMessageResponse:
      type: object
      properties:
        ok:
          type: boolean
          const: true
        message:
          $ref: '#/components/schemas/Microsoft365MailMessage'
      required:
        - ok
        - message
    UnauthorizedError:
      type: object
      properties:
        error:
          type: string
          const: unauthorized
      required:
        - error
    Microsoft365NeedsConnectionError:
      type: object
      properties:
        error:
          type: string
          const: needs_connection
        message:
          type: string
      required:
        - error
        - message
    Microsoft365GraphError:
      type: object
      properties:
        error:
          type: string
          const: microsoft_graph_error
        message:
          type: string
        outcome:
          type: string
          const: unknown
        retryable:
          type: boolean
          const: false
      required:
        - error
        - message
    Microsoft365MailMessage:
      type: object
      properties:
        id:
          type: string
        conversationId:
          type: string
        subject:
          type: string
        receivedDateTime:
          type: string
        preview:
          type: string
        from:
          anyOf:
            - $ref: '#/components/schemas/Microsoft365EmailAddress'
            - type: 'null'
        to:
          type: array
          items:
            $ref: '#/components/schemas/Microsoft365EmailAddress'
        webLink:
          type: string
        hasAttachments:
          type: boolean
        isDraft:
          type: boolean
        isRead:
          type: boolean
        categories:
          type: array
          items:
            type: string
        parentFolderId:
          type: string
        cc:
          type: array
          items:
            $ref: '#/components/schemas/Microsoft365EmailAddress'
        body:
          type: string
        bodyContentType:
          type: string
        bodyTruncated:
          type: boolean
      required:
        - id
        - conversationId
        - subject
        - receivedDateTime
        - preview
        - from
        - to
        - webLink
        - hasAttachments
        - isDraft
        - isRead
        - categories
        - parentFolderId
        - cc
        - body
        - bodyContentType
        - bodyTruncated
    Microsoft365EmailAddress:
      type: object
      properties:
        name:
          type: string
        address:
          type: string
      required:
        - name
        - address
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      bearerFormat: session-token
      description: >-
        Session token passed as `Authorization: Bearer <session-token>` for
        user-authenticated Den routes.
    denApiKey:
      type: apiKey
      in: header
      name: x-api-key
      description: >-
        Organization API key passed as the `x-api-key` header. The raw key is
        the header value; do not prefix it with `Bearer`.

````