# WatchFox > WatchFox is a hosted API that watches mailboxes (Gmail, Microsoft 365, IMAP) and calls your server with a signed webhook when an > email matches what you asked for: enquiries, invoices, support requests, purchase orders, job applications, claims, or types you > define and tune. Email content is never retained. REST + JSON, bearer-token auth. ## Start here - [Complete guide for developers and AI agents](https://watchfox.run/llms-full.txt): auth, concepts, quickstart, webhooks and signature verification, downloads, limits, errors, endpoint reference. One file, everything needed. - [OpenAPI 3 document](https://watchfox.run/v1/openapi.json): machine-readable endpoints and request bodies. ## Also useful - [Human documentation](https://watchfox.run/#/docs) - [Pricing and plan limits](https://watchfox.run/#/pricing) - [Service health](https://watchfox.run/v1/health): open, no key. ## Key facts - Authentication: `Authorization: Bearer wf_live_...`. A person creates the first key in the dashboard; sign-in is GitHub, Google or Microsoft only (no passwords). - Try everything without real mail: POST /v1/connections with {"provider":"sandbox"}, then POST /v1/connections/{id}/sandbox-emails. - Webhooks are signed: X-WatchFox-Signature = t=,v1=HMAC_SHA256(secret, "." + raw body). - Plan limits (runs per month, mailboxes, watches, custom types, team members) apply identically to the API and the dashboard; over a limit you get 400 or 429 with a clear message.