Mimecast APIConnect Mimecast without building on its API
Mimecast has a REST API. Self-serve for customers only; an administrator whose role has API Application permissions generates keys in the Administration Console. If you're reading the docs because you need Mimecast to talk to the rest of your stack, Caddi does that without you writing or maintaining integration code: you show it the job once, and it runs it across Mimecast and your other tools.
- APIREST (JSON)
- AuthOAuth 2.0 client credentials
- AccessSelf-serve for customers
What the Mimecast API gives you
- Type
- REST (JSON)
- Authentication
- OAuth 2.0 client credentials
- Who can get access
- Self-serve for customers only; an administrator whose role has API Application permissions generates keys in the Administration Console.
- What it covers
- Email security administration and data such as SIEM/audit logs, policies, users and message tracking.
Official docs: developer.services.mimecast.com. Checked September 2026. Vendors change access terms, so confirm with Mimecast before you build.
Building on the Mimecast API vs. having Caddi run it
| The job | Build it on the API | With Caddi |
|---|---|---|
| Getting access | Register an app, get Mimecast credentials, and manage tokens and refreshes. | Connect your Mimecast account once. Caddi holds the connection. |
| Writing the integration | A developer maps fields, handles pagination, retries and rate limits, and writes the sync. | You show Caddi the Mimecast task the way you'd train a new hire. It writes verified code for it. |
| Steps the API doesn't cover | Screens with no endpoint stay manual, or need a separate RPA tool. | Caddi uses a secure, audited browser session where there's no API, in the same automation. |
| The other systems in the loop | Each extra tool is another API, another set of credentials, another integration to own. | One automation runs across all the tools the job touches. |
| Keeping it running | Someone owns the code when the API version, fields or your process change. | Every automation is reviewed before it runs in production, and every run is logged. |
Building on the API is the right call when you have engineers and the integration is your product. When the goal is getting Mimecast work off someone's desk, the build is the slow part.
What teams usually want the Mimecast API for
Search and export
Caddi runs an archive search in Mimecast, exports the matching messages, and emails them to the requester.
Retrieve to matter
Caddi pulls archived messages from Mimecast and files them to the matter for review.
Continuity monitor
Caddi watches Mimecast for held or blocked messages and logs them for the IT team.
Mimecast API questions
Does Mimecast have an API?
Yes. Mimecast has a REST API, authenticated with OAuth 2.0 client credentials. The official documentation is at https://developer.services.mimecast.com/.
How do I get access to the Mimecast API?
Self-serve for customers only; an administrator whose role has API Application permissions generates keys in the Administration Console.
Can I connect Mimecast to my other tools without writing code against its API?
Yes. With Caddi you show the Mimecast task once, the way you'd train a new hire, and Caddi builds it as verified code that runs across Mimecast and the other tools the job touches. Where a step has no API, Caddi uses a secure, audited browser session in the same automation.
Do I need a developer to automate Mimecast with Caddi?
No. There is no integration code for you to write or maintain. Every automation Caddi builds for Mimecast is reviewed before it runs in production, and every run is logged.
Connect Mimecast without the build.
Drop your work email and pick a time. We'll show you Caddi running your Mimecast workflow end to end.