Prompt
Should my app call an email API directly?
Latest observation
Sep 23, 2026
OpenAI APIWeb search: off
Usually no — your app should not call an email API directly from the client unless the API is explicitly designed for browser/mobile use and you’re comfortable exposing whatever it requires.
Recommended pattern
Client app → your backend → email provider API
Why:
- Keeps API keys secret — email service credentials should not live in the frontend.
- Prevents abuse — attackers can’t easily spam your email endpoint.
- Lets you validate and rate-limit requests.
- Centralizes logic — templates, retries, logging, and auditing live in one place.
- Easier to swap providers later.
When direct calls might be okay
Only if:
- The provider offers a public client-side SDK or a token-based flow meant for frontend use.
- The action is low-risk and tightly scoped.
- No sensitive secret is exposed.
Even then, many teams still prefer a backend relay.
Best practice for common cases
- Password reset / signup / transactional email: backend only.
- Contact form submissions: frontend sends data to backend; backend sends email.
- User-invoked “send invite” features: frontend requests backend to send it.
- Marketing emails: backend or dedicated service, never direct from client.
Simple rule
If sending the email requires a secret key, don’t do it from the app directly.
If you want, I can sketch the safest architecture for your specific stack (React, mobile app, Node, etc.).