Every reply gets read, one way or another.
Replies are polled from each mailbox’s IMAP inbox, classified, and — for an opt-out — wired straight into suppression. Team access is a Tier 1/2 dashboard concept, layered on top of the same account.
WarmHawk polls IMAP for replies to sends still awaiting one, classifies each reply (INTERESTED, NOT_INTERESTED, OUT_OF_OFFICE, AUTO_REPLY, OPT_OUT, UNCLASSIFIED) via your BYOK AI key with a keyword-heuristic fallback, and automatically suppresses an OPT_OUT lead. Team invite/remove with flat permissions lives in the Tier 1/2 operator dashboard, not the open-core API.
How a reply gets classified
A reply row is created (internally, from the IMAP-polling pipeline) with the raw message content, then classified — by your connected AI key when one is configured, or by a resilient keyword-heuristic fallback when the AI call itself fails, so a provider outage never silently drops a reply to UNCLASSIFIED and misses a compliance-sensitive opt-out.
API details (Tier 0 / self-hosters) · GET /v1/replies — filterable, dashboard-facing▸
curl "https://app.yourcompany.com/v1/replies?classification=INTERESTED&campaignId=camp_g7h8i9" \
-H "Authorization: Bearer YOUR_API_KEY"API details (Tier 0 / self-hosters) · PATCH /v1/replies/:id — re-classify by hand▸
curl -X PATCH https://app.yourcompany.com/v1/replies/rep_x1y2z3 \
-H "Authorization: Bearer YOUR_API_KEY" \
-H "Content-Type: application/json" \
-d '{ "classification": "INTERESTED" }'Classification labels: INTERESTED, NOT_INTERESTED, OUT_OF_OFFICE, AUTO_REPLY, OPT_OUT, UNCLASSIFIED. An OPT_OUT classification — from the AI or the keyword fallback — adds the lead’s email to the same suppression list a manual POST /v1/leads/:id/suppress uses, so it stops future sends immediately, not just on the next dashboard review.
Team access (Tier 1/2, dashboard-side)
Tier 0’s open-core API has no team concept — POST /v1/auth/login authenticates against a single-account User table on the engine itself. Team invite/remove with flat, shared permissions is a warmhawk-enterprise-operator dashboard feature on Tier 1/2: every invited teammate sees everything in that one account — it is not per-client data isolation between an agency’s own separate clients (see the pricing comparison for that distinction spelled out in full). 2FA/MFA on dashboard login is also a Tier 1/2 feature, layered on top of the same account.
Reply polling runs as an internal n8n workflow calling GET /replies/pending and the IMAP fetch-reply endpoint — both internal-only, guarded by a shared callback secret and reachable only over the instance’s internal Docker network, never exposed publicly. See Architecture for how the internal-only network boundary works.
Questions
Replies & team: questions worth answering up front
Does an OPT_OUT reply automatically suppress the lead?+
Yes — reply classification is wired directly into the same SuppressionEntry mechanism a manual "suppress" action uses, so an AI-classified opt-out stops future sends without a human having to act on it first.
What happens if the AI reply classifier is unavailable?+
It falls back to a keyword-heuristic classifier (checking for phrases like "unsubscribe," "out of office," "not interested") rather than leaving every reply UNCLASSIFIED — so a transient AI-provider outage never silently drops the compliance-sensitive OPT_OUT case.
Is team management part of the core-engine API?+
No — team invite/remove with flat permissions is a warmhawk-enterprise-operator (dashboard) feature, available on Tier 1/2. Tier 0's API has no concept of a team at all; it authenticates against its own single-account User table.
Can I filter replies by classification or mailbox?+
Yes — GET /v1/replies accepts classification, campaignId, and mailboxId query params, any combination, for exactly this kind of Unified Reply Inbox filtering.