# sendMessage

mutation · in the family [Work and notes](/reference/work-and-notes/)

## What it does

Send a message to one person or one of your teams — optionally about a specific record.

Send ONE message to EXACTLY one recipient: a USER recipient must exist in-tenant + non-doomed (suspended still receives — a mailbox outlives a login); a TEAM recipient requires YOU to be a member of that ACTIVE team; the optional targetRef pair ('about this record') gates in-tenant + non-doomed. body ≤ 4096. The row lands in the recipient's current month bucket and persists (no deletion v1). Requires authentication. Template class (universal staff work — the addNote kinship).

## What happens

It lands in their inbox and stays there; messages can’t be deleted or edited once sent.

## Who may call it

Capability area: **Work and notes** — Tasks, notes, messages, dashboards and the everyday tools every staff member keeps.

- Owner
- System Administrator
- Manager
- Associate Manager
- Warehouse Associate
- Sales Associate
- Cashier
- An API key whose scope allows `api:sendMessage`

## Arguments

| Name | Type | Required | Notes |
| --- | --- | --- | --- |
| `toUserId` | [ID](/types/#scalars) | no | No further notes. |
| `toTeamId` | [ID](/types/#scalars) | no | No further notes. |
| `body` | [String](/types/#scalars) `String!` | yes | No further notes. |
| `targetType` | [String](/types/#scalars) | no | No further notes. |
| `targetId` | [ID](/types/#scalars) | no | No further notes. |

## Returns

[MessageRef](/types/MessageRef/) `MessageRef!` — One inbox message.

## Example request

```graphql
mutation ExampleSendMessage($toUserId: ID, $body: String!) {
  sendMessage(toUserId: $toUserId, body: $body) {
    id
    toKind
    toId
    fromKind
    fromUserId
    body
    targetType
    targetId
    createdAt
    readAt
  }
}
```

Variables:

```json
{
  "toUserId": "01900000-0000-7000-8000-486d81ea0000",
  "body": "Restock before the weekend."
}
```

Send it with the envelope naming the version: `"extensions": {"at": {"version": {"name":"genesis","number":0}}}`.

## Example response

```json
{
  "data": {
    "sendMessage": {
      "id": "01900000-0000-7000-8000-37386ae00000",
      "toKind": "USER",
      "toId": "01900000-0000-7000-8000-4dc937890000",
      "fromKind": "USER",
      "fromUserId": "01900000-0000-7000-8000-f626b68f0000",
      "body": "Restock before the weekend.",
      "targetType": "<target type>",
      "targetId": "01900000-0000-7000-8000-446adfd50000",
      "createdAt": "2027-01-31T00:00:00.000Z",
      "readAt": "2027-01-31T00:00:00.000Z"
    }
  },
  "extensions": {
    "at": {
      "callId": "01EXAMPLE-CALL-ID",
      "version": {
        "requested": {
          "name": "genesis",
          "number": 0
        },
        "serviced": {
          "name": "genesis",
          "number": 0
        }
      }
    }
  }
}
```

## Errors this call can answer

- `VALIDATION/INVALID` — Something in the request is not valid. ([VALIDATION](/errors/VALIDATION/))
- `AUTHN/REQUIRED` — Sign in to do this. ([AUTHN](/errors/AUTHN/))
- `AUTHZ/FORBIDDEN` — Your role does not allow this action. ([AUTHZ](/errors/AUTHZ/))
- `RATE_LIMIT/THROTTLED` — Too many requests in a short time. ([RATE_LIMIT](/errors/RATE_LIMIT/))
- `NOT_FOUND/*` — That record could not be found. ([NOT_FOUND](/errors/NOT_FOUND/))
- `CONFLICT/*` — The record’s state, or a change made in the meantime, does not allow this; the codes are on the CONFLICT page. ([CONFLICT](/errors/CONFLICT/))
- `VALIDATION/VERSION_REQUIRED` — The request did not say which app version it came from. ([VALIDATION](/errors/VALIDATION/))
