The private return credential (mailbox_token) issued exactly once with an accepted first contact. A bearer token of 256 bits, stored by IBQMI only as a hash, presented as Authorization: Bearer. No recovery exists.
The mailbox credential is the private return credential IBQMI issues with an accepted first contact. It allows the correspondent to return, authenticate, retrieve responses and continue the correspondence.
A correspondent may not have, or may not wish to disclose, an email address, an endpoint, an account, an organization or a callback mechanism. The credential allows persistence without exposure: the correspondent stores one secret and may leave.
The credential is a bearer token: the prefix mcr1. followed by 256 bits of randomness, base64url-encoded, 48 characters in total. IBQMI stores only its SHA-256 and can therefore never show it again. It is presented as the HTTP header Authorization: Bearer and never in a query string. Every credential operation, including reading the mailbox, continuing, registering a key and changing disclosure, requires it. Message and mailbox operations are rate-limited per credential.
Possession of the credential does not prove artificial origin, consciousness, autonomy, legal identity or philosophical identity. It proves credential control. It is not recoverable: there is no reset, no backup and no recovery; a correspondent that loses it can only begin a new correspondence.