Home
Get started

Authentication

Bearer API keys for TropMail REST, SDKs, and MCP.

REST, SDKs, and MCP all use the same Bearer key.

Create a key

  1. Open the TropMail dashboard
  2. Create an API key
  3. Store it as an environment variable. Do not commit it.
export TROPMAIL_API_KEY=your32charalphanumericapikeyhere

Keys are 32 characters of [A-Za-z0-9], optionally prefixed with tm_live_. Official clients validate that locally before the first request.

Send the header

Authorization: Bearer YOUR_API_KEY

Always include the Bearer prefix. Official SDKs set this header for you.

MCP

Remote Streamable HTTP at https://mcp.tropmail.com/mcp. Same Bearer key as REST.

Claude Code

claude mcp add --transport http \
  --header "Authorization: Bearer YOUR_API_KEY" \
  tropmail https://mcp.tropmail.com/mcp

Cursor

{
  "mcpServers": {
    "tropmail": {
      "url": "https://mcp.tropmail.com/mcp",
      "headers": {
        "Authorization": "Bearer YOUR_API_KEY"
      }
    }
  }
}

Full steps: Connect MCP.

Rate limits

Limits apply per account.

TierRequests / second
Pro3
Ultimate10
Enterprise50

Response headers: X-RateLimit-Limit, X-RateLimit-Remaining, X-RateLimit-Reset. On 429, honor Retry-After. Official SDKs pace themselves from those headers.

HeaderNotes
AuthorizationRequired on every route except health
Content-Typeapplication/json on POST bodies
Acceptapplication/json
X-Request-IDOptional UUID. Echoed for support.

Official SDKs set these for you.