The temp mail API built for developers
Disposable inboxes you can drive from code: read mail over a simple REST API, get HMAC-signed webhooks, plug into MCP agents. Every account gets a free API key; paid plans from €1.99/mo raise the limits.
# Any address on a CyberTemp domain works: the inbox is created on first read.
curl "https://api.cybertemp.xyz/[email protected]" \
-H "X-API-KEY: tk_..."
# [{"id":"...","from":"[email protected]","subject":"Your code is 482917",
# "text":"...","html":"...","date":"2026-05-17T09:31:00.000Z"}]Built for these workflows
Most CyberTemp API users are doing one of these three things.
Features
API key auth
Per-account keys, per-device CLI tokens. Revocable from the dashboard.
Webhooks
Receive new-message notifications at your endpoint. HMAC-signed.
OTP extraction
Read the newest message with one GET and pull the code out with a short regex. See the samples below.
IMAP
Connect your existing mail clients and tooling.
Custom domains
Bring your own — DNS setup support included.
MCP server
Plug-and-play tools for Claude Desktop and Cursor.
CLI
Coming soon. Until it ships, use the REST API or the MCP server.
SDKs
Client libraries for Python, Go and Rust, or plain HTTP from any language.
Real code, not pseudo-code
Wait for an OTP in a Playwright test
import { test, expect } from "@playwright/test";
const API = "https://api.cybertemp.xyz";
const headers = { "X-API-KEY": process.env.CYBERTEMP_API_KEY! };
// Polls /getMail until the newest message contains a 4-8 digit code.
async function waitForOtp(email: string, timeoutMs = 30_000) {
const deadline = Date.now() + timeoutMs;
while (Date.now() < deadline) {
const res = await fetch(`${API}/getMail?email=${encodeURIComponent(email)}`, { headers });
const mails: { subject: string; text: string }[] = await res.json();
const otp = mails[0] && `${mails[0].subject}\n${mails[0].text}`.match(/\b\d{4,8}\b/);
if (otp) return otp[0];
await new Promise((r) => setTimeout(r, 2000));
}
throw new Error("Timed out waiting for the OTP email");
}
test("signup verifies via OTP", async ({ page }) => {
const email = `e2e${Date.now()}@cybertemp.xyz`;
await page.goto("https://example.com/signup");
await page.fill("#email", email);
await page.click("button[type=submit]");
const otp = await waitForOtp(email);
await page.fill("#otp", otp);
await expect(page).toHaveURL(/dashboard/);
});Webhook receiver (Elite + Team plan)
Subscribe an HTTPS endpoint to get HMAC-SHA256-signed POSTs whenever a message lands in any of your inboxes. We retry with exponential backoff (1m, 5m, 30m, 6h) on 5xx/timeouts and auto-pause after 10 consecutive failures.
message.received— a new email lands in one of your inboxesinbox.created— a new inbox was provisioned on your accounttest.ping— fired from the dashboard "Test" button
- X-Cybertemp-Signature: sha256=<hmac_hex>
- X-Cybertemp-Event: message.received
- X-Cybertemp-Delivery: <unique_id>
- X-Cybertemp-Timestamp: <unix_seconds>
- Content-Type: application/json
{
"event": "message.received",
"delivery_id": "7c4f...",
"timestamp": 1731234567,
"data": {
"inbox_id": "5d2f...",
"inbox": "[email protected]",
"message_id": "9a1b...",
"from": "[email protected]",
"to": ["[email protected]"],
"subject": "Your verification code",
"received_at": "2026-05-17T09:31:00Z",
"size_bytes": 4732,
"encrypted": true
}
}import crypto from "node:crypto";
import express from "express";
const app = express();
// IMPORTANT: keep the raw buffer for HMAC. Express's json() throws it away.
app.use("/webhooks/cybertemp",
express.raw({ type: "application/json" }));
app.post("/webhooks/cybertemp", (req, res) => {
const header = req.header("x-cybertemp-signature") || "";
const expected = "sha256=" + crypto
.createHmac("sha256", process.env.CT_WEBHOOK_SECRET)
.update(req.body) // req.body is a Buffer thanks to express.raw
.digest("hex");
if (!crypto.timingSafeEqual(Buffer.from(header), Buffer.from(expected))) {
return res.status(401).end();
}
const event = JSON.parse(req.body.toString("utf8"));
console.log(event.data.from, "→", event.data.subject);
res.status(200).end();
});Manage endpoints and signing secrets in Settings → Webhooks. Each endpoint has a Test button that sends a test event, so you can check your signature verification without waiting for real mail.
Agent flow via MCP
User: Sign me up at acme.test with a throwaway email.
Wait for the verification code and paste it back.
Agent:
- create_inbox() -> [email protected]
- POST acme.test/signup { email: [email protected] }
- wait_for_message([email protected], timeout=60)
-> "Your code is 482917"
- POST acme.test/verify { otp: 482917 }
Done.Quickstart in 3 steps
Create a free account. No credit card required.
Sign upAny account can create keys under Settings → API keys. Free keys get Free-plan limits; paid plans raise them.
Get an API keycurl -H "X-API-KEY: tk_..." \
"https://api.cybertemp.xyz/[email protected]"From €1.99/mo
Start free with an API key. Paid plans raise rate limits and inbox caps; Elite adds webhooks.