Skip to content
CyberTemp
Developers

The temp mail API built for developers

Disposable inboxes you can drive from code: read mail over a simple REST API, get HMAC-signed webhooks, plug into MCP agents. Every account gets a free API key; paid plans from €1.99/mo raise the limits.

# Any address on a CyberTemp domain works: the inbox is created on first read.
curl "https://api.cybertemp.xyz/[email protected]" \
  -H "X-API-KEY: tk_..."

# [{"id":"...","from":"[email protected]","subject":"Your code is 482917",
#   "text":"...","html":"...","date":"2026-05-17T09:31:00.000Z"}]

Built for these workflows

Most CyberTemp API users are doing one of these three things.

Email testing in CI/CD
Use disposable inboxes in Playwright, Puppeteer, or Cypress runs. No shared inboxes, no leaked secrets in test fixtures.
OTP flows for QA automation
Point your signup flow at a fresh address, poll GET /getMail and read the code from the newest message. No shared inboxes, no flaky test mail servers.
AI agents and MCP integrations
Drop our MCP server into Claude or Cursor in seconds. Agents can sign up, confirm, and act on email-gated flows autonomously.

Features

API key auth

Per-account keys, per-device CLI tokens. Revocable from the dashboard.

Webhooks

Receive new-message notifications at your endpoint. HMAC-signed.

OTP extraction

Read the newest message with one GET and pull the code out with a short regex. See the samples below.

IMAP

Connect your existing mail clients and tooling.

Custom domains

Bring your own — DNS setup support included.

MCP server

Plug-and-play tools for Claude Desktop and Cursor.

CLI

Coming soon. Until it ships, use the REST API or the MCP server.

SDKs

Client libraries for Python, Go and Rust, or plain HTTP from any language.

Real code, not pseudo-code

Wait for an OTP in a Playwright test

import { test, expect } from "@playwright/test";

const API = "https://api.cybertemp.xyz";
const headers = { "X-API-KEY": process.env.CYBERTEMP_API_KEY! };

// Polls /getMail until the newest message contains a 4-8 digit code.
async function waitForOtp(email: string, timeoutMs = 30_000) {
  const deadline = Date.now() + timeoutMs;
  while (Date.now() < deadline) {
    const res = await fetch(`${API}/getMail?email=${encodeURIComponent(email)}`, { headers });
    const mails: { subject: string; text: string }[] = await res.json();
    const otp = mails[0] && `${mails[0].subject}\n${mails[0].text}`.match(/\b\d{4,8}\b/);
    if (otp) return otp[0];
    await new Promise((r) => setTimeout(r, 2000));
  }
  throw new Error("Timed out waiting for the OTP email");
}

test("signup verifies via OTP", async ({ page }) => {
  const email = `e2e${Date.now()}@cybertemp.xyz`;
  await page.goto("https://example.com/signup");
  await page.fill("#email", email);
  await page.click("button[type=submit]");

  const otp = await waitForOtp(email);
  await page.fill("#otp", otp);
  await expect(page).toHaveURL(/dashboard/);
});

Webhook receiver (Elite + Team plan)

Subscribe an HTTPS endpoint to get HMAC-SHA256-signed POSTs whenever a message lands in any of your inboxes. We retry with exponential backoff (1m, 5m, 30m, 6h) on 5xx/timeouts and auto-pause after 10 consecutive failures.

Event types
  • message.received — a new email lands in one of your inboxes
  • inbox.created — a new inbox was provisioned on your account
  • test.ping — fired from the dashboard "Test" button
Headers we set
  • X-Cybertemp-Signature: sha256=<hmac_hex>
  • X-Cybertemp-Event: message.received
  • X-Cybertemp-Delivery: <unique_id>
  • X-Cybertemp-Timestamp: <unix_seconds>
  • Content-Type: application/json
Payload shape
{
  "event": "message.received",
  "delivery_id": "7c4f...",
  "timestamp": 1731234567,
  "data": {
    "inbox_id": "5d2f...",
    "inbox": "[email protected]",
    "message_id": "9a1b...",
    "from": "[email protected]",
    "to": ["[email protected]"],
    "subject": "Your verification code",
    "received_at": "2026-05-17T09:31:00Z",
    "size_bytes": 4732,
    "encrypted": true
  }
}
Verify the signature
import crypto from "node:crypto";
import express from "express";

const app = express();
// IMPORTANT: keep the raw buffer for HMAC. Express's json() throws it away.
app.use("/webhooks/cybertemp",
  express.raw({ type: "application/json" }));

app.post("/webhooks/cybertemp", (req, res) => {
  const header = req.header("x-cybertemp-signature") || "";
  const expected = "sha256=" + crypto
    .createHmac("sha256", process.env.CT_WEBHOOK_SECRET)
    .update(req.body)         // req.body is a Buffer thanks to express.raw
    .digest("hex");

  if (!crypto.timingSafeEqual(Buffer.from(header), Buffer.from(expected))) {
    return res.status(401).end();
  }

  const event = JSON.parse(req.body.toString("utf8"));
  console.log(event.data.from, "→", event.data.subject);
  res.status(200).end();
});

Manage endpoints and signing secrets in Settings → Webhooks. Each endpoint has a Test button that sends a test event, so you can check your signature verification without waiting for real mail.

Agent flow via MCP

User: Sign me up at acme.test with a throwaway email.
Wait for the verification code and paste it back.

Agent:
- create_inbox()                      -> [email protected]
- POST acme.test/signup { email: [email protected] }
- wait_for_message([email protected], timeout=60)
                                      -> "Your code is 482917"
- POST acme.test/verify { otp: 482917 }
Done.

MCP server

Quickstart in 3 steps

Step 1
Sign up

Create a free account. No credit card required.

Sign up
Step 2
Get an API key

Any account can create keys under Settings → API keys. Free keys get Free-plan limits; paid plans raise them.

Get an API key
Step 3
Make a request
curl -H "X-API-KEY: tk_..." \
  "https://api.cybertemp.xyz/[email protected]"
Read the API docs

From €1.99/mo

Start free with an API key. Paid plans raise rate limits and inbox caps; Elite adds webhooks.