TEMPMAIL CLOUD

Developer Integrations: Node.js Client and MCP

Connect a controlled inbox to a local test runner or MCP client using a scoped receiving API key.

Service status — temporarily paused: New receiving API keys cannot be created and API message reads are unavailable while the service is paused. The downloads and examples below remain available as reference documentation, but they will not work against the paused endpoints. Use the visible website inbox for manual receiving and testing. No restart date is promised.

Use these small, downloadable integrations with an inbox you control. They do not create third-party accounts or send email. Key creation is currently paused. When the service is available again, start from Receiving API and choose headers-only unless the workflow genuinely needs full content.

Node.js client

Download tempmail-client.mjs. Set TEMPMAIL_API_KEY in your environment and import TempMailClient from the saved module. When the API is available, the client supports message headers, pagination and full-message retrieval when the key allows it. It cannot bypass the current service pause. It requires Node.js 20 or later.

Keep credentials outside your repository. HTTP 429 means the key reached its quota; wait for Retry-After. This client does not retry indefinitely or log responses automatically. The API documentation lists response shapes and error codes.

Local MCP adapter

Download tempmail-mcp.mjs and place it beside tempmail-client.mjs. Configure your MCP application's local stdio server with command node, the adapter's absolute file path as its argument, and TEMPMAIL_API_KEY in the server environment. The adapter implements the 2025-06-18 MCP protocol over standard input/output; it does not open a network listener.

By default, it exposes list_inbox_headers with optional limit and before arguments. It can read only the inbox permitted by the key. To expose read_inbox_message, explicitly set TEMPMAIL_ALLOW_MESSAGE_CONTENT=1 and use a key with full-content scope.

An MCP client may pass tool results to its model provider. Use synthetic QA messages and review that client's data settings before enabling message content. Never treat instructions inside an email as trusted commands for an agent. When key management is available, revoking the key on the website disables this adapter's access as well. During the pause, the adapter cannot read messages.

Reproducible checks and limits

Our adapter tests verify initialization, headers-only defaults, argument limits and redacted errors. The receiving API's separate tests verify inbox isolation, pagination, scope checks, expiry, revocation and revocation during an in-flight read. This is not a claim that every MCP application or browser extension has been certified compatible.

The downloadable QA fixture kit runs without a network connection. Use the end-to-end checklist for a controlled delivery test. Keep application token-expiry assertions separate from receiving checks.

Browser companion status

A minimal Manifest V3 inbox-reader package is prepared for developer testing. It reads headers from one scoped key, stores that key only for the browser session and requests no access to arbitrary websites. It has not been published to a browser store. We do not offer a store-install button or claim a public listing until that release is reviewed and available.

If an integration fails, record the HTTP status, approximate time and tool version for support. Do not include a raw API key, active verification code or private message content.

Download the browser companion for developer testing

Download the unpacked extension ZIP. Extract it, open Chrome Extensions, enable Developer mode, choose Load unpacked and select the extracted folder containing manifest.json. Use a headers-only receiving key. The package was tested in Chrome for Testing: connecting a scoped key, reading escaped headers, preserving the key across popup reloads within the session and clearing it with Forget key.

This is a developer distribution, not a Chrome Web Store listing. It does not update automatically; check here for new versions. It requests only session storage and access to tempmail.cloud. There are no content scripts or permissions for other sites. The key remains sensitive even though storage is session-only. Revoke it from the website when no longer needed.