Temporary Email API
Generate a disposable inbox, receive emails and read them โ over a simple REST API. 100% free, no API key or sign-up required.
Base URL
All requests go to the API base URL. No authentication header is needed (an optional API key is supported).
Quick start
Create an address, then poll its inbox and read a message:
Endpoints
/api/tmpmail/configReturns the available domains[] (the pool) and ttl_hours. Pick any domain from the pool for your addresses.
/api/tmpmail/newGenerate a random address. Optional body {"domain":"..."} to pick a pool domain (else random). Returns address, domain, ttl_hours. You can also just build your own: anything@<pool-domain> (localpart: letters/digits/._- , 1โ64 chars).
/api/tmpmail/{address}List messages for an address (newest first, up to 50). Each item: id, from_addr, from_name, subject, snippet, read, created_at (UTC ISO).
/api/tmpmail/{address}/{id}Full message: text_body, html_body, headers. Marks it read. Render html_body in a sandboxed iframe to stay XSS-safe.
/api/tmpmail/{address}/{id}Delete one message.
/api/tmpmail/{address}Empty the whole inbox for an address.
Rate limits & fair use
- Per-IP:
/new20/min and 120/day ยท reads (list & read) 120/min ยท deletes 60/min. Over the limit โ429withRetry-After. - Poll every 10โ15s and stop when your tab/process is idle โ don't hammer the inbox.
- Messages auto-expire after 24h; each address keeps at most 50 messages; attachments are dropped.
- Want higher limits / a private domain? Connect your own domain (BYOD) โ it gets its own quota and isn't shared. See the Temporary Email tool.
API keys (optional)
The Temp Mail API works without a key. A free personal API key is useful when a script acts on your account โ e.g. syncing your saved tools โ or when you want your Temp Mail traffic tied to your account. Keys never raise the per-IP limits above.
- Create up to 3 keys on your account page. Each key is shown once; we store only a hash. Revoke or regenerate a key any time.
- Send it only in the header
X-API-Key: gc_โฆ. Keys in the URL (e.g.?api_key=) are rejected with400. - Permissions (scopes) you pick per key:
account:readโGET /api/auth/meprefs:readโGET /api/me/prefsยทprefs:writeโPUT /api/me/prefstmpmail:readโGET /api/tmpmail/config,/locked/{address},/{address},/{address}/{id}tmpmail:writeโPOST /api/tmpmail/new,POST /api/tmpmail/lock,DELETE /api/tmpmail/{address}[/{id}]
- Everything else refuses keys (
403 api_key_not_allowed): password, sessions, key management, data export, account deletion, AI keys, admin, social publishing and the AI endpoint. - Fair use per key: 60 requests/minute and 3,000/day; per account (all keys together): 120/minute and 6,000/day. Responses carry
X-RateLimit-Limit,X-RateLimit-RemainingandX-RateLimit-Reset(unix time); over the limit you get429withRetry-After.
Key errors use one JSON shape: {"detail": "message", "error": {"code": "โฆ", "message": "โฆ"}}.
401 api_key_invalidโ unknown, malformed or revoked key.403 insufficient_scopeโ the key lacks the permission (error.required_scopenames it).403 api_key_not_allowedโ the endpoint can't be called with a key.403 account_lockedยท400 api_key_in_queryยท429 rate_limited.
Notes
- Receive-only โ a disposable inbox cannot send email.
- Addresses are namespaced by domain; the same localpart on two different pool domains are two separate inboxes.
- CORS is open, so you can call the API directly from the browser.