MCP Transports¶
Per-client keys¶
Streamable HTTP and SSE requests must each carry the caller's own Faxbot API key, as Authorization: Bearer <key> or X-API-Key: <key>. The MCP server forwards that key to Faxbot as X-API-Key, so every fax is sent and read with the permissions of the key's owner. Requests without a key get 401 and never reach Faxbot. With OAuth configured (OAUTH_ISSUER, OAUTH_AUDIENCE), the Bearer token must be a JWT from that issuer, and its sub is looked up in the JSON file named by MCP_OAUTH_SUBJECT_KEYS_FILE ({"<subject>": "<faxbot api key>"}); unmapped subjects get 403. Stdio uses API_KEY as one integration identity.
Streamable HTTP (Node and Python)¶
Ports
: 3001 (Node), 3004 (Python), or embedded at /mcp/http/mcp
Auth
: The caller's Faxbot key, or OAuth with a subject-to-key map. MCP_RESOURCE_URL publishes OAuth protected-resource metadata
Deployment
: Run behind TLS. Set MCP_ALLOWED_HOSTS to the public host names. Browser origins are refused unless listed in MCP_ALLOWED_ORIGINS
SSE (Python only, compatibility)¶
Port
: 3003, or embedded at /mcp/sse/sse
Auth
: Same as Streamable HTTP. The key must be sent on both GET /sse and POST /messages/
Stdio¶
Use case : Best for desktop assistants; avoids base64 limits
Files
: Prefer filePath for fidelity
Limits¶
REST API
: Raw file limit MAX_FILE_SIZE_MB (default 10 MB)
Streamable HTTP and SSE : Request body limit 16 MB (base64 payload)