Skip to content

MCP Transports

Per-client keys

Streamable HTTP and SSE requests must each carry the caller's own Faxbot API key, as Authorization: Bearer <key> or X-API-Key: <key>. The MCP server forwards that key to Faxbot as X-API-Key, so every fax is sent and read with the permissions of the key's owner. Requests without a key get 401 and never reach Faxbot. With OAuth configured (OAUTH_ISSUER, OAUTH_AUDIENCE), the Bearer token must be a JWT from that issuer, and its sub is looked up in the JSON file named by MCP_OAUTH_SUBJECT_KEYS_FILE ({"<subject>": "<faxbot api key>"}); unmapped subjects get 403. Stdio uses API_KEY as one integration identity.

Streamable HTTP (Node and Python)

Ports : 3001 (Node), 3004 (Python), or embedded at /mcp/http/mcp

Auth : The caller's Faxbot key, or OAuth with a subject-to-key map. MCP_RESOURCE_URL publishes OAuth protected-resource metadata

Deployment : Run behind TLS. Set MCP_ALLOWED_HOSTS to the public host names. Browser origins are refused unless listed in MCP_ALLOWED_ORIGINS

SSE (Python only, compatibility)

Port : 3003, or embedded at /mcp/sse/sse

Auth : Same as Streamable HTTP. The key must be sent on both GET /sse and POST /messages/

Stdio

Use case : Best for desktop assistants; avoids base64 limits

Files : Prefer filePath for fidelity

Limits

REST API : Raw file limit MAX_FILE_SIZE_MB (default 10 MB)

Streamable HTTP and SSE : Request body limit 16 MB (base64 payload)