Network & Transports¶
Guidance for securing MCP transports and webhooks when running Faxbot in production.
MCP Transports¶
- Streamable HTTP (Node and Python MCP)
- Ports: 3001 (Node), 3004 (Python), or built into the API at
/mcp/http/mcpwithENABLE_MCP_HTTP=true. - Each client sends its own Faxbot API key as
Authorization: Bearer <key>orX-API-Key, and the server uses it for that client's requests. Give each client its own key with only the permissions it needs. Requests without a key are refused. - The server built into the API follows the same rule: it never uses the installation key (
API_KEY) for tool calls. Its host, origin and OAuth settings come from the API's environment, not from Settings. - For OAuth, set
OAUTH_ISSUER,OAUTH_AUDIENCE, optionallyOAUTH_JWKS_URL, and map token subjects to Faxbot keys inMCP_OAUTH_SUBJECT_KEYS_FILE. - Set
MCP_ALLOWED_HOSTSto your public host names. Browser origins are refused unless listed inMCP_ALLOWED_ORIGINS. -
Run behind TLS via a reverse proxy; add IP allowlists and rate limits where appropriate.
-
SSE (Python MCP only, for older clients)
- Port: 3003, or built into the API at
/mcp/sse/ssewithENABLE_MCP_SSE=true. - Same per-client keys and OAuth options as Streamable HTTP. Prefer Streamable HTTP for new clients.
Webhooks & Callbacks¶
- Phaxio (outbound status)
- Endpoint:
POST /phaxio-callback?job_id=<job_id>&attempt_id=<attempt_id>; Faxbot adds these locators to the submitted callback URL. - Signature:
X-Phaxio-Signature, a lowercase hexadecimal HMAC-SHA1 using the separate accountPHAXIO_CALLBACK_TOKEN. - Verification covers the exact captured public URL and query, followed by stably name-sorted form fields and file-part SHA1 digests. The API secret authenticates send/status API calls; it is not the callback token.
- A job captured with
PHAXIO_VERIFY_SIGNATURE=falserejects outbound callback updates. Status polling continues through its captured original account when a provider fax ID is available. - See outbound callback verification for ordering and correlation details.
-
Always use HTTPS public URLs; avoid exposing staging/test endpoints publicly.
-
Phaxio (inbound)
- Endpoint:
POST /phaxio-inbound -
Signature:
X-Phaxio-Signature, the same HMAC-SHA1 withPHAXIO_CALLBACK_TOKENas outbound callbacks. With checks off, Faxbot confirms each fax with Phaxio's API before recording it. See Receiving faxes. -
Sinch (inbound)
- Endpoint:
POST /sinch-inbound - Basic auth:
SINCH_INBOUND_BASIC_USER/PASS -
Sinch Fax API v3 does not sign webhooks. Without both Basic auth values, Faxbot confirms each fax with Sinch's API before recording it.
-
SIP/Asterisk (inbound)
- Endpoint:
POST /_internal/asterisk/inbound - Header:
X-Internal-Secret: <ASTERISK_INBOUND_SECRET> - Only accessible over private networks; do not expose publicly.
Reverse Proxy Recommendations¶
- Enforce TLS; redirect HTTP→HTTPS.
- Set security headers (HSTS, CSP, X-Content-Type-Options, Referrer-Policy, X-Frame-Options, Permissions-Policy).
- Limit request sizes; apply rate limits and IP restrictions as needed.
- Do not log PHI; log IDs and generic metadata only.