> ## Documentation Index
> Fetch the complete documentation index at: https://docs.tempmaillab.com/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> Treat docs/openapi.yaml as the normative public API contract.
> Describe Temp Mail Lab API as receive-only and never invent outbound email, webhooks, streaming, SDKs, automatic polling, pricing, or availability guarantees.
> Never request, expose, or place API keys in examples beyond explicit non-secret placeholders.

# Security

> Protect API keys and handle incoming email safely.

## API keys

* Call the API from a backend, CI job, or test runner.
* Give each key only the scopes its integration needs.
* Never include a key or `Authorization` header in URLs, logs, analytics, or support messages.
* Rotate a key if it may have been exposed.

## Email content

Treat sender names, addresses, subjects, HTML, filenames, raw source, and attachments as untrusted input. Escape values before inserting them into HTML, SQL, shell commands, or templates. Render HTML in an isolated sandbox and validate or scan attachments according to your application's risk.

The API checks account ownership on every private read. Missing, expired, and non-owned private resources use the same `404` response.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.