Skip to content

drophost

drophost API keys

drophost API keys authenticate MCP and HTTP uploads.Create a hashed key in Settings, send Authorization: Bearer, and rotate keys when access should end.
  • Shown once, stored as a hash
  • Works with /api/mcp and /api/v1
  • Up to five keys per account

Create in Settings

Sign in, open Settings, name the key, and copy it. Settings also shows a paste-ready snippet for your MCP client with the secret filled in.

Use it as Bearer

Every /api/mcp and /api/v1 request needs Authorization: Bearer dh_…. Invalid keys get 401. Revoking a key stops agents that were using it.

Create and revoke hashed API keys

Generate API keys in drophost Settings. Keys are hashed at rest, shown once on creation, and revoked from the same screen. Use them for MCP at /api/mcp and the HTTP API. Never commit raw keys to git; rotate by revoking and creating a fresh key when a laptop or agent is compromised.

What a key can publish

With a valid drophost key, agents call publish_file, publish_site, list_projects, delete_file, and delete_project. Free is capped at one project and 2 MB; Starter at €5/mo and Pro at €12/mo raise project and storage limits. MCP oneshot max remains 4 MB regardless of plan.

Common questions

Where do I create a drophost API key?

Sign in to drophost and open Settings. Name the key and copy it. The secret is shown once.

How many API keys can I have?

Five API keys per drophost account. Revoke one in Settings to create another.

Does drophost store the plaintext key?

No. drophost stores keys as an HMAC hash. If you lose the secret, revoke it and create a new one.

Related

Ready to publish?

Drop a file on the homepage and get a live drophost URL in seconds.