drophost
drophost API keys
- Shown once, stored as a hash
- Works with /api/mcp and /api/v1
- Up to five keys per account
Create in Settings
Sign in, open Settings, name the key, and copy it. Settings also shows a paste-ready snippet for your MCP client with the secret filled in.
Use it as Bearer
Every /api/mcp and /api/v1 request needs Authorization: Bearer dh_…. Invalid keys get 401. Revoking a key stops agents that were using it.
Create and revoke hashed API keys
Generate API keys in drophost Settings. Keys are hashed at rest, shown once on creation, and revoked from the same screen. Use them for MCP at /api/mcp and the HTTP API. Never commit raw keys to git; rotate by revoking and creating a fresh key when a laptop or agent is compromised.
What a key can publish
With a valid drophost key, agents call publish_file, publish_site, list_projects, delete_file, and delete_project. Free is capped at one project and 2 MB; Starter at €5/mo and Pro at €12/mo raise project and storage limits. MCP oneshot max remains 4 MB regardless of plan.
Common questions
Where do I create a drophost API key?
Sign in to drophost and open Settings. Name the key and copy it. The secret is shown once.
How many API keys can I have?
Five API keys per drophost account. Revoke one in Settings to create another.
Does drophost store the plaintext key?
No. drophost stores keys as an HMAC hash. If you lose the secret, revoke it and create a new one.
Related
Ready to publish?
Drop a file on the homepage and get a live drophost URL in seconds.