Skip to main content

API keys

Every request needs an API key. Keys are scoped to your organization and start with comm_. Create one in the dashboard. It’s shown once, so copy it immediately. Pass it as a Bearer token:

Base URL

If you are migrating from older setups, you can still override the base URL via COMMUNE_BASE_URL.

Permissions

API keys can be configured with granular permissions:

Key limits

You can set per-key limits (max inboxes, max emails/day) independently from your plan’s org-level limits.

Response format

Success

Error

Pagination

List endpoints use cursor-based pagination:
Pass next_cursor as the cursor query parameter to fetch the next page.

Response codes

x402 wallet auth

Don’t want an API key? Your agent can pay per call with USDC instead. Create an x402 client with your own signer and pass it to the SDK. Every API call is paid via the x402 protocol.
No signup, no subscription. Your wallet address becomes your org identity. See the full x402 guide for setup, pricing, and networks.

Security best practices

Never expose your API key in client-side code, public repositories, or browser JavaScript. Always use environment variables.
  • Store API keys in environment variables (COMMUNE_API_KEY)
  • Use the minimum permissions necessary for each key
  • Rotate keys periodically through the dashboard
  • Set inbox and email limits on keys used by automated systems
  • Use separate keys for development and production

What’s next?

Quickstart

Build a complete email agent in 5 minutes.

Inboxes

Create and manage email addresses for your agents.

Rate Limits

Understand per-second and daily sending limits.

Agent Auth

Autonomous Ed25519 authentication without human provisioning.
Last modified on March 19, 2026