{"id":447,"date":"2026-09-23T15:47:30","date_gmt":"2026-09-23T10:17:30","guid":{"rendered":"https:\/\/emailalias.io\/blog\/?p=447"},"modified":"2026-09-23T16:09:53","modified_gmt":"2026-09-23T10:39:53","slug":"email-alias-api","status":"publish","type":"post","link":"https:\/\/emailalias.io\/blog\/email-alias-api\/","title":{"rendered":"Email Alias API: Create and Manage Aliases in Code"},"content":{"rendered":"<div class=\"post-tldr\">\n  <p class=\"post-tldr__title\">The short version<\/p>\n  <ul>\n    <li><strong>The EmailAlias API lets you create and manage aliases in code<\/strong> \u2014 a normal REST API you call with a personal key, from a script, a backend, or your own app.<\/li>\n    <li><strong>Authenticate with an <code>ea_live_<\/code> key<\/strong> generated in Settings, sent as a Bearer token. There&#8217;s an OpenAPI spec for generating SDKs and an MCP server for AI assistants.<\/li>\n    <li><strong>It&#8217;s a Premium feature<\/strong> for automating signups, wiring aliasing into your product, or letting an AI agent create aliases on your behalf.<\/li>\n  <\/ul>\n<\/div>\n\n<p>If you&#8217;d rather generate addresses in code than click a button, the email alias API turns everything the dashboard does into calls your programs can make. It&#8217;s a straightforward REST API: authenticate with a key, then create, list, update, and delete aliases \u2014 plus manage domains, destinations, and filters \u2014 exactly as you would by hand, but automated. This guide covers what the email alias API can do, how to authenticate, a working example, and the extras that make it developer-friendly: an OpenAPI spec and a ready-made MCP server for AI tools.<\/p>\n\n<nav class=\"post-toc\" aria-label=\"Table of contents\">\n  <h2 class=\"post-toc__title\">Table of contents<\/h2>\n  <ol class=\"post-toc__list\">\n    <li><a href=\"#what\">What the email alias API is<\/a><\/li>\n    <li><a href=\"#do\">What you can do with it<\/a><\/li>\n    <li><a href=\"#how\">How the email alias API works<\/a><\/li>\n    <li><a href=\"#start\">Getting started, step by step<\/a><\/li>\n    <li><a href=\"#example\">A working example<\/a><\/li>\n    <li><a href=\"#mcp\">AI assistants and the MCP server<\/a><\/li>\n    <li><a href=\"#spec\">OpenAPI spec and SDKs<\/a><\/li>\n    <li><a href=\"#limits\">Plan and limits<\/a><\/li>\n    <li><a href=\"#uses\">What people build with it<\/a><\/li>\n    <li><a href=\"#safety\">Keeping your API keys safe<\/a><\/li>\n    <li><a href=\"#final-thoughts\">Final thoughts<\/a><\/li>\n    <li><a href=\"#faq\">Frequently asked questions<\/a><\/li>\n  <\/ol>\n<\/nav>\n\n<h2 id=\"what\">What the Email Alias API Is<\/h2>\n<p>The email alias API is a <a href=\"https:\/\/en.wikipedia.org\/wiki\/REST\" rel=\"noopener\" target=\"_blank\">REST<\/a> <a href=\"https:\/\/en.wikipedia.org\/wiki\/API\" rel=\"noopener\" target=\"_blank\">API<\/a> \u2014 the same kind of interface you&#8217;d use to integrate any modern web service \u2014 that exposes your EmailAlias account to code. Anything you can do in the dashboard, from generating a fresh alias to changing where it forwards, you can also do with an HTTP request. It speaks <a href=\"https:\/\/en.wikipedia.org\/wiki\/JSON\" rel=\"noopener\" target=\"_blank\">JSON<\/a>, uses ordinary HTTP methods, and lives at a single base address: <code>https:\/\/emailalias.io\/api<\/code>.<\/p>\n<p>That means aliasing can become part of your own software rather than a manual chore. A signup script can mint a new alias for each account it registers; a backend can create a fresh forwarding address per customer; an internal tool can list and tidy your aliases on a schedule. The API is the bridge between EmailAlias&#8217;s privacy features and whatever you&#8217;re building \u2014 and it&#8217;s the same engine the dashboard itself runs on, so nothing is second-class about it. For the full developer picture, our <a href=\"https:\/\/emailalias.io\/email-alias-for-developers\" rel=\"noopener\" target=\"_blank\">developer overview<\/a> pulls the pieces together.<\/p>\n<aside class=\"post-keytakeaway\"><strong>Key takeaway:<\/strong> The email alias API is a REST API at <code>https:\/\/emailalias.io\/api<\/code> that exposes everything the dashboard does to your code \u2014 create, list, update, and delete aliases and their settings with ordinary JSON over HTTP. It&#8217;s the same engine the dashboard uses.<\/aside>\n\n<h2 id=\"do\">What You Can Do With It<\/h2>\n<p>With a key, your code can reach the same endpoints the dashboard uses. The core ones:<\/p>\n<ul>\n  <li><strong>Create an alias.<\/strong> Generate a random alias, or specify a custom one, in a single request \u2014 the workhorse call for automating signups.<\/li>\n  <li><strong>List your aliases.<\/strong> Pull the full set to audit, sync, or display them in your own tool.<\/li>\n  <li><strong>Update an alias.<\/strong> Change where it forwards, toggle it on or off, or adjust its settings.<\/li>\n  <li><strong>Delete an alias.<\/strong> Remove one you no longer need.<\/li>\n  <li><strong>Manage the rest of your account.<\/strong> The domains, destinations, analytics, and sender-filter endpoints are all reachable too, so a script can do more than just mint addresses.<\/li>\n<\/ul>\n<p>In other words, the API isn&#8217;t a cut-down subset \u2014 it&#8217;s programmatic access to your account. Whether you want to create thousands of aliases over time or just automate the one repetitive task you do by hand today, the building blocks are the same calls the dashboard makes on your behalf every day. It extends the everyday flow of <a href=\"https:\/\/emailalias.io\/blog\/how-to-create-an-email-alias\/\" rel=\"noopener\" target=\"_blank\">creating and managing aliases<\/a> into anything you can script.<\/p>\n<aside class=\"post-keytakeaway\"><strong>Key takeaway:<\/strong> The API covers the whole account: create, list, update, and delete aliases, plus manage domains, destinations, analytics, and sender filters. It&#8217;s full programmatic access, not a limited subset \u2014 the same calls the dashboard makes.<\/aside>\n\n<figure class=\"wp-block-image size-large\">\n  <img data-recalc-dims=\"1\" src=\"https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/09\/email-alias-api-example.jpg?resize=1080%2C608&#038;ssl=1\"\n       alt=\"email alias api: a brass stamping machine printing a run of fresh blank envelopes automatically\"\n       width=\"1080\" height=\"608\" loading=\"lazy\" decoding=\"async\" \/>\n  <figcaption>The API is like a stamping machine for addresses \u2014 call it and a fresh alias rolls off, as many as your workflow needs.<\/figcaption>\n<\/figure>\n\n<h2 id=\"how\">How the Email Alias API Works<\/h2>\n<p>Authentication is a personal API key. In Settings you generate a key that starts with <code>ea_live_<\/code>, and you send it on every request as a standard HTTP Bearer token in the <code>Authorization<\/code> header. The server checks the key, identifies your account, and runs the request as you \u2014 the same permissions you have in the dashboard.<\/p>\n<p>A few details worth knowing:<\/p>\n<ul>\n  <li><strong>The key is shown once.<\/strong> When you create a key, the full value is displayed a single time. Copy it then and store it safely (in a secrets manager or environment variable); afterwards only a short prefix is shown, and the full key is stored hashed, so it can&#8217;t be recovered \u2014 you&#8217;d generate a new one instead.<\/li>\n  <li><strong>It&#8217;s a Bearer token.<\/strong> Every call carries <code>Authorization: Bearer ea_live_...<\/code> \u2014 the same pattern used across modern APIs, so any HTTP client works.<\/li>\n  <li><strong>Responses are JSON.<\/strong> Create an alias and you get the new address back in the response body, ready to use immediately.<\/li>\n<\/ul>\n<p>Because it&#8217;s a plain REST API with Bearer auth, you don&#8217;t need any special library \u2014 <a href=\"https:\/\/en.wikipedia.org\/wiki\/CURL\" rel=\"noopener\" target=\"_blank\">cURL<\/a>, your language&#8217;s HTTP client, or a generated SDK all work the same way.<\/p>\n<aside class=\"post-keytakeaway\"><strong>Key takeaway:<\/strong> Authenticate with a personal <code>ea_live_<\/code> key sent as a Bearer token in the Authorization header. The key is shown once (store it safely; it&#8217;s kept hashed), responses are JSON, and any HTTP client works \u2014 no special library required.<\/aside>\n\n<h2 id=\"start\">Getting Started, Step by Step<\/h2>\n<p>From zero to your first API-created alias:<\/p>\n<ol>\n  <li><strong>Be on Premium.<\/strong> API access is a Premium feature, so make sure your account is on the paid plan.<\/li>\n  <li><strong>Open Settings \u2192 API Keys.<\/strong> In your dashboard, go to the API Keys section.<\/li>\n  <li><strong>Create a key.<\/strong> Give it a name (so you can tell keys apart later) and generate it. Copy the <code>ea_live_<\/code> value shown \u2014 this is your one chance to see it in full.<\/li>\n  <li><strong>Store it safely.<\/strong> Put it in an environment variable or secrets manager, never in code you commit.<\/li>\n  <li><strong>Make a request.<\/strong> Call the API with your key in the Authorization header (example below). Your first alias comes back in the response.<\/li>\n<\/ol>\n<p>That&#8217;s the whole setup. You can create several keys (handy for separating projects or rotating credentials), and revoke any key from the same screen the moment you no longer need it \u2014 a revoked key stops working immediately.<\/p>\n<aside class=\"post-keytakeaway\"><strong>Key takeaway:<\/strong> On Premium, go to Settings \u2192 API Keys, create a named key, and copy the <code>ea_live_<\/code> value (shown once) into a secrets store. Then call the API with it in the Authorization header. You can create several keys and revoke any of them instantly.<\/aside>\n\n<h2 id=\"example\">A Working Example<\/h2>\n<p>Here&#8217;s the single most useful call \u2014 creating a new random alias \u2014 with cURL. Swap in your own key:<\/p>\n\n\n<pre class=\"wp-block-code\"><code>curl -X POST https:\/\/emailalias.io\/api\/aliases \\\n  -H \"Authorization: Bearer ea_live_your_key_here\" \\\n  -H \"Content-Type: application\/json\" \\\n  -d '{\"alias_type\":\"random\",\"label\":\"newsletter\"}'<\/code><\/pre>\n\n\n<p>The response comes back as JSON containing the new alias address, which you can immediately drop into a signup form or store against a customer record. To create a specific address instead of a random one, send <code>\"alias_type\":\"custom\"<\/code> with your chosen local part. Listing your aliases is a <code>GET<\/code> to the same <code>\/api\/aliases<\/code> endpoint, and removing one is a <code>DELETE<\/code> to <code>\/api\/aliases\/&lt;id&gt;<\/code>. From those few calls you can build anything from a one-off cleanup script to a full integration \u2014 the same pattern EmailAlias&#8217;s own <a href=\"https:\/\/emailalias.io\/blog\/email-forwarding-api\/\" rel=\"noopener\" target=\"_blank\">email forwarding API<\/a> workflows follow.<\/p>\n<aside class=\"post-keytakeaway\"><strong>Key takeaway:<\/strong> Creating an alias is a single <code>POST<\/code> to <code>\/api\/aliases<\/code> with your key and a small JSON body; the new address comes back in the response. List with <code>GET<\/code>, remove with <code>DELETE<\/code> \u2014 a handful of calls covers most integrations.<\/aside>\n\n<h2 id=\"mcp\">AI Assistants and the MCP server<\/h2>\n<p>There&#8217;s a modern twist: EmailAlias ships an official MCP server, so AI assistants can manage your aliases through the same API. MCP (the Model Context Protocol) is the standard that lets AI tools call external services safely, and the <code>@emailalias\/mcp<\/code> package plugs EmailAlias straight into assistants like Claude Desktop, Cursor, Zed, and Cline.<\/p>\n<p>Setup is a one-liner \u2014 you run the MCP server with your <code>ea_live_<\/code> key in an environment variable, and your assistant can then create an alias, list your addresses, or clean one up in response to a plain-language request. It&#8217;s the same account, the same key, and the same underlying calls; the MCP server just makes them available to an AI agent. For anyone who lives in an AI coding tool, it turns &#8220;make me a fresh alias for this signup&#8221; into something the assistant can just do.<\/p>\n<aside class=\"post-keytakeaway\"><strong>Key takeaway:<\/strong> The official <code>@emailalias\/mcp<\/code> server lets AI assistants (Claude Desktop, Cursor, Zed, Cline) manage your aliases through the same API and key, via the Model Context Protocol \u2014 so an agent can create or tidy aliases from a plain-language request.<\/aside>\n\n<h2 id=\"spec\">OpenAPI Spec and SDKs<\/h2>\n<p>Because the API follows standards, you don&#8217;t have to hand-write a client. EmailAlias publishes an OpenAPI 3.1 specification, which describes the public API endpoints in a machine-readable form. That means:<\/p>\n<ul>\n  <li><strong>Auto-generated SDKs.<\/strong> Feed the spec to an OpenAPI generator and get a typed client in your language of choice \u2014 no manual wrapper needed.<\/li>\n  <li><strong>Live, accurate docs.<\/strong> The spec is generated from the API itself, so it always matches what the server actually accepts.<\/li>\n  <li><strong>Easy exploration.<\/strong> Point any OpenAPI-aware tool at the spec to browse and test endpoints interactively.<\/li>\n<\/ul>\n<p>Between the spec, the developer documentation, and the MCP server, the API is built to be integrated quickly rather than reverse-engineered. Our write-up on the <a href=\"https:\/\/emailalias.io\/blog\/openapi-email-alias\/\" rel=\"noopener\" target=\"_blank\">OpenAPI-driven email alias workflow<\/a> goes deeper on generating clients from the spec.<\/p>\n<aside class=\"post-keytakeaway\"><strong>Key takeaway:<\/strong> An OpenAPI 3.1 spec describes the public API endpoints, so you can auto-generate a typed SDK in your language, get docs that always match the server, and explore the API in any OpenAPI tool \u2014 no hand-written client required.<\/aside>\n\n<h2 id=\"limits\">Plan and Limits<\/h2>\n<ul>\n  <li><strong>API access is Premium.<\/strong> Generating and using API keys is part of <a href=\"https:\/\/emailalias.io\/pricing\/\" rel=\"noopener\" target=\"_blank\">Premium<\/a> ($4\/month); free accounts don&#8217;t have API access.<\/li>\n  <li><strong>You can hold several keys.<\/strong> Premium accounts can keep multiple active keys \u2014 useful for separating projects or rotating credentials \u2014 and revoke any of them instantly.<\/li>\n  <li><strong>Normal account limits still apply.<\/strong> Calls through the API count against the same limits as the dashboard \u2014 for example the per-day alias-creation cap \u2014 so bulk creation is paced rather than unlimited. This protects deliverability for everyone on the shared domain.<\/li>\n  <li><strong>Keys can be rotated.<\/strong> If a key is ever exposed, revoke it and generate a new one; because keys are stored hashed, only you ever hold the full value.<\/li>\n<\/ul>\n<aside class=\"post-keytakeaway\"><strong>Key takeaway:<\/strong> The API is a Premium feature; you can hold several keys and revoke them instantly. API calls obey the same account limits as the dashboard (including the daily alias-creation cap), so bulk creation is paced to protect deliverability.<\/aside>\n\n<h2 id=\"uses\">What People Build With It<\/h2>\n<p>The API earns its keep wherever aliasing needs to be automatic:<\/p>\n<ul>\n  <li><strong>Per-account aliases in your product.<\/strong> A SaaS backend that gives every customer their own forwarding address, created automatically at signup.<\/li>\n  <li><strong>Automated signups.<\/strong> A script that registers accounts across services, minting a fresh alias for each so every signup is traceable and disposable.<\/li>\n  <li><strong>Bulk hygiene.<\/strong> A scheduled job that audits your aliases, flags dormant ones, and tidies up \u2014 using the list and delete calls.<\/li>\n  <li><strong>AI-driven aliasing.<\/strong> Through the MCP server, an assistant that creates and manages aliases as part of a larger workflow, on request.<\/li>\n<\/ul>\n<p>If you&#8217;re weighing the API against other developer-friendly options, our roundup of the <a href=\"https:\/\/emailalias.io\/blog\/best-email-alias-for-developers\/\" rel=\"noopener\" target=\"_blank\">best email alias tools for developers<\/a> puts it in context. The through-line is the same: anything you&#8217;d do by hand in the dashboard, the API lets you do at scale, on a schedule, or inside your own software.<\/p>\n<aside class=\"post-keytakeaway\"><strong>Key takeaway:<\/strong> People use the API for per-customer aliases in their own products, automated multi-service signups, scheduled alias hygiene, and AI-driven aliasing via MCP \u2014 anywhere generating or managing addresses should happen automatically rather than by hand.<\/aside>\n\n<h2 id=\"safety\">Keeping Your API Keys Safe<\/h2>\n<p>An API key is a credential that can act on your account, so it deserves the same care as a password. A few habits keep it safe without getting in your way:<\/p>\n<ul>\n  <li><strong>Never hard-code a key.<\/strong> Keep it out of your source code and out of anything you commit to version control. Store it in an <a href=\"https:\/\/en.wikipedia.org\/wiki\/Environment_variable\" rel=\"noopener\" target=\"_blank\">environment variable<\/a> or a dedicated secrets manager, and read it from there at runtime.<\/li>\n  <li><strong>Use separate keys for separate jobs.<\/strong> Because you can hold several keys, give each project or environment its own. If one leaks, you revoke just that key without disrupting everything else.<\/li>\n  <li><strong>Rotate periodically.<\/strong> Generating a new key and retiring the old one every so often limits the damage a forgotten or exposed key could do.<\/li>\n  <li><strong>Revoke the moment you suspect exposure.<\/strong> A revoked key stops working immediately, so if a key ever ends up somewhere it shouldn&#8217;t, cut it off first and investigate second.<\/li>\n<\/ul>\n<p>None of this is unique to EmailAlias \u2014 it&#8217;s ordinary API hygiene \u2014 but it&#8217;s worth stating, because the convenience of automation is only worth having if the key behind it is handled responsibly. The design helps here: keys are stored hashed and shown only once, so even EmailAlias never holds your key in a form that could be leaked back to you or anyone else. That leaves the one copy in your hands, and these habits keep that copy safe. Treat the key like the account credential it effectively is, and the API stays a convenience rather than a liability.<\/p>\n<aside class=\"post-keytakeaway\"><strong>Key takeaway:<\/strong> Treat an API key like a password: never hard-code it, store it in an environment variable or secrets manager, use separate keys per project, rotate periodically, and revoke instantly if exposed. Keys are stored hashed and shown once, so the only copy lives with you.<\/aside>\n\n<h2 id=\"final-thoughts\">Final Thoughts<\/h2>\n<p>The email alias API takes EmailAlias from a tool you click to a service you can build on. It&#8217;s a plain REST API with Bearer-key auth, a published OpenAPI spec, and an MCP server for AI assistants \u2014 so whether you&#8217;re scripting a one-off task, embedding per-customer aliases in a product, or letting an agent handle it, the path is short: get a Premium key, send it in the Authorization header, and call <code>\/api\/aliases<\/code>. Everything the dashboard does becomes something your code can do too, which is exactly what you want from privacy infrastructure \u2014 the ability to make it automatic.<\/p>\n\n<h2 id=\"faq\">Frequently Asked Questions<\/h2>\n<div id=\"rank-math-faq\" class=\"rank-math-block\">\n<div class=\"rank-math-list \">\n<div id=\"faq-q-1\" class=\"rank-math-list-item\">\n<h3 class=\"rank-math-question \">What is the EmailAlias API?<\/h3>\n<div class=\"rank-math-answer \">\n\n<p>It&#8217;s a REST API at https:\/\/emailalias.io\/api that exposes your EmailAlias account to code. Anything you can do in the dashboard \u2014 create a random or custom alias, list your aliases, change where one forwards, delete one, and manage domains, destinations, analytics, and sender filters \u2014 you can also do with an HTTP request that returns JSON. It&#8217;s the same engine the dashboard runs on, so it&#8217;s full programmatic access to your account, not a limited subset.<\/p>\n\n<\/div>\n<\/div>\n<div id=\"faq-q-2\" class=\"rank-math-list-item\">\n<h3 class=\"rank-math-question \">How do I authenticate with the API?<\/h3>\n<div class=\"rank-math-answer \">\n\n<p>With a personal API key. In Settings \u2192 API Keys you generate a key that starts with ea_live_, and you send it on every request as a standard HTTP Bearer token in the Authorization header: Authorization: Bearer ea_live_&#8230;. The server checks the key, identifies your account, and runs the request with your permissions. The full key is shown only once when you create it, so copy it into a secrets store; afterwards it&#8217;s kept hashed and only a short prefix is shown.<\/p>\n\n<\/div>\n<\/div>\n<div id=\"faq-q-3\" class=\"rank-math-list-item\">\n<h3 class=\"rank-math-question \">How do I create an alias with the API?<\/h3>\n<div class=\"rank-math-answer \">\n\n<p>Send a POST request to \/api\/aliases with your key in the Authorization header and a small JSON body. For a random alias, use {&#8220;alias_type&#8221;:&#8221;random&#8221;,&#8221;label&#8221;:&#8221;&#8230;&#8221;}; for a specific address, use {&#8220;alias_type&#8221;:&#8221;custom&#8221;} with your chosen local part. The new alias address comes back in the JSON response, ready to drop into a signup form or store against a customer record. Listing is a GET to the same endpoint, and removing an alias is a DELETE to \/api\/aliases\/.<\/p>\n\n<\/div>\n<\/div>\n<div id=\"faq-q-4\" class=\"rank-math-list-item\">\n<h3 class=\"rank-math-question \">Is the API free?<\/h3>\n<div class=\"rank-math-answer \">\n\n<p>No \u2014 API access is a Premium feature ($4\/month). Free accounts can&#8217;t generate or use API keys. Premium accounts can hold several active keys at once (useful for separating projects or rotating credentials) and revoke any of them instantly. API calls also count against the same account limits as the dashboard, such as the daily alias-creation cap, so bulk creation is paced rather than unlimited \u2014 which keeps the shared alias domain trusted for everyone.<\/p>\n\n<\/div>\n<\/div>\n<div id=\"faq-q-5\" class=\"rank-math-list-item\">\n<h3 class=\"rank-math-question \">Is there an OpenAPI spec or SDK?<\/h3>\n<div class=\"rank-math-answer \">\n\n<p>Yes. EmailAlias publishes an OpenAPI 3.1 specification that describes the public API endpoints in machine-readable form, so you can feed it to an OpenAPI generator and get a typed SDK in your language of choice without hand-writing a client. Because the spec is generated from the API itself, the documentation always matches what the server actually accepts, and you can point any OpenAPI-aware tool at it to browse and test endpoints interactively.<\/p>\n\n<\/div>\n<\/div>\n<div id=\"faq-q-6\" class=\"rank-math-list-item\">\n<h3 class=\"rank-math-question \">Can AI assistants use the API?<\/h3>\n<div class=\"rank-math-answer \">\n\n<p>Yes. EmailAlias ships an official MCP server, the @emailalias\/mcp package, which lets AI assistants manage your aliases through the same API. MCP (the Model Context Protocol) is the standard that lets AI tools call external services, and it plugs EmailAlias into assistants like Claude Desktop, Cursor, Zed, and Cline. You run the MCP server with your ea_live_ key, and the assistant can then create, list, or tidy aliases in response to a plain-language request.<\/p>\n\n<\/div>\n<\/div>\n<div id=\"faq-q-7\" class=\"rank-math-list-item\">\n<h3 class=\"rank-math-question \">What can I build with the email alias API?<\/h3>\n<div class=\"rank-math-answer \">\n\n<p>Common uses include giving every customer in your SaaS their own forwarding address created automatically at signup; scripts that register accounts across services and mint a fresh alias for each; scheduled jobs that audit and tidy dormant aliases using the list and delete calls; and AI-driven workflows where an assistant manages aliases via the MCP server. The rule of thumb: anything you&#8217;d do by hand in the dashboard, the API lets you do at scale, on a schedule, or inside your own software.<\/p>\n\n<\/div>\n<\/div>\n<div id=\"faq-q-8\" class=\"rank-math-list-item\">\n<h3 class=\"rank-math-question \">What happens if my API key is exposed?<\/h3>\n<div class=\"rank-math-answer \">\n\n<p>Revoke it and generate a new one. From Settings \u2192 API Keys you can revoke any key instantly, and a revoked key stops working immediately, so an exposed key can be shut off the moment you notice. Because keys are stored hashed (only a short prefix is kept visible), only you ever hold the full value, and rotating keys is quick. As a habit, keep keys in a secrets manager or environment variable rather than in code you commit, and rotate them periodically.<\/p>\n\n<\/div>\n<\/div>\n<\/div>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>The short version The EmailAlias API lets you create and manage aliases in code \u2014 a normal REST API you call with a personal key, from a script, a backend,&#8230;<\/p>\n","protected":false},"author":3,"featured_media":445,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"rank_math_focus_keyword":"email alias api","rank_math_title":"Email Alias API: Create Aliases Programmatically","rank_math_description":"The email alias API lets you create and manage aliases in code \u2014 a REST API with ea_live_ keys, an OpenAPI spec, and an MCP server for AI assistants.","_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":true,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2}},"categories":[13],"tags":[],"class_list":{"0":"post-447","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-features"},"jetpack_publicize_connections":[],"jetpack_featured_media_url":"https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/09\/email-alias-api.jpg?fit=1200%2C630&ssl=1","jetpack_sharing_enabled":true,"jetpack-related-posts":[{"id":145,"url":"https:\/\/emailalias.io\/blog\/email-forwarding-api\/","url_meta":{"origin":447,"position":0},"title":"Email Forwarding API: Endpoints, Auth, and Use Cases","author":"Troy Hunt","date":"June 9, 2026","format":false,"excerpt":"An email forwarding API is the HTTP interface that lets you create, list, toggle, and revoke email aliases programmatically \u2014 without ever opening the alias provider's dashboard. The shape is familiar to anyone who's used Stripe or Twilio: REST over HTTPS, scoped API keys, JSON in and out, predictable rate\u2026","rel":"","context":"In &quot;Developers&quot;","block_context":{"text":"Developers","link":"https:\/\/emailalias.io\/blog\/category\/developers\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/06\/og-email-forwarding-api.jpg?fit=1200%2C630&ssl=1&resize=350%2C200","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/06\/og-email-forwarding-api.jpg?fit=1200%2C630&ssl=1&resize=350%2C200 1x, https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/06\/og-email-forwarding-api.jpg?fit=1200%2C630&ssl=1&resize=525%2C300 1.5x, https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/06\/og-email-forwarding-api.jpg?fit=1200%2C630&ssl=1&resize=700%2C400 2x, https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/06\/og-email-forwarding-api.jpg?fit=1200%2C630&ssl=1&resize=1050%2C600 3x"},"classes":[]},{"id":422,"url":"https:\/\/emailalias.io\/blog\/how-to-create-an-email-alias\/","url_meta":{"origin":447,"position":1},"title":"How to Create an Email Alias (and Manage Them All)","author":"Troy Hunt","date":"September 22, 2026","format":false,"excerpt":"The short version Creating an email alias takes about a minute: open the New Alias box, pick a type (random, custom, or tagged), and click Create. The alias forwards to your normal inbox right away. Use a different alias for each service. Give one to each shop, app, or newsletter\u2026","rel":"","context":"In &quot;Features&quot;","block_context":{"text":"Features","link":"https:\/\/emailalias.io\/blog\/category\/features\/"},"img":{"alt_text":"how to create an email alias, shown as labelled brass keys on a key board","src":"https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/09\/how-to-create-email-alias-1.jpg?fit=1200%2C630&ssl=1&resize=350%2C200","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/09\/how-to-create-email-alias-1.jpg?fit=1200%2C630&ssl=1&resize=350%2C200 1x, https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/09\/how-to-create-email-alias-1.jpg?fit=1200%2C630&ssl=1&resize=525%2C300 1.5x, https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/09\/how-to-create-email-alias-1.jpg?fit=1200%2C630&ssl=1&resize=700%2C400 2x, https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/09\/how-to-create-email-alias-1.jpg?fit=1200%2C630&ssl=1&resize=1050%2C600 3x"},"classes":[]},{"id":158,"url":"https:\/\/emailalias.io\/blog\/best-email-alias-for-business\/","url_meta":{"origin":447,"position":2},"title":"Best Email Alias for Business: 7 Picks for 2026","author":"Troy Hunt","date":"June 12, 2026","format":false,"excerpt":"Choosing the best email alias for business is no longer just a privacy question \u2014 it is an operational one. Every signup an employee makes on a SaaS trial, every vendor that emails them once and never stops, every recruiter that scrapes a leaked database, and every conference badge that\u2026","rel":"","context":"In &quot;Comparisons&quot;","block_context":{"text":"Comparisons","link":"https:\/\/emailalias.io\/blog\/category\/comparisons\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/06\/og-best-email-alias-for-business.jpg?fit=1200%2C630&ssl=1&resize=350%2C200","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/06\/og-best-email-alias-for-business.jpg?fit=1200%2C630&ssl=1&resize=350%2C200 1x, https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/06\/og-best-email-alias-for-business.jpg?fit=1200%2C630&ssl=1&resize=525%2C300 1.5x, https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/06\/og-best-email-alias-for-business.jpg?fit=1200%2C630&ssl=1&resize=700%2C400 2x, https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/06\/og-best-email-alias-for-business.jpg?fit=1200%2C630&ssl=1&resize=1050%2C600 3x"},"classes":[]},{"id":125,"url":"https:\/\/emailalias.io\/blog\/best-email-alias-for-developers\/","url_meta":{"origin":447,"position":3},"title":"Best Email Alias for Developers: API, CLI, Domains","author":"Troy Hunt","date":"June 4, 2026","format":false,"excerpt":"The best email alias for developers isn't the one with the prettiest landing page \u2014 it's the one with a documented API, a working CLI, and custom-domain support that survives the next provider shutdown. Developers create more accounts than anyone: every SaaS trial, every OSS release, every staging environment, every\u2026","rel":"","context":"In &quot;Developers&quot;","block_context":{"text":"Developers","link":"https:\/\/emailalias.io\/blog\/category\/developers\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/06\/og-best-email-alias-for-developers.jpg?fit=1200%2C630&ssl=1&resize=350%2C200","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/06\/og-best-email-alias-for-developers.jpg?fit=1200%2C630&ssl=1&resize=350%2C200 1x, https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/06\/og-best-email-alias-for-developers.jpg?fit=1200%2C630&ssl=1&resize=525%2C300 1.5x, https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/06\/og-best-email-alias-for-developers.jpg?fit=1200%2C630&ssl=1&resize=700%2C400 2x, https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/06\/og-best-email-alias-for-developers.jpg?fit=1200%2C630&ssl=1&resize=1050%2C600 3x"},"classes":[]},{"id":172,"url":"https:\/\/emailalias.io\/blog\/firefox-relay-alternative\/","url_meta":{"origin":447,"position":4},"title":"The Best Firefox Relay Alternative for 2026","author":"Troy Hunt","date":"June 15, 2026","format":false,"excerpt":"A Firefox Relay alternative is what most users start shopping for the moment they outgrow Mozilla's five-mask free tier, hit the @mozmail.com domain limit, or want richer per-sender intelligence on what each alias is doing. Firefox Relay is a clean, Mozilla-backed mask service \u2014 but its feature set is intentionally\u2026","rel":"","context":"In &quot;Comparisons&quot;","block_context":{"text":"Comparisons","link":"https:\/\/emailalias.io\/blog\/category\/comparisons\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/06\/og-firefox-relay-alternative.jpg?fit=1200%2C630&ssl=1&resize=350%2C200","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/06\/og-firefox-relay-alternative.jpg?fit=1200%2C630&ssl=1&resize=350%2C200 1x, https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/06\/og-firefox-relay-alternative.jpg?fit=1200%2C630&ssl=1&resize=525%2C300 1.5x, https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/06\/og-firefox-relay-alternative.jpg?fit=1200%2C630&ssl=1&resize=700%2C400 2x, https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/06\/og-firefox-relay-alternative.jpg?fit=1200%2C630&ssl=1&resize=1050%2C600 3x"},"classes":[]},{"id":108,"url":"https:\/\/emailalias.io\/blog\/proton-pass-alternative\/","url_meta":{"origin":447,"position":5},"title":"The Best Proton Pass Alternative for 2026","author":"Troy Hunt","date":"June 1, 2026","format":false,"excerpt":"A Proton Pass alternative means different things depending on which half of Proton Pass you actually use. Proton Pass bundles two products: a password manager and a built-in email alias generator (powered by SimpleLogin, which Proton acquired in 2022). The right Proton Pass alternative for someone hitting password-manager limits is\u2026","rel":"","context":"In &quot;Comparisons&quot;","block_context":{"text":"Comparisons","link":"https:\/\/emailalias.io\/blog\/category\/comparisons\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/06\/og-proton-pass-alternative.jpg?fit=1200%2C630&ssl=1&resize=350%2C200","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/06\/og-proton-pass-alternative.jpg?fit=1200%2C630&ssl=1&resize=350%2C200 1x, https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/06\/og-proton-pass-alternative.jpg?fit=1200%2C630&ssl=1&resize=525%2C300 1.5x, https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/06\/og-proton-pass-alternative.jpg?fit=1200%2C630&ssl=1&resize=700%2C400 2x, https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/06\/og-proton-pass-alternative.jpg?fit=1200%2C630&ssl=1&resize=1050%2C600 3x"},"classes":[]}],"_links":{"self":[{"href":"https:\/\/emailalias.io\/blog\/wp-json\/wp\/v2\/posts\/447","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/emailalias.io\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/emailalias.io\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/emailalias.io\/blog\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/emailalias.io\/blog\/wp-json\/wp\/v2\/comments?post=447"}],"version-history":[{"count":2,"href":"https:\/\/emailalias.io\/blog\/wp-json\/wp\/v2\/posts\/447\/revisions"}],"predecessor-version":[{"id":472,"href":"https:\/\/emailalias.io\/blog\/wp-json\/wp\/v2\/posts\/447\/revisions\/472"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/emailalias.io\/blog\/wp-json\/wp\/v2\/media\/445"}],"wp:attachment":[{"href":"https:\/\/emailalias.io\/blog\/wp-json\/wp\/v2\/media?parent=447"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/emailalias.io\/blog\/wp-json\/wp\/v2\/categories?post=447"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/emailalias.io\/blog\/wp-json\/wp\/v2\/tags?post=447"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}