Skip to content

API keys

A Muro API key unlocks the painting tools (visualize_room, get_visualization, relight_room, get_credits). The colour tools stay free with or without a key.

Painting spends the credits of the Muro account that owns the key, the same credits as the app. There are no free trials. If you have no account and want to pay per call instead, use x402.

  1. Sign in at app.usemuro.com.
  2. Open Settings and create a key under API keys.
  3. Copy it right away. The key is shown once.

A key looks like muro_sk_ followed by 43 characters (letters, digits, - and _).

Treat it like a password: it spends your money. Do not commit it to a repository or paste it into a shared chat.

Send the key on every request to https://mcp.usemuro.com/mcp:

Authorization: Bearer muro_sk_…

Only tokens that start with muro_sk_ are accepted. Any other Authorization value is ignored and the call is treated as keyless.

Terminal window
claude mcp add --transport http muro-colors https://mcp.usemuro.com/mcp --header "Authorization: Bearer muro_sk_…"

In ~/.cursor/mcp.json:

{
"mcpServers": {
"muro-colors": {
"url": "https://mcp.usemuro.com/mcp",
"headers": {
"Authorization": "Bearer muro_sk_…"
}
}
}
}

In .vscode/mcp.json:

{
"servers": {
"muro-colors": {
"type": "http",
"url": "https://mcp.usemuro.com/mcp",
"headers": {
"Authorization": "Bearer muro_sk_…"
}
}
}
}

These connectors cannot send a header. Use Sign in with Muro at https://mcp.usemuro.com/account/mcp. It creates and manages a key for you.

Terminal window
muro login # paste the key once

or set MURO_API_KEY. See the CLI guide.

Ask the assistant to run get_credits. It returns your balance and plan, for example “120 credits on the pro plan” (the numbers are yours). If the key is wrong, you get the message listed under Errors.

Open app.usemuro.com → Settings → API keys and revoke it. The next call with that key is rejected. Revoking also disconnects any assistant that signed in with Muro under that key.

Any request that carries an Authorization header is limited to 60 requests per 60 seconds per client IP, a stricter bucket than the keyless 600 per 60 seconds. Above it the server answers HTTP 429 with Retry-After: 60. The limit is enforced per Cloudflare data centre, so treat it as approximate. Details are on Pricing and limits.

A keyed call to a free colour tool counts against the 60 bucket too. If you only need colour data, leave the header off.