API keys
A Muro API key unlocks the painting tools (visualize_room, get_visualization, relight_room, get_credits). The colour tools stay free with or without a key.
Painting spends the credits of the Muro account that owns the key, the same credits as the app. There are no free trials. If you have no account and want to pay per call instead, use x402.
Create a key
Section titled “Create a key”- Sign in at app.usemuro.com.
- Open Settings and create a key under API keys.
- Copy it right away. The key is shown once.
A key looks like muro_sk_ followed by 43 characters (letters, digits, - and _).
Treat it like a password: it spends your money. Do not commit it to a repository or paste it into a shared chat.
Send it as a header
Section titled “Send it as a header”Send the key on every request to https://mcp.usemuro.com/mcp:
Authorization: Bearer muro_sk_…Only tokens that start with muro_sk_ are accepted. Any other Authorization value is ignored and the call is treated as keyless.
Claude Code
Section titled “Claude Code”claude mcp add --transport http muro-colors https://mcp.usemuro.com/mcp --header "Authorization: Bearer muro_sk_…"Cursor
Section titled “Cursor”In ~/.cursor/mcp.json:
{ "mcpServers": { "muro-colors": { "url": "https://mcp.usemuro.com/mcp", "headers": { "Authorization": "Bearer muro_sk_…" } } }}VS Code (Copilot agent mode)
Section titled “VS Code (Copilot agent mode)”In .vscode/mcp.json:
{ "servers": { "muro-colors": { "type": "http", "url": "https://mcp.usemuro.com/mcp", "headers": { "Authorization": "Bearer muro_sk_…" } } }}claude.ai and ChatGPT
Section titled “claude.ai and ChatGPT”These connectors cannot send a header. Use Sign in with Muro at https://mcp.usemuro.com/account/mcp. It creates and manages a key for you.
muro login # paste the key onceor set MURO_API_KEY. See the CLI guide.
Check it works
Section titled “Check it works”Ask the assistant to run get_credits. It returns your balance and plan, for example “120 credits on the pro plan” (the numbers are yours). If the key is wrong, you get the message listed under Errors.
Revoke a key
Section titled “Revoke a key”Open app.usemuro.com → Settings → API keys and revoke it. The next call with that key is rejected. Revoking also disconnects any assistant that signed in with Muro under that key.
Limits for keyed calls
Section titled “Limits for keyed calls”Any request that carries an Authorization header is limited to 60 requests per 60 seconds per client IP, a stricter bucket than the keyless 600 per 60 seconds. Above it the server answers HTTP 429 with Retry-After: 60. The limit is enforced per Cloudflare data centre, so treat it as approximate. Details are on Pricing and limits.
A keyed call to a free colour tool counts against the 60 bucket too. If you only need colour data, leave the header off.