August 18th, 2026

You can now set an expiration date when creating an API token, giving your team more control over how long credentials stay valid.
How it works: Set a token to expire in 1, 7, 30, 90, 180, or 365 days, pick a custom date, or configure it never to expire at all. We'll then send you both email and in-app notifications before your token expires. And once it does, it will no longer be able to authenticate API requests, but it will remain in your token list for up to 90 days along with its expiration date so you can see what happened and reissue it if needed.
This is another step toward making Mailtrap safer by default. It gives your team control over credential lifecycles and encourages stronger security practices, without adding unnecessary complexity to how tokens are managed.
Note: Existing tokens are unaffected. Any API token created before this update continues to work exactly as it did before, with no expiration.Β
For more information, please consult our official Knowledge Base article.
