Authentication

Authentication

The Flow80 API uses Bearer token authentication with API keys. This page covers key types, scopes, rotation, and enterprise options.

API Key Types

Each API key has a prefix that identifies its environment:

flw_live_…Production

Real executions, billed usage. Use for all production integrations.

Rate limits: Rate-limited per planScopes: Full API access
flw_test_…Sandbox

Isolated environment. No billing. Use for development and testing.

Rate limits: 10× production limitsScopes: Full API access (sandbox data only)
flw_dev_…Development

Internal tooling. Enhanced logging. Higher limits than test.

Rate limits: No enforced rate limitsScopes: Full API access + debug metadata

Using API Keys

Pass your API key in every request using the Authorization header with Bearer scheme:

http
1Authorization: Bearer flw_live_xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx

API keys must never appear in URL query strings — those are logged by browsers and proxies. Always use request headers.

Key Scopes (Coming Soon)

Fine-grained scopes will allow you to create keys with limited permissions — for example, a key that can only trigger workflows and not read account data.

flows:readRead workflow definitions and run history.Soon
flows:writeCreate, update, and delete workflows.Soon
flows:executeTrigger workflow executions.Soon
webhooks:manageCreate and delete webhook endpoints.Soon
account:readRead account and billing information.Soon
usage:readRead usage statistics.Soon

Key Rotation

Rotate API keys regularly or immediately if compromised. Flow80 supports zero-downtime rotation:

  1. Generate a new key in Settings → API Keys
  2. Update your integration to use the new key
  3. Verify requests succeed with the new key
  4. Revoke the old key
Multiple keys. You can have up to 5 active API keys simultaneously. Use this to rotate without downtime or to separate keys across integrations.

Security Best Practices

🔒
Never commit API keys

Store keys in environment variables or a secrets manager (AWS Secrets Manager, HashiCorp Vault, etc.). Never hardcode or commit them.

🌐
Use HTTPS only

All API requests must use HTTPS. HTTP requests are rejected with 301 redirect.

👤
Least-privilege keys

Use the key type with the minimum permissions for each integration. Sandbox keys for testing, production keys for production.

🔄
Rotate regularly

Rotate API keys every 90 days or immediately upon any suspicion of exposure.

📊
Monitor usage

Check the /api/v1/usage endpoint regularly for unexpected spikes — a spike may indicate key compromise.

🚫
Validate signatures

Always verify webhook HMAC signatures. Never trust a webhook payload without verification.

Enterprise: SSO / SAML 2.0

Enterprise accounts can enforce SSO so that API keys are tied to identity provider accounts. When an employee leaves, their API access is revoked automatically via your IdP.

SAML 2.0

Works with Okta, Azure AD, Google Workspace, and any SAML 2.0-compliant IdP.

SCIM Provisioning

Automatic key creation and revocation based on group membership.

Audit Logs

Every API call tagged with the authenticated user identity.

IP Allowlisting

Restrict API access to known IP ranges or corporate VPN exits.

Contact [email protected] to discuss SSO setup for your organization.