Authentication
The Flow80 API uses Bearer token authentication with API keys. This page covers key types, scopes, rotation, and enterprise options.
API Key Types
Each API key has a prefix that identifies its environment:
flw_live_…ProductionReal executions, billed usage. Use for all production integrations.
flw_test_…SandboxIsolated environment. No billing. Use for development and testing.
flw_dev_…DevelopmentInternal tooling. Enhanced logging. Higher limits than test.
Using API Keys
Pass your API key in every request using the Authorization header with Bearer scheme:
1Authorization: Bearer flw_live_xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxAPI keys must never appear in URL query strings — those are logged by browsers and proxies. Always use request headers.
Key Scopes (Coming Soon)
Fine-grained scopes will allow you to create keys with limited permissions — for example, a key that can only trigger workflows and not read account data.
flows:readRead workflow definitions and run history.Soonflows:writeCreate, update, and delete workflows.Soonflows:executeTrigger workflow executions.Soonwebhooks:manageCreate and delete webhook endpoints.Soonaccount:readRead account and billing information.Soonusage:readRead usage statistics.SoonKey Rotation
Rotate API keys regularly or immediately if compromised. Flow80 supports zero-downtime rotation:
- Generate a new key in Settings → API Keys
- Update your integration to use the new key
- Verify requests succeed with the new key
- Revoke the old key
Security Best Practices
Store keys in environment variables or a secrets manager (AWS Secrets Manager, HashiCorp Vault, etc.). Never hardcode or commit them.
All API requests must use HTTPS. HTTP requests are rejected with 301 redirect.
Use the key type with the minimum permissions for each integration. Sandbox keys for testing, production keys for production.
Rotate API keys every 90 days or immediately upon any suspicion of exposure.
Check the /api/v1/usage endpoint regularly for unexpected spikes — a spike may indicate key compromise.
Always verify webhook HMAC signatures. Never trust a webhook payload without verification.
Enterprise: SSO / SAML 2.0
Enterprise accounts can enforce SSO so that API keys are tied to identity provider accounts. When an employee leaves, their API access is revoked automatically via your IdP.
Works with Okta, Azure AD, Google Workspace, and any SAML 2.0-compliant IdP.
Automatic key creation and revocation based on group membership.
Every API call tagged with the authenticated user identity.
Restrict API access to known IP ranges or corporate VPN exits.
Contact [email protected] to discuss SSO setup for your organization.