API Keys

An API key is a long secret that identifies one workspace. You use it as a bearer token for the REST API, and you can also use it to connect an AI tool such as Claude Code to the hosted connector (see Connect Your AI).

A key gives full REST access to its workspace, so treat it like a password. Keys look like this:

flo_sk_live_<32 hex characters>

Create and revoke keys in the dashboard

Only workspace admins can see or manage keys. Go to Settings > API keys.

  1. Create a key and give it a name (up to 100 characters). Use one key per integration so you can revoke them separately.
  2. Copy the key when it appears. It is shown once and cannot be retrieved later. Flomailr stores only a hash.
  3. To cut a key off, revoke it. A revoked key stops working immediately and stays in the list marked as revoked.

The list shows each key's name, its first 12 characters (flo_sk_live_), when it was last used, and whether it is revoked.

Manage keys over the API

These routes use a key to manage the keys of the same workspace. Any valid key can call them.

List keys

GET /api/v1/keys

Query: limit, after (see pagination).

Each item has id, name, prefix, lastUsedAt, revokedAt and createdAt. The key itself is never returned.

Create a key

POST /api/v1/keys
{ "name": "CRM sync" }

name is required and at most 100 characters. The response is 201 and includes the key once:

{
  "data": {
    "id": "clx...",
    "name": "CRM sync",
    "prefix": "flo_sk_live_",
    "createdAt": "2026-10-04T12:00:00.000Z",
    "key": "flo_sk_live_..."
  }
}

Get a key

GET /api/v1/keys/:id

Returns the same fields as the list. 404 if the id is not in your workspace.

Revoke a key

DELETE /api/v1/keys/:id

Returns 200 with { "data": { "id": "...", "revokedAt": "..." } }. Revoking an already revoked key is not an error. A key can revoke itself, which ends its own access.

Keys and the connector

When you connect an AI tool with an API key instead of signing in, the connector acts as that workspace and can use every tool except the workspace-switching ones. Actions the AI takes with a key are written to the activity log under Settings > Activity. See Sending Safely with AI.