Authentication
Send, check, and protect your FincheckEngine API key.
Every request needs your API key in the Authorization header as a Bearer token:
Authorization: Bearer fce_…
Keys start with fce_. Send the full key after Bearer , without quotes.
Check a key
Call any endpoint. GET /api/v2/intent is the simplest, because it only reads the intents your key can use:
curl "https://your-api-origin/api/v2/intent" \
-H "Authorization: Bearer fce_your_key" \
-H "Accept: application/json"
A rejected key returns HTTP 401 (an expired key returns "api key expired" instead):
{
"error": "unauthorized"
}
If you get a 401, check that:
- you copied the entire key;
- the header starts with
Bearer; - the key belongs to the environment you are calling; and
- the key has not expired or been replaced.
Tokens in the body or URL are ignored
API v2 only reads the Authorization header. An api_token in the query string or JSON body does not authenticate the request:
?api_token=fce_…
Keeping credentials out of URLs also keeps them out of browser history, proxy logs, and analytics tools.
Protect your key
- Store it in a secret manager or a protected server-side environment variable.
- Never put it in browser JavaScript, a mobile app, a public repository, screenshots, or shared request collections.
- Always call the API over HTTPS.
- Do not log the
Authorizationheader or full request objects that contain it. - If a key may have been exposed, email support@finch-technologies.com so it can be replaced.
Testing from these docs
The Not authenticated control in the docs header checks a key and uses it for Test Request in the API Reference. The key is held in memory only, shown masked (fce_••••••1234), and cleared when you refresh the page or select Clear credentials. It is never written to browser storage, cookies, or the URL.