Fincheck

Authentication

Send, check, and protect your FincheckEngine API key.

Every request needs your API key in the Authorization header as a Bearer token:

HTTP
Authorization: Bearer fce_…

Keys start with fce_. Send the full key after Bearer , without quotes.

Check a key

Call any endpoint. GET /api/v2/intent is the simplest, because it only reads the intents your key can use:

cURL
curl "https://your-api-origin/api/v2/intent" \
  -H "Authorization: Bearer fce_your_key" \
  -H "Accept: application/json"

A rejected key returns HTTP 401 (an expired key returns "api key expired" instead):

JSON
{
  "error": "unauthorized"
}

If you get a 401, check that:

  1. you copied the entire key;
  2. the header starts with Bearer ;
  3. the key belongs to the environment you are calling; and
  4. the key has not expired or been replaced.

Tokens in the body or URL are ignored

API v2 only reads the Authorization header. An api_token in the query string or JSON body does not authenticate the request:

Text
?api_token=fce_…

Keeping credentials out of URLs also keeps them out of browser history, proxy logs, and analytics tools.

Protect your key

  • Store it in a secret manager or a protected server-side environment variable.
  • Never put it in browser JavaScript, a mobile app, a public repository, screenshots, or shared request collections.
  • Always call the API over HTTPS.
  • Do not log the Authorization header or full request objects that contain it.
  • If a key may have been exposed, email support@finch-technologies.com so it can be replaced.

Testing from these docs

The Not authenticated control in the docs header checks a key and uses it for Test Request in the API Reference. The key is held in memory only, shown masked (fce_••••••1234), and cleared when you refresh the page or select Clear credentials. It is never written to browser storage, cookies, or the URL.