---
title: Authentication and API keys
description: Create a Workspace API key and use it to call the Finerlise API.
icon: key-round
search:
  keywords: [api key, token, bearer, authentication, fnr_live]
---

The API accepts two kinds of credentials, both sent as a Bearer token:

| Credential | Looks like | Best for | Scopes |
| --- | --- | --- | --- |
| **Workspace API key** | `fnr_live_…` | Your own server reading responses. | `responses:read` |
| **OAuth access token** | `fnr_oat_…` | Approved apps acting for a user, like Zapier. | `responses:read`, `forms:read`, `hooks:write` |

```bash
curl https://finerlise.com/api/v1/me \
  -H "Authorization: Bearer fnr_live_your_key_here"
```

## Create an API key

1. **Open API keys**

    Go to **Settings → API keys** (workspace Owners and Admins).

2. **Create the key**

    Click **Create key** and give it a name, for example *Gift shop production*.

3. **Copy it now**

    The key is shown **once**. Copy it into your server's secrets. Finerlise
    only stores a hash, so it can't show it again.

A workspace can have up to 25 active keys. Keys belong to the workspace, not to a person, so they keep working when team members leave.

## Revoke a key

Click **Revoke** next to a key. Revoked keys stop working immediately. Responses stay in Finerlise.

:::warning[Keep keys secret] API keys are for server-to-server use. Never put them in browser code, mobile apps or public repositories. Requests from browsers are not allowed (there's no CORS). :::

:::note API keys can read responses only (`responses:read`). Listing forms needs `forms:read`, which is available to OAuth apps. To find a form's ID, open it in Finerlise and copy **Form ID** from **Settings → General**. :::
