Authentication
Learn how to authenticate your API requests using public and secret keys.
The Fungies API uses API keys to authenticate requests. Every request must include valid authentication headers.
Getting Your API Keys
You can create and manage your API keys in the Fungies Dashboard.
You'll receive two types of keys:
| Key Type | Prefix | Purpose |
|---|---|---|
| Public Key | pub_ | Required for all API requests |
| Secret Key | sec_ | Required for write operations (POST, PATCH, DELETE) |
| Test Public Key | pub_test_ | Minted in a test-mode dashboard session. Reads and writes your workspace's test data only. |
| Test Secret Key | sec_test_ | Minted in a test-mode dashboard session. Required for write operations against test data. |
Test-mode keys use the same host and paths as live keys; the key decides which data you see. A test
key works once the workspace has set up test mode — switch to Test mode in the dashboard once. Until
then, requests with a test key return 401 with a message saying so.
Authentication Headers
Include your API keys in the request headers:
# Required for all requests
x-fngs-public-key: pub_your_public_key_here
# Required for write operations
x-fngs-secret-key: sec_your_secret_key_hereExample Request
Here's an example of a properly authenticated request:
curl -X GET "https://api.fungies.io/v0/products/list" \
-H "x-fngs-public-key: pub_your_public_key" \
-H "x-fngs-secret-key: sec_your_secret_key"Security Best Practices
Your API keys grant access to your Fungies account. Keep them secure and never expose them publicly.
Follow these guidelines to protect your keys:
- Never commit keys to version control - Use environment variables instead
- Don't expose keys in client-side code - Secret keys should only be used server-side
- Rotate keys regularly - Generate new keys periodically and revoke old ones
- Use separate keys for different environments - Keep production and development keys separate
HTTPS Required
All API requests must be made over HTTPS. Requests made over plain HTTP will be rejected.
Error Responses
If authentication fails, you'll receive one of these responses:
| Status Code | Meaning |
|---|---|
401 Unauthorized | Missing, malformed, or invalid public key — or, on a write endpoint, a missing or invalid secret key. Also returned for a test-mode key (pub_test_/sec_test_) while the workspace hasn't set up test mode — switch to Test mode in the dashboard once — and while the workspace the key belongs to is offline — see Workspace lifecycle. |
Every authentication failure returns 401. A read endpoint called with only a public key succeeds;
a write endpoint called the same way returns 401, not 403.
Last updated