Authentication

Learn how to authenticate your API requests using public and secret keys.

The Fungies API uses API keys to authenticate requests. Every request must include valid authentication headers.

Getting Your API Keys

You can create and manage your API keys in the Fungies Dashboard.

You'll receive two types of keys:

Key TypePrefixPurpose
Public Keypub_Required for all API requests
Secret Keysec_Required for write operations (POST, PATCH, DELETE)
Test Public Keypub_test_Minted in a test-mode dashboard session. Reads and writes your workspace's test data only.
Test Secret Keysec_test_Minted in a test-mode dashboard session. Required for write operations against test data.

Test-mode keys use the same host and paths as live keys; the key decides which data you see. A test key works once the workspace has set up test mode — switch to Test mode in the dashboard once. Until then, requests with a test key return 401 with a message saying so.

Authentication Headers

Include your API keys in the request headers:

# Required for all requests
x-fngs-public-key: pub_your_public_key_here

# Required for write operations
x-fngs-secret-key: sec_your_secret_key_here

Example Request

Here's an example of a properly authenticated request:

curl -X GET "https://api.fungies.io/v0/products/list" \
  -H "x-fngs-public-key: pub_your_public_key" \
  -H "x-fngs-secret-key: sec_your_secret_key"

Security Best Practices

Your API keys grant access to your Fungies account. Keep them secure and never expose them publicly.

Follow these guidelines to protect your keys:

  • Never commit keys to version control - Use environment variables instead
  • Don't expose keys in client-side code - Secret keys should only be used server-side
  • Rotate keys regularly - Generate new keys periodically and revoke old ones
  • Use separate keys for different environments - Keep production and development keys separate

HTTPS Required

All API requests must be made over HTTPS. Requests made over plain HTTP will be rejected.

Error Responses

If authentication fails, you'll receive one of these responses:

Status CodeMeaning
401 UnauthorizedMissing, malformed, or invalid public key — or, on a write endpoint, a missing or invalid secret key. Also returned for a test-mode key (pub_test_/sec_test_) while the workspace hasn't set up test mode — switch to Test mode in the dashboard once — and while the workspace the key belongs to is offline — see Workspace lifecycle.

Every authentication failure returns 401. A read endpoint called with only a public key succeeds; a write endpoint called the same way returns 401, not 403.

Last updated