Skip to content

Quickstart in 5 minutes

This is the whole path, from zero to the first response.

  • The company needs a plan that includes the API, from Start on.
  • You need to be OWNER or ADMIN of it. Only those two roles create keys.
  • Have your panel password at hand: the creation form asks for it.

In the panel, open Settings, go to the API tab and click New key.

FieldWhat to fill in
NameTo recognise later which system uses this key, such as “Store ERP”
What this key can doTick only what the integration uses. See Permissions
ExpirationNever expires, 30 days, 90 days or 1 year
Allowed IPsOptional. One per line, address or range. Empty accepts any IP
PasswordYour panel password

Copy the key and store it in a secret manager or in an environment variable of your server. Never in code, never in a repository, never in the browser.

Terminal window
export FH_API_KEY="fh_live_your_key"

The examples below read the key from that variable. That way it is not written in the file you commit.

GET /public/v1/me answers whose key this is. It is the right call to confirm that everything is in place before you write the rest of the integration.

Terminal window
curl https://api.fatureihoje.com/public/v1/me \
-H "Authorization: Bearer $FH_API_KEY" \
-H "Accept-Language: en"
{
"object": "api_key_context",
"organization": {
"id": "0f3a5f1e-9f7a-4f2b-8f4c-2a1d9e6b7c30",
"name": "Marcenaria Souza",
"timezone": "America/Sao_Paulo",
"currency": "BRL"
},
"key": {
"id": "6d2c8b41-77a3-4a5e-9c10-3b8f0d5e41aa",
"name": "Store ERP",
"prefix": "fh_live_7Qx4Kd",
"permissions": ["clients:read", "leads:create"],
"expires_at": null
},
"acting_as": {
"member_id": "b1d4e2f0-5c69-4a31-9d77-8e2c4f6a0b53",
"name": "Ana Souza",
"role": "owner"
},
"limits": {
"requests_per_minute": 60
}
}
FieldWhat it is
organizationThe company that owns the key, with the time zone and the currency it uses
key.prefixThe start of the key, the same the panel shows in the list. It tells you which key is in use
key.permissionsWhat this key can do, in the module:action format
key.expires_atExpiration date in ISO 8601, or null when the key does not expire
acting_asThe company member the key acts as, and their role
limits.requests_per_minuteCalls per minute for the company, adding up all keys. null means no ceiling

The Reference lists these fields one by one, with type and format.

{
"error": {
"type": "authentication_error",
"code": "api_key_invalid",
"message": "Invalid, revoked or expired API key.",
"request_id": "0a8c1f2e-3b4d-4c5f-9a6b-7c8d9e0f1a2b",
"doc_url": "https://docs.fatureihoje.com/en/errors#api_key_invalid"
}
}

This is the answer to any authentication refusal, always the same. It does not say the reason, on purpose. Check in this order:

  1. The header is Authorization: Bearer <key>, with a single space between Bearer and the key.
  2. The key was copied whole, with no space or line break at the end.
  3. The key is neither revoked nor expired. The panel shows the state of each key.
  4. If the key has an IP allowlist, your server’s outbound IP is on it.
  5. The address is api.fatureihoje.com. The panel host does not answer /public/v1.

Next, open View usage in the key menu, in the panel. It shows the calls of the last 30 days with date, method, route, status, duration, IP and request_id, refused ones included. That is where you see the IP your server really uses.

Keep the request_id from the response. It is how support finds the call.

  • Authentication: key format, IP allowlist, rotation and revocation.
  • Permissions: why a key with the permission can still get a 403.