API Keys
Floe uses API keys to authenticate requests to the developer platform. There are two key types, each scoped to a different set of endpoints.
Key Types
floe_live_*
Developer key
Whole developer account
Dashboard API Keys page, floe devkeys create, or POST /v1/developer/keys
Credit API developer endpoints, agent management, webhook management, lifecycle MCP tools (agent/key/webhook management)
floe_*
Agent key
One specific agent
Agent setup wizard, floe init / floe keys create (platform CLI), POST /v1/developer/agents/:id/keys, or floe-agent register --name <name>
x402 proxy, agent balance, agent-awareness endpoints, agent-scoped runtime MCP tools
Developer keys are for your backend services — monitoring loan health, managing webhooks, registering new agents, and calling developer-scoped endpoints on the Credit API. One key per environment is typical.
Agent keys identify one specific agent. Every agent registered under a developer gets its own floe_* keys — up to five active keys per agent (floe keys create mints extras, optionally budget-capped at mint; floe keys rotate replaces one atomically). Agent keys are required for the agent-awareness endpoints (credit-remaining, loan-state, spend-limit, etc.) and for MCP server sessions scoped to a single agent.
Agent Keys
One developer can own multiple agents (up to 5 per account today). Each agent has its own scoped key. There are five ways to mint one:
Platform CLI —
npx @floelabs/cli initcreates (or selects) the agent and mints its key straight into your OS keychain — one keychain slot per agent, andfloe use <agent>switches agents without re-minting. Mint additional keys withfloe keys create(--budget <usd> [--window <dur>]caps the key's spend at mint), revoke withfloe keys revoke <keyId>, rotate withfloe keys rotate. See Floe CLI.Dashboard wizard — visit dev-dashboard.floelabs.xyz, create an agent, copy the
floe_*key shown on the final step. It is revealed once.TypeScript SDK CLI (
floe-agent) —npx floe-agent register --name my-agent --borrow-limit 10000. The key is stored in your OS keychain and surfaced once in stdout.Python SDK CLI (
floe-agent) —floe-agent register --name my-agent --borrow-limit 10000. Same behavior as the TypeScript SDK CLI.REST API —
POST /v1/developer/agentsto create, thenPOST /v1/developer/agents/:id/keysto mint. See Credit API → Developer Agents.
The SDK CLIs'
--borrow-limitflag is in USDC (10000= $10K). The REST API'sborrowLimitRawfield is in raw 6-decimal units (10000= $0.01,10000000000= $10K).Each agent caps at five active keys. Mint an additional one with
POST /v1/developer/agents/:id/keysorfloe keys create(add--budget <usd>for a fail-closed spend cap at mint); replace one atomically withPOST /v1/developer/agents/:id/keys/:keyId/rotate— the old key is revoked in the same transaction — orfloe keys rotate; free a slot withfloe keys revoke <keyId>.
Authentication
Include your key in the Authorization header as a Bearer token:
Which Credential Goes Where
Floe has two authentication systems. Sending the wrong one is the most common onboarding snag — a credential can be perfectly valid yet rejected because it's the wrong type for that endpoint.
Agent key floe_*
Authorization: Bearer floe_...
x402 proxy (/v1/proxy/*), agent balance, agent-awareness endpoints, agent-scoped runtime MCP tools
Developer key floe_live_*
Authorization: Bearer floe_live_...
Credit API developer endpoints, agent management, webhooks
Wallet signature
X-Wallet-Address + X-Signature + X-Timestamp headers (EIP-191 personal_sign over Floe Credit API\nTimestamp: <unix>)
Credit API endpoints that act on your own wallet
The x402 proxy accepts only an agent key. A developer key, dashboard session, or wallet signature is accepted by the /v1/* auth layer but rejected by the proxy itself with:
See the Agent Runtime Contract → Error Handling Matrix for the canonical /v1/proxy/* error bodies. If you see wrong_credential_type, mint an agent key (dashboard agent wizard, or POST /v1/developer/agents/:agentId/keys) and use it as the Bearer token for /v1/proxy/*.
Creating Keys
Via the Dashboard
Click Create Key
Enter a label (e.g., "production-backend" or "staging-monitor")
Select permissions: Read or Read/Write
Optionally set an expiry date
Click Create — your full key is displayed once
Copy the key immediately. It is shown only at creation and cannot be retrieved later.
Via the API
Request body:
label
string
No
Human-readable name for this key
permissions
string
No
read (default) or read_write
expiresAt
string
No
ISO 8601 expiry date. Omit for no expiry.
Response:
The key field contains the full key. This is the only time you see it.
API Endpoints
All endpoints require an existing developer key in the Authorization header.
POST /v1/developer/keys
Create a new developer key. CLI equivalent: floe devkeys create [--label <label>] [--read-only] (the key is shown once, never stored by the CLI).
Returns the full key in the response. Store it securely.
GET /v1/developer/keys
List all keys for your account. Returns prefixes only — full keys are never returned after creation. CLI equivalent: floe devkeys list --json.
Response:
DELETE /v1/developer/keys/:keyId
Revoke a key immediately. Any requests using this key will fail with 401 after revocation. CLI equivalents: floe devkeys revoke <keyId> [--yes], or floe devkeys rotate <keyId> for an atomic revoke + mint.
Response:
Security
Keys are hashed with HMAC-SHA256 before storage. The full key is never stored on Floe's servers.
The full key is displayed exactly once — at creation. If you lose it, revoke and create a new one.
All key operations are scoped to the authenticated wallet. You cannot access another wallet's keys.
Rate Limits
Developer key (floe_live_*)
100 requests/minute
Agent key (floe_*)
30 requests/minute (x402 proxy)
Rate limit headers are included in every response:
X-RateLimit-Limit
Max requests per window
X-RateLimit-Remaining
Requests remaining in current window
X-RateLimit-Reset
Unix timestamp when the window resets
If you exceed the limit, you receive a 429 Too Many Requests response. Wait until X-RateLimit-Reset before retrying.
Best Practices
Label keys by environment. Use names like
production,staging,local-devso you can identify and rotate them easily.Never commit keys to git. Use environment variables or a secrets manager. Add
.envto your.gitignore.Use read-only keys when possible. If a service only needs to read loan status or list webhooks, give it a
readkey.Rotate immediately if compromised. Revoke the old key via
DELETE /v1/developer/keys/:keyIdand create a new one — or do both atomically withfloe devkeys rotate <keyId>(agent keys:floe keys rotate). There is no downtime — the new key works instantly.Set expiry for temporary access. If you're granting a key to a contractor or CI pipeline, use
expiresAtso it auto-expires.
Next Steps
Developer Dashboard — Manage keys through the web UI.
Webhooks — Use your developer key to register webhook endpoints.
Credit API — Full API reference for lending and borrowing.
Last updated
