Authentication
Every request is authenticated with an API key, sent as a bearer token:
Authorization: Bearer sk_test_YOUR_API_KEY
Getting a key
Go to Settings → API keys in your Biflus account, then Generate key. Give it a label so you can tell your integrations apart later, then copy the key — it's shown in full only once.
Test and live
Keys are prefixed sk_test_ or
sk_live_. Test keys work immediately and are
safe to build against — nothing you do with one touches real
data. The prefix alone determines the environment, so a key only ever
works against the data it was minted for.
Revocation
A key can be revoked at any time; revoked keys are rejected immediately on the next request, with no grace period. There's no way to temporarily "pause" a key today — revoking is permanent, so if you need a break-glass way to cut off one integration without affecting others, mint a separate key per integration rather than sharing one.
- Mint a separate key per integration (Zapier, your own backend, a script) so you can revoke one without breaking the others.
- Store the key in an environment variable or secrets manager, never in client-side code — anything shipped to a browser is public.
- Treat a
401as "stop and re-check the key," not something to retry — retrying with the same bad key will never succeed.
- Don't mix up prefixes. A
sk_live_key against a script you built while testing will silently write to real customer data — there's no dry-run flag, so the prefix is the only thing standing between test and production. - Don't paste a key into a Zapier step or webhook URL as a query param. Query strings end up in logs; use the Authorization header everywhere, including in third-party tools.
- Don't assume a revoked key fails gracefully in your code. It returns a normal
401JSON body, not a network error — make sure your error handling actually inspects the status code.