B
Biflus Docs
biflus.com Get API key
API ReferenceAuthentication

Authentication

Every request is authenticated with an API key, sent as a bearer token:

Authorization: Bearer sk_test_YOUR_API_KEY

Getting a key

Go to Settings → API keys in your Biflus account, then Generate key. Give it a label so you can tell your integrations apart later, then copy the key — it's shown in full only once.

Test and live

Keys are prefixed sk_test_ or sk_live_. Test keys work immediately and are safe to build against — nothing you do with one touches real data. The prefix alone determines the environment, so a key only ever works against the data it was minted for.

Revocation

A key can be revoked at any time; revoked keys are rejected immediately on the next request, with no grace period. There's no way to temporarily "pause" a key today — revoking is permanent, so if you need a break-glass way to cut off one integration without affecting others, mint a separate key per integration rather than sharing one.

Best practices
  • Mint a separate key per integration (Zapier, your own backend, a script) so you can revoke one without breaking the others.
  • Store the key in an environment variable or secrets manager, never in client-side code — anything shipped to a browser is public.
  • Treat a 401 as "stop and re-check the key," not something to retry — retrying with the same bad key will never succeed.
Common mistakes
  • Don't mix up prefixes. A sk_live_ key against a script you built while testing will silently write to real customer data — there's no dry-run flag, so the prefix is the only thing standing between test and production.
  • Don't paste a key into a Zapier step or webhook URL as a query param. Query strings end up in logs; use the Authorization header everywhere, including in third-party tools.
  • Don't assume a revoked key fails gracefully in your code. It returns a normal 401 JSON body, not a network error — make sure your error handling actually inspects the status code.
This page is updated as the API changes. If something here doesn't match what you're seeing, that's a bug worth flagging to the Biflus team.