Workspace API keys currently use two scopes:
read and write. The current Deploy → API Keys screen lets you choose either or both scopes, and the create form starts with both selected.What an API key is in Fini
Every key:- belongs to a workspace, not to a single agent
- is created by a specific teammate
- can carry one or more scopes
- is shown in plaintext once, at creation time
- can be revoked individually
- is sent as
Authorization: Bearer <key>
fini_ prefix. In the dashboard list, Fini only shows a short prefix preview, never the full secret.
Scope model
Use least privilege:
- Keep
Writeoff for export-only or analytics-only workflows. - Include
Writewhen the integration needs to send conversation events, ingest or refresh documents, or manage knowledge content. - Some
readendpoints usePOST, so pick scopes by endpoint purpose, not by HTTP method alone.
Create an API key
Open Deploy → API Keys in Fini.1
Open the Create API key form
Click New API key at the top of the page.
2
Give the key a recognizable name
Use a name that tells you where the key is used, such as
Warehouse export, Internal dashboard, or Zapier sync. The name is the only thing you’ll see in the table later, so be specific.3
Choose the scopes
The form shows two checkboxes: Read and Write. Both are selected by default. Leave only the scopes this integration actually needs.
4
Click Create key
Fini generates the key and immediately shows the plaintext secret in a warning card, along with the scopes assigned to that key.
5
Copy and store it now
This is the only time the full key value is shown. Once you dismiss the warning card, you’ll only see the short prefix in the table.
Manage existing keys
The API Keys table shows one row per active key. Each row carries:string
Your human-readable label for the key, set at creation time. The only identifier you’ll see day to day.
array
The permissions assigned to the key. The UI shows them as
Read and Write chips.string
The visible beginning of the key, for example
fini_abc12…. Enough to match a key against a system that’s using it, never enough to reconstruct the secret.string
The teammate who generated the key. Useful for asking “do we still need this?” when a teammate leaves.
datetime
When the key was created.
datetime | null
The most recent time the API accepted this key. If
null or stale, the key is either unused or pointed at a system that’s broken.Revoke a key
Click the trash icon on a row to revoke that key. Revoke is:- immediate, clients using the key stop authenticating on their next request
- irreversible, the key cannot be reinstated; create a new one if you change your mind
- scoped to that one key only, other keys in the workspace continue working
401 Unauthorized right away.
How to use a key
Send the key in theAuthorization header as a Bearer token. The example below lists agents from the workspace tied to the key:
Security best practices
Keep keys on the server side
Keep keys on the server side
Never ship a Fini API key in browser code, mobile app bundles, or anywhere a customer can inspect. Keys belong in your backend secrets manager, or environment variables on a server you control.
One key per application or workflow
One key per application or workflow
Avoid the shared-key anti-pattern. Separate keys for your warehouse export, your internal dashboard, and your Zapier flow means you can revoke or rotate one without breaking the others, and you can tell from the Last used column which system is calling.
Revoke immediately on teammate offboarding or integration retirement
Revoke immediately on teammate offboarding or integration retirement
Anyone who had access to a key in plaintext can still use it after they leave. Treat key revocation as part of offboarding. Same on the system side: when an integration is retired, revoke its key the same day.
Rotate on suspected leakage
Rotate on suspected leakage
If a key may have been exposed, committed to git, leaked in a log, or shared in a screenshot, revoke it immediately and create a replacement. Rotation is cheap, investigation later is not.
Use descriptive names
Use descriptive names
The name is the only thing standing between you and a row of indistinguishable
fini_abc12… prefixes. Warehouse export, nightly cron, not key 3.Troubleshooting
I dismissed the warning card and now I need the key again
I dismissed the warning card and now I need the key again
The full value is shown exactly once, at creation time. Create a new key and revoke the old one. There is no way to retrieve the plaintext later.
The API returns 403 Forbidden
The API returns 403 Forbidden
The endpoint likely requires a scope the key doesn’t have. Check the assigned scope chips on the key row.
Write is required for conversation events, document ingestion, and knowledge-management mutations. Read is required for list, fetch, and status endpoints, even on a few routes that use POST.Last used never updates
Last used never updates
The Last used timestamp only moves when a request reaches Fini successfully and authenticates with that key. If your client is failing before the request lands, DNS, TLS, wrong base URL, network egress blocked, the column won’t move even though you think the key is in use.

