Authentication
How to create and use Featurely API keys.
Authentication
API Keys
Every request to a protected endpoint must include an API key. Create keys in your dashboard under Settings → API Keys.
Key formats
| Format | Use for |
|---|---|
ft_live_... | Production — real data |
ft_test_... | Testing — isolated from production |
Sending the key
You can pass your key in either header:
Authorization: Bearer ft_live_your_api_keyX-API-Key: ft_live_your_api_keyBoth headers are supported on all protected endpoints.
Permissions
Each API key is created with one or more permission scopes. You must grant the exact permissions needed for the endpoints you call.
| Permission | Endpoints |
|---|---|
public:read | /site-config, /translations, /version-check, /i18n-telemetry |
features:read | GET /features, GET /changelog, GET /roadmap |
features:write | POST /features |
bugs:write | POST /bugs |
errors:write | POST /errors |
logs:write | POST /logs |
Public endpoints
Two endpoints do not require an API key — they only need a projectId query parameter:
GET /api/public/v1/site-config?projectId=...GET /api/public/v1/version-check?projectId=...
Error responses
| Status | Meaning |
|---|---|
401 Unauthorized | Missing or invalid API key |
403 Forbidden | Key lacks the required permission |
429 Too Many Requests | Rate limit exceeded (plan quota) |
Dashboard account email verification
Email and password sign-up sends a Firebase verification email. Google and other identity providers that already verify the address are treated as verified.
Until the address is verified, Profile shows Not verified and a Resend verification email action. After you click the link, Firebase redirects back to Profile and the account shows as verified.
At the team-member limit, accepting an invite that would consume an extra seat only succeeds when the signed-in account has a verified email that already counts on that owner (membership or another pending invite). A typed, unverified address is not trusted for that free-seat path.