Featurely Docs

Authentication

How to create and use Featurely API keys.

Authentication

API Keys

Every request to a protected endpoint must include an API key. Create keys in your dashboard under Settings → API Keys.

Key formats

FormatUse for
ft_live_...Production — real data
ft_test_...Testing — isolated from production

Sending the key

You can pass your key in either header:

Authorization: Bearer ft_live_your_api_key
X-API-Key: ft_live_your_api_key

Both headers are supported on all protected endpoints.

Permissions

Each API key is created with one or more permission scopes. You must grant the exact permissions needed for the endpoints you call.

PermissionEndpoints
public:read/site-config, /translations, /version-check, /i18n-telemetry
features:readGET /features, GET /changelog, GET /roadmap
features:writePOST /features
bugs:writePOST /bugs
errors:writePOST /errors
logs:writePOST /logs

Public endpoints

Two endpoints do not require an API key — they only need a projectId query parameter:

  • GET /api/public/v1/site-config?projectId=...
  • GET /api/public/v1/version-check?projectId=...

Error responses

StatusMeaning
401 UnauthorizedMissing or invalid API key
403 ForbiddenKey lacks the required permission
429 Too Many RequestsRate limit exceeded (plan quota)

Dashboard account email verification

Email and password sign-up sends a Firebase verification email. Google and other identity providers that already verify the address are treated as verified.

Until the address is verified, Profile shows Not verified and a Resend verification email action. After you click the link, Firebase redirects back to Profile and the account shows as verified.

At the team-member limit, accepting an invite that would consume an extra seat only succeeds when the signed-in account has a verified email that already counts on that owner (membership or another pending invite). A typed, unverified address is not trusted for that free-seat path.