Skip to main content
Every request carries one key: Authorization: Bearer ff_live_…. The key is the account — everything it reads and changes is that account’s, and nothing else’s.

Making a key

1

Open Developer Tools → API keys

Owners and Admins can make keys. Developer Tools is the last entry in the side menu.
2

Name it, and choose what it may do

Give each system its own key (“Billing server”, “Website”) with only the scopes it needs.
3

Choose where it may be used from (optional)

Addresses or ranges such as 203.0.113.0/24. A request from anywhere else is refused with address_not_allowed.
4

Copy it

The whole key is shown once. OMNI keeps only a fingerprint of it, so it can’t be shown again — make a new one if it’s lost.
The API keys screen, listing keys with what each may do and when it was last used

Developer Tools → API keys

Live and test keys

Build against a test key, then switch the key, not the code.

Scopes

A key may only do what its scopes allow. A request outside them is refused with scope_missing, naming the scope it needed. The full list is on Scopes and events; the common ones: GET /v1/me needs no scope: any key may ask who it is.

Retiring a key

Revoke it in Developer Tools → API keys. It stops working at once. A key can also be given an expiry when it is made; after it, requests are refused with invalid_key. Every request a key makes is in Developer Tools → Requests for 30 days — the time, the key, the call, the answer and its request id.