Skip to content

API keys

An organization key lets your own code call the Super Flows API as your organization. It calls the same API the dashboard uses, so a key can do what the API reference lists. Every key starts with sf_.

A key belongs to the organization, not to the admin who created it. It has no expiry date and works until someone revokes it.

Owners and admins manage keys on the API keys page. A member who opens that page lands on the dashboard instead. Members can still read what a key did: runs it started show API as the starter in Run history.

  1. Open the API keys page.
  2. Type a name that says where the key will live, such as “Production backend”.
  3. Press Create key.
  4. Copy the key from the notice above the list and store it in your secret manager.

The list shows each key’s name, its first characters and the date it was created.

Send the key in the Authorization header as a bearer token. This request lists your organization’s projects:

Terminal window
curl https://superflows.app/api/v1/projects \
-H "Authorization: Bearer sf_..."

Send JSON bodies with Content-Type: application/json.

A key acts as the organization, with no member behind it.

  • It calls every route in the reference. Projects, workflows, publishing and pausing, runs, approvals, app events, agents, skills, databases, billing and the dashboard summary.
  • It starts runs. A run started with a key is recorded with the trigger api and no member as its starter. See Starting runs.
  • It decides approvals. Like any member, a key may approve or deny an action an agent step is waiting on. See Talking to agents.
  • It owns only organization skills. A skill created with a key belongs to the organization. A key cannot create a skill owned by one member.
  • Chat with an agent or use the assistant. Both are for signed-in members in the app.
  • Act as an admin. Connecting or disconnecting apps, setting the organization’s AI key, managing members and keys, and changing the subscription need a signed-in owner or admin. A route that does not accept keys answers 403 with the code forbidden.

Each key may make 1,000 requests an hour. Every request with the key counts, including requests that fail and requests that poll a run. The limit is per key.

A request over the limit answers 401 with the code unauthorized and a message about the rate limit. Wait and retry. If your code polls runs, poll every few seconds rather than in a tight loop.

Status Code Meaning
401 unauthorized The key is missing, mistyped or revoked, or it is over its limit
403 forbidden The route is for signed-in members or admins, not for keys

Every error has the same JSON shape, described in the API reference.

  1. Open the API keys page.
  2. Press Revoke on the key’s row.

Revoking takes effect at once and cannot be undone. Every caller still using the key gets 401 from its next request. Create a new key first if a running system needs to switch over without a gap.