API keys
An organization key lets your own code call the Super Flows API as your organization. It calls the
same API the dashboard uses, so a key can do what the API reference lists. Every
key starts with sf_.
A key belongs to the organization, not to the admin who created it. It has no expiry date and works until someone revokes it.
Who can manage keys
Section titled “Who can manage keys”Owners and admins manage keys on the API keys page. A member who opens that page lands on the dashboard instead. Members can still read what a key did: runs it started show API as the starter in Run history.
Create a key
Section titled “Create a key”- Open the API keys page.
- Type a name that says where the key will live, such as “Production backend”.
- Press Create key.
- Copy the key from the notice above the list and store it in your secret manager.
The list shows each key’s name, its first characters and the date it was created.
Send the key
Section titled “Send the key”Send the key in the Authorization header as a bearer token. This request lists your
organization’s projects:
curl https://superflows.app/api/v1/projects \ -H "Authorization: Bearer sf_..."Send JSON bodies with Content-Type: application/json.
What a key can do
Section titled “What a key can do”A key acts as the organization, with no member behind it.
- It calls every route in the reference. Projects, workflows, publishing and pausing, runs, approvals, app events, agents, skills, databases, billing and the dashboard summary.
- It starts runs. A run started with a key is recorded with the trigger
apiand no member as its starter. See Starting runs. - It decides approvals. Like any member, a key may approve or deny an action an agent step is waiting on. See Talking to agents.
- It owns only organization skills. A skill created with a key belongs to the organization. A key cannot create a skill owned by one member.
What a key cannot do
Section titled “What a key cannot do”- Chat with an agent or use the assistant. Both are for signed-in members in the app.
- Act as an admin. Connecting or disconnecting apps, setting the organization’s AI key,
managing members and keys, and changing the subscription need a signed-in owner or admin. A route
that does not accept keys answers
403with the codeforbidden.
Rate limit
Section titled “Rate limit”Each key may make 1,000 requests an hour. Every request with the key counts, including requests that fail and requests that poll a run. The limit is per key.
A request over the limit answers 401 with the code unauthorized and a message about the rate
limit. Wait and retry. If your code polls runs, poll every few seconds rather than in a tight loop.
Errors from the key
Section titled “Errors from the key”| Status | Code | Meaning |
|---|---|---|
| 401 | unauthorized |
The key is missing, mistyped or revoked, or it is over its limit |
| 403 | forbidden |
The route is for signed-in members or admins, not for keys |
Every error has the same JSON shape, described in the API reference.
Revoke a key
Section titled “Revoke a key”- Open the API keys page.
- Press Revoke on the key’s row.
Revoking takes effect at once and cannot be undone. Every caller still using the key gets 401
from its next request. Create a new key first if a running system needs to switch over without a
gap.