Authentication
Every /api/v1 request carries an API key and secret as headers. Create a key at
/orgs/<your-org>/settings/apikeys; the secret is shown once.
Headers
| Header | Description |
|---|---|
api-key | The key (fob_app_…) |
api-secret | The matching secret |
Example Request
curl "https://txn.finopsbricks.com/api/v1/transactions?limit=5" \
-H "api-key: fob_app_xxxxxxxxxxxx" \
-H "api-secret: yyyyyyyyyyyyyyyy"
Permissions
A key belongs to one org and carries per-resource scopes (read, create, edit, delete)
chosen at creation. A request outside the key's scopes returns 403 FORBIDDEN; missing or wrong
credentials return 401 UNAUTHORIZED. GET /api/v1/whoami returns the org and scopes for any
valid key.