Authentication

Every /api/v1 request carries an API key and secret as headers. Create a key at /orgs/<your-org>/settings/apikeys; the secret is shown once.

Headers

HeaderDescription
api-keyThe key (fob_app_…)
api-secretThe matching secret

Example Request

curl "https://txn.finopsbricks.com/api/v1/transactions?limit=5" \
  -H "api-key: fob_app_xxxxxxxxxxxx" \
  -H "api-secret: yyyyyyyyyyyyyyyy"

Permissions

A key belongs to one org and carries per-resource scopes (read, create, edit, delete) chosen at creation. A request outside the key's scopes returns 403 FORBIDDEN; missing or wrong credentials return 401 UNAUTHORIZED. GET /api/v1/whoami returns the org and scopes for any valid key.