Flux1 AIDevelopers
Flux1 AI API docs

Authentication

Send your key as a bearer token. Keys are shown once, stored hashed, and can be revoked at any time.

Send your key in the Authorization header as a bearer token. For clients migrating from other platforms, x-api-key: fx1_live_… is accepted too.

curl https://flux1.ai/api/v1/credits \
  -H "Authorization: Bearer $FLUX1_API_KEY"

Keys start with fx1_live_, are 41 characters long and are stored only as a SHA-256 hash on our side. If you lose one, revoke it and create another; the plaintext cannot be recovered.

Rules

RuleDetail
Who can create keysAny account with a completed paid credit-pack or subscription purchase. Free and gifted credits alone do not qualify.
Active keys per account5
RevocationImmediate. Requests with a revoked key return 401; generations already in flight finish normally.
ScopeA key acts as the account: it can spend credits and read that account's generations and logs, nothing else.

Keep keys on your server

Never put a key in a browser or a public repo. There is no CORS on the API on purpose; call it from your backend.

Failed authentication

A missing, malformed, unknown or revoked key returns 401 with error.code unauthorized. An account whose API access was disabled returns 403 api_access_disabled. Failed attempts are limited to 20 per minute per IP; beyond that you get 429 rate_limited until the window resets.

Manage keys at Settings → API Keys. Every request made with a key, including rejected ones, shows up under Settings → API Logs.

Access changes

Access follows your purchases: any completed paid credit-pack, monthly or yearly subscription purchase unlocks key creation and API calls. Free accounts receive 403 payment_required even if they have gift credits. Creating a key or starting a new generation requires sufficient credits; reading already-paid results and replaying the same request remain available when the balance reaches zero.

We may disable API access for an account that violates the terms of service. Its existing keys then receive 403 api_access_disabled on subsequent requests; already accepted tasks continue processing. If access is restored, keys that have not been revoked work again; revoked keys stay invalid. Write to support if you believe your account was disabled by mistake.