Skip to main content

Authentication

App API calls use a publishable x-app-key or a short-lived x-app-token, with x-user-id where the interface requires a user reference. Follow the App API guide; an App credential does not authenticate a caller-supplied user identity. For MCP, use OAuth or a revocable FloKit MCP token with read-only access. Follow assistant permissions and perform account changes in the FloKit dashboard. For measurement and provider notifications, use the exact configuration supplied by the connection workflow. Do not construct credential-bearing callback URLs from an example. For events sent to your own server, implement FloKit signature verification.

Choose your integration

Use SDK integration options, the current entitlement read, measurement callbacks, and the outbound webhook payload. Build against these documented interfaces rather than dashboard network requests. Published Flows include their checkout experience. Existing integrations using remote paywall configuration should follow the endpoint retirement notice.