Skip to main content

Authentication

Fohlio uses token-based authentication. Fetch your token with your email and password, then include it on every request as the Authorization header. Tokens are scoped to your account and inherit your role. Requests without a valid token, or with a revoked token, receive a 401 Unauthorized response. Get your token:
Use it on a request:
Treat your API token like a password. Don’t expose it in client-side code or public repositories — call the API from your server.

Authorization

Every API key carries the same role as its owner in the workspace. Requests are authorized per-endpoint against that role — a key can never do more than the user it belongs to.

Rate limits

Requests are limited to 120 requests per minute per team. Exceeding this returns a 429 Too Many Requests response. Need a higher limit? Limits are configurable — contact your account manager to adjust them for your team.