Authentication
The Fluxpool API uses API keys for authentication. All requests require a valid key sent as a Bearer token — the same format used by the OpenAI API.
API Keys
Your API key is generated in the Fluxpool app (API / MCP Access). Keys are prefixed with fp_live_ followed by 40 hex characters, and look like this:
fp_live_a1b2c3d4e5f60718293a4b5c6d7e8f90a1b2c3d4e Keep your API key secret. Do not expose it in client-side code, public repositories, or frontend applications. Use environment variables or a secrets manager.
Making Requests
Include your API key in the Authorization header of every request.
Header Format
Authorization: Bearer fp_live_xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx cURL Example
curl https://api.fluxpool.ai/v1/images/generations \
-H "Authorization: Bearer fp_live_xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx" \
-H "Content-Type: application/json" \
-d '{
"model": "flux-2-pro",
"prompt": "A dragon on a neon-lit Tokyo rooftop, 8K",
"size": "1024x1024"
}' Python Example
import os
from openai import OpenAI
client = OpenAI(
base_url="https://api.fluxpool.ai/v1",
api_key=os.environ["FLUXPOOL_API_KEY"]
)
response = client.images.generate(
model="flux-2-pro",
prompt="A dragon on a neon-lit Tokyo rooftop, 8K",
size="1024x1024"
)
print(response.data[0].url) JavaScript / Node.js Example
import OpenAI from "openai";
const client = new OpenAI({
baseURL: "https://api.fluxpool.ai/v1",
apiKey: process.env.FLUXPOOL_API_KEY,
});
const response = await client.images.generate({
model: "flux-2-pro",
prompt: "A dragon on a neon-lit Tokyo rooftop, 8K",
size: "1024x1024",
});
console.log(response.data[0].url); OpenAI SDK Compatibility
The Fluxpool API is OpenAI-compatible. If you already use the OpenAI Python or Node.js SDK, change two values: base_url and api_key. Everything else works as-is.
| Parameter | OpenAI Default | Fluxpool |
|---|---|---|
base_url / baseURL | https://api.openai.com/v1 | https://api.fluxpool.ai/v1 |
api_key / apiKey | sk-... | fp_live_... |
Tip: You don't need a Fluxpool-specific SDK. The official openai Python and Node.js packages work directly. Just change the base URL and API key.
API Key Management
Manage your keys on the API / MCP Access page in the app.
Creating a Key
- Go to API / MCP Access.
- Click "Create new key."
- Give it a name (e.g.,
production,staging,my-app). - Copy the key immediately — it is shown only once.
Copy your key on creation. For security, the full key is displayed only once. If you lose it, revoke it and create a new one.
Rotating Keys
To rotate a key without downtime:
- Create a new key.
- Update your application to use the new key.
- Verify requests succeed with the new key.
- Revoke the old key.
Revoking Keys
Revoke any key instantly from the dashboard. Revoked keys stop working immediately — all in-flight requests using that key will fail.
Multiple Keys
You can create multiple API keys per account. Use separate keys for different environments (development, staging, production) or applications to isolate usage tracking and simplify rotation.
Limits
Generations running at once. Each plan sets how many generations can be in progress at the same time for your account, whether they come from the app, the API or an MCP client. Without an active plan, your credits still work, at the lowest plan's limit.
| Plan | Concurrent generations |
|---|---|
| 1-month Trial | 10 |
| Base | 10 |
| Pro | 15 |
| Growth | 20 |
| Hero | 25 |
| Enterprise | Custom |
Connected apps. An app or agent you connect through the MCP connector (OAuth) has its own daily credit limit, 500 by default, over a rolling 24 hours. Change it or pause the connection in the app under API / MCP Access, Connected apps. API keys have no daily limit.
| Status | Code | When |
|---|---|---|
| 429 | CONCURRENCY_LIMIT_REACHED | Your plan's generations are all running. Wait for one to finish. |
| 429 | CONNECTION_LIMIT_REACHED | This connected app would go over its daily credit limit. The message says how much it has used and what the generation needs. |
| 403 | CONNECTION_PAUSED | This connected app is paused. Resume it to generate again. |
Every error uses the same body. Branch on error.code; the message is for people and may change.
{
"error": {
"message": "You have 10 generations running and your plan allows 10 at once. Wait for one to finish, or upgrade for more.",
"type": "invalid_request_error",
"param": null,
"code": "CONCURRENCY_LIMIT_REACHED"
}
}
Through the MCP server, the same object comes back as the text of the create_generation tool result.
The API does not send rate-limit headers.
Handling a 429
When all of your plan's generations are running, the API returns 429 with CONCURRENCY_LIMIT_REACHED. Wait for one to finish and retry with exponential backoff. The OpenAI SDK raises a 429 as RateLimitError. A CONNECTION_LIMIT_REACHED 429 will not clear by retrying soon, so don't loop on it.
import time
from openai import OpenAI, RateLimitError
client = OpenAI(
base_url="https://api.fluxpool.ai/v1",
api_key="fp_live_xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx"
)
def generate_with_retry(prompt, max_retries=3):
for attempt in range(max_retries):
try:
return client.images.generate(
model="flux-2-pro",
prompt=prompt
)
except RateLimitError as e:
# 429: too many generations running at once.
# A connection's daily limit won't clear by retrying soon.
if e.code != "CONCURRENCY_LIMIT_REACHED":
raise
wait = 2 ** attempt
time.sleep(wait)
raise Exception("Still at the concurrency limit after retries") Need higher limits? Contact us for custom concurrency limits and dedicated endpoints.
Security Best Practices
- Use environment variables. Never hardcode keys in source code.
Bash
export FLUXPOOL_API_KEY=fp_live_xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx - Never expose keys client-side. API calls must originate from your server or backend, not from browsers or mobile apps.
- Use separate keys per environment.
production,staging, anddevelopmentkeys make rotation and auditing simpler. - Rotate keys periodically. Even without a suspected compromise, rotate keys every 90 days.
- Revoke compromised keys immediately. If a key is leaked in a public repo, logs, or error message, revoke it from the API / MCP Access page and create a new one.
- Monitor usage. Check the Dashboard for unexpected spikes in generation volume, which could indicate key compromise.
Errors
Authentication-related error responses:
| Status | Error Code | Description | Fix |
|---|---|---|---|
401 | invalid_api_key | The API key is missing, malformed, or revoked. | Check the key value. Ensure the Authorization: Bearer prefix is present. |
401 | expired_api_key | The API key has been revoked or expired. | Create a new key in the API / MCP Access page. |
403 | insufficient_credits | Your account has no remaining credits. | Top up credits to continue generating. |
429 | CONCURRENCY_LIMIT_REACHED | Too many requests in the current window. | Wait for a generation to finish, then retry with backoff. See Limits. |
{
"error": {
"type": "invalid_api_key",
"message": "The API key provided is invalid or has been revoked.",
"code": 401
}
}