Authentication

The Fluxpool API uses API keys for authentication. All requests require a valid key sent as a Bearer token — the same format used by the OpenAI API.


API Keys

Your API key is generated in the Fluxpool app (API / MCP Access). Keys are prefixed with fp_live_ followed by 40 hex characters, and look like this:

Example Key
fp_live_a1b2c3d4e5f60718293a4b5c6d7e8f90a1b2c3d4e

Keep your API key secret. Do not expose it in client-side code, public repositories, or frontend applications. Use environment variables or a secrets manager.

Get your API key →


Making Requests

Include your API key in the Authorization header of every request.

Header Format

Header
Authorization: Bearer fp_live_xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx

cURL Example

Bash
curl https://api.fluxpool.ai/v1/images/generations \
  -H "Authorization: Bearer fp_live_xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx" \
  -H "Content-Type: application/json" \
  -d '{
    "model": "flux-2-pro",
    "prompt": "A dragon on a neon-lit Tokyo rooftop, 8K",
    "size": "1024x1024"
  }'

Python Example

Python
import os
from openai import OpenAI

client = OpenAI(
    base_url="https://api.fluxpool.ai/v1",
    api_key=os.environ["FLUXPOOL_API_KEY"]
)

response = client.images.generate(
    model="flux-2-pro",
    prompt="A dragon on a neon-lit Tokyo rooftop, 8K",
    size="1024x1024"
)

print(response.data[0].url)

JavaScript / Node.js Example

JavaScript
import OpenAI from "openai";

const client = new OpenAI({
  baseURL: "https://api.fluxpool.ai/v1",
  apiKey: process.env.FLUXPOOL_API_KEY,
});

const response = await client.images.generate({
  model: "flux-2-pro",
  prompt: "A dragon on a neon-lit Tokyo rooftop, 8K",
  size: "1024x1024",
});

console.log(response.data[0].url);

OpenAI SDK Compatibility

The Fluxpool API is OpenAI-compatible. If you already use the OpenAI Python or Node.js SDK, change two values: base_url and api_key. Everything else works as-is.

Parameter OpenAI Default Fluxpool
base_url / baseURL https://api.openai.com/v1 https://api.fluxpool.ai/v1
api_key / apiKey sk-... fp_live_...

Tip: You don't need a Fluxpool-specific SDK. The official openai Python and Node.js packages work directly. Just change the base URL and API key.


API Key Management

Manage your keys on the API / MCP Access page in the app.

Creating a Key

  1. Go to API / MCP Access.
  2. Click "Create new key."
  3. Give it a name (e.g., production, staging, my-app).
  4. Copy the key immediately — it is shown only once.

Copy your key on creation. For security, the full key is displayed only once. If you lose it, revoke it and create a new one.

Rotating Keys

To rotate a key without downtime:

  1. Create a new key.
  2. Update your application to use the new key.
  3. Verify requests succeed with the new key.
  4. Revoke the old key.

Revoking Keys

Revoke any key instantly from the dashboard. Revoked keys stop working immediately — all in-flight requests using that key will fail.

Multiple Keys

You can create multiple API keys per account. Use separate keys for different environments (development, staging, production) or applications to isolate usage tracking and simplify rotation.


Limits

Generations running at once. Each plan sets how many generations can be in progress at the same time for your account, whether they come from the app, the API or an MCP client. Without an active plan, your credits still work, at the lowest plan's limit.

Plan Concurrent generations
1-month Trial 10
Base 10
Pro 15
Growth 20
Hero 25
Enterprise Custom

Connected apps. An app or agent you connect through the MCP connector (OAuth) has its own daily credit limit, 500 by default, over a rolling 24 hours. Change it or pause the connection in the app under API / MCP Access, Connected apps. API keys have no daily limit.

Status Code When
429 CONCURRENCY_LIMIT_REACHED Your plan's generations are all running. Wait for one to finish.
429 CONNECTION_LIMIT_REACHED This connected app would go over its daily credit limit. The message says how much it has used and what the generation needs.
403 CONNECTION_PAUSED This connected app is paused. Resume it to generate again.

Every error uses the same body. Branch on error.code; the message is for people and may change.

429 response body
{
  "error": {
    "message": "You have 10 generations running and your plan allows 10 at once. Wait for one to finish, or upgrade for more.",
    "type": "invalid_request_error",
    "param": null,
    "code": "CONCURRENCY_LIMIT_REACHED"
  }
}

Through the MCP server, the same object comes back as the text of the create_generation tool result. The API does not send rate-limit headers.

Handling a 429

When all of your plan's generations are running, the API returns 429 with CONCURRENCY_LIMIT_REACHED. Wait for one to finish and retry with exponential backoff. The OpenAI SDK raises a 429 as RateLimitError. A CONNECTION_LIMIT_REACHED 429 will not clear by retrying soon, so don't loop on it.

Python — Retry with Backoff
import time
from openai import OpenAI, RateLimitError

client = OpenAI(
    base_url="https://api.fluxpool.ai/v1",
    api_key="fp_live_xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx"
)

def generate_with_retry(prompt, max_retries=3):
    for attempt in range(max_retries):
        try:
            return client.images.generate(
                model="flux-2-pro",
                prompt=prompt
            )
        except RateLimitError as e:
            # 429: too many generations running at once.
            # A connection's daily limit won't clear by retrying soon.
            if e.code != "CONCURRENCY_LIMIT_REACHED":
                raise
            wait = 2 ** attempt
            time.sleep(wait)
    raise Exception("Still at the concurrency limit after retries")

Need higher limits? Contact us for custom concurrency limits and dedicated endpoints.


Security Best Practices

  • Use environment variables. Never hardcode keys in source code.
    Bash
    export FLUXPOOL_API_KEY=fp_live_xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
  • Never expose keys client-side. API calls must originate from your server or backend, not from browsers or mobile apps.
  • Use separate keys per environment. production, staging, and development keys make rotation and auditing simpler.
  • Rotate keys periodically. Even without a suspected compromise, rotate keys every 90 days.
  • Revoke compromised keys immediately. If a key is leaked in a public repo, logs, or error message, revoke it from the API / MCP Access page and create a new one.
  • Monitor usage. Check the Dashboard for unexpected spikes in generation volume, which could indicate key compromise.

Errors

Authentication-related error responses:

Status Error Code Description Fix
401 invalid_api_key The API key is missing, malformed, or revoked. Check the key value. Ensure the Authorization: Bearer prefix is present.
401 expired_api_key The API key has been revoked or expired. Create a new key in the API / MCP Access page.
403 insufficient_credits Your account has no remaining credits. Top up credits to continue generating.
429 CONCURRENCY_LIMIT_REACHED Too many requests in the current window. Wait for a generation to finish, then retry with backoff. See Limits.
JSON — 401 Response
{
  "error": {
    "type": "invalid_api_key",
    "message": "The API key provided is invalid or has been revoked.",
    "code": 401
  }
}