Skip to main content
POST
Get a test key without an account

Body

application/json

Optional details for a new sandbox app.

name
string

The app's name, shown in the dashboard once it is claimed. Defaults to "Sandbox app".

Maximum string length: 80

Response

The new app and its key. The key and the claim token are not shown again.

A new app made without an account, with its test key. key and claim_token are shown only here.

key
string
required

The API key itself (fk_test_...). Shown once; store it as FLOW_MESSAGING_KEY.

Example:

"fk_test_..."

api_key
object
required

An API key's record. The key itself is shown once, at creation, and stored only as a hash.

account
object
required

A customer company. Holds the plan, billing and members. Every app belongs to one account.

app
object
required

One agent integration. Owns API keys (per mode), webhook endpoints and settings.

allowance
object
required

What the app may still send on the shared sandbox senders for free. Present only on apps that have one: apps made with POST /v1/sandbox/keys (anonymous, one allowance per app), and apps of people who signed in (signed_in, one allowance per person: every app the person owns or claimed draws on the same contacts and messages, so the counts here are the person's, over all those apps). Only messages your agent sends count, on the channels in channels; inbound messages are free. A contact counts once it joins an app on a sandbox sender, and keeps counting after it leaves. Sends past the allowance answer 403 permission with channel_code sandbox_allowance_used; a join past contacts.limit is refused in the chat.

claim_token
string
required

Proves you hold this app when a person signs in to claim it: pass it to POST /v1/device/authorizations. Shown once; keep it with the key. It stops working once the app is claimed.

Example:

"fct_..."

claim_url
string<uri>
required

A page where a person signs in with GitHub and claims the app in the browser, without the CLI. It holds the claim token, so treat it like one. The claim hands out no key and revokes the app's keys unless the person ticks "Keep my agent's current key working"; afterwards they make keys on the dashboard's Keys page.

Example:

"https://api.flow.engineer/admin/claim#token=fct_..."

senders
object[]
required

The shared sandbox senders the key can use, each with the link a person opens to join the app (address.link) and the join message (join_code).