Authentication
How to authenticate with the FX-Port API using Bearer tokens. Key permissions, prefixes, and security guidance.
All requests must include a Bearer token in the Authorization header.
Authorization: Bearer fxp_live_YOUR_KEYGet your API keys at fx-port.com/dashboard/api.
Permission levels
| Permission | What it allows |
|---|---|
| Read | Search, price, get quotes, retrieve bookings, airport lookups, balances, history |
| Read+Write | All read access plus creating bookings, paying held orders, cancelling reservations |
A read key returning 403 read_write_permission_required means the operation is state-changing
(booking, payment, or cancellation). Use a read+write key for those.
Key prefixes and environments
There is one base URL for all environments. The environment is determined entirely by the key prefix.
| Prefix | Environment | Behaviour |
|---|---|---|
fxp_live_ | Live | Real agency data and live financial ledger |
fxp_test_ | Sandbox | Isolated test bookings; balance endpoints return empty data |
External keys (issued to agencies) automatically resolve the agency identity from the key itself.
IP restrictions
You can restrict a live key to specific IP addresses in the dashboard. Recommended for production Read+Write keys.
Security
Key handling, minimal-permission keys, booking-ownership authorization, and general API security hygiene now live on their own page: see Security.