[{"data":1,"prerenderedAt":121},["ShallowReactive",2],{"doc:\u002Freference\u002Foverview":3},{"page":4,"toc":113,"updated":120},{"path":5,"title":6,"seoTitle":7,"description":8,"blocks":9},"\u002Freference\u002Foverview","API overview","Fingerly API Reference: Overview","The Fingerly HTTP API: regional base URLs, the two kinds of key, JSON conventions, and the endpoints your SDKs and your server call.",[10,13,18,20,37,39,41,44,71,74,83,86,88,90,93,95,98,100],{"type":11,"text":12},"p","The Fingerly API is a small JSON-over-HTTPS API with three audiences. Client SDKs call the **client API** with a public key to identify visitors. Your backend calls the **server API** with a secret key to read what was identified. Your automation calls the **management API** with a management key to manage keys, webhook endpoints and risk weights. Most integrations never call the client API directly: the SDKs do.",{"type":14,"level":15,"text":16,"id":17},"heading",2,"Base URL","base-url",{"type":11,"text":19},"Each region has its own API, and every key belongs to one region. Use the base URL of your key's region.",{"type":21,"columns":22,"rows":26},"table",[23,16,24,25],"Region","Keys","Status",[27,32],[28,29,30,31],"United States","`https:\u002F\u002Fus.api.fingerly.io\u002Fapi\u002Fv1`","`fly_pk_us_…`, `fly_sk_us_…`, `fly_px_us_…`","Available",[33,34,35,36],"European Union","`https:\u002F\u002Feu.api.fingerly.io\u002Fapi\u002Fv1`","`fly_pk_eu_…`, `fly_sk_eu_…`, `fly_px_eu_…`","Coming soon",{"type":11,"text":38},"Management keys, `fly_mk_us_…` and `fly_mk_eu_…`, belong to a region the same way.",{"type":11,"text":40},"The SDKs read the region from the key and choose the base URL for you. A key sent to another region's API is refused. See [regions and data residency](\u002Fdocs\u002Fregions).",{"type":14,"level":15,"text":42,"id":43},"Endpoints","endpoints",{"type":21,"columns":45,"rows":49},[46,47,48],"Endpoint","Key","Purpose",[50,54,57,61,64,67],[51,52,53],"[`GET \u002Fevents`](\u002Freference\u002Flist-events)","Secret","List events in a time window.",[55,52,56],"[`GET \u002Fevents\u002F{request_id}`](\u002Freference\u002Fget-event)","Read one event with its archived detail.",[58,59,60],"[`POST \u002Fidentify`](\u002Freference\u002Fidentify)","Public","Submit a signal report and get the verdict.",[62,59,63],"[`POST \u002Fevents\u002F{request_id}\u002Fsupplement`](\u002Freference\u002Fdeferred-report)","Attach the deferred report to an identification.",[65,59,66],"[`POST \u002Fattestation\u002Fchallenge`](\u002Freference\u002Fattestation-challenge)","Issue a one-time attestation challenge for the Android SDK.",[68,69,70],"[`\u002Fmanagement\u002F…`](\u002Freference\u002Fmanagement\u002Foverview)","Management","Manage SDK keys, proxy keys, webhook endpoints and risk weights.",{"type":14,"level":15,"text":72,"id":73},"Conventions","conventions",{"type":75,"items":76},"list",[77,78,79,80,81,82],"Request and response bodies are JSON (`application\u002Fjson`). Unknown request fields are rejected.","Request bodies are limited to 1 MiB. Client API requests may be sent with `Content-Encoding: gzip`, and the limit applies after decompression.","Timestamps are RFC 3339 in UTC, such as `2026-09-16T09:41:12.482Z`.","Request IDs are UUIDv7, so they sort by time and carry their own timestamp.","Optional response fields are omitted when they do not apply, unless a page says a field is `null`.","Every response carries an `X-Request-Id` header. Include it when you contact support.",{"type":14,"level":15,"text":84,"id":85},"Versioning","versioning",{"type":11,"text":87},"The version is part of the path, `\u002Fapi\u002Fv1`. Within a version, Fingerly adds fields and endpoints but does not remove or rename them, and never changes what a field means. Write clients that ignore fields they do not know.",{"type":11,"text":89},"Signal names are permanent too. If a detection ever changes what it measures, it gets a new name.",{"type":14,"level":15,"text":91,"id":92},"Health","health",{"type":11,"text":94},"`GET \u002Fapi\u002Fv1\u002Fhealthz` answers when the API process is up; `GET \u002Fapi\u002Fv1\u002Freadyz` answers when it can serve traffic. Neither needs a key.",{"type":14,"level":15,"text":96,"id":97},"OpenAPI","openapi",{"type":11,"text":99},"The whole public API is described in an OpenAPI 3.1 document, with a Postman collection generated from it. See [OpenAPI and Postman](\u002Freference\u002Fopenapi).",{"type":101,"columns":15,"cards":102},"cards",[103,108],{"title":104,"text":105,"href":106,"icon":107},"Authentication","Public, secret, proxy and management keys.","\u002Freference\u002Fauthentication","key",{"title":109,"text":110,"href":111,"icon":112},"Errors","Statuses, codes and what to do.","\u002Freference\u002Ferrors","alert",[114,115,116,117,118,119],{"id":17,"text":16,"level":15},{"id":43,"text":42,"level":15},{"id":73,"text":72,"level":15},{"id":85,"text":84,"level":15},{"id":92,"text":91,"level":15},{"id":97,"text":96,"level":15},"2026-09-17T16:56:08.000Z",1789667797838]