API Reference

Every endpoint,
in one place

108 endpoints across 10 groups, read from the API itself rather than written down and left to rot.

Base URL

https://api.fluxrail.io/api/v1

Every path below is relative to this.

Authentication

X-API-Key: flux_live_…

flux_live_ hits production, flux_test_ is fully simulated.

Trailing slashes matter

/payouts/customers//

Every path needs one except Liquidity and Forwarding, which are registered bare. There is no redirect between the two — the wrong spelling is a 404.

API keys

Create and revoke the keys that authenticate every other call. A secret is shown once and stored hashed — if it is lost, regenerate rather than hunt for it.

  • GET /api/v1/auth/api-keys/

    List your API keys, live and sandbox.

  • POST /api/v1/auth/api-keys/

    Create a key. The secret is shown once and stored hashed — we cannot recover it.

  • GET /api/v1/auth/api-keys/stats/

    Request counts per key.

  • GET /api/v1/auth/api-keys/{pk}/

    Fetch one key and its usage.

  • PUT /api/v1/auth/api-keys/{pk}/

    Replace a key’s settings.

  • PATCH /api/v1/auth/api-keys/{pk}/

    Rename a key or toggle it.

  • DELETE /api/v1/auth/api-keys/{pk}/

    Revoke a key immediately.

  • POST /api/v1/auth/api-keys/{pk}/regenerate/

    Issue a new secret for a key and invalidate the old one.

Worked examples in cURL, JavaScript and Python live in the guides.

HTTP Status Codes

200 OK - Request succeeded
201 Created - Resource created successfully
400 Bad Request - Invalid request parameters
401 Unauthorized - Invalid or missing API key
403 Forbidden - Insufficient permissions
404 Not Found - Resource not found
429 Too Many Requests - Rate limit exceeded
500 Internal Server Error - Something went wrong

Error Response Format

{
  "error": {
    "code": "invalid_request",
    "message": "The 'chain' field is required",
    "details": {
      "field": "chain",
      "reason": "This field is required"
    }
  }
}