Loopfour
API Reference

API Authentication

How to authenticate with the Loopfour API using API keys

All API requests require authentication via an API key. Keys are scoped to a company and carry specific permissions for workflow management and execution.

API Key Format

API keys follow the format wfk_ followed by a random string:

wfk_a1b2c3d4e5f6g7h8i9j0...

Using Your API Key

Include the API key in the x-api-key header on every request:

curl https://workflow.loopfour.ai/api/v1/workflows \
  -H "x-api-key: wfk_your_api_key_here"
const response = await fetch('https://workflow.loopfour.ai/api/v1/workflows', {
  headers: {
    'x-api-key': process.env.JUSTPAID_API_KEY,
  },
});
import requests

response = requests.get(
    'https://workflow.loopfour.ai/api/v1/workflows',
    headers={'x-api-key': os.environ['JUSTPAID_API_KEY']},
)

Never expose API keys in client-side code, public repositories, or browser requests. Always use environment variables or a secrets manager.

Key Permissions

ScopeDescription
workflows:readList and get workflow details
workflows:writeCreate, update, delete workflows
workflows:executeTrigger workflow runs
runs:readView run status and logs
connections:readList connections
connections:writeCreate and manage connections
secrets:readList masked workflow secrets
secrets:writeCreate, rotate, and delete workflow secrets

Rate Limits

API requests are rate-limited per API key:

Endpoint CategoryLimit
Read operations (GET)1000 requests/minute
Write operations (POST, PUT, DELETE)100 requests/minute
Workflow execution500 requests/minute

Every response from a rate-limited endpoint carries X-RateLimit-Limit, X-RateLimit-Remaining, and X-RateLimit-Reset (Unix timestamp, in seconds, when the window resets).

When you send too many requests, the API returns 429 Too Many Requests with a Retry-After header that gives the number of seconds to wait before you retry. The body uses the standard error envelope:

{
  "success": false,
  "error": {
    "code": "RATE_LIMITED",
    "message": "Rate limit exceeded. Limit: 100 requests per minute.",
    "requestId": "req_123"
  }
}

Key Rotation

To rotate an API key:

  1. Generate a new key in the dashboard
  2. Update your applications to use the new key
  3. Verify the new key works
  4. Revoke the old key

Both the old and new keys remain valid until the old key is explicitly revoked. This allows zero-downtime key rotation.

Security Best Practices

  • Use environment variables -- Store keys in JUSTPAID_API_KEY env vars, never hardcode them
  • Rotate keys regularly -- Rotate at least every 90 days
  • Use least-privilege keys -- Create keys with only the scopes your application needs
  • Monitor usage -- Check the API dashboard for unusual request patterns
  • Revoke compromised keys immediately -- If a key is exposed, revoke it and generate a new one

Frequently Asked Questions

API keys are available in the Workflow Studio dashboard under Settings > API Keys. You can generate multiple keys with different permission scopes.

Yes. You can create multiple keys with different scopes for different applications or environments. For example, one key for your production backend with full access, and another read-only key for monitoring.

Immediately revoke the key in the dashboard and generate a new one. Review your recent API logs for unauthorized activity. Update all applications using the compromised key.

API keys are the primary authentication method. For webhook endpoints, authentication uses provider-specific signature verification (Stripe signatures, HubSpot signatures, etc.) rather than API keys.

On this page