Authentication
Bluebot APIs authenticate with API keys. Each key is generated in FloDash and is scoped to a single Organization — it can only access devices and data that belong to that organization.
Generating an API key
- Sign in to FloDash.
- Open Flow API → API Key in the sidebar and select the organization the key should act on.
- Create a new key and choose which devices it can access — all devices in the organization, selected device groups, or specific devices — plus an optional expiration.
- Copy the API key value — it is shown only once.
Key format
The API key is a UUID, for example 123e4567-e89b-42d3-a456-426614174000. FloDash also shows a Key ID for identifying and managing the key. The Key ID is not an authentication credential: never send it in the bluebot-api-key header.
Some FloDash versions display the credential as keyId.uuid. In that case, send only the UUID after the dot. Sending the Key ID or the combined value directly in the authentication header is rejected with 403.
Scoping access
When you create a key, you grant access to all devices in its organization, selected device groups, or specific devices. Devices outside that scope are not visible to the key.
Single-device Flow requests such as GET /flow/datapoints/{id} and GET /flow/adaptive/{id} return 404 for an out-of-scope device. Collection and batch requests such as GET /device and GET /flow/latest return 200 but omit devices outside the key's scope.
Keys are also bound to one organization. Devices and data from other organizations are never visible to the key.
Sending the key
Pass the key (the UUID) on every request in the bluebot-api-key header.
curl https://prod.bluebot.com/management/v1/organizations/mine \
-H "bluebot-api-key: YOUR_API_KEY"