The Finerlise API
The REST API lives at https://finerlise.com/api/v1. It returns JSON, takes a Bearer token on every request, and is described by an OpenAPI 3.1 document you can load into any client generator or agent.
Use it to read a Workspace's Forms and completed Responses, or to subscribe a URL to new Responses. Building, editing and publishing forms happens in the Finerlise app.
- OpenAPI 3.1 descriptionEvery endpoint, parameter, scope and schema.
- API indexAn unauthenticated entry point that links the documents below.
Get an API key
Workspace Owners and Admins create keys in Finerlise under Settings, then API keys. Name the key, then copy it: it is shown once, and Finerlise only stores a hash.
Keys look like fnr_live_… and belong to the Workspace, not a person, so they keep working when people leave. A Workspace can have 25 active keys, and revoking one stops it immediately. API keys can read Responses (responses:read).
Keys are for server-to-server use. Keep them out of browser code, mobile apps and public repositories.
Quickstart
Check which Workspace your token acts as, then list a form's latest completed Responses, newest first. Copy a form's ID from its Settings, General page in Finerlise.
curl https://finerlise.com/api/v1/me \
-H "Authorization: Bearer $FINERLISE_API_KEY"
curl "https://finerlise.com/api/v1/forms/$FORM_ID/responses?limit=25" \
-H "Authorization: Bearer $FINERLISE_API_KEY"Endpoints
GET /me returns the Workspace (and user, for OAuth) the token acts as. GET /forms lists Forms, most recently updated first, and needs forms:read. GET /forms/{formId}/responses and GET /responses/{responseId} read completed Responses and need responses:read.
POST /hooks subscribes a URL to new Responses of one form and DELETE /hooks/{hookId} removes it; both need hooks:write. Each delivery has the same shape as a Response returned by the API.
OAuth 2.0 apps
Apps that act for a user, like the Zapier integration, use the authorization code flow. Access tokens (fnr_oat_…) last one hour; refresh them with the refresh token. Scopes are responses:read, forms:read and hooks:write.
OAuth clients are registered by the Finerlise team. To build a public integration, email [email protected]. For your own server, an API key is enough.
- Authorization server metadataRFC 8414: authorization, token and revocation endpoints.
- Protected resource metadataRFC 9728: which authorization server issues tokens for the API.
Errors and rate limits
Every error is JSON with a stable code, a message and a hint on how to fix it. Unknown /api paths return the same shape with code not_found.
Each API key and each OAuth connection can make 120 requests per minute. Over the limit you get 429 with a Retry-After header in seconds. A 404 means the resource does not exist or belongs to another Workspace.
{
"error": "Unauthorized",
"code": "unauthorized",
"message": "Unauthorized",
"hint": "Send `Authorization: Bearer <token>` …",
"docs": "/api/v1/openapi.json"
}Testing your integration
There is no separate sandbox. Create a free Workspace, publish a test form, submit a few responses yourself, and call the API with that Workspace's key. Revoke the key when you are done.
For AI agents
Finerlise publishes machine-readable discovery documents so agents can find and use the API without guessing.
- auth.mdHow an agent gets credentials.
- Agent skills indexA SKILL.md that teaches an agent the API.
- AI catalogAgentic Resource Discovery manifest.
- API catalogRFC 9727 linkset.
- llms.txtA guide to Finerlise for language models.