Learn
API key management — rotate, scope, and revoke
Best practices for managing FluxyChat API keys: project-scoped keys, rotation, and emergency revocation.
How API keys work
FluxyChat issues project-scoped API keys (prefixed with fc_) that authenticate REST and WebSocket access. Each key is tied to a specific project and inherits the project's permissions.
Keys are stored hashed in D1 using API_KEY_HASH_SALT. The raw key is only visible at creation time.
Rotating API keys
- Generate a new key via POST /projects/api-keys before removing the old one
- Update your application to use the new key
- Verify all services work with the new key
- Delete the old key via DELETE /projects/api-keys/:id
- Never have zero active keys — always overlap during rotation
Key scoping
Each project has its own set of API keys. In multi-tenant deployments (HOSTED_MULTI_TENANT=true), tenant projects cannot use worker-level keys — they must use their own project-scoped credentials.
Use ALLOW_WORKER_LLM_FALLBACK=true to let all projects use the worker's shared AI credentials as a fallback.
Emergency revocation
To immediately revoke access, delete the API key from the dashboard or via DELETE /projects/api-keys/:id. All active sessions using that key will be disconnected on the next WebSocket heartbeat.
For project-wide revocation, rotate the project's jwt_secret — all existing JWTs become invalid immediately.
Agent events on the same WebSocket as chat
When humans and copilots share a room, debugging and handoffs are easier if tool_call, tool_result, and user messages share one ordered stream — not a side channel.
Build realtime chat with Next.js and FluxyChat
Nuxt/Vue-style CF tutorials, but for Next.js App Router: Route Handler JWT, client useChat, reconnect, and history pagination on Cloudflare Workers + Durable Objects.