Pro REST API · Webhooks · v1

Your delivery graph, addressable.

Flowral computes what's ready, what's blocking what, and when a project actually lands. Build directly against that: a versioned REST API and webhooks for the software and automated workflows you own, with the same permission model as the app itself.

✦ Included with Pro · No per-call pricing · openapi.json · Want an AI assistant instead? See AI and MCP →

74 operations across 52 paths · OpenAPI 3.1, generated from the service · Bearer keys, OAuth client credentials and webhooks · Versioned: v1 won't break under you
Where this is. v1 is built: all 74 operations, webhooks, and workspace credentials. Create one under API access in the app; if the section isn't there yet, tell us what you're building and we'll switch it on. The reference is generated from the service itself, so it can't describe something that doesn't ship.
The surface

Everything the app can do to a flow — or a brainstorm

Including the derived state: status, blockers, critical path, projected finish. You never have to re-implement the dependency rules against raw edges.

🗂️

Flows

Create a project and its whole task graph in one call, with dependencies declared by position. Read, update, archive, restore, schedule, report, export to PDF or PNG, share with a client.

☑️

Tasks

Add, link, estimate, assign, comment, attach. Transitions are endpoints rather than a status field: complete checks the dependencies and the required deliverables, then tells you what it unblocked.

💡

Brainstorms

An idea tree, not a dependency graph — create a board and its starting ideas in one call, nest them under one another, comment, attach references. Share, archive, restore, publish, same as a flow.

🟢

Work

/work/available, /blocked, /in-progress, /overview, across every flow, ranked by what decides the finish date, with the top blockers named.

📈

Schedule & reports

Critical-path pass with earliest/latest start and slack per task, and the delivery report: completion, effort left, workload per person, what's unestimated.

👥

Team & templates

Members, roles, invitations. List templates and start a flow from one: useful when every engagement of a type should begin identically.

🔎

Search

Resolve the name a human typed into an id, across flows, tasks and templates. The call that makes a Slack command feel native.

Credentials

A credential is a workspace member, not a person

Created under API access in the app, with a role and a set of scopes. It keeps working when the person who made it leaves, and its actions are attributed to it rather than impersonating a colleague.

API key

One header. Right for a script, a cron, a webhook receiver. Shown once at creation and stored hashed. If you lose it, you rotate it.

curl 'https://api.flowral.app/v1/me' \
  -H 'Authorization: Bearer fl_sk_live_…'

OAuth client credentials

Right for anything long-lived. Tokens expire in an hour, so a leak is worth an hour and rotation is a token request rather than a deploy.

curl -X POST 'https://api.flowral.app/v1/oauth/token' \
  -d 'grant_type=client_credentials' \
  -d "client_id=$FLOWRAL_ID" \
  -d "client_secret=$FLOWRAL_SECRET"

{ "access_token": "fl_at_…", "expires_in": 3600,
  "scope": "flows:read flows:write work:write" }

What a credential can't do

The interesting half of a permission model.

Exceed its roleGive it viewer and every write is refused, whatever its scopes say. Scopes narrow; they never grant.
Change workspaceIt is issued for one and stays there. Blast radius is readable off the page that created it.
Skip the rulesDependencies hold, work has to be started before it can finish, required deliverables have to be in, and a past-due workspace stays read-only.
Outlive revocationDelete it and every token it issued stops working on the next request.

Scopes: flows:read flows:write work:write team:read team:write templates:read. Rate limit 120/min per credential, burst 240, 429 with Retry-After over it.

Want Flowral inside an assistant instead? The AI and MCP connector reads and moves the same flows, signed in as the person using it, with no key to manage. See AI and MCP →
Pricing

Part of Pro. No meter.

€9 per person per month, everything included: templates, dates, reports, the API and webhooks. No add-on fee, no per-call pricing, no credits to buy.

Free gives you the whole canvas: unlimited flows, gates, the Ready view, unlimited guests, two people. What Pro adds is everything that involves accounting for the work rather than doing it: a date a client can hold you to, a report an account lead forwards, and programmatic access to the workspace. Metering API calls would make people ration exactly the thing we want in their CI pipeline.

Common questions

How do I get API access?

Integration access is included with Pro. Open API access in your Flowral workspace and create the credential or webhook your setup needs.

Can I use Flowral without the API, just for an AI assistant?

Yes. That's the MCP connector, a separate way in built for assistants and agent platforms rather than code you host. See AI and MCP →

How do I authenticate API requests?

Use an API key for a simple script or internal automation. Use OAuth client credentials for a long-running service or an integration that needs short-lived access tokens. Both use the same roles and permissions.

What can an API credential access?

A credential belongs to one workspace. Its role sets the maximum access, and its scopes can narrow that access further. It cannot switch workspaces or see projects outside its role.

Are webhooks available?

Yes. Webhooks are included with Pro, so your systems can react when Flowral work changes instead of polling for every update.

What are the rate limits?

The standard limit is 120 requests per minute per credential, with short bursts up to 240. Requests above the limit return 429 with a Retry-After header. Contact us if your integration needs a higher limit.

How much does the API cost?

The REST API and webhooks are included with Pro at €9 per person per month. There is no API add-on, per-call charge or credit system.

Read the contract before you build against it.

The reference is generated from the service, so it can't drift from what ships.

Open the reference