F2F API

Authentication & Vault

Headless sessions, handled

Connect creator accounts once. F2F API rotates sessions, answers 2FA challenges and isolates every account behind its own proxy so integrations stay connected.

Session infrastructure

Session rotation

Tokens refresh automatically before expiry. Expired sessions return 401 expired_session_token with a refresh path.

Automated 2FA

SMS, TOTP and email OTP challenges surface as 422 two_factor_required with an auth_challenge_id to complete.

Proxy isolation

Each creator is pinned to a dedicated residential IP region to avoid cross-account contamination.

AES-256 vault

Session material is encrypted at rest. F2F API never asks you to paste passwords into this website.

Disconnect alerts

If a creator revokes access, you get an account.disconnected webhook immediately.

Scoped API keys

Issue keys per environment and per permission, and revoke them instantly.

Complete a 2FA challenge

When a session needs verification, submit the code the creator received.

curl -X POST "https://api.apif2f.com/v1/auth/2fa" \
  -H "Authorization: Bearer $F2F_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
    "auth_challenge_id": "ach_72e1f0",
    "code": "482913"
  }'

Authentication FAQ

Start building on F2F today.

Free sandbox access, 1,000 monthly requests, no credit card. API automation and server-side ads tracking in one key.

Prefer email? hello@apif2f.com