Authentication & Vault
Headless sessions, handled
Connect creator accounts once. F2F API rotates sessions, answers 2FA challenges and isolates every account behind its own proxy so integrations stay connected.
Session infrastructure
Session rotation
Tokens refresh automatically before expiry. Expired sessions return 401 expired_session_token with a refresh path.
Automated 2FA
SMS, TOTP and email OTP challenges surface as 422 two_factor_required with an auth_challenge_id to complete.
Proxy isolation
Each creator is pinned to a dedicated residential IP region to avoid cross-account contamination.
AES-256 vault
Session material is encrypted at rest. F2F API never asks you to paste passwords into this website.
Disconnect alerts
If a creator revokes access, you get an account.disconnected webhook immediately.
Scoped API keys
Issue keys per environment and per permission, and revoke them instantly.
Complete a 2FA challenge
When a session needs verification, submit the code the creator received.
curl -X POST "https://api.apif2f.com/v1/auth/2fa" \
-H "Authorization: Bearer $F2F_API_KEY" \
-H "Content-Type: application/json" \
-d '{
"auth_challenge_id": "ach_72e1f0",
"code": "482913"
}'Authentication FAQ
Start building on F2F today.
Free sandbox access, 1,000 monthly requests, no credit card. API automation and server-side ads tracking in one key.
Prefer email? hello@apif2f.com