Skip to content

Upcoming Change in 23.0.0: Authentication Required for the Config and Version APIs

Change

Starting in Flywheel 23.0.0, the /api/config and /api/version endpoints require authentication. Unauthenticated requests to either endpoint are rejected with an HTTP 401 Unauthorized response.

Before 23.0.0, both endpoints answer requests from any client, including clients that have not signed in. Requests made with a valid API key, including all requests made through the Flywheel web application, continue to work as before.

Purpose

Neither endpoint returns sensitive data. Flywheel is making this change as part of ongoing security hardening to reduce what an anonymous party can learn about a site.

Version and configuration details help an attacker plan an attack against a site. Requiring authentication removes this information from public view and brings these endpoints in line with the rest of the Flywheel API.

Not Affected

Use of the Flywheel SDK and the Flywheel CLI that authenticates with a User API Key or a Device API Key is not affected. This includes:

  • Scripts and notebooks that use the Flywheel SDK with an API key
  • Gears that use the Flywheel SDK
  • The New CLI (flyw) and the Legacy CLI (fw) after signing in with an API key

These tools already send the API key with every request, including requests to /api/config and /api/version. Existing versions continue to work, so you do not need to upgrade the SDK or CLI for your site's move to 23.0.0.

Who Is Affected

Integrations that call /api/config or /api/version directly without an API key. These integrations must be updated before your site upgrades to 23.0.0 so that their requests are authenticated. Common examples include:

  • Monitoring and health-check systems that poll /api/version to confirm a site is up or to record its version
  • Integrations that call /api/version or /api/config before authenticating to discover site settings
  • Ad hoc curl commands or browser bookmarks that open these endpoints directly

Requests that already send a User API Key or a Device API Key are not affected.

Before your site upgrades to Flywheel 23.0.0:

  1. Search your scripts, monitoring configuration, and integrations for direct calls to /api/config and /api/version. You can skip anything that goes through the Flywheel SDK or CLI.
  2. Add an API key to each call, as you would for any other Flywheel API request. Use a Device API Key for automated systems and a User API Key for scripts that run on behalf of a person. Send the key in the Authorization header as a bearer token. For example:

    curl -H "Authorization: Bearer $FW_API_KEY" https://your-site.flywheel.io/api/config
    

    Flywheel displays API keys with a host prefix, such as your-site.flywheel.io:abc123. The prefix is accepted, but sending only the part after the colon is recommended.