GET /users/me against the live API. You need a Fanvue creator account, or an agency admin account, with a verified email, plus curl and openssl on your machine.
Fanvue has no API keys. A creator or agency admin authorises your app through OAuth 2.0 and you call the API with the access token you receive. The authentication overview explains the flow in full; here you run it once by hand.
1
Create the app
Open the Developer Area at
https://www.fanvue.com/dev. On your first visit, click Create developer profile. Then click Create app, give the app a name and click Create. Creating an app means accepting the Fanvue Developer Terms of Service and Developer Policy.Only create apps for a service you operate. The client secret you’re about to receive acts on your account, so handing it to someone else gives them that access. If you want to connect your account to another developer’s app, use that app’s Connect button instead.2
Save the client secret
The dialog that opens shows your Client ID and Client Secret. Copy the secret into your secrets manager before you close the dialog.Your app is registered as one confidential OAuth client with the
authorization_code and refresh_token grants. There is no public client option, no personal access token and no client-credentials grant. Every access token comes from a user signing in.3
Pick API only
On App details, open the app type select and choose API only. API-only apps aren’t listed in the App Store; creators connect to them through OAuth. The page offers a Get your OAuth credentials button that opens the Authentication tab.The type isn’t final. You can change it later on the same select, and Choose your app type explains what the other two types add.
4
Set the redirect URI and scopes
On the Authentication tab, add the exact redirect URI your code will send and tick the scopes your app needs. Both apply when you save. An API-only app needs no app domain and no App Manifest.A redirect URI uses
https:// on any host and port, or http:// on localhost, 127.0.0.1 or [::1]. For this walkthrough add http://localhost:3000/callback and tick read:self.Sign in with your creator account when you run the flow. A fan account that authorises an app receives only read:self and the chat, media and experience scopes, whatever the app requests.5
Get a token with curl
PKCE is mandatory, so start by generating a verifier and its S256 challenge:
openid, offline_access and offline are the system scopes every authorisation request carries, and read:self is the scope you ticked. The state value is a random string you check when the browser comes back.http://localhost:3000/callback?code=...&state=.... Nothing needs to listen on that port: copy the code value from the address bar and check that state matches the value you sent.Now exchange the code for tokens. The code is single-use.-u flag sends your Client ID and Client Secret as an HTTP Basic Auth header. Every Fanvue app is registered with the client_secret_basic method, so credentials placed in the POST body are rejected with invalid_client. The code_verifier is the other half of PKCE: it binds the code to the browser session that started the flow, while the secret proves the request comes from your server.access_token is short-lived and expires_in is its lifetime in seconds. refresh_token gets you a new access token without another sign-in; see Token refresh when you get that far.6
Call GET /users/me
Send the access token as a Bearer token and pin the API version with A successful call returns A
X-Fanvue-API-Version: 2025-06-26. Send the header on every request: a request without it is served the current default version, which moves when a new version becomes current.- curl
- Python
- JavaScript
200 OK and your account:401 Unauthorized means the token is missing, expired or malformed: check that the header reads Bearer, one space, then the token, or exchange a new code. A 403 Forbidden means the token lacks a scope the endpoint needs.Next steps
You’re rate limited to 200 requests per minute per user per app by default; higher limits are available to agencies on request. From here, pick the path that matches what you’re building.Choose your app type
Stay API-only, or add an App URL or embed settings to list on the App Store.
Sign in with Fanvue
Add Sign in with Fanvue to a web app with the Fanvue App Starter.
Authentication overview
The OAuth 2.0 flow in full, with refresh and error handling.
Rate limits
How the budget is counted and what a
429 carries.What you can build
Listing, billing, fan experiences and the Builder SDK.