Authentication
The two key types, where each one goes, and which scopes unlock which reports
Every FullVision request carries an API key. There are two kinds and they are not interchangeable.
Use this page when you are about to paste a key somewhere and want to know which one, and what it will and won't reach.
The two key types
| Key | Prefix | Where it goes | Why |
|---|---|---|---|
| Publishable | pk_ | The tracker <script> tag on your website | It ships to every visitor's browser by design. It can only record pageviews. |
| Secret | sk_ | Your server, a cURL call, an environment variable, an MCP client config | It reads your data and writes events. Anyone holding it holds your analytics. |
Never put an sk_ key in a <script> tag, in client-side JavaScript, or in
anything a visitor can view-source. Use the pk_ key there — that is what it
is for.
Both come from the dashboard: the publishable key is rendered into the tracker snippet on the Setup page, and secret keys are minted under Settings → API keys.
Reading data — REST API
Pass a secret key as a Bearer token against https://data.fullvision.io:
curl -H "Authorization: Bearer $FULLVISION_API_KEY" \
"https://data.fullvision.io/channel-report?range=last_30_days"Read scopes
A secret key carries scopes. A report is served only when the key carries
every scope that report declares — a key holding three of four scopes is
refused with auth_scope_insufficient, and
the error names the first scope that is missing.
| Scope | What it unlocks |
|---|---|
read:* | Every report and entity on this site. The simplest choice for a dashboard or an AI agent. |
web:read | Traffic: visitors, page views, sessions, devices, countries. |
attribution:read | Which channel, page, keyword, campaign or form a customer came from. |
search:read | Google Search Console metrics — clicks, impressions, CTR, position. |
revenue:read | Stripe revenue figures. |
customer:read | Named people and their event timelines. This is the personal-data scope. |
read:* satisfies every *:read scope above, so a read:* key reaches all nine
endpoints.
What each endpoint needs
| Endpoint | Scopes the key must carry |
|---|---|
/page-report | attribution:read and revenue:read and search:read and web:read |
/channel-report | attribution:read and web:read |
/keyword-report | attribution:read and search:read and web:read |
/ad-report | attribution:read and web:read |
/email-report | attribution:read and web:read |
/form-report | attribution:read and customer:read and web:read |
/visitors | web:read |
/people | customer:read |
/journeys | customer:read |
Writing data
Server-side events and person traits go to https://db.fullvision.io with a
secret key carrying events:write — see
Server-side events. The tracker script uses the
publishable key instead, and needs no scope of its own.
MCP Server
Include a read-scoped secret key in the headers of your MCP client config:
{
"mcpServers": {
"fullvision": {
"url": "https://data.fullvision.io/mcp",
"headers": {
"Authorization": "Bearer sk_your_key"
}
}
}
}Replace sk_your_key with your FullVision API key.
