FullVision

Authentication

The two key types, where each one goes, and which scopes unlock which reports

Every FullVision request carries an API key. There are two kinds and they are not interchangeable.

Use this page when you are about to paste a key somewhere and want to know which one, and what it will and won't reach.

The two key types

KeyPrefixWhere it goesWhy
Publishablepk_The tracker <script> tag on your websiteIt ships to every visitor's browser by design. It can only record pageviews.
Secretsk_Your server, a cURL call, an environment variable, an MCP client configIt reads your data and writes events. Anyone holding it holds your analytics.

Never put an sk_ key in a <script> tag, in client-side JavaScript, or in anything a visitor can view-source. Use the pk_ key there — that is what it is for.

Both come from the dashboard: the publishable key is rendered into the tracker snippet on the Setup page, and secret keys are minted under Settings → API keys.

Reading data — REST API

Pass a secret key as a Bearer token against https://data.fullvision.io:

curl -H "Authorization: Bearer $FULLVISION_API_KEY" \
  "https://data.fullvision.io/channel-report?range=last_30_days"

Read scopes

A secret key carries scopes. A report is served only when the key carries every scope that report declares — a key holding three of four scopes is refused with auth_scope_insufficient, and the error names the first scope that is missing.

ScopeWhat it unlocks
read:*Every report and entity on this site. The simplest choice for a dashboard or an AI agent.
web:readTraffic: visitors, page views, sessions, devices, countries.
attribution:readWhich channel, page, keyword, campaign or form a customer came from.
search:readGoogle Search Console metrics — clicks, impressions, CTR, position.
revenue:readStripe revenue figures.
customer:readNamed people and their event timelines. This is the personal-data scope.

read:* satisfies every *:read scope above, so a read:* key reaches all nine endpoints.

What each endpoint needs

EndpointScopes the key must carry
/page-reportattribution:read and revenue:read and search:read and web:read
/channel-reportattribution:read and web:read
/keyword-reportattribution:read and search:read and web:read
/ad-reportattribution:read and web:read
/email-reportattribution:read and web:read
/form-reportattribution:read and customer:read and web:read
/visitorsweb:read
/peoplecustomer:read
/journeyscustomer:read

Writing data

Server-side events and person traits go to https://db.fullvision.io with a secret key carrying events:write — see Server-side events. The tracker script uses the publishable key instead, and needs no scope of its own.

MCP Server

Include a read-scoped secret key in the headers of your MCP client config:

{
  "mcpServers": {
    "fullvision": {
      "url": "https://data.fullvision.io/mcp",
      "headers": {
        "Authorization": "Bearer sk_your_key"
      }
    }
  }
}

Replace sk_your_key with your FullVision API key.

On this page