Why Your FMP API Key Is Not Working: Authentication Checks Before Changing Your Request
You create an FMP account, copy the API key, make the request, and get an authentication error.
The first instinct is often to change the request. You try another ticker, switch endpoints, add parameters, or copy a different example. That can make the original problem harder to isolate. If the key is missing, copied incorrectly, or invalid, changing AAPL to MSFT does not address the failing part of the request.
Start by checking that the key is present, that its value matches the current key in your account, and that your request sends it correctly. Then confirm that the project is using the intended account. Once authentication works, you can investigate endpoint access, symbols, and missing data separately.
Key Takeaways
- Verify that the API key is present, complete, and included in the request being sent.
- Check the authentication format before changing the endpoint, symbol, or other parameters.
- Distinguish an explicit authentication error from an access restriction, an empty result, or a generic application error.
- If a simple documented request still fails, contact support with the request details and exact error, but never the key itself.
Check That the API Key Is Actually Being Sent
The first check is simple: is the request sending an API key at all?
FMP supports API-key authentication through an apikey parameter in the request URL or an apikey request header. A header sends the key separately from the URL.
The problem is often not that the user forgot to create a key. It is that the key never reaches the API. A Python script might store the key in a variable but never include that variable in the request. A notebook might reference a different variable from the one you updated. A spreadsheet might contain the key in a configuration cell while the formula points to a blank or different cell.
Start with a simple company profile request for AAPL:
|
https://financialmodelingprep.com/stable/profile?symbol=AAPL&apikey=YOUR_API_KEY |
Replace YOUR_API_KEY with your current key. The placeholder itself will not authenticate a request.
For this test, leave out date ranges and additional filters. You are checking whether the key is accepted for a basic request, not whether the entire project works.
A spreadsheet may display #VALUE!, a notebook may show a generic exception, or an app may simply say “Request failed.” Those messages do not tell you whether the key was transmitted or what FMP returned. Where your tool allows it, inspect the final request and the response from FMP.
Keep that inspection private, and remove API keys from shared files and screenshots before asking anyone else to review them. If the key is missing, correct the request and repeat the same test.
Check the Key for Spaces, Truncation, and Copying Errors
An API key can be present and still be the wrong value.
Copying errors are easy to miss because the visible difference between two values can be small. An extra space, a line break, a missing character, or an accidental quotation mark can change what the request sends.
Copy the current key directly from your FMP account dashboard rather than retyping it. Then check the value used by the request.
|
Check |
What to look for |
|
Beginning of the key |
No accidental space or extra character |
|
End of the key |
No trailing space or line break |
|
Complete value |
No missing or changed characters |
|
Quotation marks |
No quotation marks included in the transmitted key |
|
Account |
The key comes from the account you intend to use |
Quotation marks need particular care. In Python, quotation marks around a text value are normally part of the code's syntax, not part of the value sent to FMP. Spreadsheet formulas also use quotation marks to define text. Those marks are not automatically a problem.
The error occurs when quotation marks become part of the key itself, such as when they are pasted into the URL alongside the credential. Check what the request sends rather than removing quotation marks from working code or formulas.
Do not try to repair a key by guessing which characters belong in it. If you suspect a copying error, copy it again from the dashboard and repeat the simple request.
Check Where the apikey Is Being Sent
A correct API key can still fail when the request sends it incorrectly.
For URL authentication, use the documented parameter name apikey. The punctuation before it depends on whether the URL already contains another parameter:
- If apikey is the first parameter, use ?apikey=YOUR_API_KEY.
- If another parameter is already present, use &apikey=YOUR_API_KEY.
In the profile example, symbol=AAPL is the first parameter, so the key follows it with &apikey=. Do not add a second question mark. The order of the parameters is not the issue; each must be separated correctly.
If you use header authentication, enter the following name and value in your tool's request-header settings:
|
apikey: YOUR_API_KEY |
Here, apikey is the header name and YOUR_API_KEY is the value to replace. Writing that line in a notebook or storing it in a settings file does not send it automatically. The request must actually include the header.
This is a common source of confusion when moving between tools. A request may work in a browser because the key is explicitly included in the URL, then fail in a notebook because the notebook does not include it in either the URL or a header.
Reproduce the same simple request in the tool where the failure occurs. Check how that tool sends the key before changing the requested data.
Check Whether Your Project Is Still Using an Old Key
Sometimes the request is correctly formatted, but the project is transmitting an earlier credential.
A notebook may show an updated key in one cell while the request still uses a value loaded previously. A spreadsheet may have several configuration cells containing different keys. An application may read its settings only when it starts.
The key visible on your screen and the key reaching the API are not necessarily the same.
|
Where the request runs |
What to check |
|
Notebook |
The key-loading cell has run, and the request uses that value |
|
Spreadsheet |
The formula points to the correct configuration cell |
|
Application or script |
The running program has loaded the updated settings |
|
Multiple projects |
Each project uses the intended account's current key |
|
Recently changed setup |
An older saved value is not overriding the new one |
For example, changing a key in a local settings file does not necessarily update a program that is already running. If the program loads that file only at startup, it must reload its configuration or restart before using the new value.
Notebooks have a similar issue when cells run out of order. Rerun the cell that loads the key before rerunning the request. Editing the cell without executing it does not update the value already stored in the notebook session.
Once you have confirmed that the request uses the current key, repeat the same simple test. If it still returns an authentication error, move to the account check.
Check the Account Before Blaming the Endpoint
An FMP API key belongs to an account, so account details matter when authentication continues to fail.
Confirm that you are signed into the intended account and that the project uses its current key. This is particularly important when several accounts exist, a project was inherited from someone else, or credentials were copied between environments. Check for any account-status or billing notices that may require attention.
An invalid API key error is different from a message saying that an endpoint is unavailable under your plan. A valid key does not necessarily provide access to every dataset.
There are three separate questions:
- Does FMP accept the key?
- Can that account access the requested endpoint?
- Does the endpoint have data matching the request?
If the response identifies an access restriction, check which datasets your plan includes. If the response rejects the key itself, continue checking the credential and account.
Changing the subscription plan does not correct a key that was copied incorrectly. Likewise, replacing a valid key does not resolve a dataset-access restriction.
Know Whether You Are Looking at an Authentication Error or a Data Error
Not every failed response means the API key is broken. Read the message returned by FMP, not just the summary shown by your spreadsheet, notebook, or app.
An explicit missing-key or invalid-key message points toward authentication. A response stating that an endpoint is unavailable to the account points toward access. A generic “Request failed” message does not provide enough information to decide.
|
Response you receive |
What to investigate first |
|
Missing API key message |
Whether the request includes the key |
|
Invalid key or authentication error |
The copied value, request format, and account |
|
Endpoint-access restriction |
The account's permissions for that dataset |
|
Expected data from the test request |
Authentication worked for that request |
|
Empty result, such as [] |
The full response, then the symbol, filters, and coverage |
|
Generic application error |
The underlying response and error details |
An empty array, written as [], does not by itself prove that authentication succeeded. An application can hide or replace an underlying error with an empty result. Check the response returned by FMP, including its status code and any error message, before deciding that the endpoint simply found no records.
If authentication has been established and the response contains no matching data, investigate the symbol, endpoint, dates, and coverage. Replacing the key will not explain why a correctly authenticated request returned no records.
The distinction also works in the other direction. If FMP explicitly rejects the key, changing the ticker or adding date filters does not address that error.
If the Key Still Fails, Preserve the Smallest Failing Request
If you have checked the key, its placement, the project's saved settings, and the account, but the simple request still returns an authentication error, preserve that example and contact FMP support.
Provide enough information to reproduce the problem without exposing the credential.
|
Detail |
What to include |
|
Endpoint and parameters |
The endpoint path, symbol, and other parameters, with the key replaced by YOUR_API_KEY |
|
Authentication method |
URL parameter or request header |
|
Error |
The exact response text and HTTP status code, if available |
|
Tool |
Browser, notebook, spreadsheet, script, or application |
|
Account |
The account associated with the request |
|
Test time |
The date, approximate time, and time zone |
|
Checks completed |
Confirmation that you checked the current key, formatting, and saved settings |
Do not include the real key in the ticket, copied URL, request header, screenshot, or attached log. Check the error output too, since some tools include the request URL in their error messages.
Explain that the current account key fails on the simple request and describe the checks you completed. One reproducible example is easier to investigate than a list of unrelated requests with different symbols and parameters.
Use One Successful Request as Your Starting Point
Once the simple request works, keep it as a reference while you return to the project.
Test the intended endpoint, then the symbol, then any dates or filters. Change one part at a time so that a new failure is easier to trace.
The same approach helps when moving between tools. If the simple request works in one environment but fails in another, compare how each environment loads and sends the key. If it works in both, look at the additional settings in the larger request.
With authentication established, you can move on to choosing useful fields and building a small research output. A successful response gives you something concrete to work from instead of another guess about whether the key is being accepted.
FAQs
Why is my FMP API key not working?
Start by checking that the key is included, copied completely, and sent through a documented authentication method. Then confirm that the running request uses the current key from the intended account.
Where do I put my FMP API key?
Use an apikey parameter in the request URL or an apikey request header. In a URL, use ? before the first parameter and & before each additional parameter.
Can an extra space or quotation mark cause an authentication error?
Yes, if it becomes part of the value sent to FMP. Quotation marks used by Python or a spreadsheet formula to define text are different: they are normally syntax, not part of the transmitted key.
Why does the key work in one tool but not another?
The tools may be using different saved values or sending the key differently. Compare the same simple request in both, including the key-loading settings and authentication method.
Does an empty response mean my key is working?
Not necessarily. Check the actual response from FMP rather than relying on an empty display in your application. Once authentication is confirmed, an empty data response calls for symbol, filter, or coverage checks.
Should I change the endpoint when authentication fails?
Not as the first fix. Test the current key with one simple documented request. If FMP still rejects it after the formatting and account checks, send support the request details and exact error without including the key.

Risk analysis and financial modeling for data-driven market workflows
Parth Sanghvi is a Senior Risk Consultant with experience in financial modeling, valuation, and risk analysis. For FMP, he focuses on translating complex market data and risk models into clear, accessible analysis for developers and investors. His work centers on helping readers understand how institutional-grade financial data applies to real-world workflows and decision-making.
Financial data for every need
Real-time quotes and 30+ years of historical data, including prices, fundamentals, and insider transactions — all accessible via API.
Create Free Account