Get started
Your API key
Every request carries your API key. The same key works for the API and for the MCP server.
Send your key
Put it in the Authorization header, after the word Bearer.
- The key is only read from that header. A key written in the address is not accepted: an address ends up in logs, in browser history and in
Refererheaders. - A missing or wrong key gets the error
unauthorized, with status 401. - Too many wrong keys from the same IP address are slowed down with
rate_limited.
Create and copy a key
Keys are made in the dashboard, under Connect.
- A key starts with
lss_live_, followed by 40 letters and digits. - The dashboard shows only the start of a key. Its Copy button gives you the whole key again, any time.
- You can have up to 10 active keys. A key you have just rotated keeps working for its last 24 hours on top of those. Give each key a name that says where it is used.
Rotate a key
Rotating a key gives you a new one and keeps the old one working for 24 hours, so you have time to replace it where it is used. After that the old key stops.
Revoke a key
Revoking a key stops it right away. Use it when a key may have leaked.
Keep it secret
- Read the key from an environment variable or a secret store. Do not write it in code you share.
- Never call the API from a web page or a mobile app: anyone could read the key there. Call it from your server.
- Credits and limits belong to the account, not to a key. Making more keys does not raise a limit.
A key works without a password. Anyone who has it can spend your credits. If you pasted one somewhere public, revoke it and create another.