Join our community of builders on Discord!

API Keys

A Developer API key authenticates /v1 calls (Authorization: Bearer lcai_...). Each key belongs to the wallet that minted it, and every completion made with it is paid from that wallet's prepaid balance. A wallet may hold up to 25 active keys: one per app or environment is the idea. Every key can call every /v1 route. Keys are managed with a wallet sign-in, not with a key: the routes below take the sign-in token as Authorization: Bearer <token>.

Sign in with your wallet

Sign-in is Sign-In with Ethereum (EIP-4361): an ordinary message signature that any wallet can make. No transaction, no gas.
  1. GET /api/auth/challenge?address=<your address> returns { "nonce", "message" }.
  2. Sign message with the wallet (personal_sign).
  3. POST /api/auth/verify with { "message", "signature" } returns { "token", "expiresAt", ... }. The token lasts an hour.
CodeTYPESCRIPT

Mint a key

CodeTYPESCRIPT
key appears in this response and never again. Only a hash of it is stored; store it like a password, server-side. A key has two settings, both optional; any other field of the request is ignored:
FieldMeaning
nameA label for you, up to 64 characters.
spendCapWeiWhat the key may spend in its lifetime, in wei, as a decimal string. No cap if omitted.
Rate and concurrency are the server's: every key is held to the same limits, and each key has its own budget at them. See Limits.

Spend cap

A completion reserves its job fee against the key's spendCapWei before it runs; a call that fails takes its reservation back. Once the next fee would pass the cap, completions answer 402 with code spend_cap_exceeded and the cap in error.spend_cap_wei. PATCH /api/api-keys/{id} with { "spendCapWei": "<wei>" } changes an active key's cap, and { "spendCapWei": null } removes it; the answer is the key as listed. A raised cap lets the key spend again from its next call. A cap may be set below what the key has already spent: its next completion is refused with spend_cap_exceeded. Any other field of the request is ignored, and a revoked key's cap no longer changes (409, error api_key_revoked). Only the wallet's sign-in changes a cap, never a key. The cap bounds what one key can spend. What the API can spend for your wallet in total is bounded on chain by the allowance you gave it: see Payment.

List, change, revoke and delete

CallDoes
GET /api/api-keysEvery key of the wallet, revoked ones included, newest first: id, prefix, name, spendCapWei, spentWei, how often each limit refused it (limitHits), createdAt, revokedAt. Never the key.
PATCH /api/api-keys/{id}Changes the key's spendCapWei: see Spend cap.
POST /api/api-keys/{id}/revokeRevokes the key at once (204). It stays in the listing by its prefix (lcai_ and seven characters), so a leaked key can be identified.
DELETE /api/api-keys/{id}Deletes a revoked key for good (204): it leaves the listing. An active key is refused with 409, error api_key_active: revoke it first.
A revoked or unknown key gets 401 with code invalid_api_key. A call already running when its key is revoked or deleted finishes and is answered. The request and response shapes of every route are in the API Reference.