Authentication and keys
Every request is signed with an API key in the Authorization header. A key works only with its own account’s files and only within its permissions.
The Authorization header
Authorization: Bearer lac_api_YOUR_KEYKeys start with lac_api_. Never put a key in a URL or in public code, and don’t confuse it with your account’s secret sign-in key (lac_…): that one does not work for the API.
Creation, expiry and revocation
- Keys are created and revoked only in the console: API. The API cannot manage keys.
- A key lasts 7, 30 or 90 days or a year. After that, requests get 401
API_KEY_EXPIRED. - Revocation works at once: 401
API_KEY_REVOKED. An unknown key gets 401API_KEY_INVALID. - Suspending an account disables all its keys for good: after unblocking, create new ones.
- The lacuna app for Windows gets its key by itself, through the browser: Windows app.
Permissions
Give a key only the permissions it needs: a program that only sends files needs just content:write (the “Uploads only” preset). A method without its permission answers 403 SCOPE_REQUIRED with params.scope.
| Permission | What it allows | Methods |
|---|---|---|
content:read | Read files and notes | |
content:write | Upload and edit |
|
content:delete | Delete | |
account:read | Account, quota and limits |
Request log
Requests made with keys are shown in the console: API → Request log — method, path, status, time and key, the latest 100 requests from 30 days, with a filter by key. Actions on the site are not listed; request bodies and keys are never recorded.