Skip to content

Authentication and keys

Every request is signed with an API key in the Authorization header. A key works only with its own account’s files and only within its permissions.

Creation, expiry and revocation

  • Keys are created and revoked only in the console: API. The API cannot manage keys.
  • A key lasts 7, 30 or 90 days or a year. After that, requests get 401 API_KEY_EXPIRED.
  • Revocation works at once: 401 API_KEY_REVOKED. An unknown key gets 401 API_KEY_INVALID.
  • Suspending an account disables all its keys for good: after unblocking, create new ones.
  • The lacuna app for Windows gets its key by itself, through the browser: Windows app.

Permissions

Give a key only the permissions it needs: a program that only sends files needs just content:write (the “Uploads only” preset). A method without its permission answers 403 SCOPE_REQUIRED with params.scope.

Request log

Requests made with keys are shown in the console: API → Request log — method, path, status, time and key, the latest 100 requests from 30 days, with a filter by key. Actions on the site are not listed; request bodies and keys are never recorded.

Methods

Authentication and keys · lacuna API