Authentication
Send `Authorization: Bearer <token>` on every request except the public catalog, signup, login and health checks.
Send Authorization: Bearer <token> on every request except the public catalog, signup, login and health checks.
| Token | Looks like | For | Lifetime |
|---|---|---|---|
| Session | lb_sess_… | People and dashboards. Created by signup or login. | 7 days, or until you log out |
| API key | lb_live_… | Programs and CI. Created with POST /v1/api-keys. | Until revoked or its expires_at |
Tokens are shown once and stored only as hashes; if you lose one, create another. A revoked key stops working immediately. Call GET /v1/me to check what a token can do.
An API key carries the scopes you choose when creating it (least privilege):
| Scope | Allows |
|---|---|
vm:read | List and read servers, quotes, firewall rules and operations |
vm:write | Buy, delete, start, stop, reboot servers; open the console; change firewall rules |
ssh_key:read / ssh_key:write | List / add and delete SSH keys |
billing:read | Read the wallet, its transactions, payment methods and payments |
billing:write | Start a USDC wallet top-up |
API keys cannot manage API keys, members or the audit log. Those need a session with the right role.
Quickstart
The whole flow in `curl`. Each step is explained in the reference below.
Organizations and roles
Every user belongs to at least one organization (signup creates yours). Servers and SSH keys belong to the organization. Credit, payment history and wallet transactions belong to the authenticated use