Skip to main content
Every public API operation requires an API key in the Authorization header.
Keys start with lasso_. The current key format contains 32 random bytes encoded as 64 hexadecimal characters after the prefix.

Create a key

Open the Lasso dashboard, go to Settings > API Keys, and create a key. You need the Manage API keys permission (developer.manage_api_keys).
The raw key is returned once. Store it in a secret manager or environment variable. If you lose it, deactivate the key and create another one.

Company scope

Each API key belongs to one company. The server derives the company from the key; requests cannot select another tenant. Use a separate key for each environment or integration.

Example

Authentication errors

A missing header, invalid prefix, unknown key, or inactive key returns 401 unauthenticated in the standard error envelope.