API keys
Scoped, revocable keys for machine access to your company data. Shown once, stored only as a hash, and never able to reach settings, people or security.
Settings → API & Webhooks → API keys. Creating and revoking keys needs a company administrator (or the api.keys.manage permission).
How do I create a key? New key, give it a name (so you know what to revoke later), tick its scopes and optionally an expiry date, then Create key. A key needs at least one scope.
The scopes are read or write per area: read:accounting / write:accounting, read:sales / write:sales, read:purchases / write:purchases, read:banking / write:banking, read:inventory / write:inventory, read:projects / write:projects, and read-only read:reports, read:taxes and read:payroll. A write scope includes the matching read. Reports, taxes and payroll cannot be changed through the API at all.
The key is shown exactly once. Only a SHA-256 hash is stored, so a database leak cannot be replayed against your account — and it also means nobody can show it to you again. If you lose it, revoke it and issue another.
Using it: send it in the Authorization header as the word Bearer followed by the key (it starts lp_). A key belongs to one company, so no company header is needed. To read your books into Excel, Power BI or Tableau, the same key is the password — see A live link to Excel, Power BI or Tableau (OData).
What a key can never reach. Keys reach company data only — accounting, sales, purchases, banking, inventory, projects, reports, taxes and payroll. Settings, people and roles, security, integrations, mail, text messages, other API keys and webhooks are refused, so a key cannot make another key or change who has access. A key also never does more than the person who created it: narrow that person's role, or deactivate them, and their keys narrow or stop with it.
Limits. Each key may make 3,000 requests in ten minutes; past that it is paused for ten minutes.
Revoking takes effect immediately; a revoked key stays in the list marked Revoked.
Every key records when it was last used and how many requests it has made, so an unused key is easy to spot and retire.
One detail for integrators. An unknown path under /api answers with the same JSON error envelope as every other error (ERR-GEN-001 with the method and path), never an HTML page.