Authentication
Two kinds of credentials: API keys for programs, wallet-signed sessions for the dashboard.
API keys (public API)
Every /v1/* request carries a bearer key. Keys are scoped; a key without the required scope gets 403 insufficient_scope.
Authorization: Bearer lcl_live_<kid>.<secret>Keys are hashed with a server-side pepper; the raw secret is shown once at creation. lcl_test_ keys are for test environments and follow the same rules.
Wallet sessions (dashboard)
The dashboard authenticates with an Ed25519 signature from your Solana wallet:
POST /dashboard/auth/challengewith your address returns a one-time message and nonce (expires in minutes, usable once).- Your wallet signs the message off-chain. No transaction, no fee.
POST /dashboard/auth/verifywith the challenge ID, signature and address sets an HttpOnly session cookie.
Dashboard mutations also require the header X-Requested-With: local and an allowed Origin (CSRF protection). The web app sends both automatically.
Sudo for sensitive actions
Administrative actions (catalog activation, pricing, refunds, reconciliation decisions) require a recent re-signature via POST /dashboard/auth/sudo. The dashboard prompts for it when needed.
Which to use
Use API keys in code and servers. Use the wallet session only in the browser. Never embed a session cookie in a program and never put a management-scoped key in a browser.
Who am I?
curl https://api.uselocal.sh/v1/me -H "Authorization: Bearer $LOCAL_API_KEY"
# → { "workspace": { "id", "name", "slug" }, "key": { "id", "name", "prefix", "scopes", "project_id" } }