Skip to content
Documentation menu

Authentication

Two kinds of credentials: API keys for programs, wallet-signed sessions for the dashboard.

API keys (public API)

Every /v1/* request carries a bearer key. Keys are scoped; a key without the required scope gets 403 insufficient_scope.

http
Authorization: Bearer lcl_live_<kid>.<secret>

Keys are hashed with a server-side pepper; the raw secret is shown once at creation. lcl_test_ keys are for test environments and follow the same rules.

Wallet sessions (dashboard)

The dashboard authenticates with an Ed25519 signature from your Solana wallet:

  1. POST /dashboard/auth/challenge with your address returns a one-time message and nonce (expires in minutes, usable once).
  2. Your wallet signs the message off-chain. No transaction, no fee.
  3. POST /dashboard/auth/verify with the challenge ID, signature and address sets an HttpOnly session cookie.

Dashboard mutations also require the header X-Requested-With: local and an allowed Origin (CSRF protection). The web app sends both automatically.

Sudo for sensitive actions

Administrative actions (catalog activation, pricing, refunds, reconciliation decisions) require a recent re-signature via POST /dashboard/auth/sudo. The dashboard prompts for it when needed.

Which to use

Use API keys in code and servers. Use the wallet session only in the browser. Never embed a session cookie in a program and never put a management-scoped key in a browser.

Who am I?

bash
curl https://api.uselocal.sh/v1/me -H "Authorization: Bearer $LOCAL_API_KEY"
# → { "workspace": { "id", "name", "slug" }, "key": { "id", "name", "prefix", "scopes", "project_id" } }