API keys
Owners and admins create keys in Settings → API and MCP, as read or write (access). A key starts with lucra_live_ and is shown once. Keep it on your server.
curl https://api.onlucra.com/v1/account \
-H "Authorization: Bearer $LUCRA_API_KEY" \
-H "Lucra-Version: 2026-10-01"
Rotating or revoking a key takes effect immediately.
Act for another account
A key acts for its own account. A partner also reaches the brands it manages and its roster creators: send Lucra-Account: acct_… or crtr_…, or use lucra.as(id) in the SDK. An account the key can't reach returns 403 account_not_reachable.
OAuth
Use OAuth when your app acts for accounts it doesn't own: people sign in to Lucra and approve your app instead of handing you a key. AI clients on the MCP server use it too.
Run the authorization code flow with PKCE (S256):
| Step | Endpoint |
|---|---|
| Authorize | GET https://api.onlucra.com/api/auth/oauth2/authorize |
| Token | POST https://api.onlucra.com/api/auth/oauth2/token |
| Revoke | POST https://api.onlucra.com/api/auth/oauth2/revoke |
| Register | POST https://api.onlucra.com/api/auth/oauth2/register |
| Discovery | https://api.onlucra.com/.well-known/oauth-authorization-server/api/auth |
Send resource=https://api.onlucra.com/v1 and a scope of read, read write, and offline_access for a refresh token. The token then works like a key with that access, never beyond the person's own role.
A grant lasts until the person disconnects your app, leaves the account, or a year passes. An ended token returns 401 invalid_key; ask them to authorize again.