Reference

Build on the Lucra API.

Drag a sticker to move it, or use the arrow keys while focused.

Authentication

API keys, OAuth, and the accounts they reach.

API keys

Owners and admins create keys in Settings → API and MCP, as read or write (access). A key starts with lucra_live_ and is shown once. Keep it on your server.

Terminal
curl https://api.onlucra.com/v1/account \
  -H "Authorization: Bearer $LUCRA_API_KEY" \
  -H "Lucra-Version: 2026-10-01"

Rotating or revoking a key takes effect immediately.

Act for another account

A key acts for its own account. A partner also reaches the brands it manages and its roster creators: send Lucra-Account: acct_… or crtr_…, or use lucra.as(id) in the SDK. An account the key can't reach returns 403 account_not_reachable.

OAuth

Use OAuth when your app acts for accounts it doesn't own: people sign in to Lucra and approve your app instead of handing you a key. AI clients on the MCP server use it too.

Run the authorization code flow with PKCE (S256):

StepEndpoint
AuthorizeGET https://api.onlucra.com/api/auth/oauth2/authorize
TokenPOST https://api.onlucra.com/api/auth/oauth2/token
RevokePOST https://api.onlucra.com/api/auth/oauth2/revoke
RegisterPOST https://api.onlucra.com/api/auth/oauth2/register
Discoveryhttps://api.onlucra.com/.well-known/oauth-authorization-server/api/auth

Send resource=https://api.onlucra.com/v1 and a scope of read, read write, and offline_access for a refresh token. The token then works like a key with that access, never beyond the person's own role.

A grant lasts until the person disconnects your app, leaves the account, or a year passes. An ended token returns 401 invalid_key; ask them to authorize again.