# Lago API authentication

Lago's public REST API uses bearer API keys. Send the key in the `Authorization` header on every request.

```http
Authorization: Bearer LAGO_API_KEY
Content-Type: application/json
```

## Base URLs

- US Lago Cloud: `https://api.getlago.com/api/v1`
- EU Lago Cloud: `https://api.eu.getlago.com/api/v1`
- Self-hosted: your Lago API origin followed by `/api/v1`

## Getting and managing a key

Create and manage API keys in Lago under **Developers → API keys**. Keys are organization credentials: store them in a secret manager, never expose them in browser code or logs, and rotate or revoke them when access changes.

## Permissions

API keys can be scoped to `read`, `write`, or `read_write` access for individual API resources. Grant only the resources and actions the integration needs.

## Errors

- `401 Unauthorized`: the bearer key is missing, invalid, or revoked.
- `403 Forbidden`: the key is valid but lacks permission for the requested operation.
- `422 Unprocessable Entity`: the authenticated request has invalid fields or violates a business rule.

Treat `401` and `403` as non-retryable until credentials or permissions change. Follow rate-limit and retry guidance in the API documentation for transient failures.

## OAuth and agent-auth discovery

The Lago REST API currently uses scoped API keys rather than an OAuth authorization-code flow. It does not publish `oauth-protected-resource`, `oauth-authorization-server`, or `agent_auth` dynamic registration metadata, and there is no `register_uri` or OAuth token endpoint to discover. Agents should use the server-side bearer API-key flow above and must not invent an OAuth flow.

## References

- [API key guide](https://getlago.com/docs/guide/security/api-keys)
- [API standards](https://getlago.com/docs/api-reference/api-standards)
- [Complete OpenAPI specification](https://getlago.com/api/openapi.yaml)
