Where is the API documentation?
Use developer.lexful.ai for the current API reference. The authentication guide explains how to obtain a token and make authenticated requests.
Where do I create credentials?
Open Platform → API keys as an administrator. Create a named key and securely store its Key ID and Secret, along with the Account ID displayed above the list.
See Create and manage API keys for creation, regeneration, and deletion steps.
Is the API key secret my Bearer token?
No. Exchange the Key ID and Secret at the authentication token endpoint. Use the returned access token in the Authorization Bearer header, and include the correct X-Account-ID header. Follow the authentication guide for renewal.
Can I retrieve a lost secret?
The secret is shown only when a key is created or regenerated. Regenerate it if it is lost, securely store the replacement, and update the integration. The old secret will no longer work for new authentication.
Can the API read and change everything?
No. Available operations depend on the endpoint and the request's access. An API key does not bypass account boundaries, authorization, or applicable IP restrictions. Check the current endpoint documentation for supported reads and writes.
Does Lexful support MCP?
See the MCP overview for setup and supported usage.
Are API requests unlimited?
Do not design an integration around unlimited requests. Handle throttling and temporary failures, avoid unnecessary polling, and follow any limits or retry guidance returned by the service or documented for the endpoint. Contact support if you need to confirm capacity for a particular workload.
Where should I test?
Use an agreed test account or clearly identified test data with appropriate access. Contact support if you need help arranging a suitable environment. Do not assume that every account includes a separate sandbox.
What should I send support when a request fails?
Include the endpoint, HTTP method, time, response status, and request identifier if available. Check the account header, token, permissions, and outbound IP first. Remove credentials and sensitive data from logs and screenshots before sharing them.
