What you can build
Use the Lexful API to read and maintain the records your integration is authorized to access. Common uses include inventory updates, documentation workflows, and connections to internal tools.
Start with the API reference for supported endpoints, request fields, and response examples. A custom integration needs its own mapping, scheduling, and error handling; obtaining API credentials does not start a sync.
Understand the data model
Account: the boundary for your Lexful workspace and API requests.
Organizations: the customers or business units within an account.
Asset types: the structure of a record, including its fields and relationships.
Assets: the individual records that use those types.
Select the correct account and organization context before reading or writing data. Use the type's field definitions rather than assuming every asset has the same properties.
Authenticate your integration
Create an API key under Platform → API keys.
Store the Account ID, Key ID, and Secret securely in your integration.
Exchange the Key ID and Secret for an access token using the token endpoint.
Send that token as a Bearer token, together with the
X-Account-IDheader, on API requests.
The secret is a credential used to obtain a token; it is not itself the Bearer token. Follow the authentication guide for the exact request and token renewal flow.
Access and security
API credentials do not provide unrestricted access to every account or record. Requests are subject to authentication, authorization, and applicable account restrictions. Keep credentials in a server-side secret store and out of browser code, screenshots, and source control.
If an operation is denied, check its required access, the account context, and any IP restrictions before changing the integration.
Choose the right integration approach
For a supported PSA or RMM, start with Connect and manage integrations. For a workflow you own, use Building custom integrations.
User sign-in and identity-provider provisioning are separate from a data integration. Do not assume an API connection automatically creates or removes Lexful users when your identity directory changes.
