Skip to content

Credentials

Before using this API you need credentials issued by LeanX:

  • ACCESS KEY — identifies you, and is sent as the JWT's kid and sub claims. A random base64 string with a readable prefix.
  • A signing credential, whose kind depends on the authentication method LeanX selects for your integration: a SECRET KEY (a random base64 string) for HS256, or a private/public key pair for RS256. See Authentication below.

The ACCESS KEY carries a prefix for convenience, e.g.

    company-test-sIEUpUP7b41n51WY

where the first part is your company tag, followed by a key usage hint and a random value.

Keep your ACCESS KEY private where you can, and never share your SECRET KEY or your RS256 private key.