Before using this API you need credentials issued by LeanX:
- ACCESS KEY — identifies you, and is sent as the JWT's
kidandsubclaims. A random base64 string with a readable prefix. - A signing credential, whose kind depends on the authentication method LeanX selects for your integration: a SECRET KEY (a random base64 string) for
HS256, or a private/public key pair forRS256. See Authentication below.
The ACCESS KEY carries a prefix for convenience, e.g.
company-test-sIEUpUP7b41n51WYwhere the first part is your company tag, followed by a key usage hint and a random value.
Keep your ACCESS KEY private where you can, and never share your SECRET KEY or your RS256 private key.