Environments and keys
Environments
Section titled “Environments”| Production | Sandbox | |
|---|---|---|
| API base URL | https://api.luxorr.io/api/public/v1 |
https://api.sandbox.luxorr.io/api/public/v1 |
| Key prefix | lxr_live_ |
lxr_sbx_ |
GET /me → environment |
production |
sandbox |
| Gift site for personal links | gifts.luxorr.io |
gifts.sandbox.luxorr.io |
| Docs | docs.luxorr.io |
docs.sandbox.luxorr.io |
- Separate data. The sandbox has its own accounts, catalog and campaigns. IDs from one environment do not exist in the other.
- Same behaviour. Sandbox emails are delivered, so use addresses you control. Order statuses change only when Luxorr changes them; ask your Luxorr contact to move a test order to
SENTorCOMPLETED. - Browser calls. Try-it in the API reference calls the sandbox. Production does not accept browser calls; call it from your servers.
A key is lxr_live_ or lxr_sbx_ followed by 32 random characters:
Authorization: Bearer lxr_live_7Hk2…- Environment. A sandbox key sent to production, or the reverse, answers
401 invalid_api_key. - Shown once. Luxorr stores only a hash. If a key is lost, create a new one and revoke the old one.
- Prefix. Lists show the first 12 characters, such as
lxr_live_7Hk. - Server side only. Never put a key in a browser, an app or a repository.
What a key reaches
Section titled “What a key reaches”One tenant. A key belongs to one tenant: one operator’s Luxorr account. Another tenant’s record answers 404 not_found.
Brands. GET /me returns brandIds. null means every brand of the tenant, including brands added later. A key limited to some brands:
- sees only the orders, personal links, campaigns and events of those brands;
- gets
404 not_foundfor an order or link of another brand; - gets
brand_not_foundwhen it places an order or sends links under another brand.
Scopes. Each scope covers reads and writes.
| Scope | Endpoints |
|---|---|
CATALOG |
/catalog/categories, /catalog/products, /campaigns |
ORDERS |
/orders and order messages |
PERSONAL_LINKS |
/personal-links |
| any scope | /me, /brands, /events, /webhooks:test |
A missing scope answers 403 insufficient_scope. Order events go only to keys with ORDERS. Personal-link events go only to keys with PERSONAL_LINKS.
Key management
Section titled “Key management”Keys are created by Luxorr staff or by the tenant’s Administrator in the Luxorr workspace, under Settings → API access. On that page the Administrator can:
- name a key and limit it to brands and scopes;
- set the webhook URL, send a test event and see recent deliveries;
- rotate the webhook signing secret;
- revoke the key. A revoked key is refused from the next call.
Use one key per system, for example one for the shop and one for the CRM. Each can be revoked alone, and orders and messages show which key created them.
API access switch
Section titled “API access switch”API access is off for each tenant until Luxorr switches it on. Only Luxorr changes it. The tenant’s Administrators get an email on each change.
While access is off:
- every key of the tenant answers
401 invalid_api_key; - webhooks pause. Events are still recorded;
- keys cannot be created, edited or tested, and webhook secrets cannot be rotated.
Administrators can still view existing keys and webhook deliveries, and revoke keys. When access is switched on again, the same keys work and paused webhooks are delivered.
If a working key starts to answer 401, it was revoked or API access was switched off.