Skip to content

Environments and keys

Production Sandbox
API base URL https://api.luxorr.io/api/public/v1 https://api.sandbox.luxorr.io/api/public/v1
Key prefix lxr_live_ lxr_sbx_
GET /me → environment production sandbox
Gift site for personal links gifts.luxorr.io gifts.sandbox.luxorr.io
Docs docs.luxorr.io docs.sandbox.luxorr.io
  • Separate data. The sandbox has its own accounts, catalog and campaigns. IDs from one environment do not exist in the other.
  • Same behaviour. Sandbox emails are delivered, so use addresses you control. Order statuses change only when Luxorr changes them; ask your Luxorr contact to move a test order to SENT or COMPLETED.
  • Browser calls. Try-it in the API reference calls the sandbox. Production does not accept browser calls; call it from your servers.

A key is lxr_live_ or lxr_sbx_ followed by 32 random characters:

Authorization: Bearer lxr_live_7Hk2…
  • Environment. A sandbox key sent to production, or the reverse, answers 401 invalid_api_key.
  • Shown once. Luxorr stores only a hash. If a key is lost, create a new one and revoke the old one.
  • Prefix. Lists show the first 12 characters, such as lxr_live_7Hk.
  • Server side only. Never put a key in a browser, an app or a repository.

One tenant. A key belongs to one tenant: one operator’s Luxorr account. Another tenant’s record answers 404 not_found.

Brands. GET /me returns brandIds. null means every brand of the tenant, including brands added later. A key limited to some brands:

  • sees only the orders, personal links, campaigns and events of those brands;
  • gets 404 not_found for an order or link of another brand;
  • gets brand_not_found when it places an order or sends links under another brand.

Scopes. Each scope covers reads and writes.

Scope Endpoints
CATALOG /catalog/categories, /catalog/products, /campaigns
ORDERS /orders and order messages
PERSONAL_LINKS /personal-links
any scope /me, /brands, /events, /webhooks:test

A missing scope answers 403 insufficient_scope. Order events go only to keys with ORDERS. Personal-link events go only to keys with PERSONAL_LINKS.

Keys are created by Luxorr staff or by the tenant’s Administrator in the Luxorr workspace, under Settings → API access. On that page the Administrator can:

  • name a key and limit it to brands and scopes;
  • set the webhook URL, send a test event and see recent deliveries;
  • rotate the webhook signing secret;
  • revoke the key. A revoked key is refused from the next call.

Use one key per system, for example one for the shop and one for the CRM. Each can be revoked alone, and orders and messages show which key created them.

API access is off for each tenant until Luxorr switches it on. Only Luxorr changes it. The tenant’s Administrators get an email on each change.

While access is off:

  • every key of the tenant answers 401 invalid_api_key;
  • webhooks pause. Events are still recorded;
  • keys cannot be created, edited or tested, and webhook secrets cannot be rotated.

Administrators can still view existing keys and webhook deliveries, and revoke keys. When access is switched on again, the same keys work and paused webhooks are delivered.

If a working key starts to answer 401, it was revoked or API access was switched off.