Every API request authenticates with a bearer token:
Getting an API key
Sign in at lavendly.ai and
create a key under Settings > API. Keys look like lv_<random> (agent keys
lv_ag_<random>). There is one environment, no sandbox. The key is shown once;
the key list afterwards shows only its first characters.
API keys are secrets. Treat them like passwords. The platform never
emails them back to you; if you lose one, rotate it from the
dashboard.
Token scopes
A single API key grants access to everything in your personal space: it
spends your own credits and sees your personal videos, never a workspace’s.
There are no per-operation scopes yet. To cap what an agent can spend on one
call, pass max_credits to generate and render.
An unknown or revoked key gets 401 unauthenticated with
reason: "api_key_invalid".
When you’re embedding Lavendly in another product
If you’re letting your own users render through your Lavendly
account, do not ship the key to the browser. Put your own auth
in front of any path that touches Lavendly and call the API
server-side with your key.
Recommended: idempotency on every paid call
Every mutating endpoint that costs money accepts Idempotency-Key.
The key is scoped to your account and kept for 24 hours: a retry returns the
same response, byte for byte, without running or charging again.
See Idempotency for the full pattern.