Management API keys
lr_platform_ keys authenticate requests to the platform management API
(/admin/v1/*) without a browser session. They are for automation — CI jobs,
provisioning scripts, internal tooling — and are separate from inference
lr_ keys: a platform key can never call an inference endpoint, and an
inference key can never call the management API.
Authenticate
Section titled “Authenticate”Send the key as a bearer token:
curl -H "Authorization: Bearer lr_platform_<key>" \ https://api.lunaroute.com/admin/v1/providersScopes
Section titled “Scopes”Every key carries a set of scopes named <family>:read or <family>:write.
GET and HEAD need :read; every other method needs :write. A :write
scope implies :read.
| Family | Covers |
|---|---|
stats |
/admin/v1/stats, /admin/v1/usage-stats |
organizations |
/admin/v1/organizations/* |
plans |
/admin/v1/plans/* |
providers |
/admin/v1/providers/* |
platform-credentials |
/admin/v1/platform-credentials/* |
inference-models |
/admin/v1/inference-models/*, /admin/v1/inference-model-pools, /admin/v1/inference-tokenizer-profiles |
search |
/admin/v1/search-providers, /admin/v1/search-settings |
stripe |
/admin/v1/stripe/* |
referrals |
/admin/v1/referrals/* |
capability-policies |
/admin/v1/capability-policies/* |
users |
/admin/v1/users/* (except impersonation and platform-admin grants) |
audit-logs |
/admin/v1/audit-logs |
scheduler-endpoints |
/admin/v1/scheduler-endpoints/* |
invite-codes |
/admin/v1/invite-codes/* |
billing |
/admin/v1/billing/* |
Keys can never reach /admin/v1/platform-keys/* (a key cannot mint, widen, or
revoke keys), /admin/v1/users/:id/impersonate, or
/admin/v1/users/:id/platform-admin, regardless of scopes.
Lifecycle
Section titled “Lifecycle”Keys have no expiry. Revoke one from the admin UI or
DELETE /admin/v1/platform-keys/:id. A key stops working immediately when it
is revoked, when its owner is demoted from platform admin, or when its owner
is deleted. The raw key is shown once at creation and never stored.