API Key Authentication
LexQ uses API keys to authenticate all API requests. Include your key in thex-api-key header:
Obtaining an API Key
- Log in to the LexQ Console
- Navigate to Management → API Keys
- Click Create API Key
- Copy the key immediately — it will not be shown again
lexq_us_ followed by a Base64 string (e.g., lexq_us_a1b2c3d4e5f6...).
Key Management
Revoked keys cannot be reactivated. If a key is compromised, revoke it immediately and create a new one.
Security Best Practices
- Never expose API keys in client-side code, public repositories, or browser requests
- Use environment variables or secret managers to store keys
- Rotate keys periodically
- Use separate keys for development and production environments
- Each key is scoped to a single tenant — there is no cross-tenant access
Scope
A single API key grants access to both the Management API (/api/v1/partners) and the Execution API (/api/v1/execution) for the same tenant.
Rate Limits
API requests are throttled based on your plan’s TPS (transactions per second) limit:
Exceeding the limit returns HTTP
429 Too Many Requests.
