> ## Documentation Index
> Fetch the complete documentation index at: https://docs.lorvia.online/llms.txt
> Use this file to discover all available pages before exploring further.

# API keys

> Connect an integration using a personal Lorvia API key.

Create a key in **Account → API keys**. Choose only the scopes your integration
needs. Copy the secret when it appears: it is shown once.

Send it in the `Authorization` header as `Bearer YOUR_KEY`. Keep the key in your
integration's secret store. Never place it in a URL or a public documentation file.

## Scopes

| Scope | Access |
| - | - |
| `campaigns:read` | Campaign and session reads |
| `lore:read` | Lore and notes reads |
| `lore:write` | Lore and notes writes; includes lore reads |
| `sessions:write` | Session and supported campaign-management writes |
| `mcp:tools` | Tool access through the local MCP bridge; also select resource scopes |

Scopes limit the key. They do not replace campaign membership, ownership or
role checks. A key cannot grant you access your account does not have.

## Verify a key

Call `GET https://www.lorvia.online/api/account/api-keys/whoami` with the bearer
header. A successful response contains `accountId`, `keyId` and `scopes`.
Campaign endpoints can return 404 for missing or unauthorized resources.
On 429, wait for the `Retry-After` interval before retrying.

## Replace or revoke a key

Create a replacement in Account → API keys, update your integration, verify it,
and revoke the previous key. Expired and revoked keys cannot authenticate.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.