Skip to main content
Every request to the Lusha API must include your API key. The API uses a simple key-based scheme - there are no OAuth flows or token exchanges. You pass a single header, and the server authenticates the request before processing it.

Get your API key

1

Sign up or log in

Go to lusha.com and create an account, or log in if you already have one.
2

Open the API dashboard

Generate and retrieve your API key from the Lusha API Dashboard. Copy it to a secure location.
Only account admins and managers with API feature access can view the API dashboard page.

Authenticate requests

Pass your API key in the api_key header on every request to https://api.lusha.com. The security scheme is named ApiKeyAuth.
The header name is api_key (lowercase, with an underscore). Using a different casing or header name will cause the request to be rejected.
Want to authenticate without writing code first? Import the Lusha Postman Workspace, add your API key as a collection variable, and every request in the collection picks it up automatically.

Authentication errors

If your API key is missing or invalid, the API returns a 401 Unauthorized response:
Check the following if you receive a 401:
  • Confirm the api_key header is present on the request.
  • Verify you are using the correct key from the API dashboard.
  • Ensure the key has not been revoked or regenerated since you last copied it.
Keep your API key secret. Do not commit it to version control, embed it in client-side code, or share it publicly. If a key is exposed, regenerate it immediately from the API dashboard.

Next steps

Once authentication is working, review the rate limits to understand request quotas and how to handle 429 responses in your integration.