Skip to main content

Security & API Keys

Your Lumio account uses user API keys for programmatic access — to the CLI, CI/CD pipelines, and the Developer REST API. This page explains how keys work and best practices for keeping them secure.

API keys​

User API keys are personal credentials scoped to your active account. They are used by:

  • The lumio CLI (lumio login --token <key>)
  • CI/CD pipelines running lumio deploy
  • Direct calls to the Developer REST API

Creating a key​

  1. Open lumio.vision
  2. Navigate to Dashboard → API Keys
  3. Click Create API key
  4. Enter a label (e.g. ci-github-actions)
  5. Select the permissions the key should carry
  6. Optionally set an expiry
  7. Copy the key — it is shown only once

Keys are prefixed with lm_usr_. Lumio stores only a hash of the key, so the full secret cannot be recovered after creation.

Key permissions​

Each API key carries the permissions selected at creation time. A key can never grant more permissions than the user who creates it; the backend rejects any permission the creator does not currently hold.

Revoking a key​

Revoke a key from Dashboard → API Keys. Revocation hard-deletes the key, so it cannot be restored.

Rotation recommendation​

Rotate API keys every 90 days or immediately when:

  • A team member with access to the key leaves
  • You suspect the key may have been exposed
  • You rotate secrets in your CI/CD platform

Teams and shared access​

Multiple developers can collaborate on extensions via developer teams. Each team member authenticates with their own credentials -- shared passwords or shared API keys are not needed or recommended.

Teams use a full RBAC system with 18 granular permissions across 7 categories. Three default roles (Owner, Admin, Member) are created for every team, and custom roles can be added. See Roles & Permissions for the complete permission reference.

Two-factor authentication​

Enable 2FA for your account under Account → Security → Two-Factor Authentication. Supported methods:

  • TOTP — any authenticator app (Google Authenticator, Authy, 1Password)
  • Passkey — hardware security key or platform authenticator

2FA is required for all accounts that have published paid extensions. It is strongly recommended for all accounts.

Audit log​

Every authentication event, deployment, and settings change is logged in the audit log under Account → Security → Audit Log. Log entries include:

FieldDescription
timestampUTC timestamp of the event
eventEvent type (e.g. api_key.created, extension.deployed)
actorEmail or API key label
ipSource IP address
resultsuccess or failure

Audit logs are retained for 90 days.

Responsible disclosure​

If you discover a security vulnerability in the Lumio platform, report it to [email protected]. Include a description of the issue, steps to reproduce, and impact assessment. We follow a 90-day disclosure timeline and offer recognition in our security hall of fame for valid reports.

Do not report vulnerabilities via GitHub issues or the public support channel.

Security best practices​

  • Store API keys in your CI/CD secret store (GitHub Actions secrets, GitLab CI variables), never in source code
  • Use environment-specific keys — a separate key for staging vs production deployments
  • Enable 2FA on your developer account
  • Review the audit log monthly for unexpected access
  • Revoke keys that are no longer in use
  • Never share your API key in support tickets, Discord, or forums — Lumio staff will never ask for your key