> For clean Markdown of any page, append .md to the page URL. > For a complete documentation index, see https://docs.lakera.ai/docs/red/management-api-overview/llms.txt. > For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.lakera.ai/_mcp/server. # Management API Overview The Management API is an HTTP API for administering an organization's folders, folder members, and folder-scoped API keys programmatically — the same resources you manage from **Settings** → **Manage folders** in the dashboard. It is intended for organization administrators automating workspace setup, for example provisioning folders and API keys from CI. The API operates entirely within one organization: every request is scoped to the organization of the Management API Key that authenticates it, and there is no way to read or change another organization's data. ## Base URL The API is served on a per-tenancy host. Use the base URL for the tenancy your organization belongs to: | Tenancy | Base URL | | ------- | --------------------------- | | US | `red-webhooks.lakera.ai` | | EU | `red-webhooks-eu.lakera.ai` | If you are unsure which tenancy your organization uses, check the region shown in the dashboard or ask your Check Point contact. The examples in this section export the host once and reuse it, so a request never hardcodes a region: ```bash export LAKERA_RED_HOST=red-webhooks.lakera.ai # EU tenancy: red-webhooks-eu.lakera.ai ``` Paths shown below are relative to that host. ## Authentication Every request authenticates with a **Management API Key** sent as a bearer token: ```bash curl -H "Authorization: Bearer $LAKERA_MANAGEMENT_KEY" \ https://$LAKERA_RED_HOST/management/whoami ``` A Management API Key is distinct from the folder-scoped Red Team API Keys used with the [SDK](/docs/red/sdk-quickstart): it authorizes organization-level administration rather than target and scan access. Management API Keys are created in the dashboard by an organization administrator (see [Obtaining a Management API Key](#obtaining-a-management-api-key)); the API itself never mints one. A folder-scoped key sent to a management endpoint is rejected with `403`. An organization administrator's authority is verified when the key is minted, and the key is then trusted until it is revoked. A Management API Key is revoked manually, or automatically when its owner loses organization membership. ## Obtaining a Management API Key Management API Keys are created in the dashboard, not through the API. Only an organization administrator can create one: 1. Sign in to the dashboard as an organization administrator. 2. Open **Settings** → **Management API Keys**. 3. Select **Create key**, give it a name that identifies where it will be used (for example `CI pipeline` or `terraform`), and select **Create**. 4. Copy the key from the confirmation dialog. The secret is shown only once and cannot be retrieved afterward, so store it in your secret manager before closing the dialog. The **Management API Keys** entry appears under **Settings** only for organization administrators. If you do not see it, you are not an administrator of the organization — ask an administrator to create a key for you, or to grant you the administrator role. To stop a key from working, revoke it from the same page. Revocation takes effect immediately. ## Confirm a key `GET /management/whoami` returns the organization a Management API Key administers, so automation can verify a credential before issuing real calls. ```bash curl -H "Authorization: Bearer $LAKERA_MANAGEMENT_KEY" \ https://$LAKERA_RED_HOST/management/whoami ``` ```json { "orgId": "org_abc123", "keyId": "..." } ``` ## Errors Responses use conventional HTTP status codes. Error bodies are JSON of the form `{ "error": "" }`. | Status | Meaning | | ------ | ---------------------------------------------------------------------------------------------------------------------------------------- | | 400 | The request is malformed — an invalid id, a missing required field, or a rejected value (for example, renaming the organization folder). | | 401 | No key was supplied, or the key is unknown or revoked. | | 403 | The key is not a Management API Key, or the request targets a resource in another organization. | | 404 | The addressed folder does not exist in the key's organization. | | 405 | The HTTP method is not allowed on that path. | Requesting a resource that belongs to another organization returns `404` on reads (a folder in another organization is indistinguishable from one that does not exist) and `403` on writes. ## Endpoints | Resource | Page | | ------------------------------------------------- | -------------------------------------------------- | | Folders — create, list, rename, delete | [Folders](/docs/red/management-api-folders) | | Members — list org-wide, add, change role, remove | [Members](/docs/red/management-api-members) | | Red Team API keys — create, list, rotate, revoke | [Red Team API Keys](/docs/red/management-api-keys) | | Audit trail — the organization's action history | [Audit Trail](/docs/red/management-api-audit) |