Authentication
Authentication Method
Authenticate every request with your API key as a bearer token. No other credentials are required.
Code
Missing, malformed or revoked keys return 401 with code: "unauthorized".
API Keys
Keys begin with lux_sk_. Lunch issues and revokes keys. Self-service key management is not
available.
Keep your API key secret
Each key identifies your platform. Store it server-side. Never expose it in a browser, mobile app or code repository.
Live Requests
There is no sandbox key
All keys are live. The Test panel on reference pages sends real requests to
https://api.lunchpayments.com.
To test without moving money, ask Lunch to mark an organization as a test account before sending requests for it.
These read-only endpoints are safe to call:
GET /v1/organizations/{externalId}GET /v1/webhooks- Either of the import reads
Revoking and Rotating Keys
Contact Lunch to revoke a lost key. Revocation is immediate. Subsequent requests return 401. When a
key is rotated, the new key is issued before the old one is revoked.

