Skip to main content
POST
Metered pay-per-use call

Authorizations

Authorization
string
header
required

Tenant secret key (lcr_…). Server-side only.

Headers

X-Locus-Session-Id
string

Required only when the end-user JWT carries sid. Send the original high-entropy session value; sid is its SHA-256 fingerprint. Ignored for secret-key authentication.

Required string length: 16 - 128
Pattern: ^[A-Za-z0-9][A-Za-z0-9._:-]{15,127}$
Idempotency-Key
string
required

Required. Missing → 400. Same key + different body → 409. Retries replay the stored outcome.

X-Locus-End-User
string

Case-sensitive immutable ID in the tenant namespace. Prefer an identity-provider subject, not an email address.

Required string length: 1 - 200
Pattern: ^[A-Za-z0-9][A-Za-z0-9._:@/-]{0,199}$

Path Parameters

provider
string
required
endpoint
string
required

Body

application/json

Upstream-shaped request body (see the per-endpoint docs at /credits/md)

Response

Raw upstream response