Skip to main content

Keys, URLs and profiles

One RPC key, saved once in .env, reaches every profile its account has: Lasso’s premium and public pools and each of your Custom profiles. The URL picks the profile, the strategy and the chain. Use this page to build URLs, move an app between pools without a redeploy, scope keys you have to expose, and rotate secrets with no downtime.

URL grammar

  • <chain> is a chain name or decimal chain ID from chains and prices.
  • <strategy> is optional; load-balanced is the default. See routing.
  • <profile> is premium, public or one of your Custom profile slugs. Without it, the key’s default profile serves the request.
  • <base>[/profile/<profile>]/provider/<name>/<chain> pins one provider for debugging. Managed providers use their public aliases.
Creating or rotating a key returns rpc_url and ws_url ready to use, with nothing to fill in.

Default and allowed profiles

Change a key’s default, and every URL without a profile segment moves with it, with no redeploy:
Making a Custom profile the default needs Custom access. Open WebSocket connections that used the old default close with default_profile_changed, and your client’s reconnect follows the new default.

Scope a key

allowed_profiles sets which profiles a key may use. A key scoped to a Custom profile is served and charged as premium if Custom access lapses or the profile is deleted.
A scoped key that names another profile gets forbidden, listing what it can use.

How a profile segment resolves

Whether premium is served by premium providers depends on the account’s payment state, not the URL. See serving access and pricing.

Rotate with no downtime

Rotate with an overlap, and both secrets work until previous_valid_until, so your deploys can catch up:
The response carries the new key, rpc_url and ws_url. Ship them, then let the old secret expire. See rotate a key with no downtime for the full sequence.

Existing URLs keep working

Every URL Lasso has issued keeps serving; the older forms and how they map are on upgrading from Agent API v2.

Limits

  • The API returns a key’s secret only on create and rotate. If you lose it, rotate the key or create another; admins can view active keys’ URLs in the dashboard.
  • grace_seconds defaults to 0, which stops the old secret immediately; the maximum is 86,400.
  • An account holds at most 100 active keys.
  • premium and public are reserved; Custom profile slugs can’t use them.

Next