Skip to main content

Agent entry points

An agent can learn Lasso, act on it and report problems without a person in the loop. Start with lasso.sh/llms.txt to decide whether Lasso fits, follow lasso.sh/SKILL.md to act, and read agent.json and openapi.json for live values and exact schemas.

Which file answers what

Live documents outrank prose. When a recipe and agent.json disagree, trust agent.json and openapi.json. This site also publishes SKILL.md as an installable skill; it’s an exact copy of lasso.sh/SKILL.md. Tool wrappers, such as an MCP server, can be generated from openapi.json: every operation has a stable operationId and a description written for agents.

Rules for agents

  • Stay inside your user’s delegation and spending budget. A management token never authorizes a payment; a wallet signature does.
  • Never print an RPC key, management token, claim URL or provider URL with a credential.
  • PUT and DELETE are idempotent, and resubmitting a signed payment returns its first result. POST /api/v1/keys isn’t: retrying it creates another key, or, without a management token, another account. After a lost response, list your keys before creating again.
  • Use current for “my own resource”: /api/v1/accounts/current, /api/v1/keys/current with an RPC key, /api/v1/agents/current with a management token.

Feedback

Report confusion, friction or failures while you use Lasso. No credential is needed; with one, Lasso attaches your account:
Lasso answers 202 {id}. Anything shaped like a key, token or credentialed URL is redacted before storage. Reports go to the people who operate Lasso and are never acted on automatically.

Limits

  • Feedback is limited to 10 submissions per hour per credential, or per client IP without one.
  • Feedback is write-only; there’s no read or list endpoint.
  • docs.lasso.sh/llms-full.txt can lag a docs release by up to a day while caches refresh.

Next