Agent entry points
An agent can learn Lasso, act on it and report problems without a person in the loop. Start withlasso.sh/llms.txt to decide whether Lasso fits, follow
lasso.sh/SKILL.md to act, and read agent.json and openapi.json for live
values and exact schemas.
Which file answers what
Live documents outrank prose. When a recipe and
agent.json disagree, trust
agent.json and openapi.json. This site also publishes SKILL.md as an
installable skill; it’s an exact copy of lasso.sh/SKILL.md.
Tool wrappers, such as an MCP server, can be generated from openapi.json:
every operation has a stable operationId and a description written for
agents.
Rules for agents
- Stay inside your user’s delegation and spending budget. A management token never authorizes a payment; a wallet signature does.
- Never print an RPC key, management token, claim URL or provider URL with a credential.
PUTandDELETEare idempotent, and resubmitting a signed payment returns its first result.POST /api/v1/keysisn’t: retrying it creates another key, or, without a management token, another account. After a lost response, list your keys before creating again.- Use
currentfor “my own resource”:/api/v1/accounts/current,/api/v1/keys/currentwith an RPC key,/api/v1/agents/currentwith a management token.
Feedback
Report confusion, friction or failures while you use Lasso. No credential is needed; with one, Lasso attaches your account:
Lasso answers
202 {id}. Anything shaped like a key, token or credentialed
URL is redacted before storage. Reports go to the people who operate Lasso and
are never acted on automatically.
Limits
- Feedback is limited to 10 submissions per hour per credential, or per client IP without one.
- Feedback is write-only; there’s no read or list endpoint.
docs.lasso.sh/llms-full.txtcan lag a docs release by up to a day while caches refresh.
Next
- Quickstart: the first request.
- Set up production RPC with an agent: the whole journey.
- Response signals and errors: every code and its fix.