API overview
LocalMind exposes a versioned REST API for projects, members, invitations, API keys, webhooks and audit logs.
Base URL
https://api.localmind.app/api/v1Authentication
Two methods (a third, OAuth access tokens, is reserved for the future):
-
Session cookie — browser/dashboard access uses the
better-auth.session_tokencookie, sent automatically (requests usecredentials: include). NoAuthorizationheader for session auth. -
API key — server-to-server access uses
Authorization: Bearer <key>. A key is scoped to one project and a subset of its permissions:
curl -H "Authorization: Bearer $LOCALMIND_API_KEY" \
https://api.localmind.app/api/v1/projects/{projectId}/membersSee Authentication for the full model.
Response envelope
Every success response is { data, meta }; 204 No Content has no body.
{
"data": {},
"meta": {
"timestamp": "2026-07-24T10:00:00.000Z",
"requestId": "a1b2c3d4-…",
"path": "/api/v1/projects"
}
}Pagination
List endpoints use offset pagination — page (1-based) and limit (max 100) —
with sorting via sortBy + order, and a search query where supported.
{
"data": [],
"meta": {
"pagination": { "page": 1, "limit": 20, "total": 100, "pageCount": 5 }
}
}Errors
Errors carry a stable, machine-readable errorCode — classify on that,
never on the message text.
{
"statusCode": 422,
"message": "Validation failed",
"error": {
"code": "VALIDATION_ERROR",
"message": "Invalid input",
"details": [{ "field": "name", "message": "Must not be empty" }]
}
}Cross-tenant or non-existent resources return 404 — the API never confirms that something it won't show you exists.
Idempotency
Creation (POST) endpoints accept an Idempotency-Key header; a repeated key
within 24 hours replays the original result instead of creating a duplicate.
Rate limiting
Requests are rate-limited per session or per API key. When limited, responses
return HTTP 429 with a Retry-After header (in seconds).