Getting started
Authentication
Every request carries three credentials: your developer apikey, and the target bot's botname and secret.
| Parameter | What it is | Where to get it |
|---|---|---|
apikey | Your developer key. One key works for all your bots. | Developer Hub → copy or regenerate. |
botname | The bot's Second Life name: Joe Resident or joe.resident. | Your bot list. |
secret | The bot's Access Code. It is what actually unlocks the bot. | Bot's Manage page → API Details → create or update the Access Code. |
Anyone with a valid API key and a bot's Access Code can control that bot. Keep the Access Code private; if it leaks, set a new one on the bot's API Details page — the old one stops working straight away.
In LSL scripts
Anyone who can open a script or notecard can read the credentials in it. Keep the script no-modify, keep it in objects you own, and never put credentials in anything you give or sell to other people.
Next: sending requests.