Platform — Lucy Frontline
Integrations — an API with the same rules as the product
Lucy Frontline integrates via API, not via prebuilt connectors. This is the page for your architect: surfaces, permission model, token handling and limits.
API and integration surface
- Surfaces
A REST API (JSON over HTTPS) and an MCP (Model Context Protocol, streamable HTTP) surface for AI-agent integration. Both pass through exactly the same server-side tenant, membership and permission resolution as the app — there is no side door.
- Credentials and tokens
Integration credentials are created by the tenant's administrator and bound to a tenant, workspace, actor identity and explicit scopes — currently messaging, tasks and KPI read/write. Secrets are stored as cryptographic hashes and shown in plaintext only at creation. System-to-system credentials are exchanged for signed, short-lived access tokens (default one hour). All credentials can be revoked immediately.
- Limits and error responses
Default limits: 120 reads and 30 writes per minute (operational values that may be tuned, not contractual entitlements). Exceeding a limit returns 429 with retry guidance; invalid or revoked credentials return 401. An integration can never see or affect data outside its tenant and scopes — the same membership rules as for a human.
- Cloud provider and region
Application tier: DigitalOcean App Platform, Frankfurt (Germany). Data platform: Supabase, Ireland (eu-west-1).
We list only deployed integration surfaces. If you need a flow that isn't here — ask, and we will answer honestly whether it is built, planned or not on the map.
Last verified: 2026-08-11. This page is updated when the facts change — not the other way around.
