Lambda SSH keys API

The SSH keys API from Lambda — 2 operation(s) for ssh keys.

OpenAPI Specification

lambda-labs-ssh-keys-api-openapi.yml Raw ↑
openapi: 3.1.0
info:
  title: Lambda Cloud Audit Events SSH keys API
  version: 1.10.0
  description: "The Lambda Cloud API provides a set of REST API endpoints you can use to create\nand manage your Lambda Cloud resources.\n\nRequests to the API are generally limited to one request per second. Requests to\nthe `/instance-operations/launch` endpoint are limited to one request per 12\nseconds, or five requests per minute.\n\n## Response types and formats {#formats}\n\nThe format of each response object depends on whether the request succeeded or failed.\n\n### Success responses {#success-responses}\n\nWhen a request succeeds, the API returns a response object in the following format. `<PAYLOAD>`\nrepresents the endpoint-specific data object returned as part of the response object.\n\n```json\n{\n    \"data\": <PAYLOAD>\n}\n```\n\n### Error responses {#error-responses}\n\nWhen a request fails, the API returns an error response object in the following format:\n\n```json\n{\n    \"error\": {\n        \"code\": string,\n        \"message\": string,\n        \"suggestion\": string?\n    }\n}\n```\n\n- `code`: A machine- and human-readable error code specific to a particular failure mode.\n- `message`: An explanation of the error.\n- `suggestion`: When present, a suggestion for how to address the error.\n\n:::note{type=\"info\" title=\"Note\"}\nWhen handling errors, avoid relying on the values of `message` or `suggestion`, as\nthese values are subject to change. Instead, use the value of `code`.\n:::\n\n#### Provider errors {#provider-errors}\n\nIn some cases, you might receive errors that come from upstream services/providers rather than directly\nfrom Lambda services. You can identify these errors by their error code prefix, `provider/`.\n\nCommon provider errors include:\n\n- Network outages or connectivity issues\n- Service unavailability\n- Quota limitations or resource exhaustion\n\nAn example of a typical service unavailability error:\n\n```json\n{\n  \"error\": {\n    \"code\": \"provider/internal-unavailable\",\n    \"message\": \"Provider unavailable\",\n    \"suggestion\": \"Try again shortly\"\n  }\n}\n```\n## Outgoing webhooks {#outgoing-webhooks}\n\nLambda can send webhook notifications to your URL when support ticket events occur,\nenabling near real-time integration with your systems.\n\n### Event types {#event-types}\n\n- `ticket.created` - A support ticket was created.\n- `ticket.status_changed` - A support ticket's status was updated, and the ticket remains open.\n- `ticket.resolved` - A support ticket's status was set to `solved`, or the ticket was closed.\n\n### Payload structure {#payload-structure}\n\nAll webhook payloads follow this structure:\n\n```json\n{\n  \"id\": \"a3b7c9d1e5f642a8b0c2d4e6f8a0b2c4\",\n  \"object\": \"event\",\n  \"type\": \"ticket.created\",\n  \"created\": 1700000000,\n  \"api_version\": \"2025-11-18\",\n  \"data\": {\n    \"object\": \"ticket\",\n    \"id\": \"f1e2d3c4b5a647869708192a3b4c5d6e\",\n    \"subject\": \"Issue with instance 0920582c7ff041399e34823a0be62549\",\n    \"description\": \"Detailed description of the issue...\",\n    \"request_type\": \"incident\",\n    \"severity\": \"sev_2\",\n    \"status\": \"new\",\n    \"created_at\": \"2024-11-15T10:00:00+00:00\",\n    \"updated_at\": \"2024-11-15T10:00:00+00:00\",\n    \"instance_ip\": \"192.168.1.100\",\n    \"instance_id\": \"0920582c7ff041399e34823a0be62549\",\n    \"cluster_id\": null,\n    \"source\": \"api\"\n  }\n}\n```\n\n### Webhook authentication {#webhook-authentication}\n\nWebhook requests include a Bearer token in the `Authorization` header for authentication:\n\n```http\nAuthorization: Bearer <token>\n```\n## Authentication {#authentication}\n\nThe Lambda Cloud API uses API keys to authenticate incoming requests. You\ncan generate a new API key pair or view your existing API keys by visiting\nthe [API keys page](https://cloud.lambda.ai/api-keys) in the Lambda Cloud\ndashboard.\n\nIn general, Lambda recommends passing an HTTP Bearer header that contains\nyour API key:\n\n```http\nAuthorization: Bearer <YOUR-API-KEY>\n```\n\n### Authenticating with `curl` {#authenticating-with-curl}\n\nThe API also supports passing an HTTP Basic header. This option chiefly exists\nto support `curl`'s `-u` flag, which allows you to pass your credentials\nwithout having to write out the full `Authorization: Basic` header string.\nFor example:\n\n```bash\ncurl --request GET --url 'https://cloud.lambda.ai/api/v1/instances' \\\n  --header 'accept: application/json' \\\n  --user '<YOUR-API-KEY>:'\n```\n\nIf your use case requires it, you can also pass the HTTP Basic header directly.\nThe value you pass must be a Base64-encoded string containing your API key\nand a trailing colon:\n\n```http\nAuthorization: Basic <BASE64-ENCODED-API-KEY>:\n```\n\n:::note{type=\"attention\" title=\"Important\"}\nIf you make a request without including a supported `Authorization` header,\nthe request will fail.\n:::"
servers:
- url: https://cloud.lambda.ai/
  description: Production server
- url: https://cloud.lambdalabs.com/
  description: Secondary production server (deprecated)
security:
- bearerAuth: []
- basicAuth: []
tags:
- name: SSH keys
paths:
  /api/v1/ssh-keys:
    get:
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                additionalProperties: false
                properties:
                  data:
                    type: array
                    items:
                      $ref: '#/components/schemas/SSHKey'
                required:
                - data
                type: object
        '400':
          description: Bad Request
          content:
            application/json:
              schema:
                additionalProperties: false
                properties:
                  error:
                    $ref: '#/components/schemas/ApiErrorInvalidParameters'
                required:
                - error
                type: object
        '401':
          description: Unauthorized
          content:
            application/json:
              schema:
                additionalProperties: false
                properties:
                  error:
                    $ref: '#/components/schemas/ApiErrorUnauthorized'
                required:
                - error
                type: object
        '403':
          description: Forbidden
          content:
            application/json:
              schema:
                additionalProperties: false
                properties:
                  error:
                    $ref: '#/components/schemas/ApiErrorAccountInactive'
                required:
                - error
                type: object
        '404':
          description: Not Found
          content:
            application/json:
              schema:
                additionalProperties: false
                properties:
                  error:
                    $ref: '#/components/schemas/ApiErrorNotFound'
                required:
                - error
                type: object
      tags:
      - SSH keys
      summary: List your SSH keys
      description: Retrieves a list of your SSH keys.
      operationId: listSSHKeys
    post:
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                additionalProperties: false
                properties:
                  data:
                    anyOf:
                    - $ref: '#/components/schemas/GeneratedSSHKey'
                    - $ref: '#/components/schemas/SSHKey'
                required:
                - data
                type: object
        '400':
          description: Bad Request
          content:
            application/json:
              schema:
                additionalProperties: false
                properties:
                  error:
                    $ref: '#/components/schemas/ApiErrorInvalidParameters'
                required:
                - error
                type: object
        '401':
          description: Unauthorized
          content:
            application/json:
              schema:
                additionalProperties: false
                properties:
                  error:
                    $ref: '#/components/schemas/ApiErrorUnauthorized'
                required:
                - error
                type: object
        '403':
          description: Forbidden
          content:
            application/json:
              schema:
                additionalProperties: false
                properties:
                  error:
                    $ref: '#/components/schemas/ApiErrorAccountInactive'
                required:
                - error
                type: object
        '404':
          description: Not Found
          content:
            application/json:
              schema:
                additionalProperties: false
                properties:
                  error:
                    $ref: '#/components/schemas/ApiErrorNotFound'
                required:
                - error
                type: object
      tags:
      - SSH keys
      summary: Add an SSH key
      description: "Add an SSH key to your Lambda Cloud account. You can upload an existing public\nkey, or you can generate a new key pair.\n\n-  To use an existing key pair, set the `public_key` property in the request body\n   to your public key.\n\n-  To generate a new key pair, omit the `public_key` property from the request\n   body.\n\n:::note{type=\"attention\" title=\"Important\"}\nLambda doesn't store your private key after it's been generated.\nIf you generate a new key pair, make sure to save the resulting private key locally.\n:::\n\nFor example, to generate a new key pair and associate it with a Lambda\nOn-Demand Cloud instance:\n\n1. Generate the key pair. The command provided below automatically extracts and\n    saves the returned private key to a new file called `key.pem`. Replace\n    `<NEW-KEY-NAME>` with the name you want to assign to the SSH key:\n\n    ```bash\n    curl --request POST --url 'https://cloud.lambda.ai/api/v1/ssh-keys' \\\n    --fail \\\n    --user ${LAMBDA_API_KEY}: \\\n    --data '{\"name\": \"<NEW-KEY-NAME>\"}' \\\n    | jq -r '.data.private_key' > key.pem\n    ```\n\n2. Next, set the private key's permissions to read-only:\n\n    ```bash\n    chmod 400 key.pem\n    ```\n\n3. Launch a new instance. Replace `<NEW-KEY-NAME>` with the name you assigned\n   to your SSH key.\n\n    ```bash\n    curl --request POST 'https://cloud.lambda.ai/api/v1/instance-operations/launch' \\\n    --fail \\\n    --user ${LAMBDA_API_KEY}: \\\n    --data '{\"region_name\":\"us-west-1\",\"instance_type_name\":\"gpu_1x_a10\",\"ssh_key_names\":[\"<NEW-KEY-NAME>\"],\"file_system_names\":[],\"quantity\":1,\"name\":\"My Instance\"}'\n    ```\n\n4. From your local terminal, establish an SSH connection to the instance.\n   Replace `<INSTANCE-IP>` with the public IP of the instance:\n\n    ```bash\n    ssh -i key.pem <INSTANCE-IP>\n    ```"
      operationId: addSSHKey
      requestBody:
        content:
          application/json:
            schema:
              properties:
                name:
                  type: string
                  minLength: 1
                  maxLength: 64
                  description: The name of the SSH key.
                  examples:
                  - my-public-key
                public_key:
                  type: string
                  minLength: 1
                  maxLength: 4096
                  description: The public key to store. Omit this to generate a new key pair.
                  examples:
                  - ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAICN+lJwsONkwrdsSnQsu1ydUkIuIg5oOC+Eslvmtt60T noname
              required:
              - name
              title: AddSSHKeyRequest
              type: object
        required: true
  /api/v1/ssh-keys/{id}:
    delete:
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                additionalProperties: false
                properties:
                  data:
                    $ref: '#/components/schemas/EmptyResponse'
                required:
                - data
                type: object
        '400':
          description: Bad Request
          content:
            application/json:
              schema:
                additionalProperties: false
                properties:
                  error:
                    $ref: '#/components/schemas/ApiErrorInvalidParameters'
                required:
                - error
                type: object
        '401':
          description: Unauthorized
          content:
            application/json:
              schema:
                additionalProperties: false
                properties:
                  error:
                    $ref: '#/components/schemas/ApiErrorUnauthorized'
                required:
                - error
                type: object
        '403':
          description: Forbidden
          content:
            application/json:
              schema:
                additionalProperties: false
                properties:
                  error:
                    $ref: '#/components/schemas/ApiErrorAccountInactive'
                required:
                - error
                type: object
        '404':
          description: Not Found
          content:
            application/json:
              schema:
                additionalProperties: false
                properties:
                  error:
                    $ref: '#/components/schemas/ApiErrorNotFound'
                required:
                - error
                type: object
      tags:
      - SSH keys
      summary: Delete an SSH key
      description: Deletes the specified SSH key.
      operationId: deleteSSHKey
      parameters:
      - name: id
        in: path
        description: The unique identifier (ID) of the SSH key to delete
        required: true
        schema:
          description: The unique identifier (ID) of the SSH key to delete
          example: ddf9a910ceb744a0bb95242cbba6cb50
          type: string
        example: ddf9a910ceb744a0bb95242cbba6cb50
components:
  schemas:
    GeneratedSSHKey:
      type: object
      properties:
        id:
          type: string
          description: The unique identifier (ID) of the SSH key.
          examples:
          - ddf9a910ceb744a0bb95242cbba6cb50
        name:
          type: string
          minLength: 1
          maxLength: 64
          description: The name of the SSH key.
          examples:
          - my-public-key
        public_key:
          type: string
          minLength: 1
          maxLength: 4096
          description: The public key for the SSH key.
          examples:
          - ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAICN+lJwsONkwrdsSnQsu1ydUkIuIg5oOC+Eslvmtt60T noname
        private_key:
          type: string
          description: 'The private key generated in the SSH key pair. Store this value locally;

            Lambda does not retain the private key server-side.'
          examples:
          - '-----BEGIN RSA PRIVATE KEY-----\n...\n-----END RSA PRIVATE KEY-----\n'
      required:
      - id
      - name
      - public_key
      - private_key
      title: GeneratedSSHKey
      description: Information about a server-generated SSH key.
    SSHKey:
      type: object
      properties:
        id:
          type: string
          description: The unique identifier (ID) of the SSH key.
          examples:
          - ddf9a910ceb744a0bb95242cbba6cb50
        name:
          type: string
          minLength: 1
          maxLength: 64
          description: The name of the SSH key.
          examples:
          - my-public-key
        public_key:
          type: string
          minLength: 1
          maxLength: 4096
          description: The public key for the SSH key.
          examples:
          - ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAICN+lJwsONkwrdsSnQsu1ydUkIuIg5oOC+Eslvmtt60T noname
      required:
      - id
      - name
      - public_key
      title: SSHKey
      description: Information about a stored SSH key that can be used to access instances over SSH.
    ApiErrorNotFound:
      type: object
      properties:
        code:
          const: global/not-found
          type: string
          description: The unique identifier for the type of error.
        message:
          type: string
          default: The requested resource was not found.
          description: A description of the error.
        suggestion:
          type: string
          description: One or more suggestions of possible ways to fix the error.
      required:
      - code
      - message
      title: ApiErrorNotFound
    ApiErrorUnauthorized:
      type: object
      properties:
        code:
          const: global/invalid-api-key
          type: string
          description: The unique identifier for the type of error.
        message:
          type: string
          default: API key was invalid, expired, or deleted.
          description: A description of the error.
        suggestion:
          type: string
          default: Check your API key or create a new one, then try again.
          description: One or more suggestions of possible ways to fix the error.
      required:
      - code
      - message
      - suggestion
      title: ApiErrorUnauthorized
    ApiErrorAccountInactive:
      type: object
      properties:
        code:
          const: global/account-inactive
          type: string
          description: The unique identifier for the type of error.
        message:
          type: string
          default: Your account is inactive.
          description: A description of the error.
        suggestion:
          type: string
          default: Make sure you have verified your email address and have a valid payment method. Contact Support if problems continue.
          description: One or more suggestions of possible ways to fix the error.
      required:
      - code
      - message
      - suggestion
      title: ApiErrorAccountInactive
    ApiErrorInvalidParameters:
      type: object
      properties:
        code:
          const: global/invalid-parameters
          type: string
          description: The unique identifier for the type of error.
        message:
          type: string
          default: Invalid request data.
          description: A description of the error.
        suggestion:
          type: string
          description: One or more suggestions of possible ways to fix the error.
      required:
      - code
      - message
      title: ApiErrorInvalidParameters
    EmptyResponse:
      type: object
      properties: {}
      title: EmptyResponse
  securitySchemes:
    basicAuth:
      type: http
      description: 'Basic HTTP authentication. Allowed headers:

        * `Authorization: Basic <base64 encoding of api_key>:`

        * `Authorization: Basic <api_key>`'
      scheme: basic
    bearerAuth:
      type: http
      description: 'Bearer HTTP authentication. Allowed headers:

        * `Authorization: Bearer <api_key>`'
      scheme: bearer
x-lambda-api-keys-config-url: https://cloud.lambda.ai/api-keys