Once LunaLift is tracking the AI crawlers and AI-referred visitors on your site, you can pull those numbers into your own dashboards, warehouse, or scripts. The REST API exposes the same data the app shows, authenticated with a key you mint yourself. This guide walks the path end to end: get a key, find your company and website IDs, then read your traffic. The exact field-by-field response shapes live in the API reference; here we cover the order to call things in and why.

Before you start

The API returns AI-traffic data only for a website that has been added and whose company has finished onboarding. If a call comes back empty, that is usually because onboarding is not complete or no AI traffic has been recorded yet. See Integrations and data flows to get the data flowing first.

Step 1: mint an API key

Go to the API keys page in the app and create a key. The key acts as the user who created it and is scoped to your customer account, so it can read exactly what that user can. Copy it when it is shown; you will not see the full value again.

Send the key on every request in one of two ways, whichever your HTTP client makes easier:

Authorization: Bearer ll_your_key_here
# or
X-API-Key: ll_your_key_here

Keys are prefixed ll_ so they are easy to spot in logs and secret scanners. Treat one like a password: store it in a secret manager, never commit it, and rotate it from the same page if it leaks.

Step 2: find your company and website IDs

The analytics endpoints are keyed by company. To get your company IDs, call the check-in endpoint. It returns the companies your account can see, each with its own company_id:

POST /user/user-checkin
Authorization: Bearer ll_your_key_here

# response includes:
# companies[].company_id
# companies[].company_url
# companies[].company_name

This is a read-oriented check-in for an existing account. Do not set any new-company flag when you call it from a script; you only want to list what already exists, not create anything.

You do not usually need the website ID by hand. The analytics endpoints take the company_id and resolve the website for you. If you do want it, the website analytics endpoint returns it as part of its payload:

GET /analytics/website-analytics/{company_id}

Step 3: pull your AI-traffic numbers

The traffic KPI endpoint returns both stories at once for a company: the AI crawlers hitting your site (direct) and the humans AI answers sent you (indirect).

GET /analytics/website-traffic-kpis/{company_id}
Authorization: Bearer ll_your_key_here

The response separates the two clearly. The direct AI-bot activity comes back under bot_traffic, broken out by bot type (LLM, search, social) over 1-, 7-, and 30-day windows. The AI-referred human visits come back under ai_referred_traffic, with totals, conversions, and a daily series over the same windows.

For a day-by-day chart rather than rolled-up windows, use the timeseries endpoint, which accepts a days window (clamped to 7-90):

GET /analytics/website-traffic-timeseries/{company_id}?days=30

Exact request and response shapes

Field names, types, the full nesting of every window, and the response envelope are documented and kept current in the API reference. Read the shapes there rather than copying them from this guide, since the reference tracks the live API and this prose does not repeat every field. When you are signed in, the reference also lets you run these calls with your own key from the browser.