# Labstep > Labstep is a cloud-based Electronic Lab Notebook (ELN) and research data management platform for life-science, chemistry and pharma R&D teams. It combines interactive step-by-step protocols, structured experiment data capture, inventory and sample management, order management, instrument/device integration and integrated Jupyter Notebooks, under an audit trail with electronic signatures and sample lineage. Labstep exposes a public REST API at api.labstep.com authenticated with a per-user API key, plus an official Python SDK and R package. Generated by the API Evangelist enrichment pipeline on 2026-07-19 from Labstep's own public surface. Labstep does not publish an llms.txt of its own (probed: labstep.com/llms.txt 404, help.labstep.com/llms.txt returns the help-center SPA shell, not an llms.txt). ## APIs - [Labstep API](https://help.labstep.com/en/collections/1913112-labstep-api): REST API over the same generic entity surface the Labstep app uses — experiments, protocols, resources, resource items, locations, devices, device data, orders, metadata, files, tags, collections, workspaces and users. Base URL https://api.labstep.com. ## Getting started - [Getting started with the Labstep API](https://help.labstep.com/en/articles/1786226-getting-started-with-the-labstep-api): what you can do programmatically — create protocols, set up experiments, attach instrument data. - [Installation and login](https://labsteppy.readthedocs.io/en/latest/source/installation_login.html): `pip install labstep`, then `labstep.authenticate('you@example.com', 'MY_API_KEY')`. - [Using the Labstep API with Jupyter Notebooks](https://help.labstep.com/en/articles/6463759-using-the-labstep-api-with-jupyter-notebooks) ## Authentication - Per-user API key sent in an `apikey` request header. An Authorization Bearer token form also exists for session/impersonation tokens. - Password login (`POST /public-api/user/login`) is deprecated — use an API key. - Organization controls: SAML, Google SSO, two-factor authentication, IP allowlisting. - Profile: [authentication/labstep-authentication.yml](authentication/labstep-authentication.yml) ## Conventions - Entities live at `/api/generic/`; structured queries POST to `/api/generic//filter`. - Filtering uses a predicate tree (`path`, `type` and/or `or`, `predicates` with `attribute`/`comparison`/`value`) supporting equal_to, not_equal_to, less_than, greater_than, less_than_or_equal_to, greater_than_or_equal_to, isNull, isNotNull, like, notLike. - Pagination is page-number based (`page`, `count`, `skip_total`), SDK page size defaults to 50; results come back under `items`. - Reads and filters are scoped to the active workspace via `group_id`. Entities are soft-deleted (`is_deleted`). - No idempotency-key contract and no published rate limits. - Full artifact: [conventions/labstep-conventions.yml](conventions/labstep-conventions.yml) ## SDKs and packages - [labstep (Python, PyPI)](https://pypi.org/project/labstep/) — `pip install labstep` — source https://github.com/Labstep/labstepPy, docs https://labsteppy.readthedocs.io/en/latest/ - [labstepR (R, GitHub)](https://github.com/Labstep/labstepR) — `devtools::install_github("Labstep/labstepR")` — reference https://labstep.github.io/labstepR/reference/index.html - [labstep-api-examples](https://github.com/Labstep/labstep-api-examples) — Jupyter notebooks demonstrating API usage - Catalog: [packages/labstep-packages.yml](packages/labstep-packages.yml) ## Data model - 67 entities across notebook, protocols, inventory, devices, chemistry/biology, data and files, collaboration, identity and access, and workflow domains. - Derived graph: [data-model/labstep-data-model.yml](data-model/labstep-data-model.yml) ## Errors and lifecycle - Only HTTP 200 is treated as success; errors return the raw body with the status code. No RFC 9457 problem details. See [errors/labstep-error-codes.yml](errors/labstep-error-codes.yml). - Unversioned request paths; the service root reports its own version. Product release notes at https://help.labstep.com/en/collections/945011-release-notes. No public status page, deprecation policy or SLA. See [lifecycle/labstep-lifecycle.yml](lifecycle/labstep-lifecycle.yml) and [changelog/labstep-changelog.yml](changelog/labstep-changelog.yml). ## Security and compliance - [Security](https://www.labstep.com/security): AWS hosting, TLS in transit, AES-256 at rest, annual third-party audits and grey-box penetration testing, FDA 21 CFR Part 11 support, ISO 27001 and FIPS 200 alignment, GLP/GMP capability, OWASP Top 10 adoption. - Conformance record: [conformance/labstep-conformance.yml](conformance/labstep-conformance.yml) - Domain security probe: [security/labstep-domain-security.yml](security/labstep-domain-security.yml) - No /.well-known/ discovery surface and no security.txt — see [well-known/labstep-well-known.yml](well-known/labstep-well-known.yml) ## Company - [Website](https://www.labstep.com) - [Help center](https://help.labstep.com) - [Blog](https://www.labstep.com/blogs/blog) - [GitHub](https://github.com/Labstep) - [Pricing (industry)](https://www.labstep.com/industry-pricing) and [pricing (academia)](https://www.labstep.com/academia-pricing) - [Sign up](https://app.labstep.com/signup) / [Log in](https://app.labstep.com/login) - [Terms and conditions](https://www.labstep.com/terms-conditions) / [Privacy policy](https://www.labstep.com/privacy-policy) ## Not published Labstep publishes no OpenAPI/Swagger definition, no AsyncAPI or webhook surface, no MCP server, no OAuth authorization server or scopes, no CLI, no sandbox/test-credential program, no public status page, and no security.txt or vulnerability disclosure policy.