# Lucidya > Lucidya is an AI-native customer experience management (CXM) platform for social > listening, unified customer data, omnichannel engagement, surveys, and AI text and > audio analysis, with deep Arabic-language and MENA-market capabilities. It publishes > five machine-readable REST APIs covering 73 operations, plus an outbound webhook > surface. Headquartered in Saudi Arabia; SOC 2 Type 2 and ISO 27001 certified. Lucidya does not publish an llms.txt. This file was generated by the API Evangelist enrichment pipeline (method: generated, 2026-08-13) from Lucidya's own five OpenAPI documents and its public developer documentation. ## Getting a key All five APIs use one scheme: an opaque API token in the `luc-authorization` HTTP header. There is no OAuth. Keys are generated in the CXM console (Settings → Lucidya API) **after** a Customer Success Manager approves a "Request Access" ticket. A key is bound to one API product type, carries a subnet IP allow-list, and is shown once. Max 3 keys per API type. A key idle 30 days is deactivated; a key used continuously for 60 days expires. - [Authorization](https://docs.lucidya.com/docs/Social-Listening-api/uh64vtmx7x4kl-authorization) - [Security Considerations (TLS, token expiry)](https://docs.lucidya.com/docs/Social-Listening-api/sztlqqzqzmdb0-security-considerations) - [Login](https://cxm.lucidya.com/login) · [Register](https://cxm.lucidya.com/register) ## APIs Base URL for all products: `https://api.lucidya.com` (OmniServe Analytics is served from `https://api.lucidya.com/public_api/omniserve`) - [Social Listening API](https://docs.lucidya.com/docs/Social-Listening-api/wainb9dny9w1y-lucidya-social-listening-public-api) — 8 operations. Monitors, widgets, filters, pages, and widget data for X (Twitter), Facebook, Instagram and news/blogs. OpenAPI 3.0.1. - [AI API](https://docs.lucidya.com/docs/ai-api/zl9th61r4qjdz-lucidya-public-ai-api) — 7 operations. Batch sentiment, Arabic dialect and sub-dialect, domain and theme classification, plus offline audio transcription with speaker diarization. OpenAPI 3.1.0. - [CDP API](https://docs.lucidya.com/docs/cdp-api/ns8sfqyr1dgw6-cdp-customer-data-platform-api) — 11 operations. Unified customer profiles (create/read/update, no delete), interactions, survey responses, and segment membership. OpenAPI 3.0.0. - [OmniChannel API](https://docs.lucidya.com/docs/omnichannel-api/d1ow4caem6i5x-omni-channel-api) — 29 operations. Widget data across fifteen channel families: X, Facebook, Instagram, TikTok, LinkedIn, WhatsApp, Intercom, Chats, Google My Business, Genesys, Gmail, plus aggregated Analytics and Interactions. OpenAPI 3.0.0. - [OmniServe Analytics API](https://docs.lucidya.com/docs/omniserve/mjhuba7fdw882-omni-serve-analytics-api) — 18 operations. Inbox, SLA, agent and in-chat-survey (CSAT) analytics: page/widget/filter discovery, job creation and polling, custom fields, and reference lookups. OpenAPI 3.0.3. The only spec that declares its security scheme. - [Webhooks](https://docs.lucidya.com/docs/webhooks/gjni0qgds8vl8-get-started) — outbound alert delivery. Configured in the console, not over the API. No AsyncAPI, no signing secret, no event catalogue. ## Runtime semantics an agent needs - **Pagination**: `page_id` query parameter starting at 1; response carries `{"page_number","count"}`; fixed batches of 10. - **Rate limits**: 100 requests/minute floor on four products; **6 requests/minute on the AI API**, with a 100-text batch cap and a 100-audio-minutes-per-minute duration quota. Fixed window, resets on the minute. **No `RateLimit-*` and no `Retry-After` header is returned.** - **Errors**: a published slug per status (`bad_request`, `unauthorized`, `forbidden`, `not_found`, `method_not_allowed`, `not_acceptable`, `gone`, `validation_failed`, `too_many_requests`, `server_error`, `service_unavailable`, `time_out`). Envelope is `{"error":{"status","detail"}}` — not RFC 9457. Two other shapes are also in production: `{"status","message"}` on OmniServe, and FastAPI `{"detail":[...]}` on the AI API. - **403 vs 429**: repeated erroring requests get a caller *blocked* with 403, separately from rate-limit 429. Do not retry into a 403. - **Async**: OmniChannel, OmniServe and AI audio use create-then-poll. `202` means still running. - **Idempotency**: none, anywhere. Every retried POST is a new request. - **Versioning**: v1, with no version segment in the host or path. No deprecation or sunset policy is published. - **Transport**: HTTPS required; plain HTTP is rejected. Reference articles: [Responses](https://docs.lucidya.com/docs/Social-Listening-api/jpep93q1xum4z-responses) · [Pagination](https://docs.lucidya.com/docs/Social-Listening-api/5jscj2hvwndbd-pagination) · [Rate Limiting](https://docs.lucidya.com/docs/Social-Listening-api/wi0q2azbypqk5-rate-limiting) · [Versioning](https://docs.lucidya.com/docs/Social-Listening-api/unypk371jol78-versioning) ## What Lucidya does NOT publish Stated plainly so an agent does not go looking: - No SDKs or client libraries in any package registry; the GitHub organisation has zero public repositories. - No MCP server. (Search results for "Lucidya MCP" return Lucid and Lucidworks — different companies.) - No A2A agent card at `/.well-known/agent-card.json` or `/.well-known/agent.json` on any host. - No `/.well-known/` documents at all — no security.txt, no OpenID or OAuth metadata, no api-catalog. - No AsyncAPI, no GraphQL, no gRPC, no CLI, no public Postman collection. - No sandbox or test-mode keys. The Stoplight-hosted Prism mocks derived from Lucidya's own specs do answer anonymously and are usable for contract testing — see the repo's sandbox artifact. ## Pricing - [OmniServe pricing](https://www.lucidya.com/pricing/omniserve) — Growth $125/seat/month (min 6 seats, "OmniServe limited APIs"); Enterprise $250/seat/month (min 12 seats, "OmniServe full APIs"). API reach is itself a plan feature. - [Social Listening pricing](https://www.lucidya.com/pricing/social-listening) — Basic / Professional / Enterprise, talk-to-sales, no published prices. - API calls are not separately metered. No free tier, no self-serve trial. ## Developer resources - [API Documentation](https://docs.lucidya.com/) - [Help Center](https://help.lucidya.com/) - [Product Updates / Changelog](https://news.lucidya.com/) - [Status Page](https://status.lucidya.com/) - [Trust Center](https://trust.lucidya.com/) - [Security Practices](https://www.lucidya.com/security-practices) - [Vulnerability Disclosure Policy](https://www.lucidya.com/vulnerability-disclosure-policy) - Support: customer.support@lucidya.com ## Company - [Website](https://lucidya.com) - [Blog](https://lucidya.com/blog) - [Privacy Policy](https://lucidya.com/privacy-policy) - [Service Agreement](https://www.lucidya.com/service-agreement) ## Compliance SOC 2 Type 2, ISO 27001, GDPR, and Saudi Arabia PDPL. Annual external penetration testing; SAST/DAST code analysis. Full audit reports are gated behind a Trust Center NDA.