On this page

Developers

Lensdrop developer docs

Last updated September 3, 2026

Lensdrop is a photo delivery tool for photographers, not a developer platform. Two things a developer might want from it, in order of how often they are asked for: putting a gallery on a website, which needs no code, and an API, which does not exist beyond a read-only content feed for AI agents.

Put a gallery on your website

Any active gallery can be shown inside a page on the photographer's own site, or on a client's wedding site, with one copy-paste snippet. Photos stay on Lensdrop. It takes about two minutes.

  1. Turn the embed on. Open the gallery, then Settings, then Website embed, and turn it on. A snippet appears.
  2. Paste the snippet. Copy the snippet and paste it where the gallery should appear: a code or HTML block on Squarespace, Wix, or WordPress, an embed block on Notion, or any HTML page.
  3. Set the height. Change the height value in the snippet to taste. The frame scrolls on its own inside the page.
<iframe
  src="https://lensdrop.photos/embed/g/YOUR_EMBED_TOKEN"
  title="Gallery name"
  style="width:100%;height:720px;border:0;border-radius:12px"
  loading="lazy"
  allowfullscreen
></iframe>

How the embed works

The snippet is a plain iframe pointing at a second, unguessable link that is separate from the share link, so it can be turned off or replaced without touching the link clients already have. Inside the frame the gallery behaves exactly like the share link: the PIN is asked for in the frame (with the same attempt limits), and watermark, downloads, sections, Live Mode, and the six-month window all apply, because the same server-side gates sign every URL. Turning the embed off, or generating a new embed link, stops every page using the old snippet; the share link is unaffected either way. The frame has a fixed height and scrolls on its own, which is what keeps the lightbox where a reader expects it.

Questions

Does Lensdrop have an API?

No. Lensdrop has no API for galleries, uploads, downloads, or billing. The only public API is a read-only content API that serves the marketing pages as markdown for AI agents. To show a gallery on a website, use the embed snippet instead.

Can I show a Lensdrop gallery on my own website?

Yes. Every active gallery has a Website embed switch in its Settings. Turn it on, copy the iframe snippet, and paste it into any page that accepts HTML. Photos stay on Lensdrop.

Does the PIN protect an embedded gallery?

Yes. An embedded gallery with a PIN asks visitors for it inside the frame, exactly as the share link does, with the same attempt limits. Turn the PIN off in the gallery's settings if the gallery is meant to be open on that page.

Which website builders work with the Lensdrop embed?

Any builder that accepts an iframe: a code block on Squarespace, an HTML embed on Wix, a Custom HTML block on WordPress, an embed block on Notion, or a plain HTML page. No plugin is needed.

Can clients download photos from an embedded gallery?

Downloads inside the embed follow the gallery's own download switch. With the watermark on, clients get watermarked copies and no bulk ZIP. With the watermark off, they get clean originals and the ZIP, exactly as on the share link.

What happens to an embedded gallery when it expires?

Every Lensdrop gallery has a six-month active window that can be extended from the dashboard. After it ends, the embed shows a quiet 'not available' card instead of broken images. Turning the embed off or generating a new embed link does the same for the old snippet; the share link is unaffected.

Can AI agents read Lensdrop's documentation?

Yes. Every marketing page has a markdown twin at the same URL with .md appended, an llms.txt index lists them, and openapi.json describes the content API. Access is anonymous and rate limited.

Is there an API?

No, apart from the content feed below. Specifically:

  • Galleries, uploads, downloads, and the client viewer have no third-party API. Bytes move between browsers, storage, and an image worker through signed URLs, never through a server an integration could call.
  • Billing has no API. Photographers pay Lensdrop through Dodo Payments, and there are never client-to-photographer payments.
  • Connected devices (the desktop uploader and camera FTP) use per-device credentials the app issues and revokes. They are not API keys and are not documented here.

If you are building something that needs more than the embed, say what it is: hello@lensdrop.app. What people ask for decides what gets built.

Contact

Questions about the embed, agent access, or this page: hello@lensdrop.app. Product questions belong in the help center.


Content API reference

For AI agents and crawlers. Every marketing page has a markdown twin, reachable by appending .md to its URL or by requesting the HTML URL with Accept: text/markdown. Anonymous, no key, no account. This page as markdown: /developers.md. Full description: /openapi.json.

Discovery files

  • /llms.txt Agent-readable index of Lensdrop's public content (llmstxt.org).
  • /llms-full.txt Every public page as one markdown document.
  • /openapi.json OpenAPI 3.1 description of the content API, with operationIds, typed errors, and headers.
  • /.well-known/api-catalog RFC 9727 API catalog pointing at the spec and the docs.
  • /auth.md Auth.md: how (and whether) agents authenticate. Short answer: anonymous.
  • /developers.md This page, as markdown.
  • /sitemap.xml Every indexable page.
  • /robots.txt Crawl rules. AI crawlers are allowed by name; galleries and the signed-in app are not crawlable.

Endpoints

All plain anonymous GETs on https://lensdrop.app. Operation ids and parameter schemas, including the valid slugs, are in openapi.json.

OperationSummaryReturns
GET /llms.txtIndex of Lensdrop's agent-readable contenttext/markdown
GET /llms-full.txtThe full agent-readable corpus in one documenttext/markdown
GET /index.mdWhat Lensdrop is and how delivery workstext/markdown
GET /pricing.mdLensdrop pricing: tiers, add-ons, free tier, billingtext/markdown
GET /download.mdLensdrop desktop uploadertext/markdown
GET /help.mdLensdrop help and FAQtext/markdown
GET /use-cases.mdLensdrop use cases, all niches in one documenttext/markdown
GET /compare.mdLensdrop compared with other gallery tools, all in one documenttext/markdown
GET /blog.mdLensdrop blog indextext/markdown
GET /developers.mdLensdrop developer docstext/markdown
GET /use-cases/{slug}.mdOne use case as markdowntext/markdown
GET /compare/{slug}.mdOne comparison as markdowntext/markdown
GET /blog/{slug}.mdOne blog post as markdowntext/markdown
GET /help/{slug}.mdOne help guide as markdowntext/markdown
GET /openapi.jsonOpenAPI 3.1 description of this APIapplication/openapi+json
GET /.well-known/api-catalogRFC 9727 API catalogapplication/linkset+json
GET /auth.mdHow agents authenticate (they don't)text/markdown

Errors

Every error is an RFC 9457 problem details object (application/problem+json) with a real HTTP status and a stable code. The type URL of each one points at its row below.

StatusCodeWhat to do
400bad_requestCheck the request body and parameters against the documented schema.
400unsupported_versionSend a supported value in the API-Version header, or omit the header to use the current version.
401unauthorizedThe credential is missing, malformed, or revoked. The public content API needs no credential; other surfaces are not open to third parties.
403forbiddenThe credential is valid but does not cover this resource.
404not_foundStart from /llms.txt for the agent-readable site index, /openapi.json for the API description, or /sitemap.xml for every page.
405method_not_allowedThe content API is read-only: use GET or HEAD.
406not_acceptableThis resource is served as text/markdown or application/json. Adjust the Accept header.
409conflictThe resource is in a state that does not allow this change. Re-read it and retry if appropriate.
413payload_too_largeReduce the request size; uploads go directly to storage in parts, never through this API.
429rate_limitedWait for the number of seconds in Retry-After, then retry. The RateLimit and RateLimit-Policy headers describe the quota.
500internal_errorRetry with backoff. If it persists, contact support with the instance path.
502bad_gatewayA dependency failed. Retry with backoff.
503service_unavailableRetry after a short delay; honor Retry-After when present.

Rate limits

120 requests per 60 seconds per client IP, sliding window, stated in the IETF RateLimit and RateLimit-Policy headers on every response. Over the limit answers 429 rate_limited with Retry-After.

Versioning and deprecation

The content API is versioned by the API-Version header. Every response states the version that produced it (currently 1). Requests may pin a version with the same header; omit it to get the current version. A pinned version this deployment no longer serves answers 400 with code unsupported_version and the supported list.

URLs and response shapes within a version only change additively: new fields, new endpoints, new headers. Removing or renaming anything means a new version.

When a version is deprecated, responses from it carry Deprecation (RFC 9745) and Sunset (RFC 8594) headers and a Link with rel="deprecation" pointing at the notice on this page, for at least 6 months before the sunset date. Deprecations are also listed in llms.txt.

No version has been deprecated yet.

Crawling and AI use

robots.txt allows search engines and AI crawlers by name on the public pages and publishes Content Signals permitting search, AI input, and AI training. Galleries (/g/), embeds (/embed/), the signed-in app, and /api are not crawlable.