LastPass

LastPass logo
Stores passwords, passkeys, and encrypted credentials in a shared vault your team can access securely.

LastPass API

Sign in
API key. API key; API access on: Teams/BusinessSource

Checked on 2026-10-10 in the developer documentation.

How to use LastPass

Onboard your team to LastPass

Start by selecting a LastPass business plan (Teams or Enterprise) that fits your organisation’s size. Create your company LastPass account and use the admin console to invite each team member using their work email. Make onboarding simple: explain to your marketing team why the tool is being adopted and how it will protect client and company accounts. Encourage everyone to install the LastPass browser extension and mobile app so they can access the vault wherever they work.

Organise shared vaults by project or role

Structure your LastPass vault in a way that mirrors your team’s needs. Set up shared folders for different functions or client projects for example, one folder for social media logins, another for SEO tools, and so on. Add the appropriate passwords to each folder and assign team members to them based on their role. This ensures each person only sees the credentials relevant to their work, reducing clutter and exposure. It also makes it easier to review and update credentials in one place when something changes.

Read the full guide

Enforce strong security policies

As an admin, establish clear security requirements from day one. Every user should create a long, unique master password for their LastPass account (a passphrase they don’t reuse elsewhere). Require all team members to enable multi-factor authentication on LastPass for an extra layer of protection this significantly reduces the risk of an account takeover. In the admin settings, you can also set policies like timeout periods (so vaults log out after inactivity) and minimum password length/complexity for stored credentials. Periodically use the LastPass Security Dashboard to audit for weak or reused passwords and prompt your team to update them. Building these habits and policies will fortify your password management against threats.

Enable MFA and monitor password hygiene

Make two-factor authentication mandatory for your team’s LastPass logins, using an app like LastPass Authenticator or Google Authenticator. This means even if someone’s master password is stolen, attackers cannot get in without the second factor. Regularly check the Security Dashboard or equivalent report for any red flags (such as duplicate passwords or accounts involved in known breaches). By keeping an eye on these and coaching team members to fix issues, you maintain a strong security posture over time.

Collaborate confidently with external partners

When working with freelancers, agencies, or clients, leverage LastPass to share access securely instead of sending passwords over email. If an external partner needs to log into a system, add their email as a LastPass user (you can use a free account for them) and share the specific password or folder they require. Crucially, use LastPass’s option to not allow viewing of the password, so the contractor can use the login without ever seeing the actual credentials. This keeps your account details confidential. You can also set an expiration or reminder to revoke that share when the collaboration ends.

Share passwords and revoke access when needed

Use the Sharing Centre in LastPass to manage what you’ve shared externally. For each contractor or partner, grant access only to the credentials they need, and remove access as soon as their work is done. LastPass makes this easy with a click you can update a shared item or immediately stop sharing it, which automatically blocks the other party’s future access. This way, you retain full control. Always update critical passwords after a project if they were shared out, as an extra precaution. By routinely revoking and updating, you ensure that outsiders never retain long-term access to your accounts beyond their necessity.

How to automate LastPass

Native integrations

Directory integration covers Microsoft Active Directory, Microsoft Entra ID, Google Workspace, Okta, PingOne and PingFederate, and OneLogin. Active Directory uses a small connector you run yourself, and the cloud directories sync without extra tools. The vendor also lists a catalogue of more than 1,200 single sign-on integrations. An idea: connect Google Workspace so a new hire gets a vault when their account is created, and loses it when the account is disabled.

API and webhooks

The vendor mentions a custom API for larger enterprises with complex onboarding, and SIEM reporting to Splunk, Microsoft Sentinel or through a REST API. Check in the API documentation what your plan allows. An idea: send admin events to your logging tool so you see when a shared folder changes or an admin signs in from a new place.