Welcome back.
Log in to your LakehouseBox account.
Advanced connection options
Need help? Contact support
Welcome
Set your password.
You are finishing the setup of your LakehouseBox account.
The link in the mail is valid for three days and works once. Expired? Sign up again with the same address, or ask for a reset link.
Password reset
Choose a new password.
Every session of yours is signed out when it is set. Tokens your agents hold are not affected.
The link is valid for 30 minutes and works once. Expired? Ask for another.
Forgot your password
Reset it by email.
Enter the address of your account. If it has one, a link to choose a new password is on its way; it is valid for 30 minutes.
Check your email.
If has a LakehouseBox account, a mail from no-reply@lakehousebox.com with the reset link is on its way. The link is valid for 30 minutes and works once.
Nothing arrives within a minute? Check the spam folder, then the spelling of the address; a new link can be requested once a minute. An account that logs in through an external identity provider has no password here and gets no mail.
Connect an agent
Connect this agent to your catalog?
An agent ran lhbox login on a machine and is waiting. Approving creates a token of your organisation, named after that machine, with exactly the access you choose below; its key goes to that machine only and never through the conversation. You can revoke it at any time from Connections on your account page.
First login
Name your organisation.
You are signed in, but this identity belongs to no organisation yet. Catalogs, tokens and members live in one; you will be its first admin.
Back office
Platform admin
Sign-ups per day
Storage by organisation
Storage and capacity
Top catalogs, local disk
Top catalogs, cold tier
Sign-ups by campaign
Host
People
Every account with an address, newest first. Addresses are personal data: they are shown here to platform admins and nowhere else.
Home
Catalogs
Browse your data, feeds and agents by catalog.
Tables 0
AGENTS.md
Shared context for people and agents using this catalog.
Provided to agents as catalog context. · stored as AGENTS.md
Files 0
What lives here
Plain files next to the tables: photos, documents, exports, whatever uploaders and sinks drop. Listed from as this catalog's own identity; previews and downloads come straight from the store.
Feeds 0
How feeds work
A feed commits rows to one table: a producer posts JSON arrays with its send key, a device posts what it can to its device URL, and a mapping turns that into the table's rows at each roll. Feeds are made with the CLI or by an agent (lhbox sink create); a mapping can be read, tried and changed here too. Feeds and devices.
Connections 0
What a connection is
A credential the catalog's scheduled SQL sends to a source that wants one (a bearer token, an API key in a header, or user:password), bound to one https URL prefix. The SQL names the URL; the key is added to requests under the prefix and nothing else. Paste it here, or let an agent store it (lhbox sink connection create); either way no one can read it back. Scheduled SQL.
Agents 0
Hosted agents that read this catalog. An agent belongs to the organisation and can read several catalogs; it is made and changed on the Agents page.
Permissions
Manage who can read or write this catalog.
Organisation members can read this catalog. Admins and the creator can also write.
Permissions apply to only. Removing access here changes a permission; revoking a token (Access tokens) invalidates the credential itself.
Catalog settings
Visibility, defaults and the details engines and the API use.
Details
Where this catalog lives and the identifiers behind its name, for a recipe or a request written by hand.
Visibility
Control who can read the files in this catalog.
Making this catalog public exposes all data files and retained metadata to anonymous reads. The catalog API stays private.
Only organisation admins can change visibility; the name typed out confirms it.
Catalog credential
Issue a new key pair and revoke the old one at once.
Every engine using the old recipe stops; fetch a new recipe afterwards. Storage sessions already vended keep working until they expire, up to one hour. Admins only.
SQL explorer
Query the catalogs you switch on in the explorer; one query can join across them.
Nothing attached yet.
Runs in this browser tab, read-only. Pick a table in the explorer for its schema. Connection details
This panel refuses statements other than SELECT, WITH, SHOW, DESCRIBE, EXPLAIN as a courtesy against accidents; it is not a permission. The credential is the boundary: each catalog you switch on is attached with its read-only credential (the catalog refuses commits made with it), so nothing typed here can change a table. When a catalog's endpoint does not answer from this browser, the page attaches it table by table instead, with a credential scoped to one table's prefix, and says so. A colleague's catalog is attached from the read-only recipe they send you (lhbox connect --catalog <name> --readonly); its key lives in this tab only. Writes go through your engine (DuckDB, PyIceberg, Spark) with the connection recipe. A query without a LIMIT gets one.
Query
DuckDB SQLResults
Agents
Agents that run on your data and put it to work.
Connecting Claude Code, Cursor or another client?
Allowance
The model tokens and runs this organisation's plan includes for hosted agents.
Integrations
Services your agents may use through MCP, with your consent. LakehouseBox keeps the credentials; an agent only gets what its definition names.
The machines and applications that reach this organisation's catalogs, and their keys.
To connect an agent, run lhbox login in it and approve the code here: it gets its own key for the catalogs you choose. A key made here is for a job or a script that cannot approve a login. How access works
The people of this organisation and their roles.
Members
Admins manage everything; members read every catalog.
About the two roles
Two roles: admin (everything, including inviting, removing and deleting catalogs) and member (read on every catalog, write on the ones they create or are granted). The last admin cannot leave or be demoted.
Invite
Invite a colleague into this organisation.
Organisation
Its name, its address and who may join.
Domains
Claim your email domain, publish the DNS TXT record it gives you and verify it. A claim does nothing until it is verified. Once verified and switched on below, colleagues with an address there are offered membership and join only if they accept; nobody is added automatically, and someone who left or was removed is not offered it again. Public mail domains cannot be claimed.
Account
You: your profile, how you sign in, your sessions.
You
Who is signed in, and how.
Delete account
Remove your account and revoke your keys.
What deleting does
Deletes your account now: every API key of yours revoked, your identity unlinked, your memberships removed. An organisation you are the only member of is deleted with you, with its catalogs; catalogs you made in an organisation that keeps members stay with it. If you are the only admin of an organisation with other members, make someone else an admin first. This cannot be undone.
Change password
At least 12 characters. Your other sessions sign out; this one stays.
Passkeys
Sign in with your device's fingerprint, face or PIN instead of the password. A passkey only works on lakehousebox.com, so a look-alike site cannot use it. It counts as two-factor on its own; your password keeps working as before.
Two-factor authentication
A code from an authenticator app at every login.
What it covers
A code from an authenticator app on your phone (Google Authenticator, 1Password, Aegis, Authy…) at every login, on top of the password. API keys and access tokens are not affected; approving an agent's lhbox login happens in this browser session, so it is covered.
- Scan this QR code with the authenticator app, or type the key under it.
- Type the 6-digit code the app then shows.
Key:
Sessions
Browser tabs signed in as you.
How revoking works
Every browser tab logged in as you. Revoking one signs it out at its next request; the refresh token behind it stops working at once.