Skip to content

M22.2 §1: API keys — table, settings page, bearer auth, rate limit - #199

Open
n8bar wants to merge 5 commits into
mainfrom
claude/api-keys
Open

n8bar wants to merge 5 commits into
mainfrom
claude/api-keys

Conversation

@n8bar

@n8bar n8bar commented Oct 4, 2026

Copy link
Copy Markdown
Owner

M22 Phase 2, §1 of docs/strategies/22.2_API_KEYS_AND_CONTRACT.md.

  • api_keys table + ApiKey model (SHA-256 hash stored, plain key shown once)
  • Settings › API keys page: make, one-time reveal, list with last used, revoke
  • AuthenticateApiKey middleware (alias api.key): bearer key → issuer; unknown/revoked → 401 unauthorized
  • Per-key rate limit (API_RATE_LIMIT_PER_MINUTE, default 60); 429 rate_limited with Retry-After
  • Errors use the docs/API.md format: {"error": {"code", "message"}}

Tests: 9 new (ApiKeyTest, ApiKeySettingsTest, ApiKeyAuthTest); full suite 662 pass.

🤖 Generated with Claude Code

https://claude.ai/code/session_01L5W7g1rrgyVqEwZSgLg2QM

n8bar and others added 5 commits October 4, 2026 01:18
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01L5W7g1rrgyVqEwZSgLg2QM
Only the SHA-256 hash is stored; issue() returns the plain key once.
Revoked keys are never found by their plain value.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01L5W7g1rrgyVqEwZSgLg2QM
Make a key and see it once, list keys with last used, revoke one.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01L5W7g1rrgyVqEwZSgLg2QM
… still on error

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01L5W7g1rrgyVqEwZSgLg2QM

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant