Skip to content

basalt / auth/src / ApiKeys

Class: ApiKeys ​

Defined in: auth/src/apikeys.ts:61

Issues and verifies API keys. The plaintext key is returned exactly once by issue; only its SHA-256 hash is stored, so a leaked database never yields usable keys.

Constructors ​

Constructor ​

> new ApiKeys(options?): ApiKeys

Defined in: auth/src/apikeys.ts:66

Parameters ​

options? ​

ApiKeysOptions = {}

Returns ​

ApiKeys

Methods ​

get() ​

> get(id): Promise<ApiKeyInfo | null>

Defined in: auth/src/apikeys.ts:135

Reads a single key's public info (used to authorize a revoke).

Parameters ​

id ​

string

Returns ​

Promise<ApiKeyInfo | null>


issue() ​

> issue(input): Promise<{ key: string; record: ApiKeyInfo; }>

Defined in: auth/src/apikeys.ts:73

Mints a key. Returns the record plus the plaintext key (shown once).

Parameters ​

input ​

IssueApiKeyInput

Returns ​

Promise<{ key: string; record: ApiKeyInfo; }>


list() ​

> list(filter): Promise<ApiKeyInfo[]>

Defined in: auth/src/apikeys.ts:111

Parameters ​

filter ​

ApiKeyFilter

Returns ​

Promise<ApiKeyInfo[]>


revoke() ​

> revoke(id): Promise<void>

Defined in: auth/src/apikeys.ts:116

Revokes a key by id. No-op if unknown or already revoked.

Parameters ​

id ​

string

Returns ​

Promise<void>


revokeAllForUser() ​

> revokeAllForUser(userId): Promise<void>

Defined in: auth/src/apikeys.ts:128

Revokes every live key owned by the user — for when the account's previous holder is no longer trusted (e.g. a verified social login adopted it).

Parameters ​

userId ​

string

Returns ​

Promise<void>


verify() ​

> verify(presented): Promise<ApiKeyRecord | null>

Defined in: auth/src/apikeys.ts:103

Resolves a presented key to its record, or null if it's malformed, unknown, or revoked. Updates lastUsedAt on a hit.

Parameters ​

presented ​

string

Returns ​

Promise<ApiKeyRecord | null>

Released under the MIT License.