Class: ApiKeys
Defined in: auth/src/apikeys.ts:61
Issues and verifies API keys. The plaintext key is returned exactly once by issue; only its SHA-256 hash is stored, so a leaked database never yields usable keys.
Constructors
Constructor
> new ApiKeys(options?): ApiKeys
Defined in: auth/src/apikeys.ts:66
Parameters
options?
ApiKeysOptions = {}
Returns
ApiKeys
Methods
get()
> get(id): Promise<ApiKeyInfo | null>
Defined in: auth/src/apikeys.ts:135
Reads a single key's public info (used to authorize a revoke).
Parameters
id
string
Returns
Promise<ApiKeyInfo | null>
issue()
> issue(input): Promise<{ key: string; record: ApiKeyInfo; }>
Defined in: auth/src/apikeys.ts:73
Mints a key. Returns the record plus the plaintext key (shown once).
Parameters
input
Returns
Promise<{ key: string; record: ApiKeyInfo; }>
list()
> list(filter): Promise<ApiKeyInfo[]>
Defined in: auth/src/apikeys.ts:111
Parameters
filter
Returns
Promise<ApiKeyInfo[]>
revoke()
> revoke(id): Promise<void>
Defined in: auth/src/apikeys.ts:116
Revokes a key by id. No-op if unknown or already revoked.
Parameters
id
string
Returns
Promise<void>
revokeAllForUser()
> revokeAllForUser(userId): Promise<void>
Defined in: auth/src/apikeys.ts:128
Revokes every live key owned by the user — for when the account's previous holder is no longer trusted (e.g. a verified social login adopted it).
Parameters
userId
string
Returns
Promise<void>
verify()
> verify(presented): Promise<ApiKeyRecord | null>
Defined in: auth/src/apikeys.ts:103
Resolves a presented key to its record, or null if it's malformed, unknown, or revoked. Updates lastUsedAt on a hit.
Parameters
presented
string
Returns
Promise<ApiKeyRecord | null>