basalt / auth/src / ApiKeyRecord
Interface: ApiKeyRecord
Defined in: auth/src/stores.ts:227
A stored API key. The plaintext key is never persisted — only its SHA-256 hash (for O(1) lookup) and a short prefix (for display in listings).
Properties
createdAt
> createdAt: number
Defined in: auth/src/stores.ts:241
expiresAt?
> optional expiresAt?: number
Defined in: auth/src/stores.ts:243
Unix timestamp in milliseconds; omitted means the key never expires.
hash
> hash: string
Defined in: auth/src/stores.ts:234
SHA-256 of the full presented key.
id
> id: string
Defined in: auth/src/stores.ts:228
lastUsedAt?
> optional lastUsedAt?: number
Defined in: auth/src/stores.ts:244
name
> name: string
Defined in: auth/src/stores.ts:230
Human label, e.g. "CI pipeline".
prefix
> prefix: string
Defined in: auth/src/stores.ts:232
Visible portion shown in listings, e.g. mk_live_ab12cd.
revokedAt?
> optional revokedAt?: number
Defined in: auth/src/stores.ts:245
scopes
> scopes: string[]
Defined in: auth/src/stores.ts:240
Granted scopes; * means all.
tenantId?
> optional tenantId?: string
Defined in: auth/src/stores.ts:236
Owning tenant, when created inside a tenant context.
userId?
> optional userId?: string
Defined in: auth/src/stores.ts:238
User who created the key, when created by a logged-in user.