Skip to content

basalt / auth/src / ApiKeysPluginOptions

Interface: ApiKeysPluginOptions ​

Defined in: auth/src/apikeys-plugin.ts:74

Extends ​

Properties ​

allowNarrowKeysOnUnscopedRoutes? ​

> optional allowNarrowKeysOnUnscopedRoutes?: boolean

Defined in: auth/src/apikeys-plugin.ts:99

By default a key that does not hold * is refused on routes gated by meta.auth/can/teamRole/audience unless the route also declares meta.scopes — scopes are an upper bound, not a label. true restores the old behaviour where any key with a userId acts as its owner. Default false.


allowTenantlessKeys? ​

> optional allowTenantlessKeys?: boolean

Defined in: auth/src/apikeys-plugin.ts:92

Keys issued without a tenant (machine/platform keys) are refused on any request that resolved a tenant, so they cannot be pointed at an arbitrary tenant through x-tenant-id, a subdomain or the Host. Set true only for trusted platform keys that must act across tenants. Default false.


> optional header?: string

Defined in: auth/src/apikeys-plugin.ts:80

Header carrying the key, besides Authorization: Bearer mk_.... Default x-api-key. A request carrying two different keys (one in each) is refused with 400 AUTH_APIKEY_AMBIGUOUS.


hooks? ​

> optional hooks?: HookBus

Defined in: auth/src/apikeys.ts:51

Inherited from ​

ApiKeysOptions.hooks


now? ​

> optional now?: () => number

Defined in: auth/src/apikeys.ts:53

Injectable clock — tests and deterministic runs override it.

Returns ​

number

Inherited from ​

ApiKeysOptions.now


store? ​

> optional store?: ApiKeyStore

Defined in: auth/src/apikeys.ts:50

Inherited from ​

ApiKeysOptions.store


users? ​

> optional users?: UserSource

Defined in: auth/src/apikeys-plugin.ts:85

When provided, a key that carries a userId also populates ctx().user, so scope-guarded routes can read the acting user.

Released under the MIT License.