basalt / auth/src / ApiKeysPluginOptions
Interface: ApiKeysPluginOptions
Defined in: auth/src/apikeys-plugin.ts:74
Extends
Properties
allowNarrowKeysOnUnscopedRoutes?
> optional allowNarrowKeysOnUnscopedRoutes?: boolean
Defined in: auth/src/apikeys-plugin.ts:99
By default a key that does not hold * is refused on routes gated by meta.auth/can/teamRole/audience unless the route also declares meta.scopes — scopes are an upper bound, not a label. true restores the old behaviour where any key with a userId acts as its owner. Default false.
allowTenantlessKeys?
> optional allowTenantlessKeys?: boolean
Defined in: auth/src/apikeys-plugin.ts:92
Keys issued without a tenant (machine/platform keys) are refused on any request that resolved a tenant, so they cannot be pointed at an arbitrary tenant through x-tenant-id, a subdomain or the Host. Set true only for trusted platform keys that must act across tenants. Default false.
header?
> optional header?: string
Defined in: auth/src/apikeys-plugin.ts:80
Header carrying the key, besides Authorization: Bearer mk_.... Default x-api-key. A request carrying two different keys (one in each) is refused with 400 AUTH_APIKEY_AMBIGUOUS.
hooks?
> optional hooks?: HookBus
Defined in: auth/src/apikeys.ts:51
Inherited from
now?
> optional now?: () => number
Defined in: auth/src/apikeys.ts:53
Injectable clock — tests and deterministic runs override it.
Returns
number
Inherited from
store?
> optional store?: ApiKeyStore
Defined in: auth/src/apikeys.ts:50
Inherited from
users?
> optional users?: UserSource
Defined in: auth/src/apikeys-plugin.ts:85
When provided, a key that carries a userId also populates ctx().user, so scope-guarded routes can read the acting user.