Auth
Every request needs an X-API-Key header. Keys are scoped, so a key created for read-only access can’t create or delete resources even if it leaks.
Setting the header
client.js
const res = await fetch("https://api.kitchen-sink.example.com/v1/widgets", {
headers: { "X-API-Key": process.env.ACME_API_KEY },
});Line highlighting - {1,3-4} meta
const key = process.env.ACME_API_KEY;
const url = "https://api.kitchen-sink.example.com/v1/widgets";
const headers = { "X-API-Key": key };
const res = await fetch(url, { headers });
console.log(await res.json());Line highlighting - [!code highlight]
function authenticate(request) {
const key = request.headers.get("X-API-Key");
if (!key) throw new Error("Missing API key");
return lookupKey(key);
}Word highlighting - /word/ meta
const apiKey = process.env.ACME_API_KEY;
fetch(url, { headers: { "X-Api-Key": apiKey } });Word highlighting - [!code word:...]
const scope = "widgets:read"; Focus
function setup() {
loadConfig();
authenticate();
connectToDatabase();
}Diff
const key = "sk_test_hardcoded";
const key = process.env.ACME_API_KEY; Error / warning
const safe = validateApiKey(key);
const unsafe = eval(key);
const deprecated = legacyAuth(key); Wrap
const errorMessage = "The provided API key is either missing, malformed, or has been revoked - check the dashboard under Settings → API Keys to confirm it's still active before retrying.";Line numbers
function isExpired(token) {
return Date.now() > token.expiresAt;
}
console.log(isExpired(currentToken));Expandable
Keys don’t expire by default, but you can set an expiry when creating one. An expired key returns 401 Unauthorized with { "error": "token_expired" } - the same shape as a missing or revoked key, so don’t rely on the error message alone to distinguish the two.