Skip to content

scaffold: set_key step for bring-your-own-key apps; public routes skip the key gate - #124

Merged
TeoSlayer merged 5 commits into
mainfrom
feat/signup-set-key-step
Oct 1, 2026
Merged

TeoSlayer merged 5 commits into
mainfrom
feat/signup-set-key-step

Conversation

@Alexgodoroja

Copy link
Copy Markdown
Collaborator

Two generator changes that plain bring-your-own-key apps need. The first users are Kinetic and Rent A Human (see the submissions PR that builds on this one).

signup.step: set_key

A BYO app whose users create their key on the provider's site had no way to hand that key to the adapter, short of editing $APP/secrets.json by hand and restarting the app. The new step generates a local <ns>.set_key method:

  • It takes {"api_key": "..."} and caches it under secret_key. It overwrites, so a revoked key can be replaced.
  • It is read per request, like any minted key, so no restart is needed.
  • signup.url (optional, https) says where to create a key and appears in the hint.

Step-aware "no key yet" hint

requireKey always told agents to call the signup method "once (no arguments required)". That was wrong for register flows (which need an email) and for set_key. The hint now comes from Config.SignupHint() and names what to pass.

http.public: true

Every HTTP method of a signup app was wrapped in requireKey. That made endpoints the provider serves without credentials (catalogues, recommendations, the signup handshake itself) unreachable before a key existed. A route marked public is forwarded as-is.

Tests

  • zz_set_key_test.go covers the config helpers, the step-aware hint, validation (a missing secret_key and an http:// url are rejected), generated wiring (the gated route is wrapped, the public one is not), the manifest grants, and a compile of the generated project.
  • go test ./internal/scaffold/ ./internal/publish/ is green.

🤖 Generated with Claude Code

Alexgodoroja and others added 4 commits September 25, 2026 15:07
A byo app whose users create their key on the provider's site had no way to
hand that key to the adapter short of editing $APP/secrets.json by hand and
restarting the app. The new set_key step generates a local <ns>.set_key
method that caches a caller-supplied key (overwriting, so a revoked key can be
replaced) and is read per request like any minted key. Calls made before a key
exists soft-fail with a hint naming set_key and where to get a key.

The activation hint is now step-aware: it previously told agents to call the
signup method with no arguments even for register flows that need an email.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Apps whose key comes from a signup route wrap every http method in
requireKey, so endpoints the provider serves without credentials (method
catalogues, recommendations, the signup handshake itself) were unreachable
until a key existed. A route marked public: true is forwarded as-is.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… endpoint

Some providers issue the API key in the body of an ordinary call rather than
through a signup flow the generator knows: Dial returns it once from
/auth/verify (existing account) or /auth/verify-number (new account). Those
apps forwarded the key to the agent in plain JSON and never stored it, so
every later call was unauthenticated.

A route with save_key: {path, secret_key, start} now caches the string at
path into $APP/secrets.json on a 2xx answer, replaces it in the reply, and
counts as the app's key-minting route: other calls soft-fail with a hint that
points at start until a key exists, and send the key once it does.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… the key

Dial issues its key from /auth/verify (existing account) or
/auth/verify-number (new account); naming only the first sent new users to
the wrong step.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@TeoSlayer
TeoSlayer merged commit 221caa3 into main Oct 1, 2026
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants