scaffold: set_key step for bring-your-own-key apps; public routes skip the key gate - #124
Merged
Merged
Conversation
A byo app whose users create their key on the provider's site had no way to hand that key to the adapter short of editing $APP/secrets.json by hand and restarting the app. The new set_key step generates a local <ns>.set_key method that caches a caller-supplied key (overwriting, so a revoked key can be replaced) and is read per request like any minted key. Calls made before a key exists soft-fail with a hint naming set_key and where to get a key. The activation hint is now step-aware: it previously told agents to call the signup method with no arguments even for register flows that need an email. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Apps whose key comes from a signup route wrap every http method in requireKey, so endpoints the provider serves without credentials (method catalogues, recommendations, the signup handshake itself) were unreachable until a key existed. A route marked public: true is forwarded as-is. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… endpoint
Some providers issue the API key in the body of an ordinary call rather than
through a signup flow the generator knows: Dial returns it once from
/auth/verify (existing account) or /auth/verify-number (new account). Those
apps forwarded the key to the agent in plain JSON and never stored it, so
every later call was unauthenticated.
A route with save_key: {path, secret_key, start} now caches the string at
path into $APP/secrets.json on a 2xx answer, replaces it in the reply, and
counts as the app's key-minting route: other calls soft-fail with a hint that
points at start until a key exists, and send the key once it does.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… the key Dial issues its key from /auth/verify (existing account) or /auth/verify-number (new account); naming only the first sent new users to the wrong step. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Two generator changes that plain bring-your-own-key apps need. The first users are Kinetic and Rent A Human (see the submissions PR that builds on this one).
signup.step: set_keyA BYO app whose users create their key on the provider's site had no way to hand that key to the adapter, short of editing
$APP/secrets.jsonby hand and restarting the app. The new step generates a local<ns>.set_keymethod:{"api_key": "..."}and caches it undersecret_key. It overwrites, so a revoked key can be replaced.signup.url(optional, https) says where to create a key and appears in the hint.Step-aware "no key yet" hint
requireKeyalways told agents to call the signup method "once (no arguments required)". That was wrong for register flows (which need an email) and forset_key. The hint now comes fromConfig.SignupHint()and names what to pass.http.public: trueEvery HTTP method of a signup app was wrapped in
requireKey. That made endpoints the provider serves without credentials (catalogues, recommendations, the signup handshake itself) unreachable before a key existed. A route markedpublicis forwarded as-is.Tests
zz_set_key_test.gocovers the config helpers, the step-aware hint, validation (a missingsecret_keyand anhttp://url are rejected), generated wiring (the gated route is wrapped, the public one is not), the manifest grants, and a compile of the generated project.go test ./internal/scaffold/ ./internal/publish/is green.🤖 Generated with Claude Code