Skip to content

feat: public literature:read/usage:read API-key scopes, key rename, settable expiry - #76

Merged
man4ish merged 1 commit into
mainfrom
feature/m9-api-key-literature-scope-rename-expiry
Oct 4, 2026
Merged

man4ish merged 1 commit into
mainfrom
feature/m9-api-key-literature-scope-rename-expiry

Conversation

@man4ish

@man4ish man4ish commented Oct 4, 2026

Copy link
Copy Markdown
Collaborator

Summary

  • Self-service /me/api-keys keys are now issued/displayed in the design doc's public scope vocabulary (literature:read, usage:read), translated to/from the internal dataset.read/usage.read permission names at this HTTP boundary only -- the permission registry, role grants, the org-admin /orgs/{org_id}/api-keys router, and the gateway/policy-engine's existing enforcement are all unchanged.
  • Added key rename (PATCH, both the self-service and org-admin routers), with a new API_KEY_RENAMED audit event.
  • Added an optional, future-only expires_at at creation (both routers) -- expires_at already existed in storage and in ApiKeyOut, but nothing let a caller set it.

Closes three of gap #9's five sub-items (API-key lifecycle): the public scope naming, key rename, and settable expiry. Not in this PR (deliberately, scoped out up front): omni_sk_live_/omni_sk_test_ prefixes + unbilled test-mode responses, and gating self-service creation on an active billing plan -- both bigger, cross-service changes.

Test plan

  • pytest tests/test_apikeys.py tests/test_me_api_keys.py tests/test_apikey_exchange.py tests/test_route_authorization_coverage.py -- all passing, including the updated org-scoped-route-count tripwire (43 -> 44 for the new org-admin rename route)
  • Full repo suite (pytest, excluding two pre-existing collection errors unrelated to this change) -- 1466 passed, 2 skipped
  • Confirmed the gateway/policy-engine's dataset.read/usage.read enforcement path is untouched (no changes outside omnibioai-auth)

🤖 Generated with Claude Code

…ettable expiry

Design doc's public scope vocabulary (literature:read, usage:read) is now
what self-service keys are issued/displayed in, translated to/from the
internal dataset.read/usage.read permission names at the /me/api-keys
HTTP boundary only -- the registry, role grants, the org-admin
/orgs/{org_id}/api-keys router, and the gateway/policy-engine's existing
enforcement are all untouched. Also adds key rename (PATCH, both routers)
and an optional expires_at at creation (both routers), closing three of
gap #9's five sub-items.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@man4ish
man4ish merged commit d650676 into main Oct 4, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant