Skip to content

feat: omni_sk_live_/omni_sk_test_ API key prefixes and test_mode - #77

Merged
man4ish merged 1 commit into
mainfrom
feature/m13-live-test-api-keys
Oct 4, 2026
Merged

man4ish merged 1 commit into
mainfrom
feature/m13-live-test-api-keys

Conversation

@man4ish

@man4ish man4ish commented Oct 4, 2026

Copy link
Copy Markdown
Collaborator

Summary

Closes the first of gap #9's two remaining sub-items (the other, test-mode's canned/unbilled gateway behavior, is a paired PR in omnibioai-api-gateway).

  • ApiKeyCreate.test (default False) lets a caller request a sandbox key -- both /orgs/{org_id}/api-keys and /me/api-keys -- issued as omni_sk_test_... instead of omni_sk_live_....
  • apikey_service.is_test_key() derives mode from the already-stored, non-secret key_prefix rather than a new DB column -- no migration needed.
  • exchange_api_key now reports test_mode in its response; ApiKeyOut/ApiKeyCreated report test so a key's mode is visible wherever it's listed.
  • Every key issued before this change keeps the bare omni_sk_ prefix (_PREFIX, unchanged) and is unambiguously live -- is_test_key only matches the new omni_sk_test_ prefix.

Test plan

  • pytest tests/test_apikeys.py tests/test_me_api_keys.py tests/test_apikey_exchange.py -- 48 passed, including live-by-default, explicit test-key creation (both routers), test_mode propagation through exchange, and a pre-M13 legacy bare-prefix key still exchanging successfully as non-test
  • Full repo suite -- 1472 passed, 2 skipped, 2 pre-existing MFA concurrency-timing tests confirmed flaky/unrelated (pass in isolation, no relation to API keys)

🤖 Generated with Claude Code

Replaces the single omni_sk_ prefix with omni_sk_live_/omni_sk_test_,
chosen per key at creation (ApiKeyCreate.test, both routers). A key's
mode is derived from its already-stored, non-secret key_prefix
(is_test_key) rather than a new DB column. exchange_api_key now reports
test_mode in its response, so the gateway can serve a canned, unbilled
response instead of forwarding to RAG -- see the matching
omnibioai-api-gateway change. Every key issued before this migration
keeps the bare omni_sk_ prefix and is unambiguously live.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@man4ish
man4ish merged commit f617710 into main Oct 4, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant