apikey

package
v1.0.2 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 30, 2026 License: MIT Imports: 5 Imported by: 0

Documentation

Overview

Package apikey is the API-key token format, shared by the engine (mint and resolve) and verify (routing a bearer token to the API-key path).

A token is <marker><lookup id>_<secret>. The marker is "<prefix>_st_", or "st_" without a host prefix. The lookup id is public and indexed; only a SHA-256 of the secret is stored. Both parts are base62, so the first "_" after the marker is the delimiter.

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

func HasMarker

func HasMarker(prefix, token string) bool

HasMarker reports whether token is shaped like an API key for prefix.

func Hash

func Hash(secret string) []byte

Hash is the stored form of a secret.

func Marker

func Marker(prefix string) string

Marker is the leading marker of a token for the host prefix.

func Matches

func Matches(stored []byte, secret string) bool

Matches reports, in constant time, whether secret hashes to stored.

func Parse

func Parse(prefix, token string) (lookupID, secret string, ok bool)

Parse splits a token into its lookup id and secret. ok is false unless the token carries the marker and both parts are non-empty base62.

Types

type Minted

type Minted struct {
	Token      string
	LookupID   string
	SecretHash []byte
}

Minted is a new key: store LookupID and SecretHash, and hand Token out once.

func Mint

func Mint(prefix string) (Minted, error)

Mint generates a new key for prefix.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL