studio: Improve API Keys area to better understand where and how used

Ouverte
#718 1 commentaire 0 réactions 0 personnes assignées Voir sur GitHub

Personne n'a encore pris cette issue.

Évaluation

Difficulté
5/5
Temps estimé
Plus d'une semaine
Accessibilité débutants
35/100
Type d'issue
Fonctionnalité
Clarté
À clarifier
Activité
Calme
Domaine
authentication

Piste de recherche

Commencez par examiner la zone Studio API Keys et la manière dont les noms des clés sont liés à la configuration de Command Code dans auth.json. L’issue décrit plusieurs fonctionnalités possibles ; il faut donc préciser le périmètre et les critères d’achèvement avant de commencer l’implémentation.

Rédigé par le modèle d'indexation à partir du texte de l'issue.

Description

Feature Description

Recently, I needed to delete an API key. When I went into API Keys area of the Studio, I saw I had 8-10 keys dating back to late 2025.

I found it difficult to know:

  • which keys were active (last used)
  • if they expire/d (doesn't seem they do)
  • the names were not meaningful nor did it match the name in the auth.json Command Code config settings
  • I could not edit the name to make them meaningful to me
  • recent usage of keys and where used (to identify if any key leaked and used by some strange IP address or geo)

So, I ended up just deleting all keys one by one and starting over from scratch, but then I realized:

  • the name in auth.json did not match
  • and the only way I could identify a key was by some UTC timestamp so I could tell one cli on one machine was an older key than another because I knew I created one before the other
Use Case

In general, be useful to:

  • know which key used where
  • add a description for the key purpose
  • names match installed name in auth.json
  • edit names to be descriptive
  • show some recent use (time, IP address, geo) to identify if any leaks
  • pause key
  • rotate key (vs delete and create and edit name a description)

Could take some cues from Unkey API Key management features. See: https://www.unkey.com/docs/platform/apis/keys

Additional Context

No response

How important is this to you?

Medium. But, this will increase if I use Command Code API more for inference in apps vs just the cli used on two devices or if I want to distinguish between a key for cli and a key for desktop.

Langage dominant
Aucune donnée de langage
Étoiles
4k
Forks
350
Métriques de merge des PR
Aucune PR mergée en 30 j

Guide de contribution

Aucun guide de contribution indexé pour ce dépôt

Par où commencer

  1. Lisez l'issue en entier, puis le guide de contribution du projet.
  2. Signalez en commentaire que vous la prenez — cela évite que deux personnes fassent le même travail.
  3. Forkez le dépôt et travaillez sur une branche.
  4. Ouvrez une pull request qui référence le numéro de l'issue.

Autres issues de CommandCodeAI/command-code

Toutes les issues de CommandCodeAI/command-code

Issues similaires

Plus d'issues Security

Recevez les nouvelles issues par e-mail

Un résumé court des issues GitHub adaptées aux débutants.