studio: Improve API Keys area to better understand where and how used

未关闭
#718 1 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看

还没有人认领这个 Issue。

评估

难度
5/5
预计耗时
一周以上
新手友好度
35/100
Issue 类型
功能
描述清晰度
需要澄清
活跃度
冷清

调研方向

首先查看 Studio API Keys 区域,以及密钥名称如何与 auth.json 中的 Command Code 配置相关联。该 issue 描述了多种可能的功能,因此在开始实现之前,需要先缩小范围并明确完成标准。

由索引模型根据 Issue 内容生成。

描述

Feature Description

Recently, I needed to delete an API key. When I went into API Keys area of the Studio, I saw I had 8-10 keys dating back to late 2025.

I found it difficult to know:

  • which keys were active (last used)
  • if they expire/d (doesn't seem they do)
  • the names were not meaningful nor did it match the name in the auth.json Command Code config settings
  • I could not edit the name to make them meaningful to me
  • recent usage of keys and where used (to identify if any key leaked and used by some strange IP address or geo)

So, I ended up just deleting all keys one by one and starting over from scratch, but then I realized:

  • the name in auth.json did not match
  • and the only way I could identify a key was by some UTC timestamp so I could tell one cli on one machine was an older key than another because I knew I created one before the other
Use Case

In general, be useful to:

  • know which key used where
  • add a description for the key purpose
  • names match installed name in auth.json
  • edit names to be descriptive
  • show some recent use (time, IP address, geo) to identify if any leaks
  • pause key
  • rotate key (vs delete and create and edit name a description)

Could take some cues from Unkey API Key management features. See: https://www.unkey.com/docs/platform/apis/keys

Additional Context

No response

How important is this to you?

Medium. But, this will increase if I use Command Code API more for inference in apps vs just the cli used on two devices or if I want to distinguish between a key for cli and a key for desktop.

主要语言
没有语言数据
星标
4k
派生
350
PR 合并指标
30 天内没有已合并 PR

贡献指南

这个仓库没有索引到贡献指南

从这里开始

  1. 先读完整个 Issue,再读项目的贡献指南。
  2. 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
  3. Fork 仓库,在一个分支上完成修改。
  4. 提交 Pull Request,并在描述里引用这个 Issue 编号。

CommandCodeAI/command-code 的其他 Issue

查看 CommandCodeAI/command-code 的全部 Issue

相似的 Issue

更多 Security Issue

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。