Skip to content

feat(api-keys): allow organizations to create API keys#350

Merged
stophecom merged 2 commits into
devfrom
claude/org-api-keys
Jul 17, 2026
Merged

feat(api-keys): allow organizations to create API keys#350
stophecom merged 2 commits into
devfrom
claude/org-api-keys

Conversation

@stophecom

Copy link
Copy Markdown
Owner

Owners and admins of an organization can now create and revoke API keys on the org level, from a new API Keys tab (sits next to White-label, same owner/admin gate).

How org keys differ from personal keys

  • Plan gate: resolved from the organization's tier, not the member's. Top Secret Service is the only org plan with apiAccess, so Secret Service orgs see an upgrade teaser.
  • Domain restriction: a request must send X-Host matching a white-label site owned by that org. No X-Host, the original hostname, or another org's domain are all rejected. With the npm client this is the host option — note org keys will not work with the client's default host (scrt.link), which is intentional.
  • Limits come from the org, so a key keeps working as configured if the creator downgrades or leaves.
  • Attribution: userId still holds the creator, so secrets made via an org key stay attributed to a person. Personal key queries filter on a null organizationId so org keys don't leak onto the user's own API page.

Max 5 keys per org. Any owner/admin can revoke any org key, not just their own.

Drive-by fixes

Two pre-existing bugs in api/v1/secrets that this work touched:

  • Revoked keys kept working until the nightly cron deleted the row — the lookup never filtered revoked.
  • An unknown X-Host threw on .id of undefined instead of returning a 400.

Schema

Adds api_key.organization_id (nullable FK → organization, on delete cascade). Needs db:push / a migration on deploy.

Verification

Exercised against a real org key on a Top Secret Service org with a white-label domain:

Case Result
Org key + correct org domain 200, secret created on the org's site
Org key, no X-Host 400
Org key + X-Host: localhost 400
Org key + another org's domain 400
Revoked org key 403 (was: created a secret)
Bogus key / bad checksum 403 / 400
Org key on personal API page absent

Also drove the UI: create → key listed → revoke → revoked = true, with organizationId correctly flowing through both actions. Test data cleaned up.

Known limitation

Orgs whose white-label site predates the organizationId FK (site linked to a user, not the org) can't use org keys — the endpoint requires the site to be org-owned, and loosening that would defeat the restriction. The white-label page has a legacy fallback for these; a one-off backfill of white_label_site.organization_id is the fix rather than weakening the check.

🤖 Generated with Claude Code

Owners and admins of an organization can now create and revoke API keys
on the org level, from a new "API Keys" tab.

Organization keys are gated on the org's own plan (Top Secret Service is
the only org plan with apiAccess) and are restricted to the org's
white-label domain: requests must send X-Host matching a white-label site
owned by that organization, otherwise they are rejected. Limits are
resolved from the organization's tier rather than the creator's, so a key
keeps working as configured if the creator downgrades or leaves the org.

Keys carry the creator in userId, so secrets created via an org key stay
attributed to a person; personal key queries now filter on a null
organizationId so org keys don't leak onto the user's own API page.

Also fixes two pre-existing bugs in the secrets endpoint that this work
touched: revoked keys kept working until the nightly cron deleted the row
(the lookup never filtered `revoked`), and an unknown X-Host threw on
`.id` of undefined instead of returning a 400.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@vercel

vercel Bot commented Jul 17, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
scrt-link-v2 Ready Ready Preview, Comment Jul 17, 2026 10:17am

Request Review

The five org tabs need more width than a phone viewport, so the bar pushed
the whole page ~75px wider than the screen at 375px and wrapped labels onto
two lines. Scroll the bar horizontally instead and stop the tabs shrinking.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@stophecom stophecom self-assigned this Jul 17, 2026
@stophecom
stophecom merged commit d68b43f into dev Jul 17, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant