Skip to content

@nestarc/api-keys ​

Classes ​

ApiKeyError ​

Defined in: src/errors.ts:31

Extends ​

  • HttpExceptionBase

Constructors ​

Constructor ​
ts
new ApiKeyError(code, reason?): ApiKeyError;

Defined in: src/errors.ts:38

Parameters ​
ParameterType
codeApiKeyErrorCode
reason?string
Returns ​

ApiKeyError

Overrides ​
ts
HttpExceptionBase.constructor

Properties ​

cause ​
ts
cause: unknown;

Defined in: node_modules/@nestjs/common/exceptions/http.exception.d.ts:28

Exception cause. Indicates the specific original cause of the error. It is used when catching and re-throwing an error with a more-specific or useful error message in order to still have access to the original error.

Inherited from ​
ts
HttpExceptionBase.cause

code ​
ts
readonly code: ApiKeyErrorCode;

Defined in: src/errors.ts:32

httpStatus ​
ts
readonly httpStatus: number;

Defined in: src/errors.ts:36

Backward-compatible status property. Prefer Nest's getStatus() for new code.

message ​
ts
message: string;

Defined in: node_modules/typescript/lib/lib.es5.d.ts:1077

Inherited from ​
ts
HttpExceptionBase.message

name ​
ts
name: string;

Defined in: node_modules/typescript/lib/lib.es5.d.ts:1076

Inherited from ​
ts
HttpExceptionBase.name

stack? ​
ts
optional stack?: string;

Defined in: node_modules/typescript/lib/lib.es5.d.ts:1078

Inherited from ​
ts
HttpExceptionBase.stack

stackTraceLimit ​
ts
static stackTraceLimit: number;

Defined in: node_modules/@types/node/globals.d.ts:68

The Error.stackTraceLimit property specifies the number of stack frames collected by a stack trace (whether generated by new Error().stack or Error.captureStackTrace(obj)).

The default value is 10 but may be set to any valid JavaScript number. Changes will affect any stack trace captured after the value has been changed.

If set to a non-number value, or set to a negative number, stack traces will not capture any frames.

Inherited from ​
ts
HttpExceptionBase.stackTraceLimit

Methods ​

captureStackTrace() ​
ts
static captureStackTrace(targetObject, constructorOpt?): void;

Defined in: node_modules/@types/node/globals.d.ts:52

Creates a .stack property on targetObject, which when accessed returns a string representing the location in the code at which Error.captureStackTrace() was called.

js
const myObject = {};
Error.captureStackTrace(myObject);
myObject.stack;  // Similar to `new Error().stack`

The first line of the trace will be prefixed with ${myObject.name}: ${myObject.message}.

The optional constructorOpt argument accepts a function. If given, all frames above constructorOpt, including constructorOpt, will be omitted from the generated stack trace.

The constructorOpt argument is useful for hiding implementation details of error generation from the user. For instance:

js
function a() {
  b();
}

function b() {
  c();
}

function c() {
  // Create an error without stack trace to avoid calculating the stack trace twice.
  const { stackTraceLimit } = Error;
  Error.stackTraceLimit = 0;
  const error = new Error();
  Error.stackTraceLimit = stackTraceLimit;

  // Capture the stack trace above function b
  Error.captureStackTrace(error, b); // Neither function c, nor b is included in the stack trace
  throw error;
}

a();
Parameters ​
ParameterType
targetObjectobject
constructorOpt?Function
Returns ​

void

Inherited from ​
ts
HttpExceptionBase.captureStackTrace

createBody() ​
Call Signature ​
ts
static createBody(
   nil,
   message,
   statusCode): HttpExceptionBody;

Defined in: node_modules/@nestjs/common/exceptions/http.exception.d.ts:74

Parameters ​
ParameterType
nil"" | null
messageHttpExceptionBodyMessage
statusCodenumber
Returns ​

HttpExceptionBody

Inherited from ​
ts
HttpExceptionBase.createBody
Call Signature ​
ts
static createBody(
   message,
   error,
   statusCode): HttpExceptionBody;

Defined in: node_modules/@nestjs/common/exceptions/http.exception.d.ts:75

Parameters ​
ParameterType
messageHttpExceptionBodyMessage
errorstring
statusCodenumber
Returns ​

HttpExceptionBody

Inherited from ​
ts
HttpExceptionBase.createBody
Call Signature ​
ts
static createBody<Body>(custom): Body;

Defined in: node_modules/@nestjs/common/exceptions/http.exception.d.ts:76

Type Parameters ​
Type Parameter
Body extends Record<string, unknown>
Parameters ​
ParameterType
customBody
Returns ​

Body

Inherited from ​
ts
HttpExceptionBase.createBody

extractDescriptionAndOptionsFrom() ​
ts
static extractDescriptionAndOptionsFrom(descriptionOrOptions): DescriptionAndOptions;

Defined in: node_modules/@nestjs/common/exceptions/http.exception.d.ts:84

Utility method used to extract the error description and httpExceptionOptions from the given argument. This is used by inheriting classes to correctly parse both options.

Parameters ​
ParameterType
descriptionOrOptionsstring | HttpExceptionOptions
Returns ​

DescriptionAndOptions

the error description and the httpExceptionOptions as an object.

Inherited from ​
ts
HttpExceptionBase.extractDescriptionAndOptionsFrom

getDescriptionFrom() ​
ts
static getDescriptionFrom(descriptionOrOptions): string;

Defined in: node_modules/@nestjs/common/exceptions/http.exception.d.ts:77

Parameters ​
ParameterType
descriptionOrOptionsstring | HttpExceptionOptions
Returns ​

string

Inherited from ​
ts
HttpExceptionBase.getDescriptionFrom

getHttpExceptionOptionsFrom() ​
ts
static getHttpExceptionOptionsFrom(descriptionOrOptions): HttpExceptionOptions;

Defined in: node_modules/@nestjs/common/exceptions/http.exception.d.ts:78

Parameters ​
ParameterType
descriptionOrOptionsstring | HttpExceptionOptions
Returns ​

HttpExceptionOptions

Inherited from ​
ts
HttpExceptionBase.getHttpExceptionOptionsFrom

getResponse() ​
ts
getResponse(): string | object;

Defined in: node_modules/@nestjs/common/exceptions/http.exception.d.ts:72

Returns ​

string | object

Inherited from ​
ts
HttpExceptionBase.getResponse

getStatus() ​
ts
getStatus(): number;

Defined in: node_modules/@nestjs/common/exceptions/http.exception.d.ts:73

Returns ​

number

Inherited from ​
ts
HttpExceptionBase.getStatus

initCause() ​
ts
initCause(): void;

Defined in: node_modules/@nestjs/common/exceptions/http.exception.d.ts:69

Configures error chaining support

Returns ​

void

See ​
Inherited from ​
ts
HttpExceptionBase.initCause

initMessage() ​
ts
initMessage(): void;

Defined in: node_modules/@nestjs/common/exceptions/http.exception.d.ts:70

Returns ​

void

Inherited from ​
ts
HttpExceptionBase.initMessage

initName() ​
ts
initName(): void;

Defined in: node_modules/@nestjs/common/exceptions/http.exception.d.ts:71

Returns ​

void

Inherited from ​
ts
HttpExceptionBase.initName

prepareStackTrace() ​
ts
static prepareStackTrace(err, stackTraces): any;

Defined in: node_modules/@types/node/globals.d.ts:56

Parameters ​
ParameterType
errError
stackTracesCallSite[]
Returns ​

any

See ​

https://v8.dev/docs/stack-trace-api#customizing-stack-traces

Inherited from ​
ts
HttpExceptionBase.prepareStackTrace

ApiKeyOperationError ​

Defined in: src/errors.ts:59

Extends ​

  • Error

Constructors ​

Constructor ​
ts
new ApiKeyOperationError(
   code,
   reason?,
   options?): ApiKeyOperationError;

Defined in: src/errors.ts:62

Parameters ​
ParameterType
codeApiKeyOperationErrorCode
reason?string
options?ErrorOptions
Returns ​

ApiKeyOperationError

Overrides ​
ts
Error.constructor

Properties ​

cause? ​
ts
optional cause?: unknown;

Defined in: node_modules/typescript/lib/lib.es2022.error.d.ts:26

Inherited from ​
ts
Error.cause

code ​
ts
readonly code: ApiKeyOperationErrorCode;

Defined in: src/errors.ts:60

message ​
ts
message: string;

Defined in: node_modules/typescript/lib/lib.es5.d.ts:1077

Inherited from ​
ts
Error.message

name ​
ts
name: string;

Defined in: node_modules/typescript/lib/lib.es5.d.ts:1076

Inherited from ​
ts
Error.name

stack? ​
ts
optional stack?: string;

Defined in: node_modules/typescript/lib/lib.es5.d.ts:1078

Inherited from ​
ts
Error.stack

stackTraceLimit ​
ts
static stackTraceLimit: number;

Defined in: node_modules/@types/node/globals.d.ts:68

The Error.stackTraceLimit property specifies the number of stack frames collected by a stack trace (whether generated by new Error().stack or Error.captureStackTrace(obj)).

The default value is 10 but may be set to any valid JavaScript number. Changes will affect any stack trace captured after the value has been changed.

If set to a non-number value, or set to a negative number, stack traces will not capture any frames.

Inherited from ​
ts
Error.stackTraceLimit

Methods ​

captureStackTrace() ​
ts
static captureStackTrace(targetObject, constructorOpt?): void;

Defined in: node_modules/@types/node/globals.d.ts:52

Creates a .stack property on targetObject, which when accessed returns a string representing the location in the code at which Error.captureStackTrace() was called.

js
const myObject = {};
Error.captureStackTrace(myObject);
myObject.stack;  // Similar to `new Error().stack`

The first line of the trace will be prefixed with ${myObject.name}: ${myObject.message}.

The optional constructorOpt argument accepts a function. If given, all frames above constructorOpt, including constructorOpt, will be omitted from the generated stack trace.

The constructorOpt argument is useful for hiding implementation details of error generation from the user. For instance:

js
function a() {
  b();
}

function b() {
  c();
}

function c() {
  // Create an error without stack trace to avoid calculating the stack trace twice.
  const { stackTraceLimit } = Error;
  Error.stackTraceLimit = 0;
  const error = new Error();
  Error.stackTraceLimit = stackTraceLimit;

  // Capture the stack trace above function b
  Error.captureStackTrace(error, b); // Neither function c, nor b is included in the stack trace
  throw error;
}

a();
Parameters ​
ParameterType
targetObjectobject
constructorOpt?Function
Returns ​

void

Inherited from ​
ts
Error.captureStackTrace

prepareStackTrace() ​
ts
static prepareStackTrace(err, stackTraces): any;

Defined in: node_modules/@types/node/globals.d.ts:56

Parameters ​
ParameterType
errError
stackTracesCallSite[]
Returns ​

any

See ​

https://v8.dev/docs/stack-trace-api#customizing-stack-traces

Inherited from ​
ts
Error.prepareStackTrace

ApiKeysGuard ​

Defined in: src/api-keys.guard.ts:24

Implements ​

  • CanActivate

Constructors ​

Constructor ​
ts
new ApiKeysGuard(
   service,
   reflector,
   contextWriter?,
   clientIpResolver?): ApiKeysGuard;

Defined in: src/api-keys.guard.ts:25

Parameters ​
ParameterType
serviceApiKeysService
reflectorReflector
contextWriter?ApiKeyContextWriter
clientIpResolver?ApiKeyClientIpResolver
Returns ​

ApiKeysGuard

Methods ​

canActivate() ​
ts
canActivate(context): Promise<boolean>;

Defined in: src/api-keys.guard.ts:37

Parameters ​
ParameterTypeDescription
contextExecutionContextCurrent execution context. Provides access to details about the current request pipeline.
Returns ​

Promise<boolean>

Value indicating whether or not the current request is allowed to proceed.

Implementation of ​
ts
CanActivate.canActivate

ApiKeysModule ​

Defined in: src/api-keys.module.ts:52

Constructors ​

Constructor ​
ts
new ApiKeysModule(): ApiKeysModule;
Returns ​

ApiKeysModule

Methods ​

forRoot() ​
ts
static forRoot(options): DynamicModule;

Defined in: src/api-keys.module.ts:53

Parameters ​
ParameterType
optionsApiKeysModuleOptions
Returns ​

DynamicModule


ApiKeysService ​

Defined in: src/api-keys.service.ts:81

Constructors ​

Constructor ​
ts
new ApiKeysService(deps): ApiKeysService;

Defined in: src/api-keys.service.ts:112

Parameters ​
ParameterType
depsApiKeysServiceDeps
Returns ​

ApiKeysService

Methods ​

authorizeRequest() ​
ts
authorizeRequest(input): Promise<ApiKeyContext>;

Defined in: src/api-keys.service.ts:224

Parameters ​
ParameterType
inputApiKeyRequestAuthorizationInput
Returns ​

Promise<ApiKeyContext>

create() ​
ts
create(input): Promise<CreateApiKeyResult>;

Defined in: src/api-keys.service.ts:153

Parameters ​
ParameterType
inputCreateApiKeyInput
Returns ​

Promise<CreateApiKeyResult>

list() ​
ts
list(tenantId, opts?): Promise<ApiKeySummary[]>;

Defined in: src/api-keys.service.ts:601

Parameters ​
ParameterType
tenantIdstring
optsListApiKeysOptions
Returns ​

Promise<ApiKeySummary[]>

revoke() ​
ts
revoke(id): Promise<void>;

Defined in: src/api-keys.service.ts:382

Parameters ​
ParameterType
idstring
Returns ​

Promise<void>

revokeForTenant() ​
ts
revokeForTenant(tenantId, id): Promise<void>;

Defined in: src/api-keys.service.ts:400

Parameters ​
ParameterType
tenantIdstring
idstring
Returns ​

Promise<void>

rotate() ​
ts
rotate(id, input?): Promise<RotateApiKeyResult>;

Defined in: src/api-keys.service.ts:439

Parameters ​
ParameterType
idstring
inputRotateApiKeyInput
Returns ​

Promise<RotateApiKeyResult>

rotateForTenant() ​
ts
rotateForTenant(
   tenantId,
   id,
input?): Promise<RotateApiKeyResult>;

Defined in: src/api-keys.service.ts:446

Parameters ​
ParameterType
tenantIdstring
idstring
inputRotateApiKeyInput
Returns ​

Promise<RotateApiKeyResult>

verify() ​
ts
verify(rawKey): Promise<ApiKeyContext>;

Defined in: src/api-keys.service.ts:218

Parameters ​
ParameterType
rawKeystring
Returns ​

Promise<ApiKeyContext>


ApiKeyStorageContractError ​

Defined in: src/storage/storage-contract.ts:22

Extends ​

  • Error

Constructors ​

Constructor ​
ts
new ApiKeyStorageContractError(
   adapterName,
   check,
   cause): ApiKeyStorageContractError;

Defined in: src/storage/storage-contract.ts:26

Parameters ​
ParameterType
adapterNamestring
checkstring
causeunknown
Returns ​

ApiKeyStorageContractError

Overrides ​
ts
Error.constructor

Properties ​

adapterName ​
ts
readonly adapterName: string;

Defined in: src/storage/storage-contract.ts:23

cause? ​
ts
optional cause?: unknown;

Defined in: node_modules/typescript/lib/lib.es2022.error.d.ts:26

Inherited from ​
ts
Error.cause

check ​
ts
readonly check: string;

Defined in: src/storage/storage-contract.ts:24

message ​
ts
message: string;

Defined in: node_modules/typescript/lib/lib.es5.d.ts:1077

Inherited from ​
ts
Error.message

name ​
ts
name: string;

Defined in: node_modules/typescript/lib/lib.es5.d.ts:1076

Inherited from ​
ts
Error.name

stack? ​
ts
optional stack?: string;

Defined in: node_modules/typescript/lib/lib.es5.d.ts:1078

Inherited from ​
ts
Error.stack

stackTraceLimit ​
ts
static stackTraceLimit: number;

Defined in: node_modules/@types/node/globals.d.ts:68

The Error.stackTraceLimit property specifies the number of stack frames collected by a stack trace (whether generated by new Error().stack or Error.captureStackTrace(obj)).

The default value is 10 but may be set to any valid JavaScript number. Changes will affect any stack trace captured after the value has been changed.

If set to a non-number value, or set to a negative number, stack traces will not capture any frames.

Inherited from ​
ts
Error.stackTraceLimit

Methods ​

captureStackTrace() ​
ts
static captureStackTrace(targetObject, constructorOpt?): void;

Defined in: node_modules/@types/node/globals.d.ts:52

Creates a .stack property on targetObject, which when accessed returns a string representing the location in the code at which Error.captureStackTrace() was called.

js
const myObject = {};
Error.captureStackTrace(myObject);
myObject.stack;  // Similar to `new Error().stack`

The first line of the trace will be prefixed with ${myObject.name}: ${myObject.message}.

The optional constructorOpt argument accepts a function. If given, all frames above constructorOpt, including constructorOpt, will be omitted from the generated stack trace.

The constructorOpt argument is useful for hiding implementation details of error generation from the user. For instance:

js
function a() {
  b();
}

function b() {
  c();
}

function c() {
  // Create an error without stack trace to avoid calculating the stack trace twice.
  const { stackTraceLimit } = Error;
  Error.stackTraceLimit = 0;
  const error = new Error();
  Error.stackTraceLimit = stackTraceLimit;

  // Capture the stack trace above function b
  Error.captureStackTrace(error, b); // Neither function c, nor b is included in the stack trace
  throw error;
}

a();
Parameters ​
ParameterType
targetObjectobject
constructorOpt?Function
Returns ​

void

Inherited from ​
ts
Error.captureStackTrace

prepareStackTrace() ​
ts
static prepareStackTrace(err, stackTraces): any;

Defined in: node_modules/@types/node/globals.d.ts:56

Parameters ​
ParameterType
errError
stackTracesCallSite[]
Returns ​

any

See ​

https://v8.dev/docs/stack-trace-api#customizing-stack-traces

Inherited from ​
ts
Error.prepareStackTrace

InMemoryApiKeyStorage ​

Defined in: src/storage/in-memory-storage.ts:12

Implements ​

Constructors ​

Constructor ​
ts
new InMemoryApiKeyStorage(): InMemoryApiKeyStorage;
Returns ​

InMemoryApiKeyStorage

Methods ​

findById() ​
ts
findById(id): Promise<ApiKeyRecord | null>;

Defined in: src/storage/in-memory-storage.ts:29

Parameters ​
ParameterType
idstring
Returns ​

Promise<ApiKeyRecord | null>

Implementation of ​

ApiKeyStorage.findById

findByPrefix() ​
ts
findByPrefix(prefix): Promise<ApiKeyRecord | null>;

Defined in: src/storage/in-memory-storage.ts:34

Parameters ​
ParameterType
prefixstring
Returns ​

Promise<ApiKeyRecord | null>

Implementation of ​

ApiKeyStorage.findByPrefix

insert() ​
ts
insert(record): Promise<void>;

Defined in: src/storage/in-memory-storage.ts:15

Parameters ​
ParameterType
recordApiKeyRecord
Returns ​

Promise<void>

Implementation of ​

ApiKeyStorage.insert

listByTenant() ​
ts
listByTenant(tenantId, opts?): Promise<ApiKeyRecord[]>;

Defined in: src/storage/in-memory-storage.ts:44

Return tenant records ordered by createdAt descending, then id ascending.

Parameters ​
ParameterType
tenantIdstring
optsListApiKeysOptions
Returns ​

Promise<ApiKeyRecord[]>

Implementation of ​

ApiKeyStorage.listByTenant

markRevoked() ​
ts
markRevoked(id, at): Promise<void>;

Defined in: src/storage/in-memory-storage.ts:53

Parameters ​
ParameterType
idstring
atDate
Returns ​

Promise<void>

Implementation of ​

ApiKeyStorage.markRevoked

revokeForTenant() ​
ts
revokeForTenant(input): Promise<TenantBoundRevokeApiKeyStorageResult>;

Defined in: src/storage/in-memory-storage.ts:62

Parameters ​
ParameterType
inputTenantBoundRevokeApiKeyStorageInput
Returns ​

Promise<TenantBoundRevokeApiKeyStorageResult>

Implementation of ​

ApiKeyStorage.revokeForTenant

rotate() ​
ts
rotate(input): Promise<RotateApiKeyStorageResult>;

Defined in: src/storage/in-memory-storage.ts:83

Parameters ​
ParameterType
inputRotateApiKeyStorageInput
Returns ​

Promise<RotateApiKeyStorageResult>

Implementation of ​

ApiKeyStorage.rotate

rotateForTenant() ​
ts
rotateForTenant(input): Promise<RotateApiKeyStorageResult>;

Defined in: src/storage/in-memory-storage.ts:87

Parameters ​
ParameterType
inputTenantBoundRotateApiKeyStorageInput
Returns ​

Promise<RotateApiKeyStorageResult>

Implementation of ​

ApiKeyStorage.rotateForTenant

touchLastUsed() ​
ts
touchLastUsed(id, at): Promise<void>;

Defined in: src/storage/in-memory-storage.ts:74

Parameters ​
ParameterType
idstring
atDate
Returns ​

Promise<void>

Implementation of ​

ApiKeyStorage.touchLastUsed


PrismaApiKeyStorage ​

Defined in: src/storage/prisma-storage.ts:28

Implements ​

Constructors ​

Constructor ​
ts
new PrismaApiKeyStorage(prisma): PrismaApiKeyStorage;

Defined in: src/storage/prisma-storage.ts:29

Parameters ​
ParameterType
prismaPrismaLike
Returns ​

PrismaApiKeyStorage

Methods ​

findById() ​
ts
findById(id): Promise<ApiKeyRecord | null>;

Defined in: src/storage/prisma-storage.ts:35

Parameters ​
ParameterType
idstring
Returns ​

Promise<ApiKeyRecord | null>

Implementation of ​

ApiKeyStorage.findById

findByPrefix() ​
ts
findByPrefix(prefix): Promise<ApiKeyRecord | null>;

Defined in: src/storage/prisma-storage.ts:45

Parameters ​
ParameterType
prefixstring
Returns ​

Promise<ApiKeyRecord | null>

Implementation of ​

ApiKeyStorage.findByPrefix

insert() ​
ts
insert(record): Promise<void>;

Defined in: src/storage/prisma-storage.ts:31

Parameters ​
ParameterType
recordApiKeyRecord
Returns ​

Promise<void>

Implementation of ​

ApiKeyStorage.insert

listByTenant() ​
ts
listByTenant(tenantId, opts?): Promise<ApiKeyRecord[]>;

Defined in: src/storage/prisma-storage.ts:55

Return tenant records ordered by createdAt descending, then id ascending.

Parameters ​
ParameterType
tenantIdstring
optsListApiKeysOptions
Returns ​

Promise<ApiKeyRecord[]>

Implementation of ​

ApiKeyStorage.listByTenant

markRevoked() ​
ts
markRevoked(id, at): Promise<void>;

Defined in: src/storage/prisma-storage.ts:72

Parameters ​
ParameterType
idstring
atDate
Returns ​

Promise<void>

Implementation of ​

ApiKeyStorage.markRevoked

revokeForTenant() ​
ts
revokeForTenant(input): Promise<TenantBoundRevokeApiKeyStorageResult>;

Defined in: src/storage/prisma-storage.ts:76

Parameters ​
ParameterType
inputTenantBoundRevokeApiKeyStorageInput
Returns ​

Promise<TenantBoundRevokeApiKeyStorageResult>

Implementation of ​

ApiKeyStorage.revokeForTenant

rotate() ​
ts
rotate(input): Promise<RotateApiKeyStorageResult>;

Defined in: src/storage/prisma-storage.ts:90

Parameters ​
ParameterType
inputRotateApiKeyStorageInput
Returns ​

Promise<RotateApiKeyStorageResult>

Implementation of ​

ApiKeyStorage.rotate

rotateForTenant() ​
ts
rotateForTenant(input): Promise<RotateApiKeyStorageResult>;

Defined in: src/storage/prisma-storage.ts:94

Parameters ​
ParameterType
inputTenantBoundRotateApiKeyStorageInput
Returns ​

Promise<RotateApiKeyStorageResult>

Implementation of ​

ApiKeyStorage.rotateForTenant

touchLastUsed() ​
ts
touchLastUsed(id, at): Promise<void>;

Defined in: src/storage/prisma-storage.ts:86

Parameters ​
ParameterType
idstring
atDate
Returns ​

Promise<void>

Implementation of ​

ApiKeyStorage.touchLastUsed


Sha256Hasher ​

Defined in: src/hasher.ts:15

Constructors ​

Constructor ​
ts
new Sha256Hasher(options): Sha256Hasher;

Defined in: src/hasher.ts:16

Parameters ​
ParameterType
optionsHasherOptions
Returns ​

Sha256Hasher

Methods ​

dummyVerify() ​
ts
dummyVerify(secret): boolean;

Defined in: src/hasher.ts:42

Parameters ​
ParameterType
secretstring
Returns ​

boolean

hash() ​
ts
hash(secret): HashedSecret;

Defined in: src/hasher.ts:22

Parameters ​
ParameterType
secretstring
Returns ​

HashedSecret

verify() ​
ts
verify(
   secret,
   expectedHash,
   pepperVersion): boolean;

Defined in: src/hasher.ts:32

Parameters ​
ParameterType
secretstring
expectedHashstring
pepperVersionnumber
Returns ​

boolean

Interfaces ​

ApiKeyAuthFailedEvent ​

Defined in: src/types.ts:127

Extends ​

Properties ​

at ​
ts
at: Date;

Defined in: src/types.ts:93

Inherited from ​

ApiKeyEventBase.at

code ​
ts
code: ApiKeyErrorCode;

Defined in: src/types.ts:130

environment? ​
ts
optional environment?: Environment;

Defined in: src/types.ts:133

keyId? ​
ts
optional keyId?: string;

Defined in: src/types.ts:132

prefix ​
ts
prefix: string | null;

Defined in: src/types.ts:129

tenantId? ​
ts
optional tenantId?: string;

Defined in: src/types.ts:131

type ​
ts
type: "api_key.auth_failed";

Defined in: src/types.ts:128


ApiKeyAuthorizationDeniedEvent ​

Defined in: src/types.ts:136

Extends ​

Properties ​

at ​
ts
at: Date;

Defined in: src/types.ts:93

Inherited from ​

ApiKeyEventBase.at

code ​
ts
code: ApiKeyErrorCode;

Defined in: src/types.ts:138

type ​
ts
type: "api_key.authorization_denied";

Defined in: src/types.ts:137


ApiKeyAuthorizationMetric ​

Defined in: src/types.ts:186

Properties ​

durationMs ​
ts
durationMs: number;

Defined in: src/types.ts:189

environment? ​
ts
optional environment?: Environment;

Defined in: src/types.ts:190

outcome ​
ts
outcome: ApiKeyAuthorizationOutcome;

Defined in: src/types.ts:188

type ​
ts
type: "api_key.authorization";

Defined in: src/types.ts:187


ApiKeyContext ​

Defined in: src/types.ts:53

Properties ​

allowedIpCidrs? ​
ts
optional allowedIpCidrs?: string[];

Defined in: src/types.ts:59

environment ​
ts
environment: Environment;

Defined in: src/types.ts:56

keyId ​
ts
keyId: string;

Defined in: src/types.ts:54

prefix ​
ts
prefix: string;

Defined in: src/types.ts:58

scopes ​
ts
scopes: string[];

Defined in: src/types.ts:57

tenantId ​
ts
tenantId: string;

Defined in: src/types.ts:55


ApiKeyCreatedEvent ​

Defined in: src/types.ts:96

Extends ​

Properties ​

at ​
ts
at: Date;

Defined in: src/types.ts:93

Inherited from ​

ApiKeyEventBase.at

createdBy ​
ts
createdBy: string | null;

Defined in: src/types.ts:103

environment ​
ts
environment: Environment;

Defined in: src/types.ts:101

keyId ​
ts
keyId: string;

Defined in: src/types.ts:98

prefix ​
ts
prefix: string;

Defined in: src/types.ts:100

scopes ​
ts
scopes: string[];

Defined in: src/types.ts:102

tenantId ​
ts
tenantId: string;

Defined in: src/types.ts:99

type ​
ts
type: "api_key.created";

Defined in: src/types.ts:97


ApiKeyEventBase ​

Defined in: src/types.ts:92

Extended by ​

Properties ​

at ​
ts
at: Date;

Defined in: src/types.ts:93


ApiKeyOperationMetric ​

Defined in: src/types.ts:199

Properties ​

attempts ​
ts
attempts: number;

Defined in: src/types.ts:203

operation ​
ts
operation: ApiKeyOperationMetricOperation;

Defined in: src/types.ts:201

outcome ​
ts
outcome: "prefix_collision_exhausted";

Defined in: src/types.ts:202

type ​
ts
type: "api_key.operation";

Defined in: src/types.ts:200


ApiKeyRecord ​

Defined in: src/types.ts:12

Properties ​

allowedIpCidrs? ​
ts
optional allowedIpCidrs?: string[];

Defined in: src/types.ts:21

createdAt ​
ts
createdAt: Date;

Defined in: src/types.ts:28

createdBy ​
ts
createdBy: string | null;

Defined in: src/types.ts:27

environment ​
ts
environment: Environment;

Defined in: src/types.ts:16

expiresAt ​
ts
expiresAt: Date | null;

Defined in: src/types.ts:23

hash ​
ts
hash: string;

Defined in: src/types.ts:18

id ​
ts
id: string;

Defined in: src/types.ts:13

lastUsedAt ​
ts
lastUsedAt: Date | null;

Defined in: src/types.ts:22

name ​
ts
name: string;

Defined in: src/types.ts:15

pepperVersion ​
ts
pepperVersion: number;

Defined in: src/types.ts:19

prefix ​
ts
prefix: string;

Defined in: src/types.ts:17

replacedByKeyId ​
ts
replacedByKeyId: string | null;

Defined in: src/types.ts:26

revokedAt ​
ts
revokedAt: Date | null;

Defined in: src/types.ts:24

rotatedAt ​
ts
rotatedAt: Date | null;

Defined in: src/types.ts:25

scopes ​
ts
scopes: string[];

Defined in: src/types.ts:20

tenantId ​
ts
tenantId: string;

Defined in: src/types.ts:14


ApiKeyRequestAuthorizationInput ​

Defined in: src/types.ts:210

Properties ​

clientIp? ​
ts
optional clientIp?: string;

Defined in: src/types.ts:214

clientIpResolver? ​
ts
optional clientIpResolver?: (request) => string | Promise<string | undefined> | undefined;

Defined in: src/types.ts:216

Parameters ​
ParameterType
requestunknown
Returns ​

string | Promise<string | undefined> | undefined

rawKey? ​
ts
optional rawKey?: string | null;

Defined in: src/types.ts:211

request? ​
ts
optional request?: unknown;

Defined in: src/types.ts:215

requiredEnvironment? ​
ts
optional requiredEnvironment?: Environment;

Defined in: src/types.ts:212

requiredScope? ​
ts
optional requiredScope?: Scope;

Defined in: src/types.ts:213


ApiKeyRevokedEvent ​

Defined in: src/types.ts:106

Extends ​

Properties ​

at ​
ts
at: Date;

Defined in: src/types.ts:93

Inherited from ​

ApiKeyEventBase.at

environment ​
ts
environment: Environment;

Defined in: src/types.ts:111

keyId ​
ts
keyId: string;

Defined in: src/types.ts:108

prefix ​
ts
prefix: string;

Defined in: src/types.ts:110

tenantId ​
ts
tenantId: string;

Defined in: src/types.ts:109

type ​
ts
type: "api_key.revoked";

Defined in: src/types.ts:107


ApiKeyRotatedEvent ​

Defined in: src/types.ts:114

Extends ​

Properties ​

at ​
ts
at: Date;

Defined in: src/types.ts:93

Inherited from ​

ApiKeyEventBase.at

createdBy ​
ts
createdBy: string | null;

Defined in: src/types.ts:124

environment ​
ts
environment: Environment;

Defined in: src/types.ts:121

graceExpiresAt ​
ts
graceExpiresAt: Date;

Defined in: src/types.ts:123

newKeyId ​
ts
newKeyId: string;

Defined in: src/types.ts:119

newPrefix ​
ts
newPrefix: string;

Defined in: src/types.ts:120

oldKeyId ​
ts
oldKeyId: string;

Defined in: src/types.ts:117

oldPrefix ​
ts
oldPrefix: string;

Defined in: src/types.ts:118

scopes ​
ts
scopes: string[];

Defined in: src/types.ts:122

tenantId ​
ts
tenantId: string;

Defined in: src/types.ts:116

type ​
ts
type: "api_key.rotated";

Defined in: src/types.ts:115


ApiKeysModuleOptions ​

Defined in: src/api-keys.module.ts:27

Properties ​

clientIpResolver? ​
ts
optional clientIpResolver?: ApiKeyClientIpResolver;

Defined in: src/api-keys.module.ts:48

contextWriter? ​
ts
optional contextWriter?: ApiKeyContextWriter;

Defined in: src/api-keys.module.ts:47

currentPepperVersion? ​
ts
optional currentPepperVersion?: number;

Defined in: src/api-keys.module.ts:30

debounceMs? ​
ts
optional debounceMs?: number;

Defined in: src/api-keys.module.ts:31

emitUsageEvents? ​
ts
optional emitUsageEvents?: boolean;

Defined in: src/api-keys.module.ts:45

namespace? ​
ts
optional namespace?: string;

Defined in: src/api-keys.module.ts:28

onAuthFailed? ​
ts
optional onAuthFailed?: (prefix, code) => void | PromiseLike<void>;

Defined in: src/api-keys.module.ts:36

Parameters ​
ParameterType
prefixstring | null
codestring
Returns ​

void | PromiseLike<void>

Deprecated ​

Use onEvent and handle api_key.auth_failed events instead.

onAuthorizationMetric? ​
ts
optional onAuthorizationMetric?: ApiKeyAuthorizationMetricSink;

Defined in: src/api-keys.module.ts:41

onAuthorizationMetricError? ​
ts
optional onAuthorizationMetricError?: (error, metric) => void;

Defined in: src/api-keys.module.ts:42

Parameters ​
ParameterType
errorunknown
metricApiKeyAuthorizationMetric
Returns ​

void

onEvent? ​
ts
optional onEvent?: ApiKeyEventSink;

Defined in: src/api-keys.module.ts:37

onEventError? ​
ts
optional onEventError?: (error, event) => void;

Defined in: src/api-keys.module.ts:38

Parameters ​
ParameterType
errorunknown
eventApiKeyEvent
Returns ​

void

onMetric? ​
ts
optional onMetric?: ApiKeyMetricSink;

Defined in: src/api-keys.module.ts:39

onMetricError? ​
ts
optional onMetricError?: (error, metric) => void;

Defined in: src/api-keys.module.ts:40

Parameters ​
ParameterType
errorunknown
metricApiKeyVerificationMetric
Returns ​

void

onOperationMetric? ​
ts
optional onOperationMetric?: ApiKeyOperationMetricSink;

Defined in: src/api-keys.module.ts:43

onOperationMetricError? ​
ts
optional onOperationMetricError?: (error, metric) => void;

Defined in: src/api-keys.module.ts:44

Parameters ​
ParameterType
errorunknown
metricApiKeyOperationMetric
Returns ​

void

peppers ​
ts
peppers: Record<number, string>;

Defined in: src/api-keys.module.ts:29

storage ​
ts
storage: ApiKeyStorage;

Defined in: src/api-keys.module.ts:32

ttlPolicy? ​
ts
optional ttlPolicy?: ApiKeyTtlPolicy;

Defined in: src/api-keys.module.ts:46


ApiKeysServiceDeps ​

Defined in: src/api-keys.service.ts:54

Properties ​

clock? ​
ts
optional clock?: () => Date;

Defined in: src/api-keys.service.ts:59

Returns ​

Date

debounceMs? ​
ts
optional debounceMs?: number;

Defined in: src/api-keys.service.ts:60

emitUsageEvents? ​
ts
optional emitUsageEvents?: boolean;

Defined in: src/api-keys.service.ts:76

hasher ​
ts
hasher: Sha256Hasher;

Defined in: src/api-keys.service.ts:56

idFactory? ​
ts
optional idFactory?: () => string;

Defined in: src/api-keys.service.ts:58

Returns ​

string

monotonicClock? ​
ts
optional monotonicClock?: () => number;

Defined in: src/api-keys.service.ts:78

Returns ​

number

namespace ​
ts
namespace: string;

Defined in: src/api-keys.service.ts:57

onAuthFailed? ​
ts
optional onAuthFailed?: (prefix, code) => void | PromiseLike<void>;

Defined in: src/api-keys.service.ts:64

Parameters ​
ParameterType
prefixstring | null
codestring
Returns ​

void | PromiseLike<void>

Deprecated ​

Use onEvent and handle api_key.auth_failed events instead.

onAuthorizationMetric? ​
ts
optional onAuthorizationMetric?: ApiKeyAuthorizationMetricSink;

Defined in: src/api-keys.service.ts:72

onAuthorizationMetricError? ​
ts
optional onAuthorizationMetricError?: (error, metric) => void;

Defined in: src/api-keys.service.ts:73

Parameters ​
ParameterType
errorunknown
metricApiKeyAuthorizationMetric
Returns ​

void

onEvent? ​
ts
optional onEvent?: ApiKeyEventSink;

Defined in: src/api-keys.service.ts:68

onEventError? ​
ts
optional onEventError?: (error, event) => void;

Defined in: src/api-keys.service.ts:69

Parameters ​
ParameterType
errorunknown
eventApiKeyEvent
Returns ​

void

onMetric? ​
ts
optional onMetric?: ApiKeyMetricSink;

Defined in: src/api-keys.service.ts:70

onMetricError? ​
ts
optional onMetricError?: (error, metric) => void;

Defined in: src/api-keys.service.ts:71

Parameters ​
ParameterType
errorunknown
metricApiKeyVerificationMetric
Returns ​

void

onOperationMetric? ​
ts
optional onOperationMetric?: ApiKeyOperationMetricSink;

Defined in: src/api-keys.service.ts:74

onOperationMetricError? ​
ts
optional onOperationMetricError?: (error, metric) => void;

Defined in: src/api-keys.service.ts:75

Parameters ​
ParameterType
errorunknown
metricApiKeyOperationMetric
Returns ​

void

storage ​
ts
storage: ApiKeyStorage;

Defined in: src/api-keys.service.ts:55

ttlPolicy? ​
ts
optional ttlPolicy?: ApiKeyTtlPolicy;

Defined in: src/api-keys.service.ts:77


ApiKeyStorage ​

Defined in: src/storage/api-key-storage.interface.ts:29

Methods ​

findById() ​
ts
findById(id): Promise<ApiKeyRecord | null>;

Defined in: src/storage/api-key-storage.interface.ts:31

Parameters ​
ParameterType
idstring
Returns ​

Promise<ApiKeyRecord | null>

findByPrefix() ​
ts
findByPrefix(prefix): Promise<ApiKeyRecord | null>;

Defined in: src/storage/api-key-storage.interface.ts:32

Parameters ​
ParameterType
prefixstring
Returns ​

Promise<ApiKeyRecord | null>

insert() ​
ts
insert(record): Promise<void>;

Defined in: src/storage/api-key-storage.interface.ts:30

Parameters ​
ParameterType
recordApiKeyRecord
Returns ​

Promise<void>

listByTenant() ​
ts
listByTenant(tenantId, opts?): Promise<ApiKeyRecord[]>;

Defined in: src/storage/api-key-storage.interface.ts:34

Return tenant records ordered by createdAt descending, then id ascending.

Parameters ​
ParameterType
tenantIdstring
opts?ListApiKeysOptions
Returns ​

Promise<ApiKeyRecord[]>

markRevoked() ​
ts
markRevoked(id, at): Promise<void>;

Defined in: src/storage/api-key-storage.interface.ts:35

Parameters ​
ParameterType
idstring
atDate
Returns ​

Promise<void>

revokeForTenant()? ​
ts
optional revokeForTenant(input): Promise<TenantBoundRevokeApiKeyStorageResult>;

Defined in: src/storage/api-key-storage.interface.ts:36

Parameters ​
ParameterType
inputTenantBoundRevokeApiKeyStorageInput
Returns ​

Promise<TenantBoundRevokeApiKeyStorageResult>

rotate() ​
ts
rotate(input): Promise<RotateApiKeyStorageResult>;

Defined in: src/storage/api-key-storage.interface.ts:40

Parameters ​
ParameterType
inputRotateApiKeyStorageInput
Returns ​

Promise<RotateApiKeyStorageResult>

rotateForTenant()? ​
ts
optional rotateForTenant(input): Promise<RotateApiKeyStorageResult>;

Defined in: src/storage/api-key-storage.interface.ts:41

Parameters ​
ParameterType
inputTenantBoundRotateApiKeyStorageInput
Returns ​

Promise<RotateApiKeyStorageResult>

touchLastUsed() ​
ts
touchLastUsed(id, at): Promise<void>;

Defined in: src/storage/api-key-storage.interface.ts:39

Parameters ​
ParameterType
idstring
atDate
Returns ​

Promise<void>


ApiKeyStorageContractOptions ​

Defined in: src/storage/storage-contract.ts:6

Properties ​

createStorage ​
ts
createStorage: () =>
  | ApiKeyStorage
| Promise<ApiKeyStorage>;

Defined in: src/storage/storage-contract.ts:10

Create an isolated adapter backed by disposable test data.

Returns ​

| ApiKeyStorage | Promise<ApiKeyStorage>

disposeStorage? ​
ts
optional disposeStorage?: (storage) => void | Promise<void>;

Defined in: src/storage/storage-contract.ts:12

Release adapter resources and remove contract fixture data.

Parameters ​
ParameterType
storageApiKeyStorage
Returns ​

void | Promise<void>

name ​
ts
name: string;

Defined in: src/storage/storage-contract.ts:8

Human-readable adapter name used in failures and the result.

rotationConcurrency? ​
ts
optional rotationConcurrency?: number;

Defined in: src/storage/storage-contract.ts:14

Number of simultaneous rotation attempts. Defaults to 8 and must be at least 2.


ApiKeyStorageContractResult ​

Defined in: src/storage/storage-contract.ts:17

Properties ​

checks ​
ts
checks: string[];

Defined in: src/storage/storage-contract.ts:19

name ​
ts
name: string;

Defined in: src/storage/storage-contract.ts:18


ApiKeySummary ​

Defined in: src/types.ts:36

Serialization-safe API key metadata returned by ApiKeysService.list.

Verifier material is intentionally available only on internal storage records.

Properties ​

allowedIpCidrs? ​
ts
optional allowedIpCidrs?: string[];

Defined in: src/types.ts:43

createdAt ​
ts
createdAt: Date;

Defined in: src/types.ts:50

createdBy ​
ts
createdBy: string | null;

Defined in: src/types.ts:49

environment ​
ts
environment: Environment;

Defined in: src/types.ts:40

expiresAt ​
ts
expiresAt: Date | null;

Defined in: src/types.ts:45

id ​
ts
id: string;

Defined in: src/types.ts:37

lastUsedAt ​
ts
lastUsedAt: Date | null;

Defined in: src/types.ts:44

name ​
ts
name: string;

Defined in: src/types.ts:39

prefix ​
ts
prefix: string;

Defined in: src/types.ts:41

replacedByKeyId ​
ts
replacedByKeyId: string | null;

Defined in: src/types.ts:48

revokedAt ​
ts
revokedAt: Date | null;

Defined in: src/types.ts:46

rotatedAt ​
ts
rotatedAt: Date | null;

Defined in: src/types.ts:47

scopes ​
ts
scopes: string[];

Defined in: src/types.ts:42

tenantId ​
ts
tenantId: string;

Defined in: src/types.ts:38


ApiKeyTtlPolicy ​

Defined in: src/types.ts:221

Properties ​

allowNeverExpires? ​
ts
optional allowNeverExpires?: boolean;

Defined in: src/types.ts:224

defaultExpiresInMs? ​
ts
optional defaultExpiresInMs?: number;

Defined in: src/types.ts:222

maxExpiresInMs? ​
ts
optional maxExpiresInMs?: number;

Defined in: src/types.ts:223


ApiKeyUsedEvent ​

Defined in: src/types.ts:141

Extends ​

Properties ​

at ​
ts
at: Date;

Defined in: src/types.ts:93

Inherited from ​

ApiKeyEventBase.at

environment ​
ts
environment: Environment;

Defined in: src/types.ts:146

keyId ​
ts
keyId: string;

Defined in: src/types.ts:143

prefix ​
ts
prefix: string;

Defined in: src/types.ts:145

scopes ​
ts
scopes: string[];

Defined in: src/types.ts:147

tenantId ​
ts
tenantId: string;

Defined in: src/types.ts:144

type ​
ts
type: "api_key.used";

Defined in: src/types.ts:142


ApiKeyVerificationMetric ​

Defined in: src/types.ts:168

Properties ​

durationMs ​
ts
durationMs: number;

Defined in: src/types.ts:171

environment? ​
ts
optional environment?: Environment;

Defined in: src/types.ts:172

outcome ​
ts
outcome: ApiKeyVerificationOutcome;

Defined in: src/types.ts:170

type ​
ts
type: "api_key.verification";

Defined in: src/types.ts:169


CreateApiKeyInput ​

Defined in: src/types.ts:62

Properties ​

allowedIpCidrs? ​
ts
optional allowedIpCidrs?: string[];

Defined in: src/types.ts:69

createdBy? ​
ts
optional createdBy?: string;

Defined in: src/types.ts:68

environment? ​
ts
optional environment?: Environment;

Defined in: src/types.ts:65

expiresAt? ​
ts
optional expiresAt?: Date;

Defined in: src/types.ts:67

name ​
ts
name: string;

Defined in: src/types.ts:64

scopes ​
ts
scopes: Scope[];

Defined in: src/types.ts:66

tenantId ​
ts
tenantId: string;

Defined in: src/types.ts:63


CreateApiKeyResult ​

Defined in: src/types.ts:72

Properties ​

id ​
ts
id: string;

Defined in: src/types.ts:73

key ​
ts
key: string;

Defined in: src/types.ts:74


CreateTestKeyOptions ​

Defined in: src/testing.ts:4

Properties ​

allowedIpCidrs? ​
ts
optional allowedIpCidrs?: string[];

Defined in: src/testing.ts:11

createdBy? ​
ts
optional createdBy?: string;

Defined in: src/testing.ts:10

environment? ​
ts
optional environment?: Environment;

Defined in: src/testing.ts:7

expiresAt? ​
ts
optional expiresAt?: Date;

Defined in: src/testing.ts:9

name? ​
ts
optional name?: string;

Defined in: src/testing.ts:6

scopes? ​
ts
optional scopes?: Scope[];

Defined in: src/testing.ts:8

tenantId? ​
ts
optional tenantId?: string;

Defined in: src/testing.ts:5


HashedSecret ​

Defined in: src/hasher.ts:5

Properties ​

hash ​
ts
hash: string;

Defined in: src/hasher.ts:6

pepperVersion ​
ts
pepperVersion: number;

Defined in: src/hasher.ts:7


HasherOptions ​

Defined in: src/hasher.ts:10

Properties ​

currentVersion ​
ts
currentVersion: number;

Defined in: src/hasher.ts:12

peppers ​
ts
peppers: Record<number, string>;

Defined in: src/hasher.ts:11


ListApiKeysOptions ​

Defined in: src/storage/api-key-storage.interface.ts:3

Properties ​

includeRevoked? ​
ts
optional includeRevoked?: boolean;

Defined in: src/storage/api-key-storage.interface.ts:5

Include records with a non-null revokedAt. Expired and rotated records are always included.


PrismaLike ​

Defined in: src/storage/prisma-storage.ts:24

Extends ​

  • PrismaTransactionLike

Properties ​

apiKey ​
ts
apiKey: PrismaApiKeyDelegate;

Defined in: src/storage/prisma-storage.ts:21

Inherited from ​
ts
PrismaTransactionLike.apiKey

Methods ​

$transaction() ​
ts
$transaction<T>(callback): Promise<T>;

Defined in: src/storage/prisma-storage.ts:25

Type Parameters ​
Type Parameter
T
Parameters ​
ParameterType
callback(transaction) => Promise<T>
Returns ​

Promise<T>


RequiredScope ​

Defined in: src/decorators/require-scope.decorator.ts:9

Properties ​

level ​
ts
level: ScopeLevel;

Defined in: src/decorators/require-scope.decorator.ts:11

resource ​
ts
resource: string;

Defined in: src/decorators/require-scope.decorator.ts:10


RotateApiKeyInput ​

Defined in: src/types.ts:77

Properties ​

allowedIpCidrs? ​
ts
optional allowedIpCidrs?: string[];

Defined in: src/types.ts:82

createdBy? ​
ts
optional createdBy?: string;

Defined in: src/types.ts:80

expiresAt? ​
ts
optional expiresAt?: Date | null;

Defined in: src/types.ts:81

gracePeriodMs? ​
ts
optional gracePeriodMs?: number;

Defined in: src/types.ts:78

name? ​
ts
optional name?: string;

Defined in: src/types.ts:79


RotateApiKeyResult ​

Defined in: src/types.ts:85

Properties ​

graceExpiresAt ​
ts
graceExpiresAt: Date;

Defined in: src/types.ts:89

id ​
ts
id: string;

Defined in: src/types.ts:86

key ​
ts
key: string;

Defined in: src/types.ts:87

replacedKeyId ​
ts
replacedKeyId: string;

Defined in: src/types.ts:88


RotateApiKeyStorageInput ​

Defined in: src/storage/api-key-storage.interface.ts:8

Extended by ​

Properties ​

newRecord ​
ts
newRecord: ApiKeyRecord;

Defined in: src/storage/api-key-storage.interface.ts:10

oldExpiresAt ​
ts
oldExpiresAt: Date;

Defined in: src/storage/api-key-storage.interface.ts:11

oldKeyId ​
ts
oldKeyId: string;

Defined in: src/storage/api-key-storage.interface.ts:9

rotatedAt ​
ts
rotatedAt: Date;

Defined in: src/storage/api-key-storage.interface.ts:12


Scope ​

Defined in: src/types.ts:7

Properties ​

level ​
ts
level: ScopeLevel;

Defined in: src/types.ts:9

resource ​
ts
resource: string;

Defined in: src/types.ts:8


TenantBoundRevokeApiKeyStorageInput ​

Defined in: src/storage/api-key-storage.interface.ts:15

Properties ​

expectedTenantId ​
ts
expectedTenantId: string;

Defined in: src/storage/api-key-storage.interface.ts:17

keyId ​
ts
keyId: string;

Defined in: src/storage/api-key-storage.interface.ts:16

revokedAt ​
ts
revokedAt: Date;

Defined in: src/storage/api-key-storage.interface.ts:18


TenantBoundRotateApiKeyStorageInput ​

Defined in: src/storage/api-key-storage.interface.ts:23

Extends ​

Properties ​

expectedTenantId ​
ts
expectedTenantId: string;

Defined in: src/storage/api-key-storage.interface.ts:24

newRecord ​
ts
newRecord: ApiKeyRecord;

Defined in: src/storage/api-key-storage.interface.ts:10

Inherited from ​

RotateApiKeyStorageInput.newRecord

oldExpiresAt ​
ts
oldExpiresAt: Date;

Defined in: src/storage/api-key-storage.interface.ts:11

Inherited from ​

RotateApiKeyStorageInput.oldExpiresAt

oldKeyId ​
ts
oldKeyId: string;

Defined in: src/storage/api-key-storage.interface.ts:9

Inherited from ​

RotateApiKeyStorageInput.oldKeyId

rotatedAt ​
ts
rotatedAt: Date;

Defined in: src/storage/api-key-storage.interface.ts:12

Inherited from ​

RotateApiKeyStorageInput.rotatedAt

Type Aliases ​

ApiKeyAuthorizationMetricSink ​

ts
type ApiKeyAuthorizationMetricSink = (metric) => void | Promise<void>;

Defined in: src/types.ts:193

Parameters ​

ParameterType
metricApiKeyAuthorizationMetric

Returns ​

void | Promise<void>


ApiKeyAuthorizationOutcome ​

ts
type ApiKeyAuthorizationOutcome =
  | "success"
  | "missing"
  | "credential_rejected"
  | "environment_denied"
  | "ip_denied"
  | "scope_denied"
  | "error";

Defined in: src/types.ts:177


ApiKeyClientIpResolver ​

ts
type ApiKeyClientIpResolver = (request) => string | undefined | Promise<string | undefined>;

Defined in: src/ip-allowlist.ts:5

Parameters ​

ParameterType
requestunknown

Returns ​

string | undefined | Promise<string | undefined>


ApiKeyContextWriter ​

ts
type ApiKeyContextWriter = (apiKey, request) => void | Promise<void>;

Defined in: src/context.ts:6

Parameters ​

ParameterType
apiKeyApiKeyContext
requestunknown

Returns ​

void | Promise<void>


ApiKeyErrorCode ​

ts
type ApiKeyErrorCode = typeof ApiKeyErrorCode[keyof typeof ApiKeyErrorCode];

Defined in: src/errors.ts:7


ApiKeyEvent ​

ts
type ApiKeyEvent =
  | ApiKeyCreatedEvent
  | ApiKeyRevokedEvent
  | ApiKeyRotatedEvent
  | ApiKeyAuthFailedEvent
  | ApiKeyAuthorizationDeniedEvent
  | ApiKeyUsedEvent;

Defined in: src/types.ts:150


ApiKeyEventSink ​

ts
type ApiKeyEventSink = (event) => void | Promise<void>;

Defined in: src/types.ts:158

Parameters ​

ParameterType
eventApiKeyEvent

Returns ​

void | Promise<void>


ApiKeyMetricSink ​

ts
type ApiKeyMetricSink = (metric) => void | Promise<void>;

Defined in: src/types.ts:175

Parameters ​

ParameterType
metricApiKeyVerificationMetric

Returns ​

void | Promise<void>


ApiKeyOperationErrorCode ​

ts
type ApiKeyOperationErrorCode = typeof ApiKeyOperationErrorCode[keyof typeof ApiKeyOperationErrorCode];

Defined in: src/errors.ts:48


ApiKeyOperationMetricOperation ​

ts
type ApiKeyOperationMetricOperation = "create" | "rotate";

Defined in: src/types.ts:197


ApiKeyOperationMetricSink ​

ts
type ApiKeyOperationMetricSink = (metric) => void | Promise<void>;

Defined in: src/types.ts:206

Parameters ​

ParameterType
metricApiKeyOperationMetric

Returns ​

void | Promise<void>


ApiKeyVerificationOutcome ​

ts
type ApiKeyVerificationOutcome = "success" | "malformed" | "invalid" | "revoked" | "expired" | "error";

Defined in: src/types.ts:160


Environment ​

ts
type Environment = "live" | "test";

Defined in: src/types.ts:3


RotateApiKeyStorageResult ​

ts
type RotateApiKeyStorageResult = "rotated" | "not_rotatable";

Defined in: src/storage/api-key-storage.interface.ts:27


ScopeLevel ​

ts
type ScopeLevel = "read" | "write";

Defined in: src/types.ts:5


TenantBoundRevokeApiKeyStorageResult ​

ts
type TenantBoundRevokeApiKeyStorageResult = "revoked" | "not_found";

Defined in: src/storage/api-key-storage.interface.ts:21

Variables ​

API_KEY_CLIENT_IP_RESOLVER ​

ts
const API_KEY_CLIENT_IP_RESOLVER: typeof API_KEY_CLIENT_IP_RESOLVER;

Defined in: src/ip-allowlist.ts:3


API_KEY_CONTEXT_PROPERTY ​

ts
const API_KEY_CONTEXT_PROPERTY: "apiKey" = 'apiKey';

Defined in: src/context.ts:3


API_KEY_CONTEXT_WRITER ​

ts
const API_KEY_CONTEXT_WRITER: typeof API_KEY_CONTEXT_WRITER;

Defined in: src/context.ts:4


API_KEY_NAMESPACE_MAX_LENGTH ​

ts
const API_KEY_NAMESPACE_MAX_LENGTH: 32 = 32;

Defined in: src/input-validation.ts:4


API_KEY_REDACT_REGEX ​

ts
const API_KEY_REDACT_REGEX: RegExp;

Defined in: src/key-format.ts:99


API_KEY_SCOPE_RESOURCE_MAX_LENGTH ​

ts
const API_KEY_SCOPE_RESOURCE_MAX_LENGTH: 128 = 128;

Defined in: src/input-validation.ts:5


API_KEY_TENANT_ID_MAX_LENGTH ​

ts
const API_KEY_TENANT_ID_MAX_LENGTH: 255 = 255;

Defined in: src/input-validation.ts:6


API_KEYS_OPTIONS ​

ts
const API_KEYS_OPTIONS: typeof API_KEYS_OPTIONS;

Defined in: src/api-keys.module.ts:24


API_KEYS_STORAGE ​

ts
const API_KEYS_STORAGE: typeof API_KEYS_STORAGE;

Defined in: src/api-keys.module.ts:25


ApiKeyErrorCode ​

ts
const ApiKeyErrorCode: {
  EnvironmentMismatch: "api_key_environment_mismatch";
  Expired: "api_key_expired";
  Invalid: "api_key_invalid";
  IpNotAllowed: "api_key_ip_not_allowed";
  Malformed: "api_key_malformed";
  Missing: "api_key_missing";
  Revoked: "api_key_revoked";
  ScopeInsufficient: "api_key_scope_insufficient";
};

Defined in: src/errors.ts:7

Type Declaration ​

NameTypeDefault valueDefined in
EnvironmentMismatch"api_key_environment_mismatch"'api_key_environment_mismatch'src/errors.ts:13
Expired"api_key_expired"'api_key_expired'src/errors.ts:12
Invalid"api_key_invalid"'api_key_invalid'src/errors.ts:10
IpNotAllowed"api_key_ip_not_allowed"'api_key_ip_not_allowed'src/errors.ts:15
Malformed"api_key_malformed"'api_key_malformed'src/errors.ts:9
Missing"api_key_missing"'api_key_missing'src/errors.ts:8
Revoked"api_key_revoked"'api_key_revoked'src/errors.ts:11
ScopeInsufficient"api_key_scope_insufficient"'api_key_scope_insufficient'src/errors.ts:14

ApiKeyOperationErrorCode ​

ts
const ApiKeyOperationErrorCode: {
  InvalidInput: "api_key_invalid_input";
  InvalidTime: "api_key_invalid_time";
  NotFound: "api_key_record_not_found";
  NotRotatable: "api_key_not_rotatable";
  PrefixCollision: "api_key_prefix_collision";
};

Defined in: src/errors.ts:48

Type Declaration ​

NameTypeDefault valueDefined in
InvalidInput"api_key_invalid_input"'api_key_invalid_input'src/errors.ts:53
InvalidTime"api_key_invalid_time"'api_key_invalid_time'src/errors.ts:52
NotFound"api_key_record_not_found"'api_key_record_not_found'src/errors.ts:49
NotRotatable"api_key_not_rotatable"'api_key_not_rotatable'src/errors.ts:50
PrefixCollision"api_key_prefix_collision"'api_key_prefix_collision'src/errors.ts:51

CurrentApiKey ​

ts
const CurrentApiKey: (...dataOrPipes) => ParameterDecorator;

Defined in: src/decorators/current-api-key.decorator.ts:4

Parameters ​

ParameterType
...dataOrPipesunknown[]

Returns ​

ParameterDecorator


defaultApiKeyClientIpResolver ​

ts
const defaultApiKeyClientIpResolver: ApiKeyClientIpResolver;

Defined in: src/ip-allowlist.ts:9


ENVIRONMENT_METADATA ​

ts
const ENVIRONMENT_METADATA: "nestarc:api-keys:environment" = 'nestarc:api-keys:environment';

Defined in: src/decorators/require-environment.decorator.ts:7


SCOPE_METADATA ​

ts
const SCOPE_METADATA: "nestarc:api-keys:scope" = 'nestarc:api-keys:scope';

Defined in: src/decorators/require-scope.decorator.ts:7

Functions ​

createTestKey() ​

ts
function createTestKey(service, options?): Promise<CreateApiKeyResult & {
  context: ApiKeyContext;
}>;

Defined in: src/testing.ts:14

Parameters ​

ParameterType
serviceApiKeysService
optionsCreateTestKeyOptions

Returns ​

Promise<CreateApiKeyResult & { context: ApiKeyContext; }>


flattenScopes() ​

ts
function flattenScopes(scopes): string[];

Defined in: src/scope-matcher.ts:4

Parameters ​

ParameterType
scopesScope[]

Returns ​

string[]


generateKey() ​

ts
function generateKey(options): GeneratedKey;

Defined in: src/key-format.ts:36

Parameters ​

ParameterType
options{ environment: Environment; namespace: string; }
options.environmentEnvironment
options.namespacestring

Returns ​

GeneratedKey


getApiKeyContext() ​

ts
function getApiKeyContext(request): ApiKeyContext | undefined;

Defined in: src/context.ts:11

Parameters ​

ParameterType
requestunknown

Returns ​

ApiKeyContext | undefined


isIpAllowed() ​

ts
function isIpAllowed(clientIp, allowedIpCidrs): boolean;

Defined in: src/ip-allowlist.ts:22

Parameters ​

ParameterType
clientIpstring | undefined
allowedIpCidrsreadonly string[]

Returns ​

boolean


isValidTenantId() ​

ts
function isValidTenantId(value): value is string;

Defined in: src/input-validation.ts:42

Parameters ​

ParameterType
valueunknown

Returns ​

value is string


normalizeAllowedIpCidrs() ​

ts
function normalizeAllowedIpCidrs(entries?): string[];

Defined in: src/ip-allowlist.ts:18

Parameters ​

ParameterTypeDefault value
entriesreadonly string[][]

Returns ​

string[]


parseKey() ​

ts
function parseKey(raw): ParsedKey;

Defined in: src/key-format.ts:62

Parameters ​

ParameterType
rawstring

Returns ​

ParsedKey


RequireEnvironment() ​

ts
function RequireEnvironment(environment): CustomDecorator<string>;

Defined in: src/decorators/require-environment.decorator.ts:9

Parameters ​

ParameterType
environmentEnvironment

Returns ​

CustomDecorator<string>


RequireScope() ​

ts
function RequireScope(resource, level): CustomDecorator<string>;

Defined in: src/decorators/require-scope.decorator.ts:14

Parameters ​

ParameterType
resourcestring
levelScopeLevel

Returns ​

CustomDecorator<string>


runApiKeyStorageContract() ​

ts
function runApiKeyStorageContract(options): Promise<ApiKeyStorageContractResult>;

Defined in: src/storage/storage-contract.ts:42

Run the public, framework-independent contract for a custom ApiKeyStorage adapter.

The runner uses Node assertions and throws ApiKeyStorageContractError on the first failure. It does not depend on Jest, Vitest, Mocha, or their globals.

Parameters ​

ParameterType
optionsApiKeyStorageContractOptions

Returns ​

Promise<ApiKeyStorageContractResult>


scopeSatisfies() ​

ts
function scopeSatisfies(
   granted,
   resource,
   required): boolean;

Defined in: src/scope-matcher.ts:10

Parameters ​

ParameterType
grantedstring[]
resourcestring
requiredScopeLevel

Returns ​

boolean


validateTenantId() ​

ts
function validateTenantId(value): string;

Defined in: src/input-validation.ts:51

Parameters ​

ParameterType
valueunknown

Returns ​

string

Released under the MIT License.