Skip to content

integrations/api-keys ​

Use createApiKeySubjectResolver() when machine clients authenticate with @nestarc/api-keys and also need RBAC roles or resource permissions. Import it from @nestarc/rbac/integrations/api-keys and pass the returned resolver to RbacModule.forRoot().

Authentication and identity ​

Authenticate the key before the RBAC guard runs and attach the verified context to request.apiKey. The resolver maps that context to an api_key subject; it does not validate an API-key credential. It reads the opaque string keyId or id, preserves tenantId, and retains the source record in subject.attributes.

The deprecated request.apiKeyContext is a fallback only when request.apiKey is absent. Conflicting populated canonical and legacy contexts fail closed, so migrate legacy writers instead of relying on precedence.

Register the resolver ​

This registration uses in-memory role storage for a local example. Configure authentication and seed the application's roles separately; selecting a resolver alone does not grant access.

ts
import { InMemoryRbacStorage, RbacModule } from '@nestarc/rbac';
import { createApiKeySubjectResolver } from '@nestarc/rbac/integrations/api-keys';

RbacModule.forRoot({
  storage: new InMemoryRbacStorage(),
  subjectResolver: createApiKeySubjectResolver(),
  tenant: { requiredByDefault: true },
});

Follow RBAC installation for module and guard setup, API-key integration for the authentication boundary, and Prisma storage for persistent roles. Use API-key installation to configure the authenticating package.

Functions ​

createApiKeySubjectResolver() ​

ts
function createApiKeySubjectResolver(): RbacSubjectResolver;

Defined in: src/integrations/api-keys.ts:5

Returns ​

RbacSubjectResolver

Released under the MIT License.