pub struct CredentialStore { /* private fields */ }Expand description
Manages API key storage in a TOML credentials file at <data_dir>/credentials.toml.
Implementations§
Source§impl CredentialStore
impl CredentialStore
pub fn new(data_dir: PathBuf) -> Self
Sourcepub fn get_api_key(&self, provider_id: &str) -> Option<String>
pub fn get_api_key(&self, provider_id: &str) -> Option<String>
Reads the stored API key for the given provider, or None if not found.
Sourcepub fn get_model_api_key(&self, provider_id: &str) -> Option<String>
pub fn get_model_api_key(&self, provider_id: &str) -> Option<String>
Reads a stored credential usable for model API calls.
OAuth credentials obtained through OpenAI browser login are excluded: they are account/connector tokens, not OpenAI Platform API keys.
Sourcepub fn get_oauth_api_kind(&self, provider_id: &str) -> Option<String>
pub fn get_oauth_api_kind(&self, provider_id: &str) -> Option<String>
Returns oauth_api_kind metadata for a stored OAuth token, or None.
pub fn get_api_key_for_account( &self, provider_id: &str, account_id: &str, ) -> Option<String>
pub fn get_model_api_key_for_account( &self, provider_id: &str, account_id: &str, ) -> Option<String>
pub fn has_oauth_credential(&self, provider_id: &str) -> bool
pub fn get_project_account( &self, project_dir: &Path, provider_id: &str, ) -> Option<String>
pub fn set_project_account( &self, project_dir: &Path, provider_id: &str, account_id: &str, ) -> Result<()>
pub fn list_credential_accounts( &self, provider_id: &str, project_dir: Option<&Path>, ) -> Result<Vec<CredentialAccountInfo>>
Sourcepub fn is_ignored(&self, provider_id: &str) -> bool
pub fn is_ignored(&self, provider_id: &str) -> bool
Returns true if the user explicitly ignored this provider (e.g. by deleting an env-provided key).
Sourcepub fn list_api_key_providers(&self) -> Result<Vec<String>>
pub fn list_api_key_providers(&self) -> Result<Vec<String>>
Returns the list of provider ids that have stored API keys.
Sourcepub fn get_opencode_api_key(&self) -> Option<String>
pub fn get_opencode_api_key(&self) -> Option<String>
Reads an API key from OpenCode’s auth.json file, if it exists.
Sourcepub fn set_api_key(&self, provider_id: &str, api_key: &str) -> Result<()>
pub fn set_api_key(&self, provider_id: &str, api_key: &str) -> Result<()>
Stores an API key for the given provider, creating the credentials file if needed.
Note: this replaces the provider’s credential map with a single
default account. Prefer Self::add_api_key_account for multi-account.
Sourcepub fn add_api_key_account(
&self,
provider_id: &str,
api_key: &str,
label: Option<&str>,
account_id: Option<&str>,
) -> Result<String>
pub fn add_api_key_account( &self, provider_id: &str, api_key: &str, label: Option<&str>, account_id: Option<&str>, ) -> Result<String>
Add (or update) one API-key account without wiping sibling accounts.
Returns the account_id. When account_id is None, a new id is generated.
Sourcepub fn set_default_account(
&self,
provider_id: &str,
account_id: &str,
) -> Result<()>
pub fn set_default_account( &self, provider_id: &str, account_id: &str, ) -> Result<()>
Set the default account for a provider (global selection).
Sourcepub fn set_oauth_credential(
&self,
provider_id: &str,
api_key: &str,
oauth_api_kind: &str,
) -> Result<()>
pub fn set_oauth_credential( &self, provider_id: &str, api_key: &str, oauth_api_kind: &str, ) -> Result<()>
Stores an API key with oauth_api_kind metadata (e.g. “chat-completions” for OAuth tokens that only work with Chat Completions API).
Sourcepub fn set_oauth_credential_full(
&self,
provider_id: &str,
api_key: &str,
oauth_api_kind: &str,
refresh_token: Option<&str>,
expires_at: Option<i64>,
) -> Result<()>
pub fn set_oauth_credential_full( &self, provider_id: &str, api_key: &str, oauth_api_kind: &str, refresh_token: Option<&str>, expires_at: Option<i64>, ) -> Result<()>
Stores an OAuth credential with optional refresh token and expiry.
Sourcepub fn get_oauth_refresh_token(&self, provider_id: &str) -> Option<String>
pub fn get_oauth_refresh_token(&self, provider_id: &str) -> Option<String>
Returns the stored OAuth refresh token, if any.
Sourcepub fn get_oauth_expires_at(&self, provider_id: &str) -> Option<i64>
pub fn get_oauth_expires_at(&self, provider_id: &str) -> Option<i64>
Returns the stored OAuth access-token expiry (unix seconds), if any.
Sourcepub fn set_commandcode_credential(
&self,
provider_id: &str,
api_key: &str,
metadata: CommandCodeCredentialMetadata,
) -> Result<String>
pub fn set_commandcode_credential( &self, provider_id: &str, api_key: &str, metadata: CommandCodeCredentialMetadata, ) -> Result<String>
Stores a Command Code OAuth-created API key and callback metadata.
pub fn get_commandcode_metadata( &self, provider_id: &str, ) -> Option<CommandCodeCredentialMetadata>
pub fn delete_credential_account( &self, provider_id: &str, account_id: &str, ) -> Result<bool>
Sourcepub fn delete_api_key(&self, provider_id: &str) -> Result<bool>
pub fn delete_api_key(&self, provider_id: &str) -> Result<bool>
Deletes a stored API key and adds the provider to the ignored list.
Returns true if a stored key was removed.
Sourcepub fn resolve_api_key(
&self,
provider_id: &str,
env_var: &str,
) -> Option<String>
pub fn resolve_api_key( &self, provider_id: &str, env_var: &str, ) -> Option<String>
Resolve API key for a provider: env var first (explicit override), then stored credential.
Resolves an API key by checking the environment variable first, then
the stored credential. Returns None if neither is set.
Trait Implementations§
Source§impl Clone for CredentialStore
impl Clone for CredentialStore
Auto Trait Implementations§
impl Freeze for CredentialStore
impl RefUnwindSafe for CredentialStore
impl Send for CredentialStore
impl Sync for CredentialStore
impl Unpin for CredentialStore
impl UnsafeUnpin for CredentialStore
impl UnwindSafe for CredentialStore
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
Source§impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CloneToUninit for Twhere
T: Clone,
Source§impl<T> Instrument for T
impl<T> Instrument for T
Source§fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
Source§fn in_current_span(self) -> Instrumented<Self> ⓘ
fn in_current_span(self) -> Instrumented<Self> ⓘ
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more