Skip to main content

CredentialStore

Struct CredentialStore 

Source
pub struct CredentialStore { /* private fields */ }
Expand description

Manages API key storage in a TOML credentials file at <data_dir>/credentials.toml.

Implementations§

Source§

impl CredentialStore

Source

pub fn new(data_dir: PathBuf) -> Self

Source

pub fn path(&self) -> &Path

Returns the path to the credentials file.

Source

pub fn get_api_key(&self, provider_id: &str) -> Option<String>

Reads the stored API key for the given provider, or None if not found.

Source

pub fn get_model_api_key(&self, provider_id: &str) -> Option<String>

Reads a stored credential usable for model API calls.

OAuth credentials obtained through OpenAI browser login are excluded: they are account/connector tokens, not OpenAI Platform API keys.

Source

pub fn get_oauth_api_kind(&self, provider_id: &str) -> Option<String>

Returns oauth_api_kind metadata for a stored OAuth token, or None.

Source

pub fn get_api_key_for_account( &self, provider_id: &str, account_id: &str, ) -> Option<String>

Source

pub fn get_model_api_key_for_account( &self, provider_id: &str, account_id: &str, ) -> Option<String>

Source

pub fn has_oauth_credential(&self, provider_id: &str) -> bool

Source

pub fn get_project_account( &self, project_dir: &Path, provider_id: &str, ) -> Option<String>

Source

pub fn set_project_account( &self, project_dir: &Path, provider_id: &str, account_id: &str, ) -> Result<()>

Source

pub fn list_credential_accounts( &self, provider_id: &str, project_dir: Option<&Path>, ) -> Result<Vec<CredentialAccountInfo>>

Source

pub fn is_ignored(&self, provider_id: &str) -> bool

Returns true if the user explicitly ignored this provider (e.g. by deleting an env-provided key).

Source

pub fn list_api_key_providers(&self) -> Result<Vec<String>>

Returns the list of provider ids that have stored API keys.

Source

pub fn get_opencode_api_key(&self) -> Option<String>

Reads an API key from OpenCode’s auth.json file, if it exists.

Source

pub fn set_api_key(&self, provider_id: &str, api_key: &str) -> Result<()>

Stores an API key for the given provider, creating the credentials file if needed.

Note: this replaces the provider’s credential map with a single default account. Prefer Self::add_api_key_account for multi-account.

Source

pub fn add_api_key_account( &self, provider_id: &str, api_key: &str, label: Option<&str>, account_id: Option<&str>, ) -> Result<String>

Add (or update) one API-key account without wiping sibling accounts.

Returns the account_id. When account_id is None, a new id is generated.

Source

pub fn set_default_account( &self, provider_id: &str, account_id: &str, ) -> Result<()>

Set the default account for a provider (global selection).

Source

pub fn set_oauth_credential( &self, provider_id: &str, api_key: &str, oauth_api_kind: &str, ) -> Result<()>

Stores an API key with oauth_api_kind metadata (e.g. “chat-completions” for OAuth tokens that only work with Chat Completions API).

Source

pub fn set_oauth_credential_full( &self, provider_id: &str, api_key: &str, oauth_api_kind: &str, refresh_token: Option<&str>, expires_at: Option<i64>, ) -> Result<()>

Stores an OAuth credential with optional refresh token and expiry.

Source

pub fn get_oauth_refresh_token(&self, provider_id: &str) -> Option<String>

Returns the stored OAuth refresh token, if any.

Source

pub fn get_oauth_expires_at(&self, provider_id: &str) -> Option<i64>

Returns the stored OAuth access-token expiry (unix seconds), if any.

Source

pub fn set_commandcode_credential( &self, provider_id: &str, api_key: &str, metadata: CommandCodeCredentialMetadata, ) -> Result<String>

Stores a Command Code OAuth-created API key and callback metadata.

Source

pub fn get_commandcode_metadata( &self, provider_id: &str, ) -> Option<CommandCodeCredentialMetadata>

Source

pub fn delete_credential_account( &self, provider_id: &str, account_id: &str, ) -> Result<bool>

Source

pub fn delete_api_key(&self, provider_id: &str) -> Result<bool>

Deletes a stored API key and adds the provider to the ignored list. Returns true if a stored key was removed.

Source

pub fn resolve_api_key( &self, provider_id: &str, env_var: &str, ) -> Option<String>

Resolve API key for a provider: env var first (explicit override), then stored credential. Resolves an API key by checking the environment variable first, then the stored credential. Returns None if neither is set.

Trait Implementations§

Source§

impl Clone for CredentialStore

Source§

fn clone(&self) -> Self

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl Debug for CredentialStore

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T> Instrument for T

Source§

fn instrument(self, span: Span) -> Instrumented<Self> ⓘ

Instruments this type with the provided Span, returning an Instrumented wrapper. Read more
Source§

fn in_current_span(self) -> Instrumented<Self> ⓘ

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> IntoEither for T

Source§

fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ

Converts self into a Left variant of Either<Self, Self> if into_left is true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
where F: FnOnce(&Self) -> bool,

Converts self into a Left variant of Either<Self, Self> if into_left(&self) returns true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

impl<T> MaybeSend for T

Source§

impl<T> PolicyExt for T
where T: ?Sized,

Source§

fn and<P, B, E>(self, other: P) -> And<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow only if self and other return Action::Follow. Read more
Source§

fn or<P, B, E>(self, other: P) -> Or<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow if either self or other returns Action::Follow. Read more
Source§

impl<T> Read<Exclusive, BecauseExclusive> for T
where T: ?Sized,

Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, !>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<T> WithSubscriber for T

Source§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self> ⓘ
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a WithDispatch wrapper. Read more
Source§

fn with_current_subscriber(self) -> WithDispatch<Self> ⓘ

Attaches the current default Subscriber to this type, returning a WithDispatch wrapper. Read more