Skip to main content

Module api_keys

Module api_keys 

Source
Expand description

API key management module for secure retrieval from environment variables, .env files, and configuration files.

This module provides a unified interface for retrieving API keys for different providers, prioritizing security by checking environment variables first, then .env files, and finally falling back to configuration file values.

The facade owns provider/key identity and discovery. Source precedence, storage migration, and credential material stay behind the private credential_resolution boundary.

Structs§

ApiKeySources
API key sources for different providers
DiscoveredProvider
A provider with a discoverable credential — ready to use without prompting the user to paste a key.
ResolvedCredential
A resolved credential and the source that supplied it.

Enums§

CredentialSource
Where a provider’s credential was discovered.

Functions§

api_key_env_var
clear_credential_with_mode
Clear a provider/key credential from secure storage.
credential_identity
Build the normalized identity used by credential storage for a provider and an optional configured environment-variable name.
credential_metadata_key
Return the stable configuration metadata key for a provider/key identity.
discover_available_providers
Scan all built-in providers and return those with a discoverable credential.
discover_available_providers_with_mode
Scan all built-in providers using the configured secure-storage backend.
find_discovered
Look up a provider in a discovery snapshot.
get_api_key
Get an API key for a provider using the platform-default storage backend.
get_api_key_with_mode
Get an API key using the configured secure-storage backend.
has_oauth_or_managed_auth
Check whether any provider in the slice has an OAuth session or managed auth.
load_dotenv
Load environment variables from .env file
load_stored_api_key_with_mode
Load a provider’s default API key from secure storage only.
load_stored_credential_with_mode
Load only the secure-storage value for a provider/key identity.
provider_credential_detail
Determine whether a single built-in provider has a usable credential right now, and the full detail of where it came from. Returns None when no credential is found.
provider_credential_detail_with_mode
Determine whether a provider has a usable credential using storage_mode.
provider_credential_source
Thin wrapper over provider_credential_detail that returns only the credential source. Kept for backward compatibility with callers that don’t need the env-var detail.
resolve_api_key_env
resolve_credential
Resolve a credential using the platform-default secure-storage backend.
resolve_credential_with_mode
Resolve a provider/key credential with explicit storage mode.
resolve_openai_api_key_for_auth
Resolve the API-key input for OpenAI account authentication.
store_credential_with_mode
Store a provider/key credential in the configured secure-storage backend.