Expand description
API key management module for secure retrieval from environment variables, .env files, and configuration files.
This module provides a unified interface for retrieving API keys for different providers, prioritizing security by checking environment variables first, then .env files, and finally falling back to configuration file values.
The facade owns provider/key identity and discovery. Source precedence,
storage migration, and credential material stay behind the private
credential_resolution boundary.
Structs§
- ApiKey
Sources - API key sources for different providers
- Discovered
Provider - A provider with a discoverable credential — ready to use without prompting the user to paste a key.
- Resolved
Credential - A resolved credential and the source that supplied it.
Enums§
- Credential
Source - Where a provider’s credential was discovered.
Functions§
- api_
key_ env_ var - clear_
credential_ with_ mode - Clear a provider/key credential from secure storage.
- credential_
identity - Build the normalized identity used by credential storage for a provider and an optional configured environment-variable name.
- credential_
metadata_ key - Return the stable configuration metadata key for a provider/key identity.
- discover_
available_ providers - Scan all built-in providers and return those with a discoverable credential.
- discover_
available_ providers_ with_ mode - Scan all built-in providers using the configured secure-storage backend.
- find_
discovered - Look up a provider in a discovery snapshot.
- get_
api_ key - Get an API key for a provider using the platform-default storage backend.
- get_
api_ key_ with_ mode - Get an API key using the configured secure-storage backend.
- has_
oauth_ or_ managed_ auth - Check whether any provider in the slice has an OAuth session or managed auth.
- load_
dotenv - Load environment variables from .env file
- load_
stored_ api_ key_ with_ mode - Load a provider’s default API key from secure storage only.
- load_
stored_ credential_ with_ mode - Load only the secure-storage value for a provider/key identity.
- provider_
credential_ detail - Determine whether a single built-in provider has a usable credential right
now, and the full detail of where it came from. Returns
Nonewhen no credential is found. - provider_
credential_ detail_ with_ mode - Determine whether a provider has a usable credential using
storage_mode. - provider_
credential_ source - Thin wrapper over
provider_credential_detailthat returns only the credential source. Kept for backward compatibility with callers that don’t need the env-var detail. - resolve_
api_ key_ env - resolve_
credential - Resolve a credential using the platform-default secure-storage backend.
- resolve_
credential_ with_ mode - Resolve a provider/key credential with explicit storage mode.
- resolve_
openai_ api_ key_ for_ auth - Resolve the API-key input for OpenAI account authentication.
- store_
credential_ with_ mode - Store a provider/key credential in the configured secure-storage backend.