跳到主要内容
知仓学习社ZHICANG

api-key-manager

API key generation, rotation, and management system

不碰外部(只输出文字)无严重或高危命中a5c-ai/babysitter

它会碰到什么

扫了多少2 个文本文件,3 KB
它会碰到什么不碰外部(只输出文字)
命中总数0 处
命中统计严重 0 · 高 0 · 中 0 · 低 0

这一栏是扫描器报的事实,不是结论。命中多不等于有毒(安全工具、规则库、示例脚本本来就会包含危险写法),命中少也不等于干净。它和你手上的凭据、文件、网络有什么关系,需要你自己看。

技能内容

API Key Manager Skill

Overview

This skill implements comprehensive API key management including secure generation, rotation policies, usage tracking, and quota enforcement.

Capabilities

  • Generate cryptographically secure API keys
  • Implement key rotation with grace periods
  • Track key usage and enforce quotas
  • Support key scoping and permissions
  • Configure key prefix patterns for identification
  • Implement key revocation and blacklisting
  • Support multiple key types (test, live)
  • Generate key hashes for secure storage

Target Processes

  • Authentication and Authorization Patterns
  • Developer Portal Implementation
  • Platform API Gateway Design

Integration Points

  • Key management systems (HashiCorp Vault)
  • Rate limiting middleware
  • Usage analytics systems
  • Developer portal UIs
  • API gateway key validation

Input Requirements

  • Key format requirements
  • Scoping/permission model
  • Rotation policy
  • Quota definitions
  • Storage security requirements

Output Artifacts

  • Key generation service
  • Key validation middleware
  • Rotation management system
  • Usage tracking integration
  • Quota enforcement rules
  • Admin management API

Usage Example

skill:
  name: api-key-manager
  context:
    keyFormat:
      prefix: "sk_"
      testPrefix: "sk_test_"
      livePrefix: "sk_live_"
      length: 32
    rotation:
      enabled: true
      gracePeriod: "7d"
    scopes:
      - read
      - write
      - delete
    quotas:
      default: 1000
      premium: 10000

Best Practices

  1. Use cryptographically secure random generation
  2. Prefix keys to indicate type (test/live)
  3. Store only hashed keys in database
  4. Implement rotation with overlap periods
  5. Track usage per key for analytics
  6. Support immediate revocation

想直接用这个技能?

本站把开放许可(MIT / Apache 等)的技能按仓库打包整理到网盘,点一下转存到你自己的网盘,不用一个个从 GitHub 拉。许可未声明的技能只给原始仓库链接,不打包。

它属于哪个仓库

星标★ 1,796
本站分层T1
该仓技能数2115
原文件路径library/specializations/sdk-platform-development/skills/api-key-manager/SKILL.md

同一个仓库里的其他技能

看这个仓库的全部 2115 个技能