Package com.codename1.backend.security.apikey


package com.codename1.backend.security.apikey

API keys: long-lived secrets a program presents instead of signing in.

A key is generated once and shown once. What is stored is its SHA-256, so a copy of the table is not a set of working keys, and a request is authenticated by hashing what it presents and looking that up.

GeneratedApiKey made = new ApiKeyGenerator().generate("ci-bot", "deploy", "read");
repository.save(made.getApiKey());          // the hash, the owner, the scopes
show(made.getPlaintext());                  // cn1_Zm9v...; never available again

Turned on with http.apiKey(...); see ApiKeyConfigurer.