Skip to content

feat(server): --api-key flag for bearer token auth on the HTTP API - #558

Open
santanu20 wants to merge 1 commit into
FlashML-org:mainfrom
santanu20:feat/api-key
Open

santanu20 wants to merge 1 commit into
FlashML-org:mainfrom
santanu20:feat/api-key

Conversation

@santanu20

Copy link
Copy Markdown

Summary

  • Optional --api-key flag (default: FREETOKEN_API_KEY env, flag wins) that requires Authorization: Bearer <key> on every non-health route.
  • Unset key = today's no-auth behavior, fully backward compatible; GET /health stays open so supervisors/orchestrators can poll readiness without the token.
  • 401 responses use the existing OpenAI-style error shape (invalid_request_error / invalid_api_key).
  • The gate is registered after the request-accounting middleware, so LIFO order rejects unauthorized probes before they reach the request ring.

Implements #557.

Testing

  • py_compile clean on both touched files; diff is contained to server/args.py (flag + field) and server/api_server.py (module key + middleware + wiring).
  • Behavior matrix: unset key -> no auth (unchanged); key set + valid Bearer -> passes; key set + wrong/missing token -> 401 JSON; /health always open.

Adds an optional --api-key (default: FREETOKEN_API_KEY env) that gates every
non-health route behind Authorization: Bearer <key>. Unset keeps today's
no-auth behavior; /health stays open either way so supervisors can poll
readiness. The gate runs before request accounting, so rejected probes never
reach the request ring.

Implements FlashML-org#557.
KarrAcaRn pushed a commit to KarrAcaRn/FreeToken-ByAI that referenced this pull request Oct 3, 2026
… authentication

Conflict in server/args.py: main's --allowed-local-media-path check and
the PR's FREETOKEN_API_KEY fallback sit in the same spot; kept both.
Pulled forward from the queue as the more complete of the two API-key
PRs (FlashML-org#558 lacks tests, CORS preflight and the shell client's key).

Assisted-by: Claude Opus 5.5
KarrAcaRn pushed a commit to KarrAcaRn/FreeToken-ByAI that referenced this pull request Oct 3, 2026
Logs FlashML-org#565 (reimplemented), FlashML-org#564, FlashML-org#562, FlashML-org#559 (with fixups), FlashML-org#558
(superseded by FlashML-org#305) and FlashML-org#305 (pulled forward, adopted).

Assisted-by: Claude Opus 5.5

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant