Skip to content

feat: optional bearer auth for the HTTP API - #8

Merged
PerishCode merged 1 commit into
mainfrom
feat/bearer-auth
Jun 29, 2026
Merged

PerishCode merged 1 commit into
mainfrom
feat/bearer-auth

Conversation

@PerishCode

Copy link
Copy Markdown
Owner

No description provided.

santi-api gains an optional API key (SANTI_API_KEY). When set, every endpoint
except /health requires `Authorization: Bearer <key>` (401 otherwise); unset
keeps the API open (default). The santi client gains a global --api-key flag
(env SANTI_API_KEY) and sends the bearer token on every request.

This is the door lock for exposing santi on a public host.
@PerishCode
PerishCode merged commit 31e8f51 into main Jun 29, 2026
3 checks passed
@PerishCode
PerishCode deleted the feat/bearer-auth branch June 29, 2026 11:34
PerishCode pushed a commit that referenced this pull request Aug 1, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant