Skip to content

docs(api-keys): document the API contract - #414

Merged
mikewheeleer merged 5 commits into
Agentpay-Org:mainfrom
thlpkee20-wq:docs/api-keys-01-api
Jul 29, 2026
Merged

docs(api-keys): document the API contract#414
mikewheeleer merged 5 commits into
Agentpay-Org:mainfrom
thlpkee20-wq:docs/api-keys-01-api

Conversation

@thlpkee20-wq

Copy link
Copy Markdown
Contributor

Closes #385

Adds docs/api-keys.md covering GET (list, including the cursor/offset
pagination contract), POST (create), and DELETE (revoke), plus an
error-codes table.

Test plan

  • npm run build
  • npm run lint

Note

Stacked on #410/#411/#412/#413 (same fork-only caveat noted there); this
PR's own change is the single new docs/api-keys.md file, written to
match the behavior added in those PRs.

The GET /api/v1/api-keys handler inlined the same limit/offset parsing
and slicing preamble duplicated in the webhooks list handler. Extracted
it into applyOffsetPage() in src/listPagination.ts as a single reusable
entry point; behavior is unchanged (same defaults, same response shape).
Adds a generic paginateByCursor() helper (src/cursorPagination.ts) and
an applyListPage() wrapper that layers opt-in ?cursor= paging on top of
the existing offset/limit contract: passing cursor takes priority over
offset, and both modes now report a stable nextCursor so existing
offset-based clients can migrate without a contract change. Malformed
or expired cursors return 400 invalid_request. Item shape and existing
offset behavior are unchanged.
…k labels

- GET /api/v1/api-keys now rejects any query parameter outside
  limit/offset/cursor with a structured 400 invalid_request.
- DELETE /api/v1/api-keys/:prefix rejects a malformed prefix (must be
  1-64 alphanumeric/underscore chars) with 400 before searching the
  store, instead of always falling through to a 404.
- POST /api/v1/api-keys rejects a whitespace-only label via a new
  rejectBlank option on stringField, scoped to the label field only.
Adds src/api-keys-endpoint.test.ts covering create/list/revoke, cursor
pagination across pages, blank-label rejection, unexpected-body-field
rejection, malformed delete-prefix rejection, malformed cursor rejection,
unknown-query-param rejection, and an idempotent-repeat check on the
list endpoint.
Adds docs/api-keys.md covering GET (list, with the cursor/offset
pagination contract), POST (create), and DELETE (revoke), plus an
error-codes table.
@mikewheeleer

Copy link
Copy Markdown
Contributor

well done @thlpkee20-wq, this reads well. merging in 🌟

1 similar comment
@mikewheeleer

Copy link
Copy Markdown
Contributor

well done @thlpkee20-wq, this reads well. merging in 🌟

@mikewheeleer
mikewheeleer merged commit 8aa34e7 into Agentpay-Org:main Jul 29, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Document the api-keys API contract and error codes

2 participants