Skip to main content
Version: 3.4.0-rc.1

cmind/apikey/v2/api_key_service.proto

Package: cmind.apikey.v2

Enums​

KeyType​

ValueNumberDescription
KEY_TYPE_UNSPECIFIED0
KEY_TYPE_PERSONAL1
KEY_TYPE_SERVICE_ACCOUNT2

GrantTargetType​

GrantTargetType is the kind of resource a KeyGrant targets. The set is intentionally closed: each target type has a fixed set of supported actions (see GrantAction) and a private mapping to the OpenFGA relation used for the check + the tuple write.

ValueNumberDescription
GRANT_TARGET_TYPE_UNSPECIFIED0
GRANT_TARGET_TYPE_MODEL_DEPLOYMENT1
GRANT_TARGET_TYPE_EXTERNAL_MODEL2
GRANT_TARGET_TYPE_RAG_DEPLOYMENT3
GRANT_TARGET_TYPE_GROUP4
GRANT_TARGET_TYPE_PRESET_AGENT5target_id is the PresetAgent CRD name. The agent must belong to the key's tenant.
GRANT_TARGET_TYPE_MODEL_ALIAS6

GrantAction​

GrantAction names the kind of access a key gets on the target. Not every combination of (target_type, action) is valid — the service rejects unsupported pairs with InvalidArgument.

ValueNumberDescription
GRANT_ACTION_UNSPECIFIED0
GRANT_ACTION_MODEL_INVOKE1model_deployment, external_model, model_alias
GRANT_ACTION_RAG_READ2rag_deployment
GRANT_ACTION_RAG_WRITE3rag_deployment
GRANT_ACTION_GROUP_MEMBERSHIP5group
GRANT_ACTION_AGENT_INVOKE6preset agent

Messages​

KeyGrant​

KeyGrant describes one capability attached to a key. The service maps (target_type, action) to the underlying OpenFGA relation and verifies the caller has the corresponding permission before writing the tuple.

FieldTypeNumberDescription
targetTypeGrantTargetType1
targetIdstring2
actionGrantAction3

ApiKey​

FieldTypeNumberDescription
idstring1
typeKeyType2
tenantIdstring3
userIdoptional string4
displayNamestring5
descriptionstring6
secretPrefixstring7
createdBystring8
createdAtgoogle.protobuf.Timestamp9
currentExpiresAtoptional google.protobuf.Timestamp10
revokedAtoptional google.protobuf.Timestamp11
revokedByoptional string12
disabledAtoptional google.protobuf.Timestamp13Disabling blocks every secret without changing grants or expiry.
disabledByoptional string14

CreateApiKeyRequest​

FieldTypeNumberDescription
tenantIdstring1
displayNamestring2
grantsrepeated KeyGrant3
validForoptional google.protobuf.Duration4Must be positive. Mutually exclusive with permanent.
permanentbool5
descriptionstring6Free-form longer description. Optional.

GetApiKeyRequest​

FieldTypeNumberDescription
tenantIdstring1
keyIdstring2

GetApiKeyResponse​

FieldTypeNumberDescription
apiKeyApiKey1
grantsrepeated KeyGrant2

CreateApiKeyResponse​

FieldTypeNumberDescription
apiKeyApiKey1
plaintextKeystring2
grantsrepeated KeyGrant3

RotateApiKeyRequest​

FieldTypeNumberDescription
tenantIdstring1
keyIdstring2
overlapgoogle.protobuf.Duration3Overlap window during which the previous secret remains valid. The previous secret's expires_at is set to least(existing_expires_at, now() + overlap) so rotation never extends a near-expired secret.
validForoptional google.protobuf.Duration4Must be positive. Mutually exclusive with permanent.
permanentbool5

RotateApiKeyResponse​

FieldTypeNumberDescription
apiKeyApiKey1
plaintextKeystring2

UpdateApiKeyMetadataRequest​

FieldTypeNumberDescription
tenantIdstring1
keyIdstring2
displayNameoptional string3If set, replaces the key's display_name. Must be non-empty.
descriptionoptional string4If set, replaces the key's description. May be empty to clear.

UpdateApiKeyMetadataResponse​

FieldTypeNumberDescription
apiKeyApiKey1

DisableApiKeyRequest​

Disable is idempotent and rejects permanently revoked keys.

FieldTypeNumberDescription
tenantIdstring1
keyIdstring2

DisableApiKeyResponse​

FieldTypeNumberDescription
apiKeyApiKey1

EnableApiKeyRequest​

Enable is idempotent and rejects permanently revoked keys.

FieldTypeNumberDescription
tenantIdstring1
keyIdstring2

EnableApiKeyResponse​

FieldTypeNumberDescription
apiKeyApiKey1

RevokeApiKeyRequest​

FieldTypeNumberDescription
tenantIdstring1
keyIdstring2

RevokeApiKeyResponse​

ListApiKeysRequest​

FieldTypeNumberDescription
tenantIdstring1

ListApiKeysResponse​

FieldTypeNumberDescription
apiKeysrepeated ApiKey1

Services​

ApiKeyService​

ApiKeyService manages the lifecycle of API keys. Validation does not live on this surface — it runs via the Envoy ext_authz contract at the Istio ingress (see RFC 2026-03-13-api-key-system.md). This service exposes only lifecycle operations. Every key is scoped to a tenant. The endpoints are split by key type so each RPC carries a single static authorization rule: - personal key creation check tenant membership (can_read). Rotate/Revoke enforce key ownership against the authenticated caller in the handler. - service-account endpoints check can_admin on the tenant.

CreatePersonalApiKey​

POST /cmind.apikey.v2.ApiKeyService/CreatePersonalApiKey

Personal keys

Request: CreateApiKeyRequest

Response: CreateApiKeyResponse

RotatePersonalApiKey​

POST /cmind.apikey.v2.ApiKeyService/RotatePersonalApiKey

Request: RotateApiKeyRequest

Response: RotateApiKeyResponse

UpdatePersonalApiKeyMetadata​

POST /cmind.apikey.v2.ApiKeyService/UpdatePersonalApiKeyMetadata

Request: UpdateApiKeyMetadataRequest

Response: UpdateApiKeyMetadataResponse

DisablePersonalApiKey​

POST /cmind.apikey.v2.ApiKeyService/DisablePersonalApiKey

Request: DisableApiKeyRequest

Response: DisableApiKeyResponse

EnablePersonalApiKey​

POST /cmind.apikey.v2.ApiKeyService/EnablePersonalApiKey

Request: EnableApiKeyRequest

Response: EnableApiKeyResponse

RevokePersonalApiKey​

POST /cmind.apikey.v2.ApiKeyService/RevokePersonalApiKey

Request: RevokeApiKeyRequest

Response: RevokeApiKeyResponse

ListPersonalApiKeys​

GET /cmind.apikey.v2.ApiKeyService/ListPersonalApiKeys

Request: ListApiKeysRequest

Response: ListApiKeysResponse

GetPersonalApiKey​

GET /cmind.apikey.v2.ApiKeyService/GetPersonalApiKey

Request: GetApiKeyRequest

Response: GetApiKeyResponse

CreateServiceAccountApiKey​

POST /cmind.apikey.v2.ApiKeyService/CreateServiceAccountApiKey

Service-account keys

Request: CreateApiKeyRequest

Response: CreateApiKeyResponse

RotateServiceAccountApiKey​

POST /cmind.apikey.v2.ApiKeyService/RotateServiceAccountApiKey

Request: RotateApiKeyRequest

Response: RotateApiKeyResponse

UpdateServiceAccountApiKeyMetadata​

POST /cmind.apikey.v2.ApiKeyService/UpdateServiceAccountApiKeyMetadata

Request: UpdateApiKeyMetadataRequest

Response: UpdateApiKeyMetadataResponse

DisableServiceAccountApiKey​

POST /cmind.apikey.v2.ApiKeyService/DisableServiceAccountApiKey

Request: DisableApiKeyRequest

Response: DisableApiKeyResponse

EnableServiceAccountApiKey​

POST /cmind.apikey.v2.ApiKeyService/EnableServiceAccountApiKey

Request: EnableApiKeyRequest

Response: EnableApiKeyResponse

RevokeServiceAccountApiKey​

POST /cmind.apikey.v2.ApiKeyService/RevokeServiceAccountApiKey

Request: RevokeApiKeyRequest

Response: RevokeApiKeyResponse

ListServiceAccountApiKeys​

GET /cmind.apikey.v2.ApiKeyService/ListServiceAccountApiKeys

Request: ListApiKeysRequest

Response: ListApiKeysResponse

GetServiceAccountApiKey​

GET /cmind.apikey.v2.ApiKeyService/GetServiceAccountApiKey

Request: GetApiKeyRequest

Response: GetApiKeyResponse