unsloth/studio/backend/auth
Daniel Han d2a917b9a4 Studio: add API key authentication for programmatic access
External users want to hit the Studio API (chat completions with tool
calling, training, export, etc.) without going through the browser
login flow. This adds sk-unsloth- prefixed API keys that work as a
drop-in replacement for JWTs in the Authorization: Bearer header.

Backend:
- New api_keys table in SQLite (storage.py)
- create/list/revoke/validate functions with SHA-256 hashed storage
- API key detection in _get_current_subject before the JWT path
- POST/GET/DELETE /api/auth/api-keys endpoints on the auth router

Frontend:
- /api-keys page with create form, one-time key reveal, keys table
- API Keys link in desktop and mobile navbar
- Route registered with requireAuth guard

Zero changes to any existing route handler -- every endpoint that uses
Depends(get_current_subject) automatically works with API keys.
2026-04-10 13:33:14 +00:00
..
.gitkeep root studio folder 2026-02-02 09:13:49 +00:00
__init__.py fix: remove old comments (#4292) 2026-03-14 16:50:13 +04:00
authentication.py Studio: add API key authentication for programmatic access 2026-04-10 13:33:14 +00:00
hashing.py Final cleanup 2026-03-12 18:28:04 +00:00
storage.py Studio: add API key authentication for programmatic access 2026-04-10 13:33:14 +00:00