Search the site
BACKEND
Let other systems call your API with scoped keys or OAuth tokens.
Scopes map to the same policy actions your own app uses.
ON THIS PAGE
Declare scopes and rate plans
Issue an API key
OAuth endpoints
Status
# pubspec.yaml
dartvel:
platformApi:
scopes:
orders:read: [Order.view]
orders:write: [Order.update]
ratePlans:
standard: { maxRequests: 600, window: 1m }
requireExpiry: true
oauth: trueCopy code to clipboard
Each scope lists the policy actions it allows. An action no @DVPolicy defines fails with DV-APIKEY-001.
A rate plan is a number of requests per window.
oauth: true turns on the OAuth authorization server.
final DVIssuedApiKey issued = await DV.Auth.apiKeys.issue(
user: DV.Auth.currentUser,
actor: DV.Auth.currentUser?.id,
scopes: <String>['orders:read'],
name: 'Warehouse sync',
ratePlan: 'standard',
expiresIn: const Duration(days: 90),
);
// Show issued.secret once. Clients send it as Authorization: Bearer <secret>.Copy code to clipboard
Keys start dvk_ and OAuth access tokens start dvat_.
list, rotate and revoke manage keys. rotate can keep the old key working for an overlap.
DV.Auth.oauthClients registers, lists and revokes OAuth clients.
/oauth/authorize
/oauth/token
/oauth/introspect
/oauth/revoke
/.well-known/oauth-authorization-serverCopy code to clipboard
Partial
Spec section: Platform API: Keys, Scopes and OAuth Provider
Planned work and implementation limits
No generated ApiKey model. apiKeys takes the user and actor explicitly.
No OpenID Connect or JWT tokens, and no developer portal.
Rate plans count per server instance.
FSL-1.1-MIT licensed. Built with Dartvel.
Dartvel is made by
To the bottom