Dartvel, home
Docs
Features
Studio
Cloud
Compared

Search the site

GitHub
pub.dev

GETTING STARTED

Getting started
Existing Flutter apps
Existing Native apps
Run on your phone

APP

UI and styling
Routing
State
Accessibility
Keyboard shortcuts
Localization
Devices and desktop
Native device access
Media, 3D and XR

DATA

Data models
Forms
Search
Sync and offline
Import and export
Change capture
Database
Cache
File storage
Images
Privacy and erasure

BACKEND

Backend functions
Auth and sessions
Authorization
Queues and jobs
Workers and memory
Notifications and mail
Outbound HTTP
AI
Webhooks
GraphQL and OpenAPI
API keys and OAuth
Multi-tenancy
Billing and commerce
Modules

OPERATIONS

Edge security
Secrets and environments
Monitoring
Releases

SHIPPING

Build targets
Telegram Mini Apps
Static web hosting
Servers and deploying

REFERENCE

Testing
CLI reference
Coding agents

BACKEND

API keys and OAuth

Let other systems call your API with scoped keys or OAuth tokens.

Scopes map to the same policy actions your own app uses.

ON THIS PAGE

Declare scopes and rate plans

Issue an API key

OAuth endpoints

Status

Declare scopes and rate plans

# pubspec.yaml
dartvel:
  platformApi:
    scopes:
      orders:read: [Order.view]
      orders:write: [Order.update]
    ratePlans:
      standard: { maxRequests: 600, window: 1m }
    requireExpiry: true
    oauth: true

Copy code to clipboard

Each scope lists the policy actions it allows. An action no @DVPolicy defines fails with DV-APIKEY-001.

A rate plan is a number of requests per window.

oauth: true turns on the OAuth authorization server.

Issue an API key

final DVIssuedApiKey issued = await DV.Auth.apiKeys.issue(
  user: DV.Auth.currentUser,
  actor: DV.Auth.currentUser?.id,
  scopes: <String>['orders:read'],
  name: 'Warehouse sync',
  ratePlan: 'standard',
  expiresIn: const Duration(days: 90),
);
// Show issued.secret once. Clients send it as Authorization: Bearer <secret>.

Copy code to clipboard

Keys start dvk_ and OAuth access tokens start dvat_.

list, rotate and revoke manage keys. rotate can keep the old key working for an overlap.

DV.Auth.oauthClients registers, lists and revokes OAuth clients.

OAuth endpoints

/oauth/authorize
/oauth/token
/oauth/introspect
/oauth/revoke
/.well-known/oauth-authorization-server

Copy code to clipboard

Status

Partial

Spec section: Platform API: Keys, Scopes and OAuth Provider

Planned work and implementation limits

No generated ApiKey model. apiKeys takes the user and actor explicitly.

No OpenID Connect or JWT tokens, and no developer portal.

Rate plans count per server instance.

PREVIOUS GraphQL and OpenAPI The API your models and functions already have
NEXT Multi-tenancy One deployment, many customers
GitHub
pub.dev
npm
Acknowledgements
Privacy
Terms

FSL-1.1-MIT licensed. Built with Dartvel.

Dartvel is made by

SigmaDev Digital

To the bottom