Skip to content
Back to skills

Api Key Manager

ASecurity

API key generation, rotation, and management system

  • 1,760 stars
  • 0 votes
  • 0 copies
  • 4 views
  • Added September 2, 2026
ai-agentsbashapidatabasesecurity

Works with

  • api

Security analysis

A100/100

Pro scans all 2 files and shows the line behind each finding

Scanned September 2, 2026

npx -y skills add a5c-ai/babysitter --skill api-key-manager --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Api Key Manager?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Api Key Manager
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/a5c-ai-api-key-manager-babysitter/badge)](https://www.skillsdirectory.com/skills/a5c-ai-api-key-manager-babysitter)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: api-key-manager
description: API key generation, rotation, and management system
allowed-tools:
  - Read
  - Write
  - Edit
  - Glob
  - Grep
  - Bash
graph:
  domains: [domain:software-engineering]
  specializations: [specialization:sdk-platform-development]
  skillAreas: [skill-area:authentication-authorization, skill-area:secrets-rotation]
  roles: [role:platform-engineer]
  topics: [topic:api-design, topic:developer-experience]
---

# API Key Manager Skill

## Overview

This skill implements comprehensive API key management including secure generation, rotation policies, usage tracking, and quota enforcement.

## Capabilities

- Generate cryptographically secure API keys
- Implement key rotation with grace periods
- Track key usage and enforce quotas
- Support key scoping and permissions
- Configure key prefix patterns for identification
- Implement key revocation and blacklisting
- Support multiple key types (test, live)
- Generate key hashes for secure storage

## Target Processes

- Authentication and Authorization Patterns
- Developer Portal Implementation
- Platform API Gateway Design

## Integration Points

- Key management systems (HashiCorp Vault)
- Rate limiting middleware
- Usage analytics systems
- Developer portal UIs
- API gateway key validation

## Input Requirements

- Key format requirements
- Scoping/permission model
- Rotation policy
- Quota definitions
- Storage security requirements

## Output Artifacts

- Key generation service
- Key validation middleware
- Rotation management system
- Usage tracking integration
- Quota enforcement rules
- Admin management API

## Usage Example

```yaml
skill:
  name: api-key-manager
  context:
    keyFormat:
      prefix: "sk_"
      testPrefix: "sk_test_"
      livePrefix: "sk_live_"
      length: 32
    rotation:
      enabled: true
      gracePeriod: "7d"
    scopes:
      - read
      - write
      - delete
    quotas:
      default: 1000
      premium: 10000
```

## Best Practices

1. Use cryptographically secure random generation
2. Prefix keys to indicate type (test/live)
3. Store only hashed keys in database
4. Implement rotation with overlap periods
5. Track usage per key for analytics
6. Support immediate revocation

Files in this skill

  • README.md469 B
  • SKILL.md2.2 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…