java.lang.Object
com.broadleafcommerce.auth.server.domain.apikey.ApiKey
All Implemented Interfaces:
Serializable
Direct Known Subclasses:
ApiKeyCreateResponse

public class ApiKey extends Object implements Serializable
Represents an API Key that is tied to an AuthorizedClient. Authentication Service 3.0.0, Release Train 3.0.0
See Also:
  • Constructor Details

    • ApiKey

      public ApiKey()
  • Method Details

    • getId

      public String getId()
      The unique identifier (primary key) for this API key record.
    • getName

      public String getName()
      A user-friendly name to identify this key (e.g., "Main Storefront Key").
    • getHashedKey

      public String getHashedKey()
      The cryptographically secure hash of the raw API key. This is what is stored and used for verification. This field should never be exposed in the API, and should only be leveraged by internal components for relevant operations.
    • getDisplaySafeKeyPreview

      public String getDisplaySafeKeyPreview()
      A non-sensitive preview of the key (e.g., "sk_live_****3c4d") used for identifying the key in UIs and logs without exposing the secret.
    • getAuthorizedClientId

      public String getAuthorizedClientId()
      The ID of the AuthorizedClient (API Account) this key belongs to.
    • getCreatedAt

      public Instant getCreatedAt()
      The timestamp when this key was created.
    • isEnabled

      public boolean isEnabled()
      Whether this key is currently active and can be used for authentication.
    • getWhitelistedDomains

      public List<String> getWhitelistedDomains()
      A list of allowed origins (domains) for this key. This is primarily relevant for DefaultApiKeyVisibilityType.PUBLISHABLE keys used in browser-based environments to prevent unauthorized use on other domains.
    • setId

      public void setId(String id)
      The unique identifier (primary key) for this API key record.
    • setName

      public void setName(String name)
      A user-friendly name to identify this key (e.g., "Main Storefront Key").
    • setHashedKey

      public void setHashedKey(String hashedKey)
      The cryptographically secure hash of the raw API key. This is what is stored and used for verification. This field should never be exposed in the API, and should only be leveraged by internal components for relevant operations.
    • setDisplaySafeKeyPreview

      public void setDisplaySafeKeyPreview(String displaySafeKeyPreview)
      A non-sensitive preview of the key (e.g., "sk_live_****3c4d") used for identifying the key in UIs and logs without exposing the secret.
    • setAuthorizedClientId

      public void setAuthorizedClientId(String authorizedClientId)
      The ID of the AuthorizedClient (API Account) this key belongs to.
    • setCreatedAt

      public void setCreatedAt(Instant createdAt)
      The timestamp when this key was created.
    • setEnabled

      public void setEnabled(boolean enabled)
      Whether this key is currently active and can be used for authentication.
    • setWhitelistedDomains

      public void setWhitelistedDomains(List<String> whitelistedDomains)
      A list of allowed origins (domains) for this key. This is primarily relevant for DefaultApiKeyVisibilityType.PUBLISHABLE keys used in browser-based environments to prevent unauthorized use on other domains.
    • equals

      public boolean equals(Object o)
      Overrides:
      equals in class Object
    • canEqual

      protected boolean canEqual(Object other)
    • hashCode

      public int hashCode()
      Overrides:
      hashCode in class Object
    • toString

      public String toString()
      Overrides:
      toString in class Object