Class ApiKey
java.lang.Object
com.broadleafcommerce.auth.server.domain.apikey.ApiKey
- All Implemented Interfaces:
Serializable
- Direct Known Subclasses:
ApiKeyCreateResponse
Represents an API Key that is tied to an
AuthorizedClient.
Authentication Service 3.0.0, Release Train 3.0.0- See Also:
-
Constructor Summary
Constructors -
Method Summary
Modifier and TypeMethodDescriptionprotected booleanbooleanThe ID of theAuthorizedClient(API Account) this key belongs to.The timestamp when this key was created.A non-sensitive preview of the key (e.g., "sk_live_****3c4d") used for identifying the key in UIs and logs without exposing the secret.The cryptographically secure hash of the raw API key.getId()The unique identifier (primary key) for this API key record.getName()A user-friendly name to identify this key (e.g., "Main Storefront Key").A list of allowed origins (domains) for this key.inthashCode()booleanWhether this key is currently active and can be used for authentication.voidsetAuthorizedClientId(String authorizedClientId) The ID of theAuthorizedClient(API Account) this key belongs to.voidsetCreatedAt(Instant createdAt) The timestamp when this key was created.voidsetDisplaySafeKeyPreview(String displaySafeKeyPreview) A non-sensitive preview of the key (e.g., "sk_live_****3c4d") used for identifying the key in UIs and logs without exposing the secret.voidsetEnabled(boolean enabled) Whether this key is currently active and can be used for authentication.voidsetHashedKey(String hashedKey) The cryptographically secure hash of the raw API key.voidThe unique identifier (primary key) for this API key record.voidA user-friendly name to identify this key (e.g., "Main Storefront Key").voidsetWhitelistedDomains(List<String> whitelistedDomains) A list of allowed origins (domains) for this key.toString()
-
Constructor Details
-
ApiKey
public ApiKey()
-
-
Method Details
-
getId
The unique identifier (primary key) for this API key record. -
getName
A user-friendly name to identify this key (e.g., "Main Storefront Key"). -
getHashedKey
The cryptographically secure hash of the raw API key. This is what is stored and used for verification. This field should never be exposed in the API, and should only be leveraged by internal components for relevant operations. -
getDisplaySafeKeyPreview
A non-sensitive preview of the key (e.g., "sk_live_****3c4d") used for identifying the key in UIs and logs without exposing the secret. -
getAuthorizedClientId
The ID of theAuthorizedClient(API Account) this key belongs to. -
getCreatedAt
The timestamp when this key was created. -
isEnabled
public boolean isEnabled()Whether this key is currently active and can be used for authentication. -
getWhitelistedDomains
A list of allowed origins (domains) for this key. This is primarily relevant forDefaultApiKeyVisibilityType.PUBLISHABLEkeys used in browser-based environments to prevent unauthorized use on other domains. -
setId
The unique identifier (primary key) for this API key record. -
setName
A user-friendly name to identify this key (e.g., "Main Storefront Key"). -
setHashedKey
The cryptographically secure hash of the raw API key. This is what is stored and used for verification. This field should never be exposed in the API, and should only be leveraged by internal components for relevant operations. -
setDisplaySafeKeyPreview
A non-sensitive preview of the key (e.g., "sk_live_****3c4d") used for identifying the key in UIs and logs without exposing the secret. -
setAuthorizedClientId
The ID of theAuthorizedClient(API Account) this key belongs to. -
setCreatedAt
The timestamp when this key was created. -
setEnabled
public void setEnabled(boolean enabled) Whether this key is currently active and can be used for authentication. -
setWhitelistedDomains
A list of allowed origins (domains) for this key. This is primarily relevant forDefaultApiKeyVisibilityType.PUBLISHABLEkeys used in browser-based environments to prevent unauthorized use on other domains. -
equals
-
canEqual
-
hashCode
public int hashCode() -
toString
-