{"_id":"@emdzej/keycloak-api-keys-fastify","name":"@emdzej/keycloak-api-keys-fastify","dist-tags":{"latest":"0.1.0"},"versions":{"0.1.0":{"name":"@emdzej/keycloak-api-keys-fastify","version":"0.1.0","publishConfig":{"access":"public"},"type":"module","main":"./dist/index.js","types":"./dist/index.d.ts","exports":{".":{"import":"./dist/index.js","types":"./dist/index.d.ts"}},"scripts":{"build":"tsup src/index.ts --format esm --dts","test":"vitest run","typecheck":"tsc --noEmit"},"dependencies":{"fastify-plugin":"^5.0.0"},"peerDependencies":{"fastify":"^5.0.0"},"devDependencies":{"@types/node":"^22.0.0","fastify":"^5.0.0","tsup":"^8.0.0","typescript":"^5.7.0","vitest":"^3.0.0"},"license":"Apache-2.0","repository":{"type":"git","url":"git+https://github.com/emdzej/keycloak-api-keys.git","directory":"packages/fastify"},"homepage":"https://github.com/emdzej/keycloak-api-keys#readme","bugs":{"url":"https://github.com/emdzej/keycloak-api-keys/issues"},"author":{"name":"Michał Jaskólski"},"gitHead":"4424e7c221030d05b8db510df70a03c9640523e3","_id":"@emdzej/keycloak-api-keys-fastify@0.1.0","description":"Fastify plugin for validating Keycloak API keys and attaching decoded auth info to the request.","_nodeVersion":"22.22.0","_npmVersion":"11.11.0","dist":{"integrity":"sha512-SzdTnF0bQztBPOZzmoTkwms2xfcLoG5epNpRfwSbxvNan8ay4N0neNwliDU1uX6Rb+7BzbZsOLlQ8jEinQQS8A==","shasum":"ba37e16c1bb7ae93f80d4e84c5edb37794b6bb9f","tarball":"https://registry.npmjs.org/@emdzej/keycloak-api-keys-fastify/-/keycloak-api-keys-fastify-0.1.0.tgz","fileCount":12,"unpackedSize":19685,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIQCdjenBi8Kr4MaSeHKl355/Xh9zHf6mjQMGWfUUrcQo2wIgPfg2Pk0F/snreqj/VfLiFddSYz/OuAIOBfi/EVR/b0Q="}]},"_npmUser":{"name":"emdzej","email":"michal@jaskolski.pro"},"directories":{},"maintainers":[{"name":"emdzej","email":"michal@jaskolski.pro"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/keycloak-api-keys-fastify_0.1.0_1774019007346_0.6148106854498965"},"_hasShrinkwrap":false}},"time":{"created":"2026-03-20T15:03:27.227Z","0.1.0":"2026-03-20T15:03:27.532Z","modified":"2026-03-20T15:03:27.775Z"},"maintainers":[{"name":"emdzej","email":"michal@jaskolski.pro"}],"description":"Fastify plugin for validating Keycloak API keys and attaching decoded auth info to the request.","homepage":"https://github.com/emdzej/keycloak-api-keys#readme","repository":{"type":"git","url":"git+https://github.com/emdzej/keycloak-api-keys.git","directory":"packages/fastify"},"author":{"name":"Michał Jaskólski"},"bugs":{"url":"https://github.com/emdzej/keycloak-api-keys/issues"},"license":"Apache-2.0","readme":"# @emdzej/keycloak-api-keys-fastify\n\nFastify plugin for validating Keycloak API keys and attaching decoded auth info to the request.\n\n## Installation\n\n```bash\npnpm add @emdzej/keycloak-api-keys-fastify fastify\n```\n\n## Usage\n\n```ts\nimport Fastify from 'fastify';\nimport { keycloakApiKeyPlugin } from '@emdzej/keycloak-api-keys-fastify';\n\nconst fastify = Fastify();\n\nawait fastify.register(keycloakApiKeyPlugin, {\n  realm: 'my-realm',\n  serverUrl: 'https://keycloak.example.com',\n  clientId: 'my-app',\n  clientSecret: process.env.CLIENT_SECRET\n});\n\nfastify.get('/api/data', async (request) => {\n  const userId = request.auth?.sub;\n  const roles = request.auth?.realm_access?.roles;\n  return { userId, roles };\n});\n```\n\n## Configuration\n\n```ts\nawait fastify.register(keycloakApiKeyPlugin, {\n  serverUrl: 'https://keycloak.example.com',\n  realm: 'my-realm',\n  clientId: 'my-app',\n  clientSecret: process.env.CLIENT_SECRET,\n  headerName: 'X-API-Key', // optional, default: X-API-Key\n  cacheTtl: 300, // optional, seconds\n  prefix: '/api' // optional, route prefix to protect\n});\n```\n\n### Options\n\n- `serverUrl` (string, required) — Keycloak base URL.\n- `realm` (string, required) — Keycloak realm name.\n- `clientId` (string, required) — OAuth client ID.\n- `clientSecret` (string, optional) — Required for confidential clients.\n- `headerName` (string, optional) — API key header (default `X-API-Key`).\n- `cacheTtl` (number, optional) — Cache TTL in seconds (default `300`).\n- `prefix` (string, optional) — Route prefix to protect (default `/api`).\n\n## Behavior\n\n- **Missing API key** → `401 Unauthorized`\n- **Invalid API key** → `401 Unauthorized`\n- **Rate limited** → `429 Too Many Requests` (rate limit headers forwarded)\n\n## TypeScript\n\nThe plugin augments `FastifyRequest` with `auth`:\n\n```ts\ninterface AuthInfo {\n  sub: string;\n  azp: string;\n  api_key_id: string;\n  realm_access?: { roles: string[] };\n  scope?: string;\n  [key: string]: unknown;\n}\n```\n","readmeFilename":"README.md","_rev":"1-bc7f4a72a20ced69d2743876e51e968b"}