summaryrefslogtreecommitdiff
path: root/internal/auth/static.go
diff options
context:
space:
mode:
authorChia <Chia@93.nz>2026-08-06 15:58:57 +1200
committerChia <Chia@93.nz>2026-08-06 15:58:57 +1200
commit3f702084d20b3c3a3ea916f3110e99b22bda60b3 (patch)
tree517f76c51025ce1ee085ea4898c60f799e5c37ea /internal/auth/static.go
parent41e322c53d7b4b796eb377d0df9c29ecd10ba431 (diff)
feat: complete commercial developer workflowspublish-commercial-control-plane
Add tenant-safe usage observability, prepaid billing controls, API key lifecycle management, Embeddings metering, configurable billing alerts, and resilient provider health propagation. Harden Stripe failure handling, migrations, readiness, and the authenticated control-plane UI with end-to-end verification evidence.
Diffstat (limited to 'internal/auth/static.go')
-rw-r--r--internal/auth/static.go6
1 files changed, 5 insertions, 1 deletions
diff --git a/internal/auth/static.go b/internal/auth/static.go
index 2b44158..67756bf 100644
--- a/internal/auth/static.go
+++ b/internal/auth/static.go
@@ -27,6 +27,9 @@ type KeyRecord struct {
Scopes []string `json:"scopes"`
AllowedModels []string `json:"allowed_models,omitempty"`
MonthlySpendMicros int64 `json:"monthly_spend_micros,omitempty"`
+ DailySpendMicros int64 `json:"daily_spend_micros,omitempty"`
+ RequestsPerMinute int64 `json:"requests_per_minute,omitempty"`
+ TokensPerMinute int64 `json:"tokens_per_minute,omitempty"`
ExpiresAt *time.Time `json:"expires_at,omitempty"`
}
@@ -78,7 +81,8 @@ func NewStatic(raw string, allowAnonymous bool) (*StaticAuthenticator, error) {
hashed = append(hashed, HashedKeyRecord{Hash: hash, Principal: domain.Principal{
KeyID: record.KeyID, TenantID: record.TenantID, ProjectID: record.ProjectID,
Scopes: append([]string(nil), record.Scopes...), AllowedModels: allowedModels,
- MonthlySpendMicros: record.MonthlySpendMicros, ExpiresAt: record.ExpiresAt,
+ MonthlySpendMicros: record.MonthlySpendMicros, DailySpendMicros: record.DailySpendMicros,
+ RequestsPerMinute: record.RequestsPerMinute, TokensPerMinute: record.TokensPerMinute, ExpiresAt: record.ExpiresAt,
}})
}
if len(hashed) == 0 && !allowAnonymous {