# API Keys (Notchset): prompt.md (v1.0.0)

- id: `api-keys` · version 1.0.0 · block · pro (Pro)
- category: Application UI
- build: Base UI (one set of files; its dependencies follow the build)
- install (this build): `npx shadcn@latest add @beautiful-ui-pro/api-keys`
- npm dependencies: class-variance-authority@^0.7
- registry dependencies: utils, @beautiful-ui/segmented-control, https://beautiful-ui.dev/r/notchset-foundation.json
- docs: https://beautiful-ui.dev/components/api-keys
- The install command carries everything this item needs (files, CSS, tokens, npm and registry dependencies). Prefer it to copying source by hand.

An API key manager: LIVE and TEST groups whose folded headers keep their counts and warnings; keys with masked secrets, scopes and last use (stale ones flagged), opening to 14 days of requests, restrictions, ROLL KEY and a confirmed REVOKE; and a create form with least-privilege scopes whose secret is shown once behind an I-saved-it check.

## Build it
- Stack: React 19 (`ref` is a plain prop), TypeScript, Tailwind CSS v4 utilities, a shadcn-initialised project with the `@/*` alias.
- Packages: `class-variance-authority@^0.7`.
- Files: `components/ui/notchset/blocks/api-keys.tsx`; shared code: `lib/beautiful-ui/notchset/instrument.tsx`, `lib/beautiful-ui/notchset/root.ts`, `lib/beautiful-ui/notchset/button-variants.ts`, `lib/beautiful-ui/notchset/field-classes.ts`.
- Registry dependencies, installed with it automatically: shadcn `utils` (cn), `segmented-control`, `notchset-foundation`.
- Builds: one set of files for both, but its dependencies come in Base UI and Radix builds. Install the one that matches the project (see Install): a free item's bare URL installs the Base UI build of it and its dependencies.
- Exports to keep: `ApiKeys`, and every exported type.
- CSS: the install adds the notchset foundation (tokens, keyframes, motion levels) to your global stylesheet once. Nothing to import by hand.
- Re-running `add` (or `--overwrite`) re-applies those rules: put overrides in your own CSS, never in the installed rules.
- Tokens: retheme with the `--notchset-*` custom properties (`--notchset-check`, `--notchset-control-edge`, `--notchset-draw-from`, `--notchset-ease-bloom`, `--notchset-ease-glide`, `--notchset-ease-key-down`, `--notchset-ease-key-up`, `--notchset-ease-travel`, `--notchset-fade`, `--notchset-focus-color`, `--notchset-focus-inset`, `--notchset-grow-to`, `--notchset-key-down`, `--notchset-key-up`, `--notchset-life-from`, `--notchset-life-ms`, `--notchset-node-blink`, `--notchset-node-bloom`, `--notchset-node-delay`, `--notchset-plate-color`, `--notchset-rise-from`, `--notchset-rule`, `--notchset-scan-to`, `--notchset-scroll`, `--notchset-signal`, `--notchset-sweep-to`, `--notchset-travel`). Never add Tailwind colour classes inside the component.

```tsx
import { ApiKeys, type ApiKey } from "@/components/ui/notchset/blocks/api-keys";
```

## Parts

| Part | data-slot | What it is for |
|---|---|---|
| `ApiKeys` | `api-keys` | The header, the create panel and the LIVE and TEST groups. |

Style a part with `[data-slot="<slot>"]` selectors or its `className`; keep the attributes when editing.

## Sound
- Keep every `data-slot` and `data-sound` attribute: the sound layer reads them.
- Installing this item adds no audio. Nothing plays until the app mounts `SoundProvider` once (install: `npx shadcn@latest add https://beautiful-ui.dev/r/notchset-sound.json`, import from `@/components/ui/notchset/sound-provider`); `useSound()` gives `muted` and `setMuted` for a mute control. Without a provider the audio engine never loads.

## Match the original
- Read `components/ui/notchset/blocks/api-keys.tsx` as the reference implementation before changing or recreating anything, and match it: sizes, colours per theme, motion timings, copy and behaviour.
- If you deviate (a prop you can't honour, a style you changed, a dependency you swapped), say so in your reply, part by part.
- Keep the accessibility contract, the keyboard map and the motion levels listed below.

## Use it when
- api keys, secret keys, access tokens, developer settings, create api key, revoke key, rotate key, roll key, scopes, Notchset
- A developer settings page where customers manage server-side keys
- Products that need scoped, expiring keys with a show-once secret

### Not when
- Personal OAuth connections: use Integrations
- Publishable client-side keys that aren't secret: a copy field is enough

## Mistakes
- Never return or log the full secret anywhere but the create response
- Flag keys unused for 30 days so they get revoked

## Usage

```tsx
import { ApiKeys, type ApiKey } from "@/components/ui/notchset/blocks/api-keys";

export function Keys({ keys }: { keys: ApiKey[] }) {
  return (
    <ApiKeys
      keys={keys}
      scopes={[{ value: "runs:read" }, { value: "runs:write" }, { value: "deploy:prod", danger: true }]}
      onCreate={async (draft) => {
        const r = await fetch("/api/keys", { method: "POST", body: JSON.stringify(draft) });
        if (!r.ok) throw new Error("create failed");
        return r.json(); // { key, secret }
      }}
      onRoll={(key) => fetch(`/api/keys/${key.id}/roll`, { method: "POST" }).then((r) => r.json())}
      onRevoke={(key) => fetch(`/api/keys/${key.id}`, { method: "DELETE" })}
    />
  );
}
```

## Props

| Prop | Type | Default | What it does |
|---|---|---|---|
| `keys` | `{ id, name, env, suffix, scopes, lastUsed, stale?, created, requests, restriction, expiry, expiringSoon? }[]` |  | Only the last four characters of a secret reach the client. requests is 14 daily counts. |
| `scopes` | `{ value, danger? }[]` |  | The scopes to offer; danger ones turn signal when picked. |
| `onCreate` | `({ name, env, scopes, expiry }) => Promise<{ key, secret }>` |  | Create on your server; the secret is shown once and dropped on DONE. |
| `onRoll / onRevoke` | `(key) => Promise<key> / (key) => Promise` |  | Roll resolves with the updated key; revoke is confirmed inline first. |
| `expiries / note` | `string[] / ReactNode` |  | Expiry choices (default 30 D, 90 D, NEVER) and the line under the title. |

Full docs: https://beautiful-ui.dev/components/api-keys

## Customising
- Colours: the component reads your shadcn tokens (`--background`, `--foreground`, `--border` …), refined by the `--notchset-*` tokens. The signal colour is `--notchset-signal` (it falls back to `--destructive`). Set tokens on `:root`, or on any container to retheme one area.
- Dark mode follows the `.dark` class on an ancestor (the shadcn and next-themes convention).
- Update later by re-running the install with `--overwrite` (review the diff if you edited it). Changelog: https://beautiful-ui.dev/r/changelog.json

## Keyboard

| Keys | Action |
|---|---|
| Enter | Create from the name field |
| ← → | Environment and expiry |
| Space | Toggle a scope or the saved check |

## Performance

- Plain rows and small SVG strips; nothing runs while idle.

## Responsive

- Under 640px (container width) a key stacks its name, scopes and last use; the create form stacks under 520px.

## Motion inventory

| Interaction | What moves |
|---|---|
| Create | The panel unrolls in 420ms; CREATE KEY's + turns into × |
| Reveal | The secret rises in; the saved check draws |
| Roll | The scanner, then the last four characters roll |
| Invalid | A signal edge and a short shake on the name |

## Accessibility contract (preserve when editing)
- Groups and keys are buttons with aria-expanded; folded content is inert
- Scopes are checkboxes; environment and expiry are radio groups (the Segmented Control)
- Results (created, rolled, revoked, blocked) are announced in the status line; DONE is aria-disabled until you confirm the key is saved

## Install

```bash
npx shadcn@latest add @beautiful-ui-pro/api-keys
```

Pro item: needs the `@beautiful-ui-pro` registry in `components.json` and `BEAUTIFUL_UI_TOKEN` in `.env.local` (https://beautiful-ui.dev/account). Setup: https://beautiful-ui.dev/docs/pro. Your components.json `style` picks the build: radix-*, new-york and default get Radix, base-* gets Base UI.

## Credits
- Built on shadcn/ui (https://ui.shadcn.com)

The notchset foundation (the tokens listed above, keyframes and motion levels) installs once with the first component; its CSS is public at https://beautiful-ui.dev/r/notchset-foundation.json.
