KeyForge
Embeddable API key management SDK with LLM token budget tracking.
from keyforge import KeyForge
kf = KeyForge("sqlite:///keys.db")
await kf.setup()
# Create key — plaintext shown once
result = await kf.create_key(
name="Production",
rate_limit={"requests": 100, "window": "1m"},
token_budget={"monthly": 1_000_000},
permissions=["models.invoke"],
)
print(result.plaintext) # kf_live_abc123...
# Verify on every request
v = await kf.verify(result.plaintext)
print(v.valid, v.permissions, v.token_budget_remaining)
# Track LLM usage
await kf.track_usage(result.key.id, input_tokens=500, output_tokens=200, model="claude-sonnet-5-5")
Install
pip install keyforge # core (SQLite)
pip install 'keyforge[cli]' # + CLI
pip install 'keyforge[all]' # everything
CLI
keyforge init
keyforge create --name "my-key" --rate-requests 100 --monthly-tokens 500000
keyforge verify kf_live_xxx
keyforge list
keyforge usage key_xxx
keyforge rotate key_xxx
keyforge revoke key_xxx
Storage backends
- SQLite (default) — dev / single-server
- PostgreSQL —
pip install 'keyforge[postgres]', usepostgresql://...URL - Redis —
pip install 'keyforge[redis]', for rate limiting
FastAPI middleware
from keyforge.middleware.fastapi import KeyForgeAuth
auth = KeyForgeAuth(kf, require_permissions=["models.invoke"])
@app.post("/chat", dependencies=[Depends(auth)])
async def chat(request: Request):
key_id = request.state.key_id # injected by middleware
MCP server (LLM agents)
keyforge serve
Tools: create_api_key, verify_api_key, list_api_keys, revoke_api_key, track_token_usage, get_usage_stats
Key design
- Format:
kf_live_<256-bit-random>(Stripe pattern, enables GitHub secret scanning) - Hash: SHA-256 (high-entropy keys; argon2 too slow for hot-path verification)
- Rate limiting: sliding window algorithm (Cloudflare-proven)
- Plaintext shown once at creation — never stored
Metadata
Release files for keysigil 0.1.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| keysigil-0.1.0.tar.gz | 17.6 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| keysigil-0.1.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 40.4 kB
Release files / keysigil-0.1.0.tar.gz
| Download URL | keysigil-0.1.0.tar.gz |
|---|---|
| Size | 17.6 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
ed0fe884266a9eb7c930292d57baa00957d760e69760383584bd451a1fad3001
|
|
BLAKE2b-256 checksum How to use checksums |
cfc28ff104a2aa93c30274625d8ce2a6ebd6b97ce6acec256a6991fdab014da7
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.12.14
|
Release files / keysigil-0.1.0-py3-none-any.whl
| Download URL | keysigil-0.1.0-py3-none-any.whl |
|---|---|
| Size | 22.8 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
02ea57a4ec20ae11a0691f59ad7c9b21bf94f05445d3c9509ac7faf89f553479
|
|
BLAKE2b-256 checksum How to use checksums |
daeecad89d484fbf6c7c18ec3abd7c97729c4fd234cfe362baa76b392336fdd2
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.12.14
|