Skip to main content

KeyForge

Embeddable API key management SDK with LLM token budget tracking.

from keysigil import KeyForge

kf = KeyForge("sqlite:///keys.db")
await kf.setup()

# Create key — plaintext shown once
result = await kf.create_key(
    name="Production",
    rate_limit={"requests": 100, "window": "1m"},
    token_budget={"monthly": 1_000_000},
    permissions=["models.invoke"],
)
print(result.plaintext)  # kf_live_abc123...

# Verify on every request
v = await kf.verify(result.plaintext)
print(v.valid, v.permissions, v.token_budget_remaining)

# Track LLM usage
await kf.track_usage(result.key.id, input_tokens=500, output_tokens=200, model="claude-sonnet-5-5")

Install

pip install keysigil                    # core (SQLite)
pip install 'keysigil[cli]'             # + CLI
pip install 'keysigil[all]'             # everything

CLI

keysigil init
keysigil create --name "my-key" --rate-requests 100 --monthly-tokens 500000
keysigil verify kf_live_xxx
keysigil list
keysigil usage key_xxx
keysigil rotate key_xxx
keysigil revoke key_xxx

Storage backends

  • SQLite (default) — dev / single-server
  • PostgreSQL — pip install 'keysigil[postgres]', use postgresql://... URL
  • Redis — pip install 'keysigil[redis]', for rate limiting

FastAPI middleware

from keysigil.middleware.fastapi import KeyForgeAuth

auth = KeyForgeAuth(kf, require_permissions=["models.invoke"])

@app.post("/chat", dependencies=[Depends(auth)])
async def chat(request: Request):
    key_id = request.state.key_id  # injected by middleware

MCP server (LLM agents)

keysigil serve

Tools: create_api_key, verify_api_key, list_api_keys, revoke_api_key, track_token_usage, get_usage_stats

Key design

  • Format: kf_live_<256-bit-random> (Stripe pattern, enables GitHub secret scanning)
  • Hash: SHA-256 (high-entropy keys; argon2 too slow for hot-path verification)
  • Rate limiting: sliding window algorithm (Cloudflare-proven)
  • Plaintext shown once at creation — never stored

Metadata

Release files for keysigil 0.1.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for keysigil 0.1.1
File Size Uploaded
keysigil-0.1.1.tar.gz 17.6 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for keysigil 0.1.1
File Interpreter ABI Platform
keysigil-0.1.1-py3-none-any.whl Python 3 none any Details

Total release size: 40.4 kB

Release files / keysigil-0.1.1.tar.gz

Download URL keysigil-0.1.1.tar.gz
Size 17.6 kB
Tags Source
SHA-256 checksum
How to use checksums
8991790d99b8dace6d856641f035663eecda03e1f114830947dd4809f4638b53
BLAKE2b-256 checksum
How to use checksums
b17604a5b4ac8fe8c7caddec04a79e489aafc612efc104236637234445f42d6b
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.12.14

Release files / keysigil-0.1.1-py3-none-any.whl

Download URL keysigil-0.1.1-py3-none-any.whl
Size 22.8 kB
Tags Python 3
SHA-256 checksum
How to use checksums
65e93f2bc35a47abf3c729d36ebfe1552bb7ddf5d8ba337845d58033f8c107df
BLAKE2b-256 checksum
How to use checksums
e5589ecc49a375c9db6104631bfaec0736e11bd9f415781798003a1a165a8df6
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.12.14

Release history Release notifications | RSS feed

0.1.2

2 release files

This release

0.1.1 This release

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page