Skip to content

Commit 4d5c7c4

Browse files
authored
feat: Implement API key permissions (#15)
* feat: Implement API key permissions * ref: add examples * fix: lint errors
1 parent 6d2def8 commit 4d5c7c4

File tree

10 files changed

+704
-54
lines changed

10 files changed

+704
-54
lines changed

docs/resources/project_api_key.md

Lines changed: 32 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -25,6 +25,23 @@ resource "openai_project_api_key" "example" {
2525
project_id = "proj_000000000000000000000000"
2626
service_account_id = "my-service-account"
2727
}
28+
29+
# Create a read-only API key
30+
resource "openai_project_api_key" "example" {
31+
organization_id = "org-000000000000000000000000"
32+
service_account_id = "my-service-account"
33+
read_only = true
34+
}
35+
36+
# Create an API key with specific permissions
37+
resource "openai_project_api_key" "example" {
38+
organization_id = "org-000000000000000000000000"
39+
service_account_id = "my-service-account"
40+
permissions {
41+
models = "read"
42+
model_capabilities = "write"
43+
}
44+
}
2845
```
2946

3047
<!-- schema generated by tfplugindocs -->
@@ -38,14 +55,28 @@ resource "openai_project_api_key" "example" {
3855
### Optional
3956

4057
- `name` (String) The name of the API key.
58+
- `permissions` (Block, Optional) The permission of the API key. If omitted, the API key will have full permissions. (see [below for nested schema](#nestedblock--permissions))
4159
- `project_id` (String) The ID of the project. If not set, the default project will be used.
42-
- `scopes` (Set of String) The scopes of the API key. If not set, all scopes will be used.
60+
- `read_only` (Boolean) Whether the API key is read-only. If omitted, the API key will have full permissions.
4361

4462
### Read-Only
4563

4664
- `created` (Number) The timestamp when the API key was created.
4765
- `id` (String, Sensitive) The API key.
4866
- `redacted_key` (String, Sensitive) The redacted API key.
67+
- `scopes` (Set of String) The scopes of the API key.
68+
69+
<a id="nestedblock--permissions"></a>
70+
### Nested Schema for `permissions`
71+
72+
Optional:
73+
74+
- `assistants` (String) Create and retrieve Assistants. `/v1/assistants`, `/v1/models (required for Assistants)`. Valid values: `read`, `write`. If omitted, the API key will not have access.
75+
- `files` (String) Create and retrieve files. `/v1/files`. Valid values: `read`, `write`. If omitted, the API key will not have access.
76+
- `fine_tuning` (String) Create and retrieve fine tuning jobs. `/v1/fine_tuning`. Valid values: `read`, `write`. If omitted, the API key will not have access.
77+
- `model_capabilities` (String) Create chat completions, audio, embeddings, and images. `/v1/audio`, `/v1/chat/completions`, `/v1/embeddings`, `/v1/images`, `/v1/moderations`. Valid value: `write`. If omitted, the API key will not have access.
78+
- `models` (String) List models this organization has access to. `/v1/models`. Valid value: `read`. If omitted, the API key will not have access.
79+
- `threads` (String) Create and retrieve Threads/Messages/Runs. `/v1/threads`, `/v1/models (required for Threads)`. Valid values: `read`, `write`. If omitted, the API key will not have access.
4980

5081
## Import
5182

examples/resources/openai_project_api_key/resource.tf

Lines changed: 17 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -10,3 +10,20 @@ resource "openai_project_api_key" "example" {
1010
project_id = "proj_000000000000000000000000"
1111
service_account_id = "my-service-account"
1212
}
13+
14+
# Create a read-only API key
15+
resource "openai_project_api_key" "example" {
16+
organization_id = "org-000000000000000000000000"
17+
service_account_id = "my-service-account"
18+
read_only = true
19+
}
20+
21+
# Create an API key with specific permissions
22+
resource "openai_project_api_key" "example" {
23+
organization_id = "org-000000000000000000000000"
24+
service_account_id = "my-service-account"
25+
permissions {
26+
models = "read"
27+
model_capabilities = "write"
28+
}
29+
}

go.mod

Lines changed: 9 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -5,9 +5,11 @@ go 1.21
55
require (
66
github.com/hashicorp/terraform-plugin-docs v0.19.4
77
github.com/hashicorp/terraform-plugin-framework v1.9.0
8+
github.com/hashicorp/terraform-plugin-framework-validators v0.12.0
89
github.com/hashicorp/terraform-plugin-go v0.23.0
910
github.com/hashicorp/terraform-plugin-sdk/v2 v2.34.0
1011
github.com/hashicorp/terraform-plugin-testing v1.8.0
12+
github.com/iancoleman/orderedmap v0.3.0
1113
github.com/oapi-codegen/oapi-codegen/v2 v2.3.0
1214
github.com/oapi-codegen/runtime v1.1.1
1315
)
@@ -78,14 +80,14 @@ require (
7880
github.com/yuin/goldmark-meta v1.1.0 // indirect
7981
github.com/zclconf/go-cty v1.14.4 // indirect
8082
go.abhg.dev/goldmark/frontmatter v0.2.0 // indirect
81-
golang.org/x/crypto v0.23.0 // indirect
82-
golang.org/x/exp v0.0.0-20230809150735-7b3493d9a819 // indirect
83-
golang.org/x/mod v0.17.0 // indirect
84-
golang.org/x/net v0.25.0 // indirect
83+
golang.org/x/crypto v0.24.0 // indirect
84+
golang.org/x/exp v0.0.0-20240613232115-7f521ea00fb8 // indirect
85+
golang.org/x/mod v0.18.0 // indirect
86+
golang.org/x/net v0.26.0 // indirect
8587
golang.org/x/sync v0.7.0 // indirect
86-
golang.org/x/sys v0.20.0 // indirect
87-
golang.org/x/text v0.15.0 // indirect
88-
golang.org/x/tools v0.21.0 // indirect
88+
golang.org/x/sys v0.21.0 // indirect
89+
golang.org/x/text v0.16.0 // indirect
90+
golang.org/x/tools v0.22.0 // indirect
8991
google.golang.org/appengine v1.6.8 // indirect
9092
google.golang.org/genproto/googleapis/rpc v0.0.0-20240521202816-d264139d666e // indirect
9193
google.golang.org/grpc v1.64.0 // indirect

go.sum

Lines changed: 20 additions & 16 deletions
Original file line numberDiff line numberDiff line change
@@ -111,6 +111,8 @@ github.com/hashicorp/terraform-plugin-docs v0.19.4 h1:G3Bgo7J22OMtegIgn8Cd/CaSey
111111
github.com/hashicorp/terraform-plugin-docs v0.19.4/go.mod h1:4pLASsatTmRynVzsjEhbXZ6s7xBlUw/2Kt0zfrq8HxA=
112112
github.com/hashicorp/terraform-plugin-framework v1.9.0 h1:caLcDoxiRucNi2hk8+j3kJwkKfvHznubyFsJMWfZqKU=
113113
github.com/hashicorp/terraform-plugin-framework v1.9.0/go.mod h1:qBXLDn69kM97NNVi/MQ9qgd1uWWsVftGSnygYG1tImM=
114+
github.com/hashicorp/terraform-plugin-framework-validators v0.12.0 h1:HOjBuMbOEzl7snOdOoUfE2Jgeto6JOjLVQ39Ls2nksc=
115+
github.com/hashicorp/terraform-plugin-framework-validators v0.12.0/go.mod h1:jfHGE/gzjxYz6XoUwi/aYiiKrJDeutQNUtGQXkaHklg=
114116
github.com/hashicorp/terraform-plugin-go v0.23.0 h1:AALVuU1gD1kPb48aPQUjug9Ir/125t+AAurhqphJ2Co=
115117
github.com/hashicorp/terraform-plugin-go v0.23.0/go.mod h1:1E3Cr9h2vMlahWMbsSEcNrOCxovCZhOOIXjFHbjc/lQ=
116118
github.com/hashicorp/terraform-plugin-log v0.9.0 h1:i7hOA+vdAItN1/7UrfBqBwvYPQ9TFvymaRGZED3FCV0=
@@ -127,6 +129,8 @@ github.com/hashicorp/yamux v0.1.1 h1:yrQxtgseBDrq9Y652vSRDvsKCJKOUD+GzTS4Y0Y8pvE
127129
github.com/hashicorp/yamux v0.1.1/go.mod h1:CtWFDAQgb7dxtzFs4tWbplKIe2jSi3+5vKbgIO0SLnQ=
128130
github.com/huandu/xstrings v1.3.3 h1:/Gcsuc1x8JVbJ9/rlye4xZnVAbEkGauT8lbebqcQws4=
129131
github.com/huandu/xstrings v1.3.3/go.mod h1:y5/lhBue+AyNmUVz9RLU9xbLR0o4KIIExikq4ovT0aE=
132+
github.com/iancoleman/orderedmap v0.3.0 h1:5cbR2grmZR/DiVt+VJopEhtVs9YGInGIxAoMJn+Ichc=
133+
github.com/iancoleman/orderedmap v0.3.0/go.mod h1:XuLcCUkdL5owUCQeF2Ue9uuw1EptkJDkXXS7VoV7XGE=
130134
github.com/imdario/mergo v0.3.11/go.mod h1:jmQim1M+e3UYxmgPu/WyfjB3N3VflVyUjjjwH0dnCYA=
131135
github.com/imdario/mergo v0.3.15 h1:M8XP7IuFNsqUx6VPK2P9OSmsYsI/YFaGil0uD21V3dM=
132136
github.com/imdario/mergo v0.3.15/go.mod h1:WBLT9ZmE3lPoWsEzCh9LPo3TiwVN+ZKEjmz+hD27ysY=
@@ -235,20 +239,20 @@ go.abhg.dev/goldmark/frontmatter v0.2.0/go.mod h1:XqrEkZuM57djk7zrlRUB02x8I5J0px
235239
golang.org/x/crypto v0.0.0-20190308221718-c2843e01d9a2/go.mod h1:djNgcEr1/C05ACkg1iLfiJU5Ep61QUkGW8qpdssI0+w=
236240
golang.org/x/crypto v0.0.0-20210921155107-089bfa567519/go.mod h1:GvvjBRRGRdwPK5ydBHafDWAxML/pGHZbMvKqRZ5+Abc=
237241
golang.org/x/crypto v0.3.0/go.mod h1:hebNnKkNXi2UzZN1eVRvBB7co0a+JxK6XbPiWVs/3J4=
238-
golang.org/x/crypto v0.23.0 h1:dIJU/v2J8Mdglj/8rJ6UUOM3Zc9zLZxVZwwxMooUSAI=
239-
golang.org/x/crypto v0.23.0/go.mod h1:CKFgDieR+mRhux2Lsu27y0fO304Db0wZe70UKqHu0v8=
240-
golang.org/x/exp v0.0.0-20230809150735-7b3493d9a819 h1:EDuYyU/MkFXllv9QF9819VlI9a4tzGuCbhG0ExK9o1U=
241-
golang.org/x/exp v0.0.0-20230809150735-7b3493d9a819/go.mod h1:FXUEEKJgO7OQYeo8N01OfiKP8RXMtf6e8aTskBGqWdc=
242+
golang.org/x/crypto v0.24.0 h1:mnl8DM0o513X8fdIkmyFE/5hTYxbwYOjDS/+rK6qpRI=
243+
golang.org/x/crypto v0.24.0/go.mod h1:Z1PMYSOR5nyMcyAVAIQSKCDwalqy85Aqn1x3Ws4L5DM=
244+
golang.org/x/exp v0.0.0-20240613232115-7f521ea00fb8 h1:yixxcjnhBmY0nkL253HFVIm0JsFHwrHdT3Yh6szTnfY=
245+
golang.org/x/exp v0.0.0-20240613232115-7f521ea00fb8/go.mod h1:jj3sYF3dwk5D+ghuXyeI3r5MFf+NT2An6/9dOA95KSI=
242246
golang.org/x/mod v0.6.0-dev.0.20220419223038-86c51ed26bb4/go.mod h1:jJ57K6gSWd91VN4djpZkiMVwK6gcyfeH4XE8wZrZaV4=
243-
golang.org/x/mod v0.17.0 h1:zY54UmvipHiNd+pm+m0x9KhZ9hl1/7QNMyxXbc6ICqA=
244-
golang.org/x/mod v0.17.0/go.mod h1:hTbmBsO62+eylJbnUtE2MGJUyE7QWk4xUqPFrRgJ+7c=
247+
golang.org/x/mod v0.18.0 h1:5+9lSbEzPSdWkH32vYPBwEpX8KwDbM52Ud9xBUvNlb0=
248+
golang.org/x/mod v0.18.0/go.mod h1:hTbmBsO62+eylJbnUtE2MGJUyE7QWk4xUqPFrRgJ+7c=
245249
golang.org/x/net v0.0.0-20190404232315-eb5bcb51f2a3/go.mod h1:t9HGtf8HONx5eT2rtn7q6eTqICYqUVnKs3thJo3Qplg=
246250
golang.org/x/net v0.0.0-20190620200207-3b0461eec859/go.mod h1:z5CRVTTTmAJ677TzLLGU+0bjPO0LkuOLi4/5GtJWs/s=
247251
golang.org/x/net v0.0.0-20210226172049-e18ecbb05110/go.mod h1:m0MpNAwzfU5UDzcl9v0D8zg8gWTRqZa9RBIspLL5mdg=
248252
golang.org/x/net v0.0.0-20220722155237-a158d28d115b/go.mod h1:XRhObCWvk6IyKnWLug+ECip1KBveYUHfp+8e9klMJ9c=
249253
golang.org/x/net v0.2.0/go.mod h1:KqCZLdyyvdV855qA2rE3GC2aiw5xGR5TEjj8smXukLY=
250-
golang.org/x/net v0.25.0 h1:d/OCCoBEUq33pjydKrGQhw7IlUPI2Oylr+8qLx49kac=
251-
golang.org/x/net v0.25.0/go.mod h1:JkAGAh7GEvH74S6FOH42FLoXpXbE/aqXSrIQjXgsiwM=
254+
golang.org/x/net v0.26.0 h1:soB7SVo0PWrY4vPW/+ay0jKDNScG2X9wFeYlXIvJsOQ=
255+
golang.org/x/net v0.26.0/go.mod h1:5YKkiSynbBIh3p6iOc/vibscux0x38BZDkn8sCUPxHE=
252256
golang.org/x/sync v0.0.0-20180314180146-1d60e4601c6f/go.mod h1:RxMgew5VJxzue5/jJTE5uejpjVlOe/izrB70Jof72aM=
253257
golang.org/x/sync v0.0.0-20190423024810-112230192c58/go.mod h1:RxMgew5VJxzue5/jJTE5uejpjVlOe/izrB70Jof72aM=
254258
golang.org/x/sync v0.0.0-20220722155255-886fb9371eb4/go.mod h1:RxMgew5VJxzue5/jJTE5uejpjVlOe/izrB70Jof72aM=
@@ -267,26 +271,26 @@ golang.org/x/sys v0.0.0-20220722155257-8c9f86f7a55f/go.mod h1:oPkhp1MJrh7nUepCBc
267271
golang.org/x/sys v0.0.0-20220811171246-fbc7d0a398ab/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg=
268272
golang.org/x/sys v0.2.0/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg=
269273
golang.org/x/sys v0.6.0/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg=
270-
golang.org/x/sys v0.20.0 h1:Od9JTbYCk261bKm4M/mw7AklTlFYIa0bIp9BgSm1S8Y=
271-
golang.org/x/sys v0.20.0/go.mod h1:/VUhepiaJMQUp4+oa/7Zr1D23ma6VTLIYjOOTFZPUcA=
274+
golang.org/x/sys v0.21.0 h1:rF+pYz3DAGSQAxAu1CbC7catZg4ebC4UIeIhKxBZvws=
275+
golang.org/x/sys v0.21.0/go.mod h1:/VUhepiaJMQUp4+oa/7Zr1D23ma6VTLIYjOOTFZPUcA=
272276
golang.org/x/term v0.0.0-20201126162022-7de9c90e9dd1/go.mod h1:bj7SfCRtBDWHUb9snDiAeCFNEtKQo2Wmx5Cou7ajbmo=
273277
golang.org/x/term v0.0.0-20210927222741-03fcf44c2211/go.mod h1:jbD1KX2456YbFQfuXm/mYQcufACuNUgVhRMnK/tPxf8=
274278
golang.org/x/term v0.2.0/go.mod h1:TVmDHMZPmdnySmBfhjOoOdhjzdE1h4u1VwSiw2l1Nuc=
275-
golang.org/x/term v0.20.0 h1:VnkxpohqXaOBYJtBmEppKUG6mXpi+4O6purfc2+sMhw=
276-
golang.org/x/term v0.20.0/go.mod h1:8UkIAJTvZgivsXaD6/pH6U9ecQzZ45awqEOzuCvwpFY=
279+
golang.org/x/term v0.21.0 h1:WVXCp+/EBEHOj53Rvu+7KiT/iElMrO8ACK16SMZ3jaA=
280+
golang.org/x/term v0.21.0/go.mod h1:ooXLefLobQVslOqselCNF4SxFAaoS6KujMbsGzSDmX0=
277281
golang.org/x/text v0.3.0/go.mod h1:NqM8EUOU14njkJ3fqMW+pc6Ldnwhi/IjpwHt7yyuwOQ=
278282
golang.org/x/text v0.3.2/go.mod h1:bEr9sfX3Q8Zfm5fL9x+3itogRgK3+ptLWKqgva+5dAk=
279283
golang.org/x/text v0.3.3/go.mod h1:5Zoc/QRtKVWzQhOtBMvqHzDpF6irO9z98xDceosuGiQ=
280284
golang.org/x/text v0.3.7/go.mod h1:u+2+/6zg+i71rQMx5EYifcz6MCKuco9NR6JIITiCfzQ=
281285
golang.org/x/text v0.3.8/go.mod h1:E6s5w1FMmriuDzIBO73fBruAKo1PCIq6d2Q6DHfQ8WQ=
282286
golang.org/x/text v0.4.0/go.mod h1:mrYo+phRRbMaCq/xk9113O4dZlRixOauAjOtrjsXDZ8=
283-
golang.org/x/text v0.15.0 h1:h1V/4gjBv8v9cjcR6+AR5+/cIYK5N/WAgiv4xlsEtAk=
284-
golang.org/x/text v0.15.0/go.mod h1:18ZOQIKpY8NJVqYksKHtTdi31H5itFRjB5/qKTNYzSU=
287+
golang.org/x/text v0.16.0 h1:a94ExnEXNtEwYLGJSIUxnWoxoRz/ZcCsV63ROupILh4=
288+
golang.org/x/text v0.16.0/go.mod h1:GhwF1Be+LQoKShO3cGOHzqOgRrGaYc9AvblQOmPVHnI=
285289
golang.org/x/tools v0.0.0-20180917221912-90fa682c2a6e/go.mod h1:n7NCudcB/nEzxVGmLbDWY5pfWTLqBcC2KZ6jyYvM4mQ=
286290
golang.org/x/tools v0.0.0-20191119224855-298f0cb1881e/go.mod h1:b+2E5dAYhXwXZwtnZ6UAqBI28+e2cm9otk0dWdXHAEo=
287291
golang.org/x/tools v0.1.12/go.mod h1:hNGJHUnrk76NpqgfD5Aqm5Crs+Hm0VOH/i9J2+nxYbc=
288-
golang.org/x/tools v0.21.0 h1:qc0xYgIbsSDt9EyWz05J5wfa7LOVW0YTLOXrqdLAWIw=
289-
golang.org/x/tools v0.21.0/go.mod h1:aiJjzUbINMkxbQROHiO6hDPo2LHcIPhhQsa9DLh0yGk=
292+
golang.org/x/tools v0.22.0 h1:gqSGLZqv+AI9lIQzniJ0nZDRG5GBPsSi+DRNHWNz6yA=
293+
golang.org/x/tools v0.22.0/go.mod h1:aCwcsjqvq7Yqt6TNyX7QMU2enbQ/Gt0bo6krSeEri+c=
290294
golang.org/x/xerrors v0.0.0-20190717185122-a985d3407aa7/go.mod h1:I/5z698sn9Ka8TeJc9MKroUUfqBBauWjQqLJ2OPfmY0=
291295
golang.org/x/xerrors v0.0.0-20191204190536-9bdfabe68543/go.mod h1:I/5z698sn9Ka8TeJc9MKroUUfqBBauWjQqLJ2OPfmY0=
292296
google.golang.org/appengine v1.1.0/go.mod h1:EbEs0AVv82hx2wNQdGPgUI5lhzA/G0D9YwlJXL52JkM=

internal/apiclient/api.yaml

Lines changed: 39 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,4 @@
1-
openapi: "3.1.0"
1+
openapi: "3.0.3"
22
info:
33
title: OpenAI API
44
servers:
@@ -356,6 +356,44 @@ paths:
356356
$ref: "#/components/responses/BadRequest"
357357
401:
358358
$ref: "#/components/responses/Unauthorized"
359+
/dashboard/user/api_keys/scopes:
360+
get:
361+
operationId: getApiKeyScopes
362+
responses:
363+
200:
364+
content:
365+
application/json:
366+
schema:
367+
type: array
368+
items:
369+
type: object
370+
required:
371+
- description
372+
- name
373+
- permissions_to_scopes
374+
- endpoints
375+
properties:
376+
name:
377+
type: string
378+
description:
379+
type: string
380+
permissions_to_scopes:
381+
type: object
382+
properties:
383+
read:
384+
type: array
385+
items:
386+
type: string
387+
write:
388+
type: array
389+
items:
390+
type: string
391+
endpoints:
392+
type: array
393+
items:
394+
type: string
395+
401:
396+
$ref: "#/components/responses/Unauthorized"
359397
components:
360398
securitySchemes:
361399
bearerAuth:

0 commit comments

Comments
 (0)