API tab: Server tokens (B2B) section - create, reveal once, list, revoke - #128
Merged
Merged
Conversation
Port of #125 onto the internationalised page: App ID / App Secret naming, a table mapping user, app and server (B2B) tokens to when each applies, and a Connect-an-AI-assistant section with the hosted MCP OAuth URL (hidden when VITE_MCP_PUBLIC_URL is empty). All copy via translation keys in en/fr/es. Claude-Session: https://claude.ai/code/session_012vLfiJYUhB9V1Tny95Lx8Q
Uses the backend's /v2/apps/:appId/server-tokens endpoints (2610). A new token is shown once behind the existing Secret control with a curl example for the x-custom-token header; tokens can be revoked individually. The whole section stays hidden when the list endpoint returns 404, so the page works on deployments that predate the backend change. Copy in en/fr/es. Claude-Session: https://claude.ai/code/session_012vLfiJYUhB9V1Tny95Lx8Q
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Stacks on #126 (merge that first). Adds a Server tokens (B2B) section to the API settings tab against the backend endpoints being added on ethora-backend 2610: POST/GET /v2/apps/:appId/server-tokens and DELETE /v2/apps/:appId/server-tokens/:id. Create form (name, 30/90/365 days), one-time reveal behind the existing Secret control with a curl example for the x-custom-token header, list with revoke and confirm. Hidden entirely when the list endpoint 404s, so it is safe to ship before the backend lands. Strings in en/fr/es. typecheck, eslint (changed files) and build clean; the remaining eslint findings in src/http.ts are pre-existing lines.
https://claude.ai/code/session_012vLfiJYUhB9V1Tny95Lx8Q