Skip to content

Platform tokens follow-ups: edge reject on inference routes, per-IP limiter, revoke on sign-out-all #167

Description

@sre-helmcode

Follow-ups from cloud-api #323 review (#166).

  • Edge (nan-devops, Worker api-edge-normaliser): reject Authorization: Bearer nan_pat_... (any whitespace, tabs incl.) on every non-platform route of api.nan.builders, so inference routes served directly by LiteLLM (/v1/chat/completions, /v1/responses, /v1/embeddings, ...) never even receive a PAT. LiteLLM already 401s them; this is defence in depth. Tests: byte-identical behavior for sk- keys; /v1/runs* passthrough unchanged.
  • cloud-api: per-IP limiter for malformed/unknown PATs (each well-formed unknown token costs one DB lookup; 256-bit tokens are unguessable, this is load protection only), mirroring the sk- key limiter.
  • cloud-ui: "Sign out of all sessions" should offer to revoke platform tokens too.

Activity

  1. sre-helmcode commented on Oct 10, 2026

    @sre-helmcode
    ContributorAuthor

    Additional follow-ups (from the API reference review, 2026-10-10):

    • cloud-api: the session_required 401 message ("API keys only work for inference") is outdated since member sk- keys and nan_pat_ tokens work on GET /api/workspaces[/{uuid}] and /v1/runs*. Reword it (the website docs quote it verbatim in src/data/openapi.json; update both together).
    • Document the 429 / 500 bodies the /api auth layer can return in the API reference.
  2. sre-helmcode commented on Oct 11, 2026

    @sre-helmcode
    ContributorAuthor

    Follow-up from T-167 (cloud-api #326): the per-IP limiter for rejected platform tokens (30/min, burst 5) also 429s VALID tokens from the same IP once the bucket is spent. Workspaces egress through their host's public IP, so a misbehaving agent in one member's workspace could briefly 429 another member's valid PAT calls from the same host (same property as the existing sk- limiter). Options: exempt the fleet egress IPs (devops fleet registry) from the IP bucket and rely on per-token limits there, or key the bucket by token prefix + IP.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions