Skip to content

feat(#455 slice 5, optional): dual-header mode — send gateway token as both Authorization: Bearer and X-Api-Key #493

Description

@initializ-mk

Optional follow-up slice of #455. Claude Code's apiKeyHelper sends the returned token as both Authorization: Bearer and X-Api-Key, so a gateway can validate on either. #455 lists this as "consider matching … configurable via auth_scheme / auth_header_name."

Forge today can send the token in exactly one native placement:

There is no scheme that sends BOTH Authorization: Bearer AND x-api-key with the same token.

Scope (only if a real gateway needs both)

  • A scheme/flag (e.g. auth_scheme: bearer_and_x_api_key, or a dual_header bool) that writes the token to both Authorization: Bearer and x-api-key.
  • Update forge validate + docs.

Status

Lowest priority — no known gateway requires both today (the customer Kong/OIDC route validates Bearer only, which bearer from #464 satisfies). Filing for completeness against the #455 deliverable list; close as wontfix if no gateway needs it.

Depends on #455 slice 1 (#464).

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or requestforge-coreAffects the forge-core library (runtime, security, types, llm, mcp, auth)

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions