Optional follow-up slice of #455. Claude Code's apiKeyHelper sends the returned token as both Authorization: Bearer and X-Api-Key, so a gateway can validate on either. #455 lists this as "consider matching … configurable via auth_scheme / auth_header_name."
Forge today can send the token in exactly one native placement:
There is no scheme that sends BOTH Authorization: Bearer AND x-api-key with the same token.
Scope (only if a real gateway needs both)
- A scheme/flag (e.g.
auth_scheme: bearer_and_x_api_key, or a dual_header bool) that writes the token to both Authorization: Bearer and x-api-key.
- Update
forge validate + docs.
Status
Lowest priority — no known gateway requires both today (the customer Kong/OIDC route validates Bearer only, which bearer from #464 satisfies). Filing for completeness against the #455 deliverable list; close as wontfix if no gateway needs it.
Depends on #455 slice 1 (#464).
Optional follow-up slice of #455. Claude Code's
apiKeyHelpersends the returned token as bothAuthorization: BearerandX-Api-Key, so a gateway can validate on either. #455 lists this as "consider matching … configurable viaauth_scheme/auth_header_name."Forge today can send the token in exactly one native placement:
bearer→Authorization: Bearer(x-api-key suppressed) — shipped in feat(settings): local-dev model-gateway api_key_helper overlay + login gate (#455 slice 1) #464.x-api-key(anthropic) /Authorization: Bearer(openai).apikey_header[_only]→ a non-native custom header (the feat(llm): apikey_header auth scheme for Kong AI Gateway key-auth #303 collision guard refusesauthorization/x-api-key).There is no scheme that sends BOTH
Authorization: BearerANDx-api-keywith the same token.Scope (only if a real gateway needs both)
auth_scheme: bearer_and_x_api_key, or adual_headerbool) that writes the token to bothAuthorization: Bearerandx-api-key.forge validate+ docs.Status
Lowest priority — no known gateway requires both today (the customer Kong/OIDC route validates Bearer only, which
bearerfrom #464 satisfies). Filing for completeness against the #455 deliverable list; close as wontfix if no gateway needs it.Depends on #455 slice 1 (#464).