v2.0.0December 25, 2024
API Key Security Upgrade
🔒 Security
- Implemented bcrypt hashing for API key storage
- Added view-once key generation with truncated display
- New runtime validation middleware with prefix-based lookup
- Rate limiting on API key generation endpoints (10 ops/hour)
✨ New Features
- API key scopes support (full access by default)
- Last used timestamp tracking
- Enhanced developer documentation website
⚠️ Breaking Changes
- All existing API keys must be regenerated
- New key format:
pk_live_xxxxxxxx...xxxx - Authentication header changed to
x-api-key