feat(api): document public API authentication - #1038

Merged
brendan-kellam merged 7 commits into
sourcebot-dev:mainfrom
KonradStanski:konrad/public-api-auth
Mar 31, 2026
Merged

feat(api): document public API authentication#1038
brendan-kellam merged 7 commits into
sourcebot-dev:mainfrom
KonradStanski:konrad/public-api-auth

Conversation

@KonradStanski

@KonradStanskiKonradStanski commented Mar 24, 2026

Copy link
Copy Markdown
Contributor

Summary

This documents authentication for the public Sourcebot API in the generated OpenAPI spec and Mintlify docs.

Changes:

  • add public API auth metadata to the OpenAPI document
  • document supported auth schemes for external clients
  • clarify auth usage in the API reference intro docs
  • remove the stale hard-coded version example from the version schema

Details

The spec now documents these auth paths:

  • X-Sourcebot-Api-Key: sbk_...
  • Authorization: Bearer sbk_...
  • Authorization: Bearer sboa_... for EE OAuth access tokens

The API reference docs now lead users to the runtime spec endpoint and explain how auth works for public API consumers.

Testing

  • yarn openapi:generate

Notes

  • The public API may allow anonymous access depending on instance configuration, so the spec reflects that auth can be optional on some deployments.
  • SSE responses are still documented as text/event-stream; OpenAPI does not model typed SSE frames especially well.

Closes#101

Summary by CodeRabbit

  • Documentation
    • Added API authentication guide: how to create/use API keys or bearer tokens; OAuth noted for EE instances.
    • Clarified instance-dependent auth behavior, including possible anonymous access.
    • Published API security schemes and a global auth option to improve tooling and client generation.
    • Added stable operation IDs for key endpoints to help client tooling.
    • Removed an example value from the public version response schema.

@coderabbitai

coderabbitaiBot commented Mar 24, 2026

Copy link
Copy Markdown
Contributor

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review

Walkthrough

Updated the public OpenAPI spec, generator, and docs to declare API-key and bearer authentication (with a top-level security matrix permitting bearer, API key, or anonymous), added operationId values to seven public endpoints, and removed an example from the version response schema.

Changes

Cohort / File(s)Summary
OpenAPI spec
docs/api-reference/sourcebot-public.openapi.json
Added top-level security entries (allow bearerAuth, sourcebotApiKey, or anonymous); added components.securitySchemes for bearerAuth (HTTP bearer) and sourcebotApiKey (header X-Sourcebot-Api-Key); removed example on PublicVersionResponse.version; added operationIds for several operations.
OpenAPI generation code
packages/web/src/openapi/publicApiDocument.ts
Created typed components including securitySchemes, injected global security matrix into the generated document, extended info.description with instance-dependent auth details, and added operationId values to public paths (search, streamSearch, listRepositories, getVersion, getFileSource, getFileTree, listFiles).
Schema definitions
packages/web/src/openapi/publicApiSchemas.ts
Removed the example metadata from the version field in publicVersionResponseSchema (no shape/signature change).
API docs
docs/docs/api-reference/overview.mdx
Added authentication guidance: create API keys and send via X-Sourcebot-Api-Key or Authorization: Bearer; noted some instances may allow anonymous access and EE instances may accept OAuth bearer tokens with sboa_... prefix.
Changelog
CHANGELOG.md
Added entry under Unreleased → Added noting public API authentication documentation was added to generated OpenAPI and docs.

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~22 minutes

Suggested reviewers

  • brendan-kellam
  • msukkari
🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check nameStatusExplanationResolution
Docstring Coverage⚠️ WarningDocstring coverage is 0.00% which is insufficient. The required threshold is 80.00%.Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title accurately describes the main change: documenting public API authentication in the OpenAPI spec and docs.
Linked Issues check✅ PassedThe PR directly contributes to #101 by documenting the official REST API surface with authentication schemes and usage examples.
Out of Scope Changes check✅ PassedAll changes are in-scope: OpenAPI spec updates for auth documentation, API reference docs, schema metadata updates, and operationId additions.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@brendan-kellam
brendan-kellam merged commit f0e521f into sourcebot-dev:mainMar 31, 2026
4 of 5 checks passed
@github-actionsgithub-actionsBot mentioned this pull request Mar 31, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[FR] Sourcebot REST API support

2 participants

@KonradStanski@brendan-kellam
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

feat(api): document public API authentication - #1038

Merged
brendan-kellam merged 7 commits into
sourcebot-dev:mainfrom
KonradStanski:konrad/public-api-auth
Mar 31, 2026
Merged

feat(api): document public API authentication#1038
brendan-kellam merged 7 commits into
sourcebot-dev:mainfrom
KonradStanski:konrad/public-api-auth

Conversation

@KonradStanski

@KonradStanskiKonradStanski commented Mar 24, 2026

Copy link
Copy Markdown
Contributor

Summary

This documents authentication for the public Sourcebot API in the generated OpenAPI spec and Mintlify docs.

Changes:

  • add public API auth metadata to the OpenAPI document
  • document supported auth schemes for external clients
  • clarify auth usage in the API reference intro docs
  • remove the stale hard-coded version example from the version schema

Details

The spec now documents these auth paths:

  • X-Sourcebot-Api-Key: sbk_...
  • Authorization: Bearer sbk_...
  • Authorization: Bearer sboa_... for EE OAuth access tokens

The API reference docs now lead users to the runtime spec endpoint and explain how auth works for public API consumers.

Testing

  • yarn openapi:generate

Notes

  • The public API may allow anonymous access depending on instance configuration, so the spec reflects that auth can be optional on some deployments.
  • SSE responses are still documented as text/event-stream; OpenAPI does not model typed SSE frames especially well.

Closes#101

Summary by CodeRabbit

  • Documentation
    • Added API authentication guide: how to create/use API keys or bearer tokens; OAuth noted for EE instances.
    • Clarified instance-dependent auth behavior, including possible anonymous access.
    • Published API security schemes and a global auth option to improve tooling and client generation.
    • Added stable operation IDs for key endpoints to help client tooling.
    • Removed an example value from the public version response schema.

@coderabbitai

coderabbitaiBot commented Mar 24, 2026

Copy link
Copy Markdown
Contributor

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review

Walkthrough

Updated the public OpenAPI spec, generator, and docs to declare API-key and bearer authentication (with a top-level security matrix permitting bearer, API key, or anonymous), added operationId values to seven public endpoints, and removed an example from the version response schema.

Changes

Cohort / File(s)Summary
OpenAPI spec
docs/api-reference/sourcebot-public.openapi.json
Added top-level security entries (allow bearerAuth, sourcebotApiKey, or anonymous); added components.securitySchemes for bearerAuth (HTTP bearer) and sourcebotApiKey (header X-Sourcebot-Api-Key); removed example on PublicVersionResponse.version; added operationIds for several operations.
OpenAPI generation code
packages/web/src/openapi/publicApiDocument.ts
Created typed components including securitySchemes, injected global security matrix into the generated document, extended info.description with instance-dependent auth details, and added operationId values to public paths (search, streamSearch, listRepositories, getVersion, getFileSource, getFileTree, listFiles).
Schema definitions
packages/web/src/openapi/publicApiSchemas.ts
Removed the example metadata from the version field in publicVersionResponseSchema (no shape/signature change).
API docs
docs/docs/api-reference/overview.mdx
Added authentication guidance: create API keys and send via X-Sourcebot-Api-Key or Authorization: Bearer; noted some instances may allow anonymous access and EE instances may accept OAuth bearer tokens with sboa_... prefix.
Changelog
CHANGELOG.md
Added entry under Unreleased → Added noting public API authentication documentation was added to generated OpenAPI and docs.

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~22 minutes

Suggested reviewers

  • brendan-kellam
  • msukkari
🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check nameStatusExplanationResolution
Docstring Coverage⚠️ WarningDocstring coverage is 0.00% which is insufficient. The required threshold is 80.00%.Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title accurately describes the main change: documenting public API authentication in the OpenAPI spec and docs.
Linked Issues check✅ PassedThe PR directly contributes to #101 by documenting the official REST API surface with authentication schemes and usage examples.
Out of Scope Changes check✅ PassedAll changes are in-scope: OpenAPI spec updates for auth documentation, API reference docs, schema metadata updates, and operationId additions.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@brendan-kellam
brendan-kellam merged commit f0e521f into sourcebot-dev:mainMar 31, 2026
4 of 5 checks passed
@github-actionsgithub-actionsBot mentioned this pull request Mar 31, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[FR] Sourcebot REST API support

2 participants

@KonradStanski@brendan-kellam
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat(api): document public API authentication - #1038

Merged
brendan-kellam merged 7 commits into
sourcebot-dev:mainfrom
KonradStanski:konrad/public-api-auth
Mar 31, 2026
Merged

feat(api): document public API authentication#1038
brendan-kellam merged 7 commits into
sourcebot-dev:mainfrom
KonradStanski:konrad/public-api-auth

Conversation

@KonradStanski

@KonradStanskiKonradStanski commented Mar 24, 2026

Copy link
Copy Markdown
Contributor

Summary

This documents authentication for the public Sourcebot API in the generated OpenAPI spec and Mintlify docs.

Changes:

  • add public API auth metadata to the OpenAPI document
  • document supported auth schemes for external clients
  • clarify auth usage in the API reference intro docs
  • remove the stale hard-coded version example from the version schema

Details

The spec now documents these auth paths:

  • X-Sourcebot-Api-Key: sbk_...
  • Authorization: Bearer sbk_...
  • Authorization: Bearer sboa_... for EE OAuth access tokens

The API reference docs now lead users to the runtime spec endpoint and explain how auth works for public API consumers.

Testing

  • yarn openapi:generate

Notes

  • The public API may allow anonymous access depending on instance configuration, so the spec reflects that auth can be optional on some deployments.
  • SSE responses are still documented as text/event-stream; OpenAPI does not model typed SSE frames especially well.

Closes#101

Summary by CodeRabbit

  • Documentation
    • Added API authentication guide: how to create/use API keys or bearer tokens; OAuth noted for EE instances.
    • Clarified instance-dependent auth behavior, including possible anonymous access.
    • Published API security schemes and a global auth option to improve tooling and client generation.
    • Added stable operation IDs for key endpoints to help client tooling.
    • Removed an example value from the public version response schema.

@coderabbitai

coderabbitaiBot commented Mar 24, 2026

Copy link
Copy Markdown
Contributor

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review

Walkthrough

Updated the public OpenAPI spec, generator, and docs to declare API-key and bearer authentication (with a top-level security matrix permitting bearer, API key, or anonymous), added operationId values to seven public endpoints, and removed an example from the version response schema.

Changes

Cohort / File(s)Summary
OpenAPI spec
docs/api-reference/sourcebot-public.openapi.json
Added top-level security entries (allow bearerAuth, sourcebotApiKey, or anonymous); added components.securitySchemes for bearerAuth (HTTP bearer) and sourcebotApiKey (header X-Sourcebot-Api-Key); removed example on PublicVersionResponse.version; added operationIds for several operations.
OpenAPI generation code
packages/web/src/openapi/publicApiDocument.ts
Created typed components including securitySchemes, injected global security matrix into the generated document, extended info.description with instance-dependent auth details, and added operationId values to public paths (search, streamSearch, listRepositories, getVersion, getFileSource, getFileTree, listFiles).
Schema definitions
packages/web/src/openapi/publicApiSchemas.ts
Removed the example metadata from the version field in publicVersionResponseSchema (no shape/signature change).
API docs
docs/docs/api-reference/overview.mdx
Added authentication guidance: create API keys and send via X-Sourcebot-Api-Key or Authorization: Bearer; noted some instances may allow anonymous access and EE instances may accept OAuth bearer tokens with sboa_... prefix.
Changelog
CHANGELOG.md
Added entry under Unreleased → Added noting public API authentication documentation was added to generated OpenAPI and docs.

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~22 minutes

Suggested reviewers

  • brendan-kellam
  • msukkari
🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check nameStatusExplanationResolution
Docstring Coverage⚠️ WarningDocstring coverage is 0.00% which is insufficient. The required threshold is 80.00%.Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title accurately describes the main change: documenting public API authentication in the OpenAPI spec and docs.
Linked Issues check✅ PassedThe PR directly contributes to #101 by documenting the official REST API surface with authentication schemes and usage examples.
Out of Scope Changes check✅ PassedAll changes are in-scope: OpenAPI spec updates for auth documentation, API reference docs, schema metadata updates, and operationId additions.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@brendan-kellam
brendan-kellam merged commit f0e521f into sourcebot-dev:mainMar 31, 2026
4 of 5 checks passed
@github-actionsgithub-actionsBot mentioned this pull request Mar 31, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[FR] Sourcebot REST API support

2 participants

@KonradStanski@brendan-kellam
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat(api): document public API authentication - #1038

Merged
brendan-kellam merged 7 commits into
sourcebot-dev:mainfrom
KonradStanski:konrad/public-api-auth
Mar 31, 2026
Merged

feat(api): document public API authentication#1038
brendan-kellam merged 7 commits into
sourcebot-dev:mainfrom
KonradStanski:konrad/public-api-auth

Conversation

@KonradStanski

@KonradStanskiKonradStanski commented Mar 24, 2026

Copy link
Copy Markdown
Contributor

Summary

This documents authentication for the public Sourcebot API in the generated OpenAPI spec and Mintlify docs.

Changes:

  • add public API auth metadata to the OpenAPI document
  • document supported auth schemes for external clients
  • clarify auth usage in the API reference intro docs
  • remove the stale hard-coded version example from the version schema

Details

The spec now documents these auth paths:

  • X-Sourcebot-Api-Key: sbk_...
  • Authorization: Bearer sbk_...
  • Authorization: Bearer sboa_... for EE OAuth access tokens

The API reference docs now lead users to the runtime spec endpoint and explain how auth works for public API consumers.

Testing

  • yarn openapi:generate

Notes

  • The public API may allow anonymous access depending on instance configuration, so the spec reflects that auth can be optional on some deployments.
  • SSE responses are still documented as text/event-stream; OpenAPI does not model typed SSE frames especially well.

Closes#101

Summary by CodeRabbit

  • Documentation
    • Added API authentication guide: how to create/use API keys or bearer tokens; OAuth noted for EE instances.
    • Clarified instance-dependent auth behavior, including possible anonymous access.
    • Published API security schemes and a global auth option to improve tooling and client generation.
    • Added stable operation IDs for key endpoints to help client tooling.
    • Removed an example value from the public version response schema.

@coderabbitai

coderabbitaiBot commented Mar 24, 2026

Copy link
Copy Markdown
Contributor

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review

Walkthrough

Updated the public OpenAPI spec, generator, and docs to declare API-key and bearer authentication (with a top-level security matrix permitting bearer, API key, or anonymous), added operationId values to seven public endpoints, and removed an example from the version response schema.

Changes

Cohort / File(s)Summary
OpenAPI spec
docs/api-reference/sourcebot-public.openapi.json
Added top-level security entries (allow bearerAuth, sourcebotApiKey, or anonymous); added components.securitySchemes for bearerAuth (HTTP bearer) and sourcebotApiKey (header X-Sourcebot-Api-Key); removed example on PublicVersionResponse.version; added operationIds for several operations.
OpenAPI generation code
packages/web/src/openapi/publicApiDocument.ts
Created typed components including securitySchemes, injected global security matrix into the generated document, extended info.description with instance-dependent auth details, and added operationId values to public paths (search, streamSearch, listRepositories, getVersion, getFileSource, getFileTree, listFiles).
Schema definitions
packages/web/src/openapi/publicApiSchemas.ts
Removed the example metadata from the version field in publicVersionResponseSchema (no shape/signature change).
API docs
docs/docs/api-reference/overview.mdx
Added authentication guidance: create API keys and send via X-Sourcebot-Api-Key or Authorization: Bearer; noted some instances may allow anonymous access and EE instances may accept OAuth bearer tokens with sboa_... prefix.
Changelog
CHANGELOG.md
Added entry under Unreleased → Added noting public API authentication documentation was added to generated OpenAPI and docs.

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~22 minutes

Suggested reviewers

  • brendan-kellam
  • msukkari
🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check nameStatusExplanationResolution
Docstring Coverage⚠️ WarningDocstring coverage is 0.00% which is insufficient. The required threshold is 80.00%.Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title accurately describes the main change: documenting public API authentication in the OpenAPI spec and docs.
Linked Issues check✅ PassedThe PR directly contributes to #101 by documenting the official REST API surface with authentication schemes and usage examples.
Out of Scope Changes check✅ PassedAll changes are in-scope: OpenAPI spec updates for auth documentation, API reference docs, schema metadata updates, and operationId additions.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@brendan-kellam
brendan-kellam merged commit f0e521f into sourcebot-dev:mainMar 31, 2026
4 of 5 checks passed
@github-actionsgithub-actionsBot mentioned this pull request Mar 31, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[FR] Sourcebot REST API support

2 participants

@KonradStanski@brendan-kellam
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

feat(api): document public API authentication - #1038

Merged
brendan-kellam merged 7 commits into
sourcebot-dev:mainfrom
KonradStanski:konrad/public-api-auth
Mar 31, 2026
Merged

feat(api): document public API authentication#1038
brendan-kellam merged 7 commits into
sourcebot-dev:mainfrom
KonradStanski:konrad/public-api-auth

Conversation

@KonradStanski

@KonradStanskiKonradStanski commented Mar 24, 2026

Copy link
Copy Markdown
Contributor

Summary

This documents authentication for the public Sourcebot API in the generated OpenAPI spec and Mintlify docs.

Changes:

  • add public API auth metadata to the OpenAPI document
  • document supported auth schemes for external clients
  • clarify auth usage in the API reference intro docs
  • remove the stale hard-coded version example from the version schema

Details

The spec now documents these auth paths:

  • X-Sourcebot-Api-Key: sbk_...
  • Authorization: Bearer sbk_...
  • Authorization: Bearer sboa_... for EE OAuth access tokens

The API reference docs now lead users to the runtime spec endpoint and explain how auth works for public API consumers.

Testing

  • yarn openapi:generate

Notes

  • The public API may allow anonymous access depending on instance configuration, so the spec reflects that auth can be optional on some deployments.
  • SSE responses are still documented as text/event-stream; OpenAPI does not model typed SSE frames especially well.

Closes#101

Summary by CodeRabbit

  • Documentation
    • Added API authentication guide: how to create/use API keys or bearer tokens; OAuth noted for EE instances.
    • Clarified instance-dependent auth behavior, including possible anonymous access.
    • Published API security schemes and a global auth option to improve tooling and client generation.
    • Added stable operation IDs for key endpoints to help client tooling.
    • Removed an example value from the public version response schema.

@coderabbitai

coderabbitaiBot commented Mar 24, 2026

Copy link
Copy Markdown
Contributor

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review

Walkthrough

Updated the public OpenAPI spec, generator, and docs to declare API-key and bearer authentication (with a top-level security matrix permitting bearer, API key, or anonymous), added operationId values to seven public endpoints, and removed an example from the version response schema.

Changes

Cohort / File(s)Summary
OpenAPI spec
docs/api-reference/sourcebot-public.openapi.json
Added top-level security entries (allow bearerAuth, sourcebotApiKey, or anonymous); added components.securitySchemes for bearerAuth (HTTP bearer) and sourcebotApiKey (header X-Sourcebot-Api-Key); removed example on PublicVersionResponse.version; added operationIds for several operations.
OpenAPI generation code
packages/web/src/openapi/publicApiDocument.ts
Created typed components including securitySchemes, injected global security matrix into the generated document, extended info.description with instance-dependent auth details, and added operationId values to public paths (search, streamSearch, listRepositories, getVersion, getFileSource, getFileTree, listFiles).
Schema definitions
packages/web/src/openapi/publicApiSchemas.ts
Removed the example metadata from the version field in publicVersionResponseSchema (no shape/signature change).
API docs
docs/docs/api-reference/overview.mdx
Added authentication guidance: create API keys and send via X-Sourcebot-Api-Key or Authorization: Bearer; noted some instances may allow anonymous access and EE instances may accept OAuth bearer tokens with sboa_... prefix.
Changelog
CHANGELOG.md
Added entry under Unreleased → Added noting public API authentication documentation was added to generated OpenAPI and docs.

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~22 minutes

Suggested reviewers

  • brendan-kellam
  • msukkari
🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check nameStatusExplanationResolution
Docstring Coverage⚠️ WarningDocstring coverage is 0.00% which is insufficient. The required threshold is 80.00%.Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title accurately describes the main change: documenting public API authentication in the OpenAPI spec and docs.
Linked Issues check✅ PassedThe PR directly contributes to #101 by documenting the official REST API surface with authentication schemes and usage examples.
Out of Scope Changes check✅ PassedAll changes are in-scope: OpenAPI spec updates for auth documentation, API reference docs, schema metadata updates, and operationId additions.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@brendan-kellam
brendan-kellam merged commit f0e521f into sourcebot-dev:mainMar 31, 2026
4 of 5 checks passed
@github-actionsgithub-actionsBot mentioned this pull request Mar 31, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[FR] Sourcebot REST API support

2 participants

@KonradStanski@brendan-kellam
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat(api): document public API authentication - #1038

Merged
brendan-kellam merged 7 commits into
sourcebot-dev:mainfrom
KonradStanski:konrad/public-api-auth
Mar 31, 2026
Merged

feat(api): document public API authentication#1038
brendan-kellam merged 7 commits into
sourcebot-dev:mainfrom
KonradStanski:konrad/public-api-auth

Conversation

@KonradStanski

@KonradStanskiKonradStanski commented Mar 24, 2026

Copy link
Copy Markdown
Contributor

Summary

This documents authentication for the public Sourcebot API in the generated OpenAPI spec and Mintlify docs.

Changes:

  • add public API auth metadata to the OpenAPI document
  • document supported auth schemes for external clients
  • clarify auth usage in the API reference intro docs
  • remove the stale hard-coded version example from the version schema

Details

The spec now documents these auth paths:

  • X-Sourcebot-Api-Key: sbk_...
  • Authorization: Bearer sbk_...
  • Authorization: Bearer sboa_... for EE OAuth access tokens

The API reference docs now lead users to the runtime spec endpoint and explain how auth works for public API consumers.

Testing

  • yarn openapi:generate

Notes

  • The public API may allow anonymous access depending on instance configuration, so the spec reflects that auth can be optional on some deployments.
  • SSE responses are still documented as text/event-stream; OpenAPI does not model typed SSE frames especially well.

Closes#101

Summary by CodeRabbit

  • Documentation
    • Added API authentication guide: how to create/use API keys or bearer tokens; OAuth noted for EE instances.
    • Clarified instance-dependent auth behavior, including possible anonymous access.
    • Published API security schemes and a global auth option to improve tooling and client generation.
    • Added stable operation IDs for key endpoints to help client tooling.
    • Removed an example value from the public version response schema.

@coderabbitai

coderabbitaiBot commented Mar 24, 2026

Copy link
Copy Markdown
Contributor

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review

Walkthrough

Updated the public OpenAPI spec, generator, and docs to declare API-key and bearer authentication (with a top-level security matrix permitting bearer, API key, or anonymous), added operationId values to seven public endpoints, and removed an example from the version response schema.

Changes

Cohort / File(s)Summary
OpenAPI spec
docs/api-reference/sourcebot-public.openapi.json
Added top-level security entries (allow bearerAuth, sourcebotApiKey, or anonymous); added components.securitySchemes for bearerAuth (HTTP bearer) and sourcebotApiKey (header X-Sourcebot-Api-Key); removed example on PublicVersionResponse.version; added operationIds for several operations.
OpenAPI generation code
packages/web/src/openapi/publicApiDocument.ts
Created typed components including securitySchemes, injected global security matrix into the generated document, extended info.description with instance-dependent auth details, and added operationId values to public paths (search, streamSearch, listRepositories, getVersion, getFileSource, getFileTree, listFiles).
Schema definitions
packages/web/src/openapi/publicApiSchemas.ts
Removed the example metadata from the version field in publicVersionResponseSchema (no shape/signature change).
API docs
docs/docs/api-reference/overview.mdx
Added authentication guidance: create API keys and send via X-Sourcebot-Api-Key or Authorization: Bearer; noted some instances may allow anonymous access and EE instances may accept OAuth bearer tokens with sboa_... prefix.
Changelog
CHANGELOG.md
Added entry under Unreleased → Added noting public API authentication documentation was added to generated OpenAPI and docs.

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~22 minutes

Suggested reviewers

  • brendan-kellam
  • msukkari
🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check nameStatusExplanationResolution
Docstring Coverage⚠️ WarningDocstring coverage is 0.00% which is insufficient. The required threshold is 80.00%.Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title accurately describes the main change: documenting public API authentication in the OpenAPI spec and docs.
Linked Issues check✅ PassedThe PR directly contributes to #101 by documenting the official REST API surface with authentication schemes and usage examples.
Out of Scope Changes check✅ PassedAll changes are in-scope: OpenAPI spec updates for auth documentation, API reference docs, schema metadata updates, and operationId additions.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@brendan-kellam
brendan-kellam merged commit f0e521f into sourcebot-dev:mainMar 31, 2026
4 of 5 checks passed
@github-actionsgithub-actionsBot mentioned this pull request Mar 31, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[FR] Sourcebot REST API support

2 participants

@KonradStanski@brendan-kellam
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat(api): document public API authentication - #1038

Merged
brendan-kellam merged 7 commits into
sourcebot-dev:mainfrom
KonradStanski:konrad/public-api-auth
Mar 31, 2026
Merged

feat(api): document public API authentication#1038
brendan-kellam merged 7 commits into
sourcebot-dev:mainfrom
KonradStanski:konrad/public-api-auth

Conversation

@KonradStanski

@KonradStanskiKonradStanski commented Mar 24, 2026

Copy link
Copy Markdown
Contributor

Summary

This documents authentication for the public Sourcebot API in the generated OpenAPI spec and Mintlify docs.

Changes:

  • add public API auth metadata to the OpenAPI document
  • document supported auth schemes for external clients
  • clarify auth usage in the API reference intro docs
  • remove the stale hard-coded version example from the version schema

Details

The spec now documents these auth paths:

  • X-Sourcebot-Api-Key: sbk_...
  • Authorization: Bearer sbk_...
  • Authorization: Bearer sboa_... for EE OAuth access tokens

The API reference docs now lead users to the runtime spec endpoint and explain how auth works for public API consumers.

Testing

  • yarn openapi:generate

Notes

  • The public API may allow anonymous access depending on instance configuration, so the spec reflects that auth can be optional on some deployments.
  • SSE responses are still documented as text/event-stream; OpenAPI does not model typed SSE frames especially well.

Closes#101

Summary by CodeRabbit

  • Documentation
    • Added API authentication guide: how to create/use API keys or bearer tokens; OAuth noted for EE instances.
    • Clarified instance-dependent auth behavior, including possible anonymous access.
    • Published API security schemes and a global auth option to improve tooling and client generation.
    • Added stable operation IDs for key endpoints to help client tooling.
    • Removed an example value from the public version response schema.

@coderabbitai

coderabbitaiBot commented Mar 24, 2026

Copy link
Copy Markdown
Contributor

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review

Walkthrough

Updated the public OpenAPI spec, generator, and docs to declare API-key and bearer authentication (with a top-level security matrix permitting bearer, API key, or anonymous), added operationId values to seven public endpoints, and removed an example from the version response schema.

Changes

Cohort / File(s)Summary
OpenAPI spec
docs/api-reference/sourcebot-public.openapi.json
Added top-level security entries (allow bearerAuth, sourcebotApiKey, or anonymous); added components.securitySchemes for bearerAuth (HTTP bearer) and sourcebotApiKey (header X-Sourcebot-Api-Key); removed example on PublicVersionResponse.version; added operationIds for several operations.
OpenAPI generation code
packages/web/src/openapi/publicApiDocument.ts
Created typed components including securitySchemes, injected global security matrix into the generated document, extended info.description with instance-dependent auth details, and added operationId values to public paths (search, streamSearch, listRepositories, getVersion, getFileSource, getFileTree, listFiles).
Schema definitions
packages/web/src/openapi/publicApiSchemas.ts
Removed the example metadata from the version field in publicVersionResponseSchema (no shape/signature change).
API docs
docs/docs/api-reference/overview.mdx
Added authentication guidance: create API keys and send via X-Sourcebot-Api-Key or Authorization: Bearer; noted some instances may allow anonymous access and EE instances may accept OAuth bearer tokens with sboa_... prefix.
Changelog
CHANGELOG.md
Added entry under Unreleased → Added noting public API authentication documentation was added to generated OpenAPI and docs.

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~22 minutes

Suggested reviewers

  • brendan-kellam
  • msukkari
🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check nameStatusExplanationResolution
Docstring Coverage⚠️ WarningDocstring coverage is 0.00% which is insufficient. The required threshold is 80.00%.Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title accurately describes the main change: documenting public API authentication in the OpenAPI spec and docs.
Linked Issues check✅ PassedThe PR directly contributes to #101 by documenting the official REST API surface with authentication schemes and usage examples.
Out of Scope Changes check✅ PassedAll changes are in-scope: OpenAPI spec updates for auth documentation, API reference docs, schema metadata updates, and operationId additions.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@brendan-kellam
brendan-kellam merged commit f0e521f into sourcebot-dev:mainMar 31, 2026
4 of 5 checks passed
@github-actionsgithub-actionsBot mentioned this pull request Mar 31, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[FR] Sourcebot REST API support

2 participants

@KonradStanski@brendan-kellam
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

feat(api): document public API authentication - #1038

Merged
brendan-kellam merged 7 commits into
sourcebot-dev:mainfrom
KonradStanski:konrad/public-api-auth
Mar 31, 2026
Merged

feat(api): document public API authentication#1038
brendan-kellam merged 7 commits into
sourcebot-dev:mainfrom
KonradStanski:konrad/public-api-auth

Conversation

@KonradStanski

@KonradStanskiKonradStanski commented Mar 24, 2026

Copy link
Copy Markdown
Contributor

Summary

This documents authentication for the public Sourcebot API in the generated OpenAPI spec and Mintlify docs.

Changes:

  • add public API auth metadata to the OpenAPI document
  • document supported auth schemes for external clients
  • clarify auth usage in the API reference intro docs
  • remove the stale hard-coded version example from the version schema

Details

The spec now documents these auth paths:

  • X-Sourcebot-Api-Key: sbk_...
  • Authorization: Bearer sbk_...
  • Authorization: Bearer sboa_... for EE OAuth access tokens

The API reference docs now lead users to the runtime spec endpoint and explain how auth works for public API consumers.

Testing

  • yarn openapi:generate

Notes

  • The public API may allow anonymous access depending on instance configuration, so the spec reflects that auth can be optional on some deployments.
  • SSE responses are still documented as text/event-stream; OpenAPI does not model typed SSE frames especially well.

Closes#101

Summary by CodeRabbit

  • Documentation
    • Added API authentication guide: how to create/use API keys or bearer tokens; OAuth noted for EE instances.
    • Clarified instance-dependent auth behavior, including possible anonymous access.
    • Published API security schemes and a global auth option to improve tooling and client generation.
    • Added stable operation IDs for key endpoints to help client tooling.
    • Removed an example value from the public version response schema.

@coderabbitai

coderabbitaiBot commented Mar 24, 2026

Copy link
Copy Markdown
Contributor

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review

Walkthrough

Updated the public OpenAPI spec, generator, and docs to declare API-key and bearer authentication (with a top-level security matrix permitting bearer, API key, or anonymous), added operationId values to seven public endpoints, and removed an example from the version response schema.

Changes

Cohort / File(s)Summary
OpenAPI spec
docs/api-reference/sourcebot-public.openapi.json
Added top-level security entries (allow bearerAuth, sourcebotApiKey, or anonymous); added components.securitySchemes for bearerAuth (HTTP bearer) and sourcebotApiKey (header X-Sourcebot-Api-Key); removed example on PublicVersionResponse.version; added operationIds for several operations.
OpenAPI generation code
packages/web/src/openapi/publicApiDocument.ts
Created typed components including securitySchemes, injected global security matrix into the generated document, extended info.description with instance-dependent auth details, and added operationId values to public paths (search, streamSearch, listRepositories, getVersion, getFileSource, getFileTree, listFiles).
Schema definitions
packages/web/src/openapi/publicApiSchemas.ts
Removed the example metadata from the version field in publicVersionResponseSchema (no shape/signature change).
API docs
docs/docs/api-reference/overview.mdx
Added authentication guidance: create API keys and send via X-Sourcebot-Api-Key or Authorization: Bearer; noted some instances may allow anonymous access and EE instances may accept OAuth bearer tokens with sboa_... prefix.
Changelog
CHANGELOG.md
Added entry under Unreleased → Added noting public API authentication documentation was added to generated OpenAPI and docs.

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~22 minutes

Suggested reviewers

  • brendan-kellam
  • msukkari
🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check nameStatusExplanationResolution
Docstring Coverage⚠️ WarningDocstring coverage is 0.00% which is insufficient. The required threshold is 80.00%.Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title accurately describes the main change: documenting public API authentication in the OpenAPI spec and docs.
Linked Issues check✅ PassedThe PR directly contributes to #101 by documenting the official REST API surface with authentication schemes and usage examples.
Out of Scope Changes check✅ PassedAll changes are in-scope: OpenAPI spec updates for auth documentation, API reference docs, schema metadata updates, and operationId additions.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@brendan-kellam
brendan-kellam merged commit f0e521f into sourcebot-dev:mainMar 31, 2026
4 of 5 checks passed
@github-actionsgithub-actionsBot mentioned this pull request Mar 31, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[FR] Sourcebot REST API support

2 participants

@KonradStanski@brendan-kellam