Skip to main content
Drupal is a registered trademark of Dries Buytaert
Release: OpenID Connect / OAuth client 3.0.0-alpha9 New alpha version released for module openid_connect (3.0.0-alpha9). Usage Milestone: Google Analytics Module google_analytics crossed 1,000 active installs. Release: Timelinr 1.0.1 Minor update available for module timelinr (1.0.1). Release: GraphQL Compose Codegen 1.1.2 Minor update available for module graphql_compose_codegen (1.1.2). Release: Mapy.com 1.1.3 Minor update available for module mapycom (1.1.3). Release: Ckeditor5 entity browser 3.0.3 Minor update available for module ckeditor5_entity_browser (3.0.3). Release: Ckeditor5 entity browser 3.0.1 Minor update available for module ckeditor5_entity_browser (3.0.1). Release: Ckeditor5 entity browser 3.0.2 Minor update available for module ckeditor5_entity_browser (3.0.2). Release: Teamleader Integration 4.0.2 Minor update available for module teamleader (4.0.2). Module Revived: Entityqueue Buttons 1.1.2 Module entityqueue_buttons updated after 8 months of inactivity (1.1.2).

Key auth

5,110 sites Security covered Drupal 9–11 KEY ecosystem
View on drupal.org

This module provides simple, user-specific key-based authentication, ideal for APIs that don't require usernames or passwords. It allows keys to be detected via headers or query parameters and securely stored within user entities.

Provides simple key-based authentication on a per-user basis similar to basic_auth but without requiring usernames or passwords. This is ideal for sites that expose consumer-facing APIs via rest, jsonapi, or something similar.

Keys are stored in the user entity so there are no additional tables or entities.

Available configuration

  • Optionally automatically generate a key for users when accounts are created
  • Key length (defaults to 32 characters)
  • Control the parameter name that contains the key (defaults to api-key)
  • Detect the key via a header, query, or both

Setup and usage

  • Remove View published content permission from role, you are using this module for.
  • Install the module.
  • Grant users the Use key authentication permission.
  • Configure the basic settings at admin/config/services/key-auth.
  • Users with adequate permissions can view/update/delete their key at user/{user}/key-auth.
  • To use with core rest, enable the key_auth authentication provider for your endpoints of choice.
  • To use with jsonapi, no additional configuration is required.
  • If Header detection is enabled, pass in a header with the name chosen in the configuration, and a value of your user's key (ie, api-key: b9a9a0ee50ceab7191282b51c).
  • If Query detection is enabled, include a query parameter in the endpoint URL with the name chosen in the configuration, and a value of your user's key (ie, ?api-key=b9a9a0ee50ceab7191282b51c).

Important Access Note

To deny the anonymous user role access to a REST endpoint, one need to change permissions and deny the anonymous user the permission "View published content". Then one can enable this module and use Key authentication (as an alternative to Basic authentication) to get access to the endpoint.

AI Usage

AI may be used or referenced during the development process for the creation of bug fixes and for code generation. Development is done primarily with human skill, and AI is mostly used for boilerplate or consultation.

Maintainers

Actively maintained by solideogloria.

Depends on

Dependencies of the latest stable release

  • user Drupal core

Required by

Tracked projects that depend on this one

No tracked projects depend on this one yet.

Activity

Tracked releases
5
Tracked since
Mar 2025
Latest release
2 weeks ago
Releases (12 mo)
4 ▲ from 1
Maintenance
Active

Release Timeline

Releases

Version Type Core Release date
2.2.3 Stable 9–11 Aug 11, 2026
3.x-dev Dev 9–11 Aug 11, 2026
2.2.2 Stable 9–11 Aug 10, 2026
2.2.1 Stable 9–11 Aug 10, 2026
2.x-dev Dev 9–11 Mar 7, 2025