# Auth Domain This domain handles API key management and authentication. ## Structure ``` auth/ ├── router.py # Auth routes ├── controller.py # Auth logic └── schemas.py # Auth models ``` ## Authentication Flow 1. Client sends `X-API-Key` header 2. Middleware validates key (via `shared/auth.py`) 3. User context set in `shared/context.py` 4. Routes use `Depends(require_auth)` for protected endpoints ## Integration with Tatlock API keys are validated against the tatlock-ui/core-api user management system. ```python # In shared/auth.py async def validate_api_key(api_key: str) -> Optional[User]: async with httpx.AsyncClient() as client: response = await client.get( f"{settings.tatlock_api_url}/auth/validate", headers={"X-API-Key": api_key} ) if response.status_code == 200: return User(**response.json()) return None ``` ## TODO - [ ] Implement tatlock API key validation - [ ] Add API key generation endpoint - [ ] Add rate limiting per API key - [ ] Add usage tracking