Skip to content
Product block

API Key Management

Masked keys, a create flow that reveals the secret exactly once, and a revoke that confirms before it fires.

226 lineslucide-reactAdded 8 Aug 2026Updated 2 Sept 2026
  • api keys
  • secrets
  • developer
  • security
  • tokens

What's included

  • components/settings-api-keys.tsx
  • Needs lucide-react

Works with

  • React
  • Next.js
  • Tailwind CSS
  • TypeScript

npx hoverlab add settings-api-keys

Or over MCP, from your editor's agent — no account needed.

License

Free to read, copy and install, for personal and non-commercial projects. Shipping it in client work or a paid product needs Pro ($79 once). The source lands in your repo and stops being ours — no attribution, nothing to upgrade.

Was this useful?

Start a page with this section — add more, order them, and leave with the page source.

Preview

API keys

Keys carry full account access. Treat them like passwords.

  • Production server

    sk_live_••••••••••••4f2a

    Created 12 Mar 2026

    Last used 2 hours ago

  • CI pipeline

    sk_live_••••••••••••9c1e

    Created 3 Jun 2026

    Last used Yesterday

  • Local development

    sk_test_••••••••••••b7d0

    Created 28 Jul 2026

    Never used

Rendered live in your current theme — this is the same component whose source is below, not a screenshot of it.

Source

components/settings-api-keys.tsx
'use client'

/**
 * <SettingsApiKeys> — issue, reveal, copy and revoke API keys.
 *
 * The security model is the design here:
 *
 *  - Stored keys are shown masked, with only the prefix and last four
 *    characters. A settings page that renders live secrets in full puts
 *    them into screen shares, screenshots and shoulder-surfing range.
 *  - A newly created key is shown in full exactly once, in a panel that
 *    says so. That is the only moment the plaintext should exist in the UI,
 *    and users need to be told they cannot come back for it.
 *  - Revoke is immediate and irreversible, so it asks first.
 *
 * `navigator.clipboard` is guarded — it is undefined on insecure origins,
 * and an unguarded call throws where the page is served over plain HTTP.
 */

import * as React from 'react'
import { Copy, Check, Trash2, Plus, KeyRound, TriangleAlert } from 'lucide-react'

export interface ApiKey {
  id: string
  name: string
  /** Visible prefix, e.g. `sk_live_`. */
  prefix: string
  last4: string
  created: string
  lastUsed?: string
}

export interface SettingsApiKeysProps {
  keys?: ApiKey[]
  onCreate?: (name: string) => Promise<string>
  onRevoke?: (id: string) => void
  className?: string
}

const DEFAULT_KEYS: ApiKey[] = [
  {
    id: '1',
    name: 'Production server',
    prefix: 'sk_live_',
    last4: '4f2a',
    created: '12 Mar 2026',
    lastUsed: '2 hours ago',
  },
  {
    id: '2',
    name: 'CI pipeline',
    prefix: 'sk_live_',
    last4: '9c1e',
    created: '3 Jun 2026',
    lastUsed: 'Yesterday',
  },
  {
    id: '3',
    name: 'Local development',
    prefix: 'sk_test_',
    last4: 'b7d0',
    created: '28 Jul 2026',
  },
]

export function SettingsApiKeys({
  keys: initialKeys = DEFAULT_KEYS,
  onCreate,
  onRevoke,
  className = '',
}: SettingsApiKeysProps) {
  const [keys, setKeys] = React.useState(initialKeys)
  const [freshKey, setFreshKey] = React.useState<string | null>(null)
  const [copied, setCopied] = React.useState(false)
  const [confirmingId, setConfirmingId] = React.useState<string | null>(null)

  async function copy(value: string) {
    // Undefined on insecure origins — never assume it is there.
    if (!navigator.clipboard) return
    await navigator.clipboard.writeText(value)
    setCopied(true)
    window.setTimeout(() => setCopied(false), 1600)
  }

  async function create() {
    const name = `Key ${keys.length + 1}`
    const secret = (await onCreate?.(name)) ?? `sk_live_${Math.random().toString(36).slice(2, 10)}fake`
    setFreshKey(secret)
    setKeys((prev) => [
      ...prev,
      {
        id: String(prev.length + 1),
        name,
        prefix: secret.slice(0, 8),
        last4: secret.slice(-4),
        created: 'Just now',
      },
    ])
  }

  function revoke(id: string) {
    setKeys((prev) => prev.filter((k) => k.id !== id))
    setConfirmingId(null)
    onRevoke?.(id)
  }

  return (
    <div className={`overflow-hidden rounded-2xl border border-border/60 bg-card/60 ${className}`}>
      <div className="flex flex-wrap items-center justify-between gap-3 border-b border-border/60 px-6 py-4">
        <div>
          <h2 className="font-semibold tracking-tight">API keys</h2>
          <p className="mt-0.5 text-sm text-muted-foreground">
            Keys carry full account access. Treat them like passwords.
          </p>
        </div>

        <button
          type="button"
          onClick={create}
          className="inline-flex items-center gap-2 rounded-xl bg-primary px-3.5 py-2 text-sm font-semibold text-primary-foreground transition-colors hover:bg-primary/90"
        >
          <Plus aria-hidden className="h-4 w-4" />
          Create key
        </button>
      </div>

      {/* The one and only time the plaintext is shown. */}
      {freshKey ? (
        <div className="border-b border-border/60 bg-amber-500/5 px-6 py-4">
          <p className="flex items-center gap-2 text-sm font-semibold text-amber-600 dark:text-amber-400">
            <TriangleAlert aria-hidden className="h-4 w-4" />
            Copy this key now — it will not be shown again
          </p>

          <div className="mt-3 flex items-center gap-2">
            <code className="flex-1 overflow-x-auto rounded-xl border border-border/60 bg-background px-3 py-2 font-mono text-sm">
              {freshKey}
            </code>
            <button
              type="button"
              onClick={() => copy(freshKey)}
              className="inline-flex shrink-0 items-center gap-1.5 rounded-xl border border-border/60 bg-background px-3 py-2 text-sm font-medium transition-colors hover:bg-muted"
            >
              {copied ? (
                <Check aria-hidden className="h-4 w-4 text-emerald-500" />
              ) : (
                <Copy aria-hidden className="h-4 w-4" />
              )}
              {copied ? 'Copied' : 'Copy'}
            </button>
          </div>

          <button
            type="button"
            onClick={() => setFreshKey(null)}
            className="mt-3 text-xs font-medium text-muted-foreground hover:text-foreground"
          >
            I have saved it — dismiss
          </button>
        </div>
      ) : null}

      <ul className="divide-y divide-border/40">
        {keys.map((key) => (
          <li key={key.id} className="flex flex-wrap items-center gap-3 px-6 py-3.5">
            <span
              aria-hidden
              className="flex h-9 w-9 shrink-0 items-center justify-center rounded-lg bg-muted text-muted-foreground"
            >
              <KeyRound className="h-4 w-4" />
            </span>

            <div className="min-w-0 flex-1">
              <p className="truncate text-sm font-medium">{key.name}</p>
              <p className="truncate font-mono text-xs text-muted-foreground">
                {key.prefix}
                {'•'.repeat(12)}
                {key.last4}
              </p>
            </div>

            <div className="text-end text-xs text-muted-foreground">
              <p>Created {key.created}</p>
              <p>{key.lastUsed ? `Last used ${key.lastUsed}` : 'Never used'}</p>
            </div>

            {confirmingId === key.id ? (
              <span className="flex items-center gap-2">
                <button
                  type="button"
                  onClick={() => revoke(key.id)}
                  className="rounded-lg bg-destructive px-2.5 py-1.5 text-xs font-semibold text-destructive-foreground"
                >
                  Revoke
                </button>
                <button
                  type="button"
                  onClick={() => setConfirmingId(null)}
                  className="rounded-lg px-2.5 py-1.5 text-xs font-medium text-muted-foreground hover:text-foreground"
                >
                  Cancel
                </button>
              </span>
            ) : (
              <button
                type="button"
                onClick={() => setConfirmingId(key.id)}
                aria-label={`Revoke ${key.name}`}
                className="rounded-lg p-1.5 text-muted-foreground transition-colors hover:bg-destructive/10 hover:text-destructive"
              >
                <Trash2 aria-hidden className="h-4 w-4" />
              </button>
            )}
          </li>
        ))}

        {keys.length === 0 ? (
          <li className="px-6 py-10 text-center text-sm text-muted-foreground">
            No API keys yet.
          </li>
        ) : null}
      </ul>
    </div>
  )
}

Before you paste

  • Styling is Tailwind utility classes on semantic tokens (bg-card, text-muted-foreground) — it inherits your theme instead of overriding it.
  • Install: npm i lucide-react
  • Every prop has a default, so it renders standalone before you wire it up.

Where it goes

Drop it at components/settings-api-keys.tsx and import it where you need the section:

import { SettingsApiKeys } from '@/components/settings-api-keys'

Props

Read out of the component’s own type and signature, so this cannot drift from the source below. Every prop has a default — the component renders standalone before you pass it anything.

PropTypeDefault
keysApiKey[]—
onCreate(name: string) => Promise<string>—
onRevoke(id: string) => void—
classNamestring''

Not using React?

The same block rendered once to markup, wrapped as a file your framework compiles. Tailwind classes are framework-agnostic, so the design transfers intact — the behaviour does not.

This block is interactive. The markup below is its initial state with the event handlers stripped — you will need to re-wire the behaviour in your framework.

settings-api-keys.html
<!--
  API Key Management — markup from the Hoverlab catalog.

  This is the block rendered once to HTML and wrapped as a component
  file. It is not a port of the React source: the Tailwind classes carry
  the design, which is the part that took the work, and they are the same
  in every framework.

  This block is interactive in React and the handlers are NOT here.
  Buttons, toggles and menus render in their initial state and do
  nothing until you wire them up.
-->
<div class="overflow-hidden rounded-2xl border border-border/60 bg-card/60 ">
  <div class="flex flex-wrap items-center justify-between gap-3 border-b border-border/60 px-6 py-4">
    <div>
      <h2 class="font-semibold tracking-tight">API keys</h2>
      <p class="mt-0.5 text-sm text-muted-foreground">Keys carry full account access. Treat them like passwords.</p>
    </div>
    <button type="button" class="inline-flex items-center gap-2 rounded-xl bg-primary px-3.5 py-2 text-sm font-semibold text-primary-foreground transition-colors hover:bg-primary/90"><svg xmlns="http://www.w3.org/2000/svg" width="24" height="24" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-plus h-4 w-4" aria-hidden="true"><path d="M5 12h14"></path><path d="M12 5v14"></path></svg>Create key</button>
  </div>
  <ul class="divide-y divide-border/40">
    <li class="flex flex-wrap items-center gap-3 px-6 py-3.5">
      <span aria-hidden="true" class="flex h-9 w-9 shrink-0 items-center justify-center rounded-lg bg-muted text-muted-foreground">
        <svg xmlns="http://www.w3.org/2000/svg" width="24" height="24" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-key-round h-4 w-4" aria-hidden="true">
          <path d="M2.586 17.414A2 2 0 0 0 2 18.828V21a1 1 0 0 0 1 1h3a1 1 0 0 0 1-1v-1a1 1 0 0 1 1-1h1a1 1 0 0 0 1-1v-1a1 1 0 0 1 1-1h.172a2 2 0 0 0 1.414-.586l.814-.814a6.5 6.5 0 1 0-4-4z"></path>
          <circle cx="16.5" cy="7.5" r=".5" fill="currentColor"></circle>
        </svg>
      </span>
      <div class="min-w-0 flex-1">
        <p class="truncate text-sm font-medium">Production server</p>
        <p class="truncate font-mono text-xs text-muted-foreground">sk_live_••••••••••••4f2a</p>
      </div>
      <div class="text-end text-xs text-muted-foreground">
        <p>Created 12 Mar 2026</p>
        <p>Last used 2 hours ago</p>
      </div>
      <button type="button" aria-label="Revoke Production server" class="rounded-lg p-1.5 text-muted-foreground transition-colors hover:bg-destructive/10 hover:text-destructive">
        <svg xmlns="http://www.w3.org/2000/svg" width="24" height="24" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-trash2 lucide-trash-2 h-4 w-4" aria-hidden="true">
          <path d="M3 6h18"></path>
          <path d="M19 6v14c0 1-1 2-2 2H7c-1 0-2-1-2-2V6"></path>
          <path d="M8 6V4c0-1 1-2 2-2h4c1 0 2 1 2 2v2"></path>
          <line x1="10" x2="10" y1="11" y2="17"></line>
          <line x1="14" x2="14" y1="11" y2="17"></line>
        </svg>
      </button>
    </li>
    <li class="flex flex-wrap items-center gap-3 px-6 py-3.5">
      <span aria-hidden="true" class="flex h-9 w-9 shrink-0 items-center justify-center rounded-lg bg-muted text-muted-foreground">
        <svg xmlns="http://www.w3.org/2000/svg" width="24" height="24" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-key-round h-4 w-4" aria-hidden="true">
          <path d="M2.586 17.414A2 2 0 0 0 2 18.828V21a1 1 0 0 0 1 1h3a1 1 0 0 0 1-1v-1a1 1 0 0 1 1-1h1a1 1 0 0 0 1-1v-1a1 1 0 0 1 1-1h.172a2 2 0 0 0 1.414-.586l.814-.814a6.5 6.5 0 1 0-4-4z"></path>
          <circle cx="16.5" cy="7.5" r=".5" fill="currentColor"></circle>
        </svg>
      </span>
      <div class="min-w-0 flex-1">
        <p class="truncate text-sm font-medium">CI pipeline</p>
        <p class="truncate font-mono text-xs text-muted-foreground">sk_live_••••••••••••9c1e</p>
      </div>
      <div class="text-end text-xs text-muted-foreground">
        <p>Created 3 Jun 2026</p>
        <p>Last used Yesterday</p>
      </div>
      <button type="button" aria-label="Revoke CI pipeline" class="rounded-lg p-1.5 text-muted-foreground transition-colors hover:bg-destructive/10 hover:text-destructive">
        <svg xmlns="http://www.w3.org/2000/svg" width="24" height="24" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-trash2 lucide-trash-2 h-4 w-4" aria-hidden="true">
          <path d="M3 6h18"></path>
          <path d="M19 6v14c0 1-1 2-2 2H7c-1 0-2-1-2-2V6"></path>
          <path d="M8 6V4c0-1 1-2 2-2h4c1 0 2 1 2 2v2"></path>
          <line x1="10" x2="10" y1="11" y2="17"></line>
          <line x1="14" x2="14" y1="11" y2="17"></line>
        </svg>
      </button>
    </li>
    <li class="flex flex-wrap items-center gap-3 px-6 py-3.5">
      <span aria-hidden="true" class="flex h-9 w-9 shrink-0 items-center justify-center rounded-lg bg-muted text-muted-foreground">
        <svg xmlns="http://www.w3.org/2000/svg" width="24" height="24" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-key-round h-4 w-4" aria-hidden="true">
          <path d="M2.586 17.414A2 2 0 0 0 2 18.828V21a1 1 0 0 0 1 1h3a1 1 0 0 0 1-1v-1a1 1 0 0 1 1-1h1a1 1 0 0 0 1-1v-1a1 1 0 0 1 1-1h.172a2 2 0 0 0 1.414-.586l.814-.814a6.5 6.5 0 1 0-4-4z"></path>
          <circle cx="16.5" cy="7.5" r=".5" fill="currentColor"></circle>
        </svg>
      </span>
      <div class="min-w-0 flex-1">
        <p class="truncate text-sm font-medium">Local development</p>
        <p class="truncate font-mono text-xs text-muted-foreground">sk_test_••••••••••••b7d0</p>
      </div>
      <div class="text-end text-xs text-muted-foreground">
        <p>Created 28 Jul 2026</p>
        <p>Never used</p>
      </div>
      <button type="button" aria-label="Revoke Local development" class="rounded-lg p-1.5 text-muted-foreground transition-colors hover:bg-destructive/10 hover:text-destructive">
        <svg xmlns="http://www.w3.org/2000/svg" width="24" height="24" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-trash2 lucide-trash-2 h-4 w-4" aria-hidden="true">
          <path d="M3 6h18"></path>
          <path d="M19 6v14c0 1-1 2-2 2H7c-1 0-2-1-2-2V6"></path>
          <path d="M8 6V4c0-1 1-2 2-2h4c1 0 2 1 2 2v2"></path>
          <line x1="10" x2="10" y1="11" y2="17"></line>
          <line x1="14" x2="14" y1="11" y2="17"></line>
        </svg>
      </button>
    </li>
  </ul>
</div>
  • This is rendered HTML, not a translation of the React source. The Tailwind classes carry the design and work in any framework.
  • It is one frame: the component in its initial state, with no props applied beyond the defaults.
  • This block is interactive in React — toggles, menus or form state. None of that survives here; the markup is the closed/default state and the handlers are gone. Re-wire them in your own framework.
  • Requires Tailwind, and the design tokens the classes reference (bg-card, text-muted-foreground, and so on). The template ZIPs ship a globals.css that defines them.

What each framework gets across the whole catalog — effects convert properly; this rung is markup.

For AI

The component, its props, the design tokens it expects and the command that installs it — as one prompt. Paste it into Claude, Cursor, v0 or ChatGPT and what they build around it will match the rest of the catalog instead of inventing its own system.

See the prompt

Used in these pages

Want the whole screen instead of this one section? Open a page and copy it entire.

7 more blocks in Settings

All of them free to read, copy and install — no account, no locked tiles, no watermarked preview. The whole catalog is open, and so are the API and the CLI.

Browse Settings

Shipping one commercially

Copying the code is free. Putting it in client work or a paid product is what Pro is for — the licence, not the access.

  • A commercial licence for everything in the catalog
  • Unlimited bundle exports, in Vue, Svelte and Tailwind
  • One payment — no subscription, nothing to renew
Pro — $79 once

More Settings blocks

View category
Open the full page for this block

Grouped Settings Layout

Sidebar-and-panel settings shell that becomes a horizontal scroller on mobile instead of collapsing into a select.

Settings119 lines1 dep
Open the full page for this block

Profile Form With Save Bar

Avatar, fields and a character counter, with a sticky save bar that only appears once something has genuinely changed.

Settings220 lines1 dep
Open the full page for this block

Team Members & Invites

Member list with role selects, pending invites shown inline, and the last owner locked so a workspace cannot be orphaned.

Settings200 lines1 dep
Open the full page for this block

Danger Zone

Destructive actions gated by typing the resource name exactly — the pattern GitHub and Stripe use, and for good reason.

Settings184 lines1 dep
Open the full page for this block

Active Sessions & Devices

The screen people go looking for after losing a laptop. Sign out everywhere states what it does not reach — API keys keep working — locations are written as estimates, and this device is labelled rather than revocable by misclick.

Settings302 lines1 dep
Open the full page for this block

Notification Channel Matrix

Every event against every delivery channel in one grid, with column toggles and required rows that show the policy instead of a disabled checkbox.

Settings221 lines1 dep
Open the full page for this block

Audit Log

A compliance-grade trail with named actors, before and after values, IP addresses, and a stated retention window — plus a count of what the active filter is hiding.

Settings270 lines1 dep