Grouped Settings Layout
Sidebar-and-panel settings shell that becomes a horizontal scroller on mobile instead of collapsing into a select.
Masked keys, a create flow that reveals the secret exactly once, and a revoke that confirms before it fires.
components/settings-api-keys.tsxnpx hoverlab add settings-api-keys
Or over MCP, from your editor's agent — no account needed.
Free to read, copy and install, for personal and non-commercial projects. Shipping it in client work or a paid product needs Pro ($79 once). The source lands in your repo and stops being ours — no attribution, nothing to upgrade.
Start a page with this section — add more, order them, and leave with the page source.
Keys carry full account access. Treat them like passwords.
Production server
sk_live_••••••••••••4f2a
Created 12 Mar 2026
Last used 2 hours ago
CI pipeline
sk_live_••••••••••••9c1e
Created 3 Jun 2026
Last used Yesterday
Local development
sk_test_••••••••••••b7d0
Created 28 Jul 2026
Never used
Rendered live in your current theme — this is the same component whose source is below, not a screenshot of it.
'use client'
/**
* <SettingsApiKeys> — issue, reveal, copy and revoke API keys.
*
* The security model is the design here:
*
* - Stored keys are shown masked, with only the prefix and last four
* characters. A settings page that renders live secrets in full puts
* them into screen shares, screenshots and shoulder-surfing range.
* - A newly created key is shown in full exactly once, in a panel that
* says so. That is the only moment the plaintext should exist in the UI,
* and users need to be told they cannot come back for it.
* - Revoke is immediate and irreversible, so it asks first.
*
* `navigator.clipboard` is guarded — it is undefined on insecure origins,
* and an unguarded call throws where the page is served over plain HTTP.
*/
import * as React from 'react'
import { Copy, Check, Trash2, Plus, KeyRound, TriangleAlert } from 'lucide-react'
export interface ApiKey {
id: string
name: string
/** Visible prefix, e.g. `sk_live_`. */
prefix: string
last4: string
created: string
lastUsed?: string
}
export interface SettingsApiKeysProps {
keys?: ApiKey[]
onCreate?: (name: string) => Promise<string>
onRevoke?: (id: string) => void
className?: string
}
const DEFAULT_KEYS: ApiKey[] = [
{
id: '1',
name: 'Production server',
prefix: 'sk_live_',
last4: '4f2a',
created: '12 Mar 2026',
lastUsed: '2 hours ago',
},
{
id: '2',
name: 'CI pipeline',
prefix: 'sk_live_',
last4: '9c1e',
created: '3 Jun 2026',
lastUsed: 'Yesterday',
},
{
id: '3',
name: 'Local development',
prefix: 'sk_test_',
last4: 'b7d0',
created: '28 Jul 2026',
},
]
export function SettingsApiKeys({
keys: initialKeys = DEFAULT_KEYS,
onCreate,
onRevoke,
className = '',
}: SettingsApiKeysProps) {
const [keys, setKeys] = React.useState(initialKeys)
const [freshKey, setFreshKey] = React.useState<string | null>(null)
const [copied, setCopied] = React.useState(false)
const [confirmingId, setConfirmingId] = React.useState<string | null>(null)
async function copy(value: string) {
// Undefined on insecure origins — never assume it is there.
if (!navigator.clipboard) return
await navigator.clipboard.writeText(value)
setCopied(true)
window.setTimeout(() => setCopied(false), 1600)
}
async function create() {
const name = `Key ${keys.length + 1}`
const secret = (await onCreate?.(name)) ?? `sk_live_${Math.random().toString(36).slice(2, 10)}fake`
setFreshKey(secret)
setKeys((prev) => [
...prev,
{
id: String(prev.length + 1),
name,
prefix: secret.slice(0, 8),
last4: secret.slice(-4),
created: 'Just now',
},
])
}
function revoke(id: string) {
setKeys((prev) => prev.filter((k) => k.id !== id))
setConfirmingId(null)
onRevoke?.(id)
}
return (
<div className={`overflow-hidden rounded-2xl border border-border/60 bg-card/60 ${className}`}>
<div className="flex flex-wrap items-center justify-between gap-3 border-b border-border/60 px-6 py-4">
<div>
<h2 className="font-semibold tracking-tight">API keys</h2>
<p className="mt-0.5 text-sm text-muted-foreground">
Keys carry full account access. Treat them like passwords.
</p>
</div>
<button
type="button"
onClick={create}
className="inline-flex items-center gap-2 rounded-xl bg-primary px-3.5 py-2 text-sm font-semibold text-primary-foreground transition-colors hover:bg-primary/90"
>
<Plus aria-hidden className="h-4 w-4" />
Create key
</button>
</div>
{/* The one and only time the plaintext is shown. */}
{freshKey ? (
<div className="border-b border-border/60 bg-amber-500/5 px-6 py-4">
<p className="flex items-center gap-2 text-sm font-semibold text-amber-600 dark:text-amber-400">
<TriangleAlert aria-hidden className="h-4 w-4" />
Copy this key now — it will not be shown again
</p>
<div className="mt-3 flex items-center gap-2">
<code className="flex-1 overflow-x-auto rounded-xl border border-border/60 bg-background px-3 py-2 font-mono text-sm">
{freshKey}
</code>
<button
type="button"
onClick={() => copy(freshKey)}
className="inline-flex shrink-0 items-center gap-1.5 rounded-xl border border-border/60 bg-background px-3 py-2 text-sm font-medium transition-colors hover:bg-muted"
>
{copied ? (
<Check aria-hidden className="h-4 w-4 text-emerald-500" />
) : (
<Copy aria-hidden className="h-4 w-4" />
)}
{copied ? 'Copied' : 'Copy'}
</button>
</div>
<button
type="button"
onClick={() => setFreshKey(null)}
className="mt-3 text-xs font-medium text-muted-foreground hover:text-foreground"
>
I have saved it — dismiss
</button>
</div>
) : null}
<ul className="divide-y divide-border/40">
{keys.map((key) => (
<li key={key.id} className="flex flex-wrap items-center gap-3 px-6 py-3.5">
<span
aria-hidden
className="flex h-9 w-9 shrink-0 items-center justify-center rounded-lg bg-muted text-muted-foreground"
>
<KeyRound className="h-4 w-4" />
</span>
<div className="min-w-0 flex-1">
<p className="truncate text-sm font-medium">{key.name}</p>
<p className="truncate font-mono text-xs text-muted-foreground">
{key.prefix}
{'•'.repeat(12)}
{key.last4}
</p>
</div>
<div className="text-end text-xs text-muted-foreground">
<p>Created {key.created}</p>
<p>{key.lastUsed ? `Last used ${key.lastUsed}` : 'Never used'}</p>
</div>
{confirmingId === key.id ? (
<span className="flex items-center gap-2">
<button
type="button"
onClick={() => revoke(key.id)}
className="rounded-lg bg-destructive px-2.5 py-1.5 text-xs font-semibold text-destructive-foreground"
>
Revoke
</button>
<button
type="button"
onClick={() => setConfirmingId(null)}
className="rounded-lg px-2.5 py-1.5 text-xs font-medium text-muted-foreground hover:text-foreground"
>
Cancel
</button>
</span>
) : (
<button
type="button"
onClick={() => setConfirmingId(key.id)}
aria-label={`Revoke ${key.name}`}
className="rounded-lg p-1.5 text-muted-foreground transition-colors hover:bg-destructive/10 hover:text-destructive"
>
<Trash2 aria-hidden className="h-4 w-4" />
</button>
)}
</li>
))}
{keys.length === 0 ? (
<li className="px-6 py-10 text-center text-sm text-muted-foreground">
No API keys yet.
</li>
) : null}
</ul>
</div>
)
}
bg-card, text-muted-foreground) — it inherits your theme instead of overriding it.Drop it at components/settings-api-keys.tsx and import it where you need the section:
import { SettingsApiKeys } from '@/components/settings-api-keys'Read out of the component’s own type and signature, so this cannot drift from the source below. Every prop has a default — the component renders standalone before you pass it anything.
| Prop | Type | Default |
|---|---|---|
keys | ApiKey[] | — |
onCreate | (name: string) => Promise<string> | — |
onRevoke | (id: string) => void | — |
className | string | '' |
The same block rendered once to markup, wrapped as a file your framework compiles. Tailwind classes are framework-agnostic, so the design transfers intact — the behaviour does not.
This block is interactive. The markup below is its initial state with the event handlers stripped — you will need to re-wire the behaviour in your framework.
<!--
API Key Management — markup from the Hoverlab catalog.
This is the block rendered once to HTML and wrapped as a component
file. It is not a port of the React source: the Tailwind classes carry
the design, which is the part that took the work, and they are the same
in every framework.
This block is interactive in React and the handlers are NOT here.
Buttons, toggles and menus render in their initial state and do
nothing until you wire them up.
-->
<div class="overflow-hidden rounded-2xl border border-border/60 bg-card/60 ">
<div class="flex flex-wrap items-center justify-between gap-3 border-b border-border/60 px-6 py-4">
<div>
<h2 class="font-semibold tracking-tight">API keys</h2>
<p class="mt-0.5 text-sm text-muted-foreground">Keys carry full account access. Treat them like passwords.</p>
</div>
<button type="button" class="inline-flex items-center gap-2 rounded-xl bg-primary px-3.5 py-2 text-sm font-semibold text-primary-foreground transition-colors hover:bg-primary/90"><svg xmlns="http://www.w3.org/2000/svg" width="24" height="24" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-plus h-4 w-4" aria-hidden="true"><path d="M5 12h14"></path><path d="M12 5v14"></path></svg>Create key</button>
</div>
<ul class="divide-y divide-border/40">
<li class="flex flex-wrap items-center gap-3 px-6 py-3.5">
<span aria-hidden="true" class="flex h-9 w-9 shrink-0 items-center justify-center rounded-lg bg-muted text-muted-foreground">
<svg xmlns="http://www.w3.org/2000/svg" width="24" height="24" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-key-round h-4 w-4" aria-hidden="true">
<path d="M2.586 17.414A2 2 0 0 0 2 18.828V21a1 1 0 0 0 1 1h3a1 1 0 0 0 1-1v-1a1 1 0 0 1 1-1h1a1 1 0 0 0 1-1v-1a1 1 0 0 1 1-1h.172a2 2 0 0 0 1.414-.586l.814-.814a6.5 6.5 0 1 0-4-4z"></path>
<circle cx="16.5" cy="7.5" r=".5" fill="currentColor"></circle>
</svg>
</span>
<div class="min-w-0 flex-1">
<p class="truncate text-sm font-medium">Production server</p>
<p class="truncate font-mono text-xs text-muted-foreground">sk_live_••••••••••••4f2a</p>
</div>
<div class="text-end text-xs text-muted-foreground">
<p>Created 12 Mar 2026</p>
<p>Last used 2 hours ago</p>
</div>
<button type="button" aria-label="Revoke Production server" class="rounded-lg p-1.5 text-muted-foreground transition-colors hover:bg-destructive/10 hover:text-destructive">
<svg xmlns="http://www.w3.org/2000/svg" width="24" height="24" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-trash2 lucide-trash-2 h-4 w-4" aria-hidden="true">
<path d="M3 6h18"></path>
<path d="M19 6v14c0 1-1 2-2 2H7c-1 0-2-1-2-2V6"></path>
<path d="M8 6V4c0-1 1-2 2-2h4c1 0 2 1 2 2v2"></path>
<line x1="10" x2="10" y1="11" y2="17"></line>
<line x1="14" x2="14" y1="11" y2="17"></line>
</svg>
</button>
</li>
<li class="flex flex-wrap items-center gap-3 px-6 py-3.5">
<span aria-hidden="true" class="flex h-9 w-9 shrink-0 items-center justify-center rounded-lg bg-muted text-muted-foreground">
<svg xmlns="http://www.w3.org/2000/svg" width="24" height="24" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-key-round h-4 w-4" aria-hidden="true">
<path d="M2.586 17.414A2 2 0 0 0 2 18.828V21a1 1 0 0 0 1 1h3a1 1 0 0 0 1-1v-1a1 1 0 0 1 1-1h1a1 1 0 0 0 1-1v-1a1 1 0 0 1 1-1h.172a2 2 0 0 0 1.414-.586l.814-.814a6.5 6.5 0 1 0-4-4z"></path>
<circle cx="16.5" cy="7.5" r=".5" fill="currentColor"></circle>
</svg>
</span>
<div class="min-w-0 flex-1">
<p class="truncate text-sm font-medium">CI pipeline</p>
<p class="truncate font-mono text-xs text-muted-foreground">sk_live_••••••••••••9c1e</p>
</div>
<div class="text-end text-xs text-muted-foreground">
<p>Created 3 Jun 2026</p>
<p>Last used Yesterday</p>
</div>
<button type="button" aria-label="Revoke CI pipeline" class="rounded-lg p-1.5 text-muted-foreground transition-colors hover:bg-destructive/10 hover:text-destructive">
<svg xmlns="http://www.w3.org/2000/svg" width="24" height="24" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-trash2 lucide-trash-2 h-4 w-4" aria-hidden="true">
<path d="M3 6h18"></path>
<path d="M19 6v14c0 1-1 2-2 2H7c-1 0-2-1-2-2V6"></path>
<path d="M8 6V4c0-1 1-2 2-2h4c1 0 2 1 2 2v2"></path>
<line x1="10" x2="10" y1="11" y2="17"></line>
<line x1="14" x2="14" y1="11" y2="17"></line>
</svg>
</button>
</li>
<li class="flex flex-wrap items-center gap-3 px-6 py-3.5">
<span aria-hidden="true" class="flex h-9 w-9 shrink-0 items-center justify-center rounded-lg bg-muted text-muted-foreground">
<svg xmlns="http://www.w3.org/2000/svg" width="24" height="24" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-key-round h-4 w-4" aria-hidden="true">
<path d="M2.586 17.414A2 2 0 0 0 2 18.828V21a1 1 0 0 0 1 1h3a1 1 0 0 0 1-1v-1a1 1 0 0 1 1-1h1a1 1 0 0 0 1-1v-1a1 1 0 0 1 1-1h.172a2 2 0 0 0 1.414-.586l.814-.814a6.5 6.5 0 1 0-4-4z"></path>
<circle cx="16.5" cy="7.5" r=".5" fill="currentColor"></circle>
</svg>
</span>
<div class="min-w-0 flex-1">
<p class="truncate text-sm font-medium">Local development</p>
<p class="truncate font-mono text-xs text-muted-foreground">sk_test_••••••••••••b7d0</p>
</div>
<div class="text-end text-xs text-muted-foreground">
<p>Created 28 Jul 2026</p>
<p>Never used</p>
</div>
<button type="button" aria-label="Revoke Local development" class="rounded-lg p-1.5 text-muted-foreground transition-colors hover:bg-destructive/10 hover:text-destructive">
<svg xmlns="http://www.w3.org/2000/svg" width="24" height="24" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-trash2 lucide-trash-2 h-4 w-4" aria-hidden="true">
<path d="M3 6h18"></path>
<path d="M19 6v14c0 1-1 2-2 2H7c-1 0-2-1-2-2V6"></path>
<path d="M8 6V4c0-1 1-2 2-2h4c1 0 2 1 2 2v2"></path>
<line x1="10" x2="10" y1="11" y2="17"></line>
<line x1="14" x2="14" y1="11" y2="17"></line>
</svg>
</button>
</li>
</ul>
</div>
What each framework gets across the whole catalog — effects convert properly; this rung is markup.
The component, its props, the design tokens it expects and the command that installs it — as one prompt. Paste it into Claude, Cursor, v0 or ChatGPT and what they build around it will match the rest of the catalog instead of inventing its own system.
Want the whole screen instead of this one section? Open a page and copy it entire.
All of them free to read, copy and install — no account, no locked tiles, no watermarked preview. The whole catalog is open, and so are the API and the CLI.
Browse SettingsCopying the code is free. Putting it in client work or a paid product is what Pro is for — the licence, not the access.
Sidebar-and-panel settings shell that becomes a horizontal scroller on mobile instead of collapsing into a select.
Avatar, fields and a character counter, with a sticky save bar that only appears once something has genuinely changed.
Member list with role selects, pending invites shown inline, and the last owner locked so a workspace cannot be orphaned.
Destructive actions gated by typing the resource name exactly — the pattern GitHub and Stripe use, and for good reason.
The screen people go looking for after losing a laptop. Sign out everywhere states what it does not reach — API keys keep working — locations are written as estimates, and this device is labelled rather than revocable by misclick.
Every event against every delivery channel in one grid, with column toggles and required rows that show the policy instead of a disabled checkbox.