API Key Management
Let users create and control API credentials without ever showing a secret twice.
What it adds
A self-serve screen for issuing, scoping, rotating, and revoking API keys, with secrets stored only as hashes.
What your agent is told to do
5
What your agent is told to do
5-
1
Generate keys with a cryptographically secure random source and a recognisable prefix so leaked keys can be identified in logs and scanners.
-
2
Show the full secret exactly once, at creation, with a copy control and a clear warning that it will not be shown again. Store only a hash.
-
3
Give each key a name, a scope set, an optional expiry, and a last-used timestamp so users can tell which key is safe to delete.
-
4
Support rotation as a first-class action: issue a replacement while the old key stays valid for a short overlap, then revoke it.
-
5
Do NOT log, email, or include the raw secret in any audit record, error report, or support view. The hash is the only copy the system keeps.
Edge cases it handles
6
Edge cases it handles
6- Revocation must invalidate cached authentication immediately, not at the next cache expiry.
- A key with an expiry must stop working at the expiry, and the owner should be warned before it lapses.
- Verify keys with a constant-time comparison against the hash.
- A key must never carry more permission than the user who created it has now — re-check on use, not just at issue.
- Per-key rate limits are useful, but the account-level limit still applies; one key must not be able to spend the whole account budget.
- Deleting a user or removing them from a workspace must revoke the keys they issued.
Definition of done
8
Definition of done
8- The raw secret is displayed once and never retrievable afterwards.
- Only a hash of the key is stored, and comparison is constant-time.
- Keys have names, scopes, optional expiry, and last-used timestamps.
- Rotation issues a new key with a defined overlap window.
- Revocation takes effect immediately, including behind caches.
- Key creation, rotation, and revocation are audited without the secret.
- The feature matches the existing design system.
- No existing functionality is broken.
Related features
AI Cost Budgets
AI Cost Budgets
Cap what AI features are allowed to spend before the bill arrives.
What it does
Monetary spending limits on AI work, scoped by workspace, feature, and time period, enforced before a run starts.
How it works
- 1 Find every place the app calls a model and route all of them through one accounting point that records estimated and actual spend against a scope. A budget that only covers the chat feature is not a budget.
- 2 Estimate the cost of a run from the size of its input before dispatching it, and refuse anything that would exceed the remaining budget on its own.
- 3 Reserve the estimate against the budget when the run starts, then reconcile to the real usage figures when it finishes, releasing whatever was over-reserved.
Copy the prompt
No account needed
Add this feature to my app:
https://addthisfeature.com/x/ai-cost-budgets
Multi-Model Routing
Multi-Model Routing
Send each AI request to the right model using rules you can read and test.
What it does
A deterministic routing layer that picks a model per request from task type, context size, latency budget, and data sensitivity.
How it works
- 1 Express routing as explicit, ordered rules over inputs the app can measure: task type, estimated context size, latency budget, and the sensitivity classification of the data involved. A rule set that can be read line by line can be reviewed and tested.
- 2 Make routing deterministic. The same inputs must always produce the same route, so a bad output can be reproduced and a rule change can be evaluated. Randomised or load-based selection turns every incident into guesswork.
- 3 Classify data before routing and refuse to route restricted content to any destination not approved for it. This check is a hard block, not a preference, and it must run before the request is assembled.
Copy the prompt
No account needed
Add this feature to my app:
https://addthisfeature.com/x/multi-model-routing
SEO Setup
SEO Setup
Make your app findable — titles, meta, Open Graph, sitemap, robots.
What it does
The baseline SEO and social-preview setup every public app should have, and most skip.
How it works
- 1 Give every public page a unique, descriptive title and meta description. Find the app's layout and add a mechanism for each page to set them.
- 2 Add Open Graph and Twitter Card tags so shared links render a preview instead of a bare URL.
- 3 Generate a sitemap.xml covering every public, indexable page, and a robots.txt pointing at it.
Copy the prompt
No account needed
Add this feature to my app:
https://addthisfeature.com/x/seo-setup
How it works
-
1
Copy the link
Grab the Markdown instruction URL for this feature.
-
2
Give it to your AI
Paste it into Claude Code, Cursor, v0, Lovable — whatever you build with.
-
3
It inspects, then implements
Your agent reads your existing app first, then adds the feature to fit it.
Works with your stack
These instructions are written to adapt. They tell the agent to detect your framework, match your existing design system, and reuse what you already have — rather than assuming a particular stack.
Need it tighter than that? Customize the feature and tell it exactly what you're running.