返回 Skill 列表
extension
分类: 开发与工程无需 API Key

exa-security-basics

应用Exa安全最佳实践来保护密钥和访问控制。在保护API密钥、实施最小权限访问或审核Exa安全配置时使用。可以通过诸如“exa安全”、“exa密钥”、“保护exa”、“exa API密钥安全”等短语触发。

person作者: jakexiaohubgithub

Exa Security Basics

Overview

Security best practices for Exa API keys, tokens, and access control.

Prerequisites

  • Exa SDK installed
  • Understanding of environment variables
  • Access to Exa dashboard

Instructions

Step 1: Configure Environment Variables

# .env (NEVER commit to git)
EXA_API_KEY=sk_live_***
EXA_SECRET=***

# .gitignore
.env
.env.local
.env.*.local

Step 2: Implement Secret Rotation

# 1. Generate new key in Exa dashboard
# 2. Update environment variable
export EXA_API_KEY="new_key_here"

# 3. Verify new key works
curl -H "Authorization: Bearer ${EXA_API_KEY}" \
  https://api.exa.com/health

# 4. Revoke old key in dashboard

Step 3: Apply Least Privilege

| Environment | Recommended Scopes | |-------------|-------------------| | Development | read:* | | Staging | read:*, write:limited | | Production | Only required scopes |

Output

  • Secure API key storage
  • Environment-specific access controls
  • Audit logging enabled

Error Handling

| Security Issue | Detection | Mitigation | |----------------|-----------|------------| | Exposed API key | Git scanning | Rotate immediately | | Excessive scopes | Audit logs | Reduce permissions | | Missing rotation | Key age check | Schedule rotation |

Examples

Service Account Pattern

const clients = {
  reader: new ExaClient({
    apiKey: process.env.EXA_READ_KEY,
  }),
  writer: new ExaClient({
    apiKey: process.env.EXA_WRITE_KEY,
  }),
};

Webhook Signature Verification

import crypto from 'crypto';

function verifyWebhookSignature(
  payload: string, signature: string, secret: string
): boolean {
  const expected = crypto.createHmac('sha256', secret).update(payload).digest('hex');
  return crypto.timingSafeEqual(Buffer.from(signature), Buffer.from(expected));
}

Security Checklist

  • [ ] API keys in environment variables
  • [ ] .env files in .gitignore
  • [ ] Different keys for dev/staging/prod
  • [ ] Minimal scopes per environment
  • [ ] Webhook signatures validated
  • [ ] Audit logging enabled

Audit Logging

interface AuditEntry {
  timestamp: Date;
  action: string;
  userId: string;
  resource: string;
  result: 'success' | 'failure';
  metadata?: Record<string, any>;
}

async function auditLog(entry: Omit<AuditEntry, 'timestamp'>): Promise<void> {
  const log: AuditEntry = { ...entry, timestamp: new Date() };

  // Log to Exa analytics
  await exaClient.track('audit', log);

  // Also log locally for compliance
  console.log('[AUDIT]', JSON.stringify(log));
}

// Usage
await auditLog({
  action: 'exa.api.call',
  userId: currentUser.id,
  resource: '/v1/resource',
  result: 'success',
});

Resources

Next Steps

For production deployment, see exa-prod-checklist.