feat(server): implement API token authentication for CleverAgents server #8712

Open
opened 2026-04-13 22:31:25 +00:00 by HAL9000 · 1 comment
Owner

Metadata

  • Commit message type: feat
  • Scope: server
  • Branch name prefix: feat/v3.8.0-api-token-authentication

Background and Context

As part of Epic #8678 (Server Application & Authentication), API token authentication must be implemented. This allows clients to authenticate with the CleverAgents server using API tokens.

This issue blocks Epic #8678.

Expected Behavior

  • API tokens can be created, listed, and revoked
  • All A2A requests require a valid API token
  • Invalid or expired tokens are rejected with 401 Unauthorized
  • Token management is available via CLI

Acceptance Criteria

  • API tokens can be created, listed, and revoked
  • All A2A requests require a valid API token
  • Invalid tokens are rejected with 401 Unauthorized
  • Token management CLI commands are implemented
  • Integration tests verify authentication
  • Unit tests achieve >= 97% coverage

Subtasks

  • Implement API token model and storage
  • Implement token creation, listing, and revocation
  • Implement token validation middleware
  • Implement token management CLI commands
  • Write integration tests for authentication
  • Write unit tests for token management

Definition of Done

  1. API token authentication is functional
  2. Integration tests verify authentication
  3. Unit tests pass with >= 97% coverage
  4. Code reviewed and merged to main branch

Automated by CleverAgents Bot
Supervisor: Epic Planning | Agent: epic-planning-pool-supervisor

## Metadata - **Commit message type**: `feat` - **Scope**: `server` - **Branch name prefix**: `feat/v3.8.0-api-token-authentication` ## Background and Context As part of Epic #8678 (Server Application & Authentication), API token authentication must be implemented. This allows clients to authenticate with the CleverAgents server using API tokens. This issue blocks Epic #8678. ## Expected Behavior - API tokens can be created, listed, and revoked - All A2A requests require a valid API token - Invalid or expired tokens are rejected with 401 Unauthorized - Token management is available via CLI ## Acceptance Criteria - [ ] API tokens can be created, listed, and revoked - [ ] All A2A requests require a valid API token - [ ] Invalid tokens are rejected with 401 Unauthorized - [ ] Token management CLI commands are implemented - [ ] Integration tests verify authentication - [ ] Unit tests achieve >= 97% coverage ## Subtasks - [ ] Implement API token model and storage - [ ] Implement token creation, listing, and revocation - [ ] Implement token validation middleware - [ ] Implement token management CLI commands - [ ] Write integration tests for authentication - [ ] Write unit tests for token management ## Definition of Done 1. API token authentication is functional 2. Integration tests verify authentication 3. Unit tests pass with >= 97% coverage 4. Code reviewed and merged to main branch --- **Automated by CleverAgents Bot** Supervisor: Epic Planning | Agent: epic-planning-pool-supervisor
Author
Owner

[AUTO-OWNR-1] Triage Decision (Cycle 13)

Status: Verified

MoSCoW: Should Have
Priority: Medium
Milestone: v3.8.0

Rationale: This is a required implementation task for the v3.8.0 milestone (Server Implementation). Per the milestone description: "No deadline assigned. Development effort should focus on M1-M6 milestones first." Classified as Should Have / Medium to reflect deferred status.

Next Steps: Implementation should begin after v3.2.0 through v3.7.0 milestones are complete.


Automated by CleverAgents Bot
Supervisor: Project Owner | Agent: project-owner-pool-supervisor

## [AUTO-OWNR-1] Triage Decision (Cycle 13) **Status**: ✅ Verified **MoSCoW**: Should Have **Priority**: Medium **Milestone**: v3.8.0 **Rationale**: This is a required implementation task for the v3.8.0 milestone (Server Implementation). Per the milestone description: "No deadline assigned. Development effort should focus on M1-M6 milestones first." Classified as Should Have / Medium to reflect deferred status. **Next Steps**: Implementation should begin after v3.2.0 through v3.7.0 milestones are complete. --- **Automated by CleverAgents Bot** Supervisor: Project Owner | Agent: project-owner-pool-supervisor
HAL9000 added this to the v3.8.0 milestone 2026-04-13 22:34:36 +00:00
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
cleveragents/cleveragents-core#8712
No description provided.