Validate API keys across 10+ providers - check status, rate limits, and permissions in one dashboard.
Debugging a broken API key shouldn't take hours. KeyPing lets you paste any API key and get a full validation report: status, health score, rate limits, scopes, and latency in under 2 seconds. Built for developers and teams who ship fast and can't afford silent key failures in production.
Keys are validated server-side via Supabase Edge Functions - your full key is never stored, only the last 4 characters are saved for reference.
| Aspect | Before | After |
|---|---|---|
| Dashboard Pages | 9 separate routes with significant duplication | 5 focused pages with shared logic |
| Analytics | Split across 2 files (DashboardWidgets + StatsPage) with duplicate data fetching | Single useAnalytics() hook powering both overview and full analytics |
| History/Vault | Two separate pages with different data limits (20 vs 500) | Unified History page with view toggle (list/cards) |
| Documentation | Separate page that added navigation clutter | Integrated into Settings > Help & Docs |
| Alerts | Separate page, isolated from workflow | Alerts management integrated into Settings |
| Type Safety | Missing updated_at fields in TypeScript types |
All types match schema |
| Edge Function | Outdated Deno std library (0.168.0) | Updated to 0.220.0+ |
| SSRF Protection | Basic hostname blocking | Enhanced with cloud metadata endpoint blocking + port validation |
| Team Creation | Two-step insert with race condition risk | Atomic RPC function create_team_with_owner() |
| AWS Provider | Wasteful HTTP request with "Bearer unsupported" | Short-circuits before making request |
| Data Fetching | Duplicate queries across components | Centralized hooks with React Query caching |
- Bounded retries for provider calls - The edge function retries transient
failures (HTTP 429 rate limits, HTTP 5xx, network errors, timeouts) with
exponential backoff + jitter, respecting
Retry-Afterwhen provided. Only idempotent requests (GET) are retried on HTTP errors; a small retry count prevents endless hammering, and persistent failures surface as a controlled error to the UI. - Graceful timeouts - The Vercel health check and keep-alive cron fail clearly within a fixed timeout instead of hanging when Supabase is unavailable.
- Read-only health checks -
/api/healthperforms a minimal, read-onlykey_testsquery that never modifies data or creates records.
- Instant Key Validation - Paste any API key and get a pass/fail result with full details in under 2 seconds
- Health Score (0-100) - Every validation produces a composite score based on validity, rate limits, scopes, and response latency
- Latency Benchmarking - Measures real round-trip latency to each provider's auth endpoint
- Bulk Testing - Test up to 10 keys simultaneously; export results as a PDF report
- Secure Key Vault - Only the last 4 characters of each key are stored; full keys are tested at the edge and immediately discarded
- Expiry Alerts - Set reminders for key expiry dates with configurable lead times
- Team Workspaces - Create teams, invite members via shareable links
- Analytics Dashboard - Track validation history, provider distribution, health trends, and latency over time
- 10+ Supported Providers - OpenAI, Groq, Anthropic, Stripe, GitHub, Twitter/X, Notion, AWS, and custom endpoints
- Dark / Light Mode - Full theme support with smooth transitions
- Command Palette - Keyboard-first navigation across the entire app (Cmd+K)
| Category | Technology |
|---|---|
| Frontend | React 18 + TypeScript + Vite 5 |
| Styling | Tailwind CSS v3 + shadcn/ui + Radix UI |
| Backend | Supabase (Auth + PostgreSQL + RLS + Edge Functions) |
| Auth | Supabase Auth (Google OAuth) |
| Animations | Framer Motion |
| Charts | Recharts |
| PDF Export | jsPDF |
| Forms | React Hook Form + Zod |
| State | TanStack Query v5, React Context (auth) |
| Testing | Vitest + Testing Library |
| Deployment | Vercel (SPA + Edge Functions) |
| Route | Page | Description |
|---|---|---|
/dashboard |
Tester | Main key validation interface + compact stats overview |
/dashboard/analytics |
Analytics | Full charts, trends, provider breakdowns |
/dashboard/history |
History & Vault | Unified view with list/cards toggle, filters |
/dashboard/bulk |
Bulk Test | Test up to 10 keys in parallel |
/dashboard/team |
Team | Team workspace management |
/dashboard/settings |
Settings | Profile, notifications, security, help & docs |
- Node.js 18+
- pnpm
- Supabase account
# 1. Clone the repo
git clone https://github.com/MuhammadTanveerAbbas/Keyping.git
cd Keyping
# 2. Install dependencies
pnpm install
# 3. Set up environment variables
cp .env.example .env.local
# Fill in your values (see Environment Variables section below)
# 4. Run the development server
pnpm dev
# 5. Open in browser
# http://localhost:5173- Create a new project at supabase.com
- Run the SQL from
supabase/schema.sqlvia the Supabase SQL editor - Deploy the edge function:
supabase functions deploy test-api-key - Copy your project URL and anon key into
.env.local
| Variable | Required | Description |
|---|---|---|
VITE_SUPABASE_URL |
Yes | Supabase project URL (client-safe) |
VITE_SUPABASE_ANON_KEY |
Yes | Supabase anon/public key (client-safe) |
SUPABASE_SERVICE_ROLE_KEY |
Edge functions only | Supabase service role key (server-only) |
SUPABASE_ANON_KEY |
Edge functions only | Supabase anon key for edge function auth verification (server-only) |
CRON_SECRET |
Vercel Cron only | Secret for authenticating cron job requests |
Get your keys at supabase.com -> Project Settings -> API.
Keyping/
├── api/ # Vercel serverless/edge functions
│ ├── health.ts # Health check endpoint
│ └── keep-alive.ts # Cron job to prevent cold starts
├── public/ # Static assets
├── src/
│ ├── components/ # Reusable UI components
│ │ ├── dashboard/ # Dashboard-specific UI primitives
│ │ └── ui/ # shadcn/ui primitives
│ ├── pages/ # Route-level page components (5 pages)
│ ├── hooks/ # Shared custom React hooks
│ │ ├── useAnalytics.ts # Analytics data + computations
│ │ └── useHistory.ts # History filtering + CRUD
│ ├── lib/ # Auth, providers config, schemas, utilities
│ └── integrations/
│ └── supabase/ # Supabase client + generated types
├── supabase/
│ ├── functions/
│ │ └── test-api-key/ # Edge function: validates keys server-side
│ └── schema.sql # Database schema + RLS policies + indexes
├── .env.example
├── package.json
└── README.md
Single source of truth for all analytics data. Fetches tests once, computes all metrics:
- Total/monthly tests with trend
- Uptime rate, average latency, health score
- Provider distribution, latency by provider
- Health distribution, status breakdown
- Daily counts for sparklines
Unified history with filtering and CRUD:
- Filter by provider and status
- Delete functionality
- Returns raw test data for list/cards views
| Command | Description |
|---|---|
pnpm dev |
Start development server (port 8080) |
pnpm build |
Build for production |
pnpm build:dev |
Build in development mode |
pnpm preview |
Preview production build |
pnpm lint |
Run ESLint |
pnpm test |
Run tests (single run) |
pnpm test:watch |
Run tests in watch mode |
Deployed on Vercel.
- Push to GitHub
- Import repo into Vercel
- Set environment variables in Vercel dashboard
- Deploy
- Deploy edge functions:
supabase functions deploy test-api-key --project-ref your-project-id
| Improvement | Details |
|---|---|
| Enhanced SSRF Protection | Blocks cloud metadata endpoints (AWS, GCP, Alibaba), validates port 443 only |
| Atomic Team Creation | New RPC function prevents orphaned teams if member insert fails |
| Type-Safe Scopes | Runtime Array.isArray() check before casting JSON scopes |
| SSR-Safe Storage | typeof window guard for localStorage in Supabase client |
| Proxy Trap Coverage | Added apply trap to Supabase client proxy |
| Database Indexes | Added composite indexes for analytics queries |
| AWS Short-Circuit | Skips wasteful HTTP request for unsupported provider |
- Single key validation with health score
- Bulk key testing (up to 10 keys)
- Secure key vault (last 4 chars only)
- Expiry alerts with configurable reminders
- Team workspaces with invite links
- Analytics dashboard with charts
- PDF export for bulk test reports
- Dark / light mode
- Command palette
- Code consolidation (9 pages -> 5 pages)
- Shared hooks architecture
- Security hardening
- Email/webhook notifications for expiry alerts
- REST API for programmatic key validation
- Stripe subscription integration
- Rate limiting on edge functions
Contributions are welcome!
- Fork the repository
- Create a feature branch (
git checkout -b feature/amazing-feature) - Commit your changes (
git commit -m 'Add amazing feature') - Push to the branch (
git push origin feature/amazing-feature) - Open a Pull Request
Distributed under the MIT License. See LICENSE for more information.
SaaS Developer | Production-ready MVPs Portfolio: https://themvpguy.vercel.app