# What AI Authentication Methods Does DBX Support? API Key and Bearer Tokens Explained

> Learn about DBX AI authentication methods including API Keys and Bearer tokens. Understand how these methods secure your AI integrations effectively.

- Repository: [skyler/dbx](https://github.com/t8y2/dbx)
- Tags: api-reference
- Published: 2026-07-04

---

**DBX supports two distinct AI authentication methods: API Key (static secret) and Bearer (OAuth 2.0 style token), defined in the `AiAuthMethod` type within the desktop client's settings store.**

The DBX desktop application, maintained in the `t8y2/dbx` repository, implements a flexible authentication system for AI provider integrations. Understanding these **AI authentication methods** is essential for configuring secure connections to language models like Claude, OpenAI, and DeepSeek. The implementation centralizes all provider configurations in a single TypeScript store that maps each service to its required authentication scheme.

## Supported AI Authentication Methods in DBX

The `AiAuthMethod` type in [`apps/desktop/src/stores/settingsStore.ts`](https://github.com/t8y2/dbx/blob/main/apps/desktop/src/stores/settingsStore.ts) (lines 16-19) explicitly defines two authentication strategies. Each method determines how the `Authorization` header is constructed when making requests to AI endpoints.

### API Key Authentication

**API Key** authentication uses a static secret token passed directly in the request headers. DBX formats this as `Authorization: Api-Key <key>`, following the pattern used by providers like Anthropic's Claude. This method treats the key as an opaque credential that remains constant across requests, requiring no token refresh or session management.

### Bearer Token Authentication

**Bearer** authentication implements the standard OAuth 2.0 bearer token pattern, sending `Authorization: Bearer <token>` in request headers. This is the default authentication method for most providers in the DBX ecosystem, including OpenAI, DeepSeek, Qwen, Ollama, and OpenAI-compatible endpoints. Bearer tokens can represent either long-lived API keys or temporary access tokens, depending on the provider's implementation.

## How Provider Presets Configure Authentication

The `AI_PROVIDER_PRESETS` map (lines 108-189 of [`apps/desktop/src/stores/settingsStore.ts`](https://github.com/t8y2/dbx/blob/main/apps/desktop/src/stores/settingsStore.ts)) assigns the appropriate authentication method to each supported AI service. This configuration determines which header format DBX uses when communicating with specific endpoints.

- **Claude** uses `authMethod: "api-key"`
- **OpenAI**, **DeepSeek**, **Qwen**, **Ollama**, **OpenAI-compatible**, **Codex-CLI**, and **Custom** providers all use `authMethod: "bearer"`

Each preset also includes a `requiresApiKey` boolean flag indicating whether credentials are mandatory, though the underlying authentication scheme remains strictly either API Key or Bearer.

## Implementing AI Authentication in DBX

The following TypeScript example demonstrates how to retrieve a provider's authentication configuration and construct the appropriate headers for API requests:

```typescript
import { AI_PROVIDER_PRESETS } from '@/stores/settingsStore';

// Select a provider from the available presets
const provider = 'openai'; // or 'claude', 'deepseek', etc.

// Access the preset configuration
const preset = AI_PROVIDER_PRESETS[provider as keyof typeof AI_PROVIDER_PRESETS];

// Build headers based on the provider's authMethod
function buildAuthHeader(apiKey: string): Record<string, string> {
  if (preset.authMethod === 'api-key') {
    return { Authorization: `Api-Key ${apiKey}` };
  }
  // Default to Bearer for all other providers
  return { Authorization: `Bearer ${apiKey}` };
}

// Execute an authenticated AI request
async function callAiEndpoint(payload: any, apiKey: string) {
  const headers = {
    'Content-Type': 'application/json',
    ...buildAuthHeader(apiKey),
  };
  
  const response = await fetch(preset.endpoint, {
    method: 'POST',
    headers,
    body: JSON.stringify(payload),
  });
  
  return response.json();
}

```

This pattern ensures that DBX sends correctly formatted authentication headers regardless of which provider the user selects.

## Source Code Locations and Testing

The authentication logic is thoroughly validated in the DBX codebase. The [`packages/app-tests/settingsStore.test.ts`](https://github.com/t8y2/dbx/blob/main/packages/app-tests/settingsStore.test.ts) file contains test cases confirming that each provider maps to the correct `authMethod` value—for example, verifying that OpenAI resolves to "bearer" while Claude resolves to "api-key".

Additional documentation in [`docs/mq-quick-start.md`](https://github.com/t8y2/dbx/blob/main/docs/mq-quick-start.md) provides concrete examples of API key provisioning, illustrating how the "api-key" authentication pattern integrates with messaging queue configurations.

## Summary

- **API Key** and **Bearer** are the only two **AI authentication methods** supported by DBX, defined in [`apps/desktop/src/stores/settingsStore.ts`](https://github.com/t8y2/dbx/blob/main/apps/desktop/src/stores/settingsStore.ts).
- Claude exclusively uses API Key authentication (`Api-Key <key>`), while OpenAI, DeepSeek, and other major providers use Bearer tokens (`Bearer <token>`).
- The `AI_PROVIDER_PRESETS` map (lines 108-189) configures which method each provider uses, ensuring correct header formatting for every request.
- Provider authentication preferences are enforced through TypeScript type definitions and validated by the application's test suite.

## Frequently Asked Questions

### Does DBX support OAuth 2.0 flows for AI providers?

DBX supports Bearer token authentication, which is compatible with OAuth 2.0 access tokens, but it does not implement the full OAuth 2.0 authorization flow (authorization codes, refresh tokens, or token endpoints). Users must provide the bearer token directly, which DBX then passes as `Authorization: Bearer <token>` in all API requests.

### Which AI providers use API Key vs Bearer authentication in DBX?

According to the `AI_PROVIDER_PRESETS` definition in [`settingsStore.ts`](https://github.com/t8y2/dbx/blob/main/settingsStore.ts), only **Claude** uses the API Key method (`authMethod: "api-key"`). All other built-in providers—including OpenAI, DeepSeek, Qwen, Ollama, Codex-CLI, and custom OpenAI-compatible endpoints—use Bearer authentication (`authMethod: "bearer"`).

### How does DBX store AI authentication credentials?

While the source code defines the authentication methods and header formats in [`apps/desktop/src/stores/settingsStore.ts`](https://github.com/t8y2/dbx/blob/main/apps/desktop/src/stores/settingsStore.ts), the actual storage mechanism for API keys depends on the desktop client's secure storage implementation. The `AiAuthMethod` type and provider presets determine how credentials are formatted when retrieved and sent to external APIs, but the secure persistence layer is handled separately by the application's settings store.

### Can I use a custom authentication method with DBX AI providers?

DBX strictly supports only the two authentication methods defined in the `AiAuthMethod` type: "api-key" and "bearer". When configuring a custom provider through the "Custom" or "OpenAI-compatible" presets, DBX will use Bearer authentication. The application does not support custom header formats, signature-based authentication, or query parameter-based keys outside of these two standardized Authorization header patterns.