What AI Authentication Methods Does DBX Support? API Key and Bearer Tokens Explained

DBX supports two distinct AI authentication methods: API Key (static secret) and Bearer (OAuth 2.0 style token), defined in the AiAuthMethod type within the desktop client's settings store.

The DBX desktop application, maintained in the t8y2/dbx repository, implements a flexible authentication system for AI provider integrations. Understanding these AI authentication methods is essential for configuring secure connections to language models like Claude, OpenAI, and DeepSeek. The implementation centralizes all provider configurations in a single TypeScript store that maps each service to its required authentication scheme.

Supported AI Authentication Methods in DBX

The AiAuthMethod type in apps/desktop/src/stores/settingsStore.ts (lines 16-19) explicitly defines two authentication strategies. Each method determines how the Authorization header is constructed when making requests to AI endpoints.

API Key Authentication

API Key authentication uses a static secret token passed directly in the request headers. DBX formats this as Authorization: Api-Key <key>, following the pattern used by providers like Anthropic's Claude. This method treats the key as an opaque credential that remains constant across requests, requiring no token refresh or session management.

Bearer Token Authentication

Bearer authentication implements the standard OAuth 2.0 bearer token pattern, sending Authorization: Bearer <token> in request headers. This is the default authentication method for most providers in the DBX ecosystem, including OpenAI, DeepSeek, Qwen, Ollama, and OpenAI-compatible endpoints. Bearer tokens can represent either long-lived API keys or temporary access tokens, depending on the provider's implementation.

How Provider Presets Configure Authentication

The AI_PROVIDER_PRESETS map (lines 108-189 of apps/desktop/src/stores/settingsStore.ts) assigns the appropriate authentication method to each supported AI service. This configuration determines which header format DBX uses when communicating with specific endpoints.

  • Claude uses authMethod: "api-key"
  • OpenAI, DeepSeek, Qwen, Ollama, OpenAI-compatible, Codex-CLI, and Custom providers all use authMethod: "bearer"

Each preset also includes a requiresApiKey boolean flag indicating whether credentials are mandatory, though the underlying authentication scheme remains strictly either API Key or Bearer.

Implementing AI Authentication in DBX

The following TypeScript example demonstrates how to retrieve a provider's authentication configuration and construct the appropriate headers for API requests:

import { AI_PROVIDER_PRESETS } from '@/stores/settingsStore';

// Select a provider from the available presets
const provider = 'openai'; // or 'claude', 'deepseek', etc.

// Access the preset configuration
const preset = AI_PROVIDER_PRESETS[provider as keyof typeof AI_PROVIDER_PRESETS];

// Build headers based on the provider's authMethod
function buildAuthHeader(apiKey: string): Record<string, string> {
  if (preset.authMethod === 'api-key') {
    return { Authorization: `Api-Key ${apiKey}` };
  }
  // Default to Bearer for all other providers
  return { Authorization: `Bearer ${apiKey}` };
}

// Execute an authenticated AI request
async function callAiEndpoint(payload: any, apiKey: string) {
  const headers = {
    'Content-Type': 'application/json',
    ...buildAuthHeader(apiKey),
  };
  
  const response = await fetch(preset.endpoint, {
    method: 'POST',
    headers,
    body: JSON.stringify(payload),
  });
  
  return response.json();
}

This pattern ensures that DBX sends correctly formatted authentication headers regardless of which provider the user selects.

Source Code Locations and Testing

The authentication logic is thoroughly validated in the DBX codebase. The packages/app-tests/settingsStore.test.ts file contains test cases confirming that each provider maps to the correct authMethod value—for example, verifying that OpenAI resolves to "bearer" while Claude resolves to "api-key".

Additional documentation in docs/mq-quick-start.md provides concrete examples of API key provisioning, illustrating how the "api-key" authentication pattern integrates with messaging queue configurations.

Summary

  • API Key and Bearer are the only two AI authentication methods supported by DBX, defined in apps/desktop/src/stores/settingsStore.ts.
  • Claude exclusively uses API Key authentication (Api-Key <key>), while OpenAI, DeepSeek, and other major providers use Bearer tokens (Bearer <token>).
  • The AI_PROVIDER_PRESETS map (lines 108-189) configures which method each provider uses, ensuring correct header formatting for every request.
  • Provider authentication preferences are enforced through TypeScript type definitions and validated by the application's test suite.

Frequently Asked Questions

Does DBX support OAuth 2.0 flows for AI providers?

DBX supports Bearer token authentication, which is compatible with OAuth 2.0 access tokens, but it does not implement the full OAuth 2.0 authorization flow (authorization codes, refresh tokens, or token endpoints). Users must provide the bearer token directly, which DBX then passes as Authorization: Bearer <token> in all API requests.

Which AI providers use API Key vs Bearer authentication in DBX?

According to the AI_PROVIDER_PRESETS definition in settingsStore.ts, only Claude uses the API Key method (authMethod: "api-key"). All other built-in providers—including OpenAI, DeepSeek, Qwen, Ollama, Codex-CLI, and custom OpenAI-compatible endpoints—use Bearer authentication (authMethod: "bearer").

How does DBX store AI authentication credentials?

While the source code defines the authentication methods and header formats in apps/desktop/src/stores/settingsStore.ts, the actual storage mechanism for API keys depends on the desktop client's secure storage implementation. The AiAuthMethod type and provider presets determine how credentials are formatted when retrieved and sent to external APIs, but the secure persistence layer is handled separately by the application's settings store.

Can I use a custom authentication method with DBX AI providers?

DBX strictly supports only the two authentication methods defined in the AiAuthMethod type: "api-key" and "bearer". When configuring a custom provider through the "Custom" or "OpenAI-compatible" presets, DBX will use Bearer authentication. The application does not support custom header formats, signature-based authentication, or query parameter-based keys outside of these two standardized Authorization header patterns.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →