QDG Knowledge Base Read-only viewer QWebHub
quick-reference

Quick Reference

Version 2 · Replace the inline HTTP API section with a pointer to the new dedicated API Reference page, to avoid maintaining the same endpoint contracts in two places

GateKeeper — Quick Reference

Run it locally

# Prereqs: .NET 8 SDK, MySQL 8.0.16+, Redis
dotnet restore
dotnet build

# Load schema against a fresh database (see Known Issues — seed rows 101/205/310 will FK-fail as-is)
mysql -u root -p gatekeeper < docs/gatekeeper-schema.sql

dotnet run --project GateKeeper.Api        # http://localhost:5080
dotnet run --project GateKeeper.AdminUI    # http://localhost:5190

docs/gatekeeper-schema.sql seeds two customers, CWS (id 401) and WSB (id 402), with no tokens/packages/subscriptions attached. Issue a token via the Admin API or AdminUI, then call /v1/meetings with the issued client-guid and secret in the X-Client-Guid / X-Api-Secret headers.

Full onboarding walkthrough (create customer → issue token → assign package → hand off credentials → rotate/revoke later) is in the README's "Onboarding an external client" section.

HTTP API

See API Reference for the full endpoint contracts — client-facing /v1/meetings and the ten /admin/* routes, with exact request/response shapes read from source. In short: client requests need X-Client-Guid + X-Api-Secret; admin requests need X-Admin-Key.

Configuration

Setting Where Notes
ConnectionStrings:MySql appsettings.json (API + AdminUI) MySQL host/port/database/credentials, semicolon-delimited connection string
ConnectionStrings:Redis same host:port, e.g. localhost:6379
Admin:ApiKey same Shared value checked by AdminAuthMiddleware and the AdminUI login screen
Cache:TokenTtlMinutes same (optional) Redis TTL for the token cache. Default 5. 0/negative = no expiry.
Cache:EntitlementTtlMinutes same (optional) Redis TTL for the entitlement cache. Default 5. 0/negative = no expiry.

Docker Compose/Swarm maps two environment variables (see .env.example) onto the MySQL connection string and admin key settings via ASP.NET Core's double-underscore config binding. launchSettings.json for both API and AdminUI can also carry local dev connection-string overrides directly (e.g. pointing at a docker-mapped MySQL port) — never commit real credentials there; use a local, non-shared dev value.

Do not commit real credentials. appsettings.json and gatekeeper-schema.sql use placeholder values for secrets — but see Known Issues for a real credential currently committed in one Development config file.

Related docs in docs/

  • entitlement-system-design.md — original design proposal (architecture rationale, worked examples)
  • gatekeeper-schema.sql — MySQL DDL + seed data
  • gatekeeper-db-documentation.md — table-by-table DB reference
  • entitlement-system-architecture.svg, entitlement-system-full-picture.html — diagrams
Updated by Claude on Aug. 11, 2026, 11:13 a.m. · Task: create related apis document using in gatekeeper and update API in qdgwiki