Quick Reference
Version 2 · Replace the inline HTTP API section with a pointer to the new dedicated API Reference page, to avoid maintaining the same endpoint contracts in two places
GateKeeper — Quick Reference
Run it locally
# Prereqs: .NET 8 SDK, MySQL 8.0.16+, Redis
dotnet restore
dotnet build
# Load schema against a fresh database (see Known Issues — seed rows 101/205/310 will FK-fail as-is)
mysql -u root -p gatekeeper < docs/gatekeeper-schema.sql
dotnet run --project GateKeeper.Api # http://localhost:5080
dotnet run --project GateKeeper.AdminUI # http://localhost:5190
docs/gatekeeper-schema.sql seeds two customers, CWS (id 401) and WSB (id 402), with no tokens/packages/subscriptions attached. Issue a token via the Admin API or AdminUI, then call /v1/meetings with the issued client-guid and secret in the X-Client-Guid / X-Api-Secret headers.
Full onboarding walkthrough (create customer → issue token → assign package → hand off credentials → rotate/revoke later) is in the README's "Onboarding an external client" section.
HTTP API
See API Reference for the full endpoint contracts — client-facing /v1/meetings and the ten /admin/* routes, with exact request/response shapes read from source. In short: client requests need X-Client-Guid + X-Api-Secret; admin requests need X-Admin-Key.
Configuration
| Setting | Where | Notes |
|---|---|---|
ConnectionStrings:MySql |
appsettings.json (API + AdminUI) |
MySQL host/port/database/credentials, semicolon-delimited connection string |
ConnectionStrings:Redis |
same | host:port, e.g. localhost:6379 |
Admin:ApiKey |
same | Shared value checked by AdminAuthMiddleware and the AdminUI login screen |
Cache:TokenTtlMinutes |
same (optional) | Redis TTL for the token cache. Default 5. 0/negative = no expiry. |
Cache:EntitlementTtlMinutes |
same (optional) | Redis TTL for the entitlement cache. Default 5. 0/negative = no expiry. |
Docker Compose/Swarm maps two environment variables (see .env.example) onto the MySQL connection string and admin key settings via ASP.NET Core's double-underscore config binding. launchSettings.json for both API and AdminUI can also carry local dev connection-string overrides directly (e.g. pointing at a docker-mapped MySQL port) — never commit real credentials there; use a local, non-shared dev value.
Do not commit real credentials. appsettings.json and gatekeeper-schema.sql use placeholder values for secrets — but see Known Issues for a real credential currently committed in one Development config file.
Related docs in docs/
entitlement-system-design.md— original design proposal (architecture rationale, worked examples)gatekeeper-schema.sql— MySQL DDL + seed datagatekeeper-db-documentation.md— table-by-table DB referenceentitlement-system-architecture.svg,entitlement-system-full-picture.html— diagrams