* fix: unify session and automation API keys into a single credential
Both the agent-server and automation backend now share the same API key
value. The agent-server validates it via `X-Session-API-Key` and the
automation backend validates it via `Authorization: Bearer …` — different
header formats, same credential.
Changes:
- Frontend: automation axios client reads `VITE_SESSION_API_KEY` instead
of the now-removed `VITE_AUTOMATION_API_KEY`
- Dev launcher: removed separate `AUTOMATION_LOCAL_API_KEY` generation
and persistence (`automation-api-key.txt`); `localApiKey` is set to
`sessionApiKey` so both backends receive the same value
- Static build: stopped baking `VITE_AUTOMATION_API_KEY` (the frontend
reads from `VITE_SESSION_API_KEY`)
- Docker entrypoint: `OPENHANDS_AUTOMATION_API_KEY`,
`AUTOMATION_LOCAL_API_KEY`, and `AUTOMATION_AGENT_SERVER_API_KEY` all
default to the session key when not explicitly overridden
- Tests updated to verify unified key behavior
Fixes the 401 on `/api/automation/v1` when the automation backend is
running but no separate `VITE_AUTOMATION_API_KEY` was configured.
Co-authored-by: openhands <openhands@all-hands.dev>
* fix: use X-Session-API-Key header for automation backend auth (consistent with agent-server)
Switch automation backend requests from `Authorization: Bearer …` to
`X-Session-API-Key` header, matching the agent-server's auth pattern.
Both backends now authenticate using the same header and the same key
value (`VITE_SESSION_API_KEY`).
Co-authored-by: openhands <openhands@all-hands.dev>
* fix: address review — remove localApiKey alias, dead constant, add entrypoint guard
- Remove `localApiKey` from config; all call sites now use
`config.sessionApiKey` directly, making the unified-key intent obvious.
- Delete `DEFAULT_AUTOMATION_API_KEY_PATH` constant and its export
(no downstream consumers in beta).
- Add fail-fast guard in docker/entrypoint.sh when no session key is
available, instead of silently exporting empty strings.
Co-authored-by: openhands <openhands@all-hands.dev>
* fix: update stale comment on AUTOMATION_LOCAL_API_KEY to reflect unified session key
Co-authored-by: openhands <openhands@all-hands.dev>
---------
Co-authored-by: openhands <openhands@all-hands.dev>