Athenian Secure API & Credentials Manager
Overview
Product overview
- Plugin name: Athenian Secure API Key Manager
- Plugin slug/package:
athenian-secure-api-key-manager - Current version reviewed:
1.0.4 - Primary file:
athenian-secure-api-key-manager.php - Text domain:
athenian-secure-api-key-manager - Requires WordPress:
6.0+ - Requires PHP:
7.4+ - Primary category: Security, Compliance & Trust
- Primary audience: WordPress administrators, WooCommerce operators, Athenian platform developers, agencies, DevOps support teams, and integration-heavy commerce sites
Use cases
- API credential administration
- Integration secret governance
- Scoped service connections
- Security review and audit preparation
Developer
Developer starting point
The documentation describes the reviewed storage and access architecture. It does not claim that existing production credentials are readable or that any external provider transaction has succeeded.
Technical Architecture
File Structure Reviewed
athenian-secure-api-key-manager.php
includes/
Admin.php
CLI.php
Rest.php
SecureStore.php
assets/
css/admin.css
js/admin.js
docs/
asakm-marketing-document.md
athenian-platform-marketing.md
athenian-platform-technical.mdBootstrap Flow
- The main plugin file defines constants such as
ASAKM_VERSION,ASAKM_PATH,ASAKM_URL, andASAKM_OPT_PREFIX. - Core classes are loaded from
includes/SecureStore.php,includes/Admin.php, andincludes/Rest.php. - Admin assets are enqueued only on the plugin settings page.
- PHP helper functions are declared if not already present.
ASAKM_LOADEDis defined for detection by dependent plugins.- WP-CLI support is conditionally loaded during
plugins_loadedwhenWP_CLIis active.
Main Classes
| Class | Responsibility | | --- | --- | | Athenian\SecureAPI\SecureStore | Encrypts, decrypts, saves, fetches, deletes, lists, and masks service credentials. | | Athenian\SecureAPI\Admin | Registers the settings page, renders the credential workspace, manages save/delete requests, and exposes the service registry. | | Athenian\SecureAPI\Rest | Registers admin-only health, masked status, and OpenAI proxy REST routes. | | Athenian\SecureAPI\CLI | Registers the asakm WP-CLI command group. | | Athenian\SecureAPI\ASAKM_Command | Implements diagnostics, service listing, get/set/delete, and validation commands. |
Storage Model
Each service is stored in a separate WordPress option using the configured prefix:
asakm_<service_slug>For example:
asakm_openai
asakm_google_maps
asakm_stripe
asakm_paypalThe option value is an encrypted blob shaped like:
{
"iv": "base64-encoded initialization vector",
"tag": "base64-encoded authentication tag",
"ct": "base64-encoded ciphertext"
}Options are saved with autoload disabled to avoid loading secrets into memory on every WordPress request.
Encryption Model
- Cipher:
aes-256-gcm - Key derivation: SHA-256 over WordPress auth keys and secure auth salt
- IV length: 12 random bytes
- AAD:
asakm:v1 - Tag length: 16 bytes
- Storage output: Base64-encoded
iv,tag, and ciphertext fields
Masking Model
The masked view preserves enough structure to indicate that a value exists without showing the raw secret:
- Short values are replaced with asterisks.
- Longer values show the first three and last three characters with the middle masked.
- Non-string values are shown as
(set).
This makes the plugin useful for support and diagnostics while reducing accidental credential disclosure in admin screenshots or shared support sessions.
WordPress Hooks and Integration Points
Actions
| Hook | Usage | | --- | --- | | admin_enqueue_scripts | Loads the admin CSS/JS on the ASAKM settings page only. | | plugins_loaded | Conditionally loads WP-CLI support. | | admin_menu | Registers the settings page under Settings. | | admin_post_asakm_save | Handles credential save requests. | | admin_post_asakm_delete | Handles full service credential deletion. | | rest_api_init | Registers the plugin REST routes. |
Filters
| Filter | Usage | | --- | --- | | asakm/services_meta | Allows plugins to extend the service registry with new credential groups. |
Admin Workflow
Configure a Service
- Open
Settings > Athenian API Keys. - Select a service from the sidebar.
- Review the service description and required fields.
- Enter new credential values.
- Save changes.
- Confirm the service indicator changes to configured.
Rotate a Credential
- Select the service.
- Enter only the field that needs to change.
- Leave other fields blank to preserve them.
- Save changes.
- Use
/health,/status/<service>, orwp asakm validateto confirm state.
Clear a Single Field
- Select the service.
- Enter a single hyphen (
-) in the field to clear. - Save changes.
Delete a Service Configuration
- Select the service.
- Click Delete Stored Values.
- Confirm deletion.
- The service status changes back to missing/unconfigured.
Developer Usage Examples
Fetch an Entire Service Configuration
$openai = asakm_fetch('openai');
$api_key = $openai['api_key'] ?? '';Fetch a Single Field with a Default
$paypal_env = asakm_get('paypal', 'environment', 'sandbox');Check Whether the Manager Is Available
if (defined('ASAKM_LOADED') && function_exists('asakm_get')) {
$stripe_secret = asakm_get('stripe', 'secret_key');
}Save a Custom Service Programmatically
asakm_save('custom_vendor_api', [
'api_key' => $key,
'endpoint' => $endpoint,
]);Security Notes
Strengths
- Uses authenticated encryption via AES-256-GCM.
- Derives encryption material from WordPress salts/keys instead of shipping a static plugin key.
- Saves each service in a separate non-autoloaded option.
- Masks secrets in the admin after storage.
- Restricts admin pages, save/delete actions, REST health/status, and proxy routes to
manage_optionsusers. - Provides server-side helper functions so other plugins do not need to expose secrets to the browser.
- Includes WP-CLI doctor checks for OpenSSL/cipher support and encryption round-trip validation.
Operational Considerations
- Because encryption is derived from WordPress salts/keys, changing those salts can make existing encrypted values unreadable unless credentials are re-entered.
- Raw values are available through PHP helper functions and WP-CLI to trusted server operators, so server access and administrator accounts should remain tightly controlled.
- The included OpenAI proxy route is admin-only and should be treated as an example/controlled backend workflow rather than a public frontend API.
- Browser-safe keys, such as a Google Maps browser key, still require provider-side restrictions because they may need to be used client-side by consuming plugins.
Implementation Review Notes
- The plugin is lightweight and focused: five PHP files plus admin CSS/JS and documentation.
- The current version does not register shortcodes, custom post types, taxonomies, database tables, scheduled jobs, or WooCommerce-specific hooks.
- The primary data model is WordPress options prefixed with
asakm_. - The admin page is registered under Settings rather than as a top-level menu.
- Service metadata is intentionally filterable so this plugin can act as a credential backbone for other Athenian modules.
- PHP linting passed for all PHP files in the inspected package.
Install
- Reviewed source folder: athenian-secure-api-key-manager
- Plugin version reviewed: 1.0.4
- Local source inventory: 13 files (vendor, temporary, test, and Git metadata excluded).
- GitHub baseline: https://github.com/Athenian-Brands/athenian-secure-api-manager at baseline/devdocs-1.0.4-20261006 / 02b2b2666df64ca08b9b3144901dfb7ba8599e1d.
- WordPress and the PHP cryptography/runtime capabilities declared by the source.
- Provider authentication, credential readability, and external transactions require separate target-environment verification.
Configuration
- Plugin Identity — see the linked technical reference excerpt.
- Executive Summary — see the linked technical reference excerpt.
- Marketing Positioning — see the linked technical reference excerpt.
- The Problem It Solves — see the linked technical reference excerpt.
- Key Capabilities — see the linked technical reference excerpt.
- Technical Architecture — see the linked technical reference excerpt.
- WordPress Hooks and Integration Points — see the linked technical reference excerpt.
- Admin Workflow — see the linked technical reference excerpt.
- Developer Usage Examples — see the linked technical reference excerpt.
- Ecosystem Fit — see the linked technical reference excerpt.
- Security Notes — see the linked technical reference excerpt.
- Differentiators — see the linked technical reference excerpt.
- Suggested Product Page Sections — see the linked technical reference excerpt.
- SEO Keywords — see the linked technical reference excerpt.
Usage
- Shortcodes detected in local PHP source: 0
- Static action/filter hooks detected in local PHP source: 7
- REST route registrations detected in local PHP source: 1
Shortcodes
- No static add_shortcode registrations were detected by the baseline scanner.
REST Endpoints
- asakm/v1 — includes/Rest.php
Hooks
- admin_enqueue_scripts — athenian-secure-api-key-manager.php
- admin_menu — includes/Admin.php
- admin_post_asakm_delete — includes/Admin.php
- admin_post_asakm_save — includes/Admin.php
- asakm/services_meta — includes/Admin.php
- plugins_loaded — athenian-secure-api-key-manager.php
- rest_api_init — includes/Rest.php
Data Model
- WordPress Hooks and Integration Points — described in the local technical reference.
API Reference
- Local source digest: 7f36942bc0cab02f58f2a3f579cfb6d58ee653ebfb6306a9c158db39e35812b2
- Repository URL: https://github.com/Athenian-Brands/athenian-secure-api-manager
- Repository reference: baseline/devdocs-1.0.4-20261006
- Repository commit: 02b2b2666df64ca08b9b3144901dfb7ba8599e1d
Source files include: assets/css/admin.css, assets/js/admin.js, athenian-secure-api-key-manager.php, athenian-secure-api-key-manager.png, athenian-secure-api-key-manager.zip, docs/asakm-marketing-document.md, docs/athenian-platform-marketing.md, docs/athenian-platform-technical.md, docs/technical-marketing.md, includes/Admin.php, includes/CLI.php, includes/Rest.php, includes/SecureStore.php
Troubleshooting
The documentation describes the reviewed storage and access architecture. It does not claim that existing production credentials are readable or that any external provider transaction has succeeded.
- Confirm the deployed plugin version, active dependencies, and current repository tree before using implementation details as a release contract.
- Treat payment, carrier, vendor, shipment, inventory, account, credential, and external-provider behavior as integration-dependent until exercised in the target environment.
FAQ
What is this page intended to establish?
A versioned, product-linked starting point for iterative developer documentation. It combines the local implementation reference with a compact detected-code inventory and a committed GitHub baseline.
Is the linked repository baseline verified?
Yes. The repository URL, ref, and commit recorded on this page were verified from the clean GitHub baseline prepared for this documentation pass. That does not by itself prove fleet deployment parity.
What remains for release-grade documentation?
Reconcile the recorded source baseline with the deployed plugin version, then exercise the relevant authenticated, store, provider, payment, carrier, or generated-artifact paths in the target environment.