Plugin tools and model API keys support configuring visibility scope. #20302

Closed
opened 2026-02-21 20:06:44 -05:00 by yindo · 1 comment
Owner

Originally created by @run626exe on GitHub (Nov 13, 2025).

Self Checks

  • I have read the Contributing Guide and Language Policy.
  • I have searched for existing issues search for existing issues, including closed ones.
  • I confirm that I am using English to submit this report, otherwise it will be closed.
  • Please do not modify this template :) and fill in all the required fields.

1. Is this request related to a challenge you're experiencing? Tell me about your story.

The current plugin tools and model API keys now support multiple configurations, which is beneficial for permission isolation. However, users can still freely choose all API keys to use, which may lead to permission abuse, such as using others' keys to access data or services that they originally do not have permission to access.
It is hoped that a visibility scope setting can be added when configuring the API key, supporting the selection of the corresponding scope to open, similar to the visibility scope of the knowledge base.

2. Additional context or comments

No response

3. Can you help us with this feature?

  • I am interested in contributing to this feature.
Originally created by @run626exe on GitHub (Nov 13, 2025). ### Self Checks - [x] I have read the [Contributing Guide](https://github.com/langgenius/dify/blob/main/CONTRIBUTING.md) and [Language Policy](https://github.com/langgenius/dify/issues/1542). - [x] I have searched for existing issues [search for existing issues](https://github.com/langgenius/dify/issues), including closed ones. - [x] I confirm that I am using English to submit this report, otherwise it will be closed. - [x] Please do not modify this template :) and fill in all the required fields. ### 1. Is this request related to a challenge you're experiencing? Tell me about your story. The current plugin tools and model API keys now support multiple configurations, which is beneficial for permission isolation. However, users can still freely choose all API keys to use, which may lead to permission abuse, such as using others' keys to access data or services that they originally do not have permission to access. It is hoped that a visibility scope setting can be added when configuring the API key, supporting the selection of the corresponding scope to open, similar to the visibility scope of the knowledge base. ### 2. Additional context or comments _No response_ ### 3. Can you help us with this feature? - [ ] I am interested in contributing to this feature.
yindo added the 💪 enhancement🔨 feat:tools labels 2026-02-21 20:06:44 -05:00
yindo closed this issue 2026-02-21 20:06:45 -05:00
Author
Owner

@dosubot[bot] commented on GitHub (Dec 14, 2025):

Hi, @run626exe. I'm Dosu, and I'm helping the Dify team manage their backlog and am marking this issue as stale.

Issue Summary:

  • You requested a feature to add visibility scope settings for plugin tools and model API keys.
  • The goal is to prevent permission abuse by restricting user access to specific keys.
  • You suggested configuring API key access similarly to the existing knowledge base visibility scope.
  • There has been no further activity or comments on this issue since it was opened.
  • The issue remains unresolved.

Next Steps:

  • Please let me know if this feature request is still relevant to the latest version of Dify by commenting on this issue.
  • If I do not hear back within 15 days, I will automatically close this issue.

Thank you for your understanding and contribution!

@dosubot[bot] commented on GitHub (Dec 14, 2025): Hi, @run626exe. I'm [Dosu](https://dosu.dev), and I'm helping the Dify team manage their backlog and am marking this issue as stale. **Issue Summary:** - You requested a feature to add visibility scope settings for plugin tools and model API keys. - The goal is to prevent permission abuse by restricting user access to specific keys. - You suggested configuring API key access similarly to the existing knowledge base visibility scope. - There has been no further activity or comments on this issue since it was opened. - The issue remains unresolved. **Next Steps:** - Please let me know if this feature request is still relevant to the latest version of Dify by commenting on this issue. - If I do not hear back within 15 days, I will automatically close this issue. Thank you for your understanding and contribution!
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: langgenius/dify#20302