[FeatureRequest] Make the users that use your published workflow/tool use their own API KEY #6066

Closed
opened 2026-02-21 18:13:54 -05:00 by yindo · 1 comment
Owner

Originally created by @Emasoft on GitHub (Oct 12, 2024).

Self Checks

  • I have searched for existing issues search for existing issues, including closed ones.
  • I confirm that I am using English to submit this report (我已阅读并同意 Language Policy).
  • [FOR CHINESE USERS] 请务必使用英文提交 Issue,否则会被关闭。谢谢!:)
  • Please do not modify this template :) and fill in all the required fields.

1. Is this request related to a challenge you're experiencing? Tell me about your story.

I discovered with horror that published workflows/tools can be used by other users (nothing strange here) but that also the workflow will use my API KEY instead of that of the user (and this is very strange!). This is clearly wrong, and should be solved ASAP making Dify to ask the user to add the API KEY needed by the app/tool to their Dify configuration, and automatically use that one. Never an user should be able to explot the API KEY of the developer when he publish a web app/tool on Dify cloud.

2. Additional context or comments

No response

3. Can you help us with this feature?

  • I am interested in contributing to this feature.
Originally created by @Emasoft on GitHub (Oct 12, 2024). ### Self Checks - [X] I have searched for existing issues [search for existing issues](https://github.com/langgenius/dify/issues), including closed ones. - [X] I confirm that I am using English to submit this report (我已阅读并同意 [Language Policy](https://github.com/langgenius/dify/issues/1542)). - [X] [FOR CHINESE USERS] 请务必使用英文提交 Issue,否则会被关闭。谢谢!:) - [X] Please do not modify this template :) and fill in all the required fields. ### 1. Is this request related to a challenge you're experiencing? Tell me about your story. I discovered with horror that published workflows/tools can be used by other users (nothing strange here) but that also the workflow will use my API KEY instead of that of the user (and this is very strange!). This is clearly wrong, and should be solved ASAP making Dify to ask the user to add the API KEY needed by the app/tool to their Dify configuration, and automatically use that one. Never an user should be able to explot the API KEY of the developer when he publish a web app/tool on Dify cloud. ### 2. Additional context or comments _No response_ ### 3. Can you help us with this feature? - [ ] I am interested in contributing to this feature.
yindo added the 💪 enhancement label 2026-02-21 18:13:54 -05:00
yindo closed this issue 2026-02-21 18:13:54 -05:00
Author
Owner

@crazywoola commented on GitHub (Oct 14, 2024):

Thanks for the suggestion, however this is an expected behavior.
Dify is a platform for developers, you should notice that, we do not provide a user login system to shared applications nor the shared workflows. This should be maintained by the developers, they can choose their own strategies, as well as the api endpoint. You can simply treat these are meant for developers. For example, products are provided by AWS always gives you a pari of keys(ak, sk) or some api keys. You will not allow the user to get/set these keyparis.

@crazywoola commented on GitHub (Oct 14, 2024): Thanks for the suggestion, however this is an expected behavior. Dify is a platform for developers, you should notice that, we do not provide a user login system to shared applications nor the shared workflows. This should be maintained by the developers, they can choose their own strategies, as well as the api endpoint. You can simply treat these are meant for developers. For example, products are provided by AWS always gives you a pari of keys(ak, sk) or some api keys. You will not allow the user to get/set these keyparis.
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: langgenius/dify#6066