Hmbown/CodeWhale · error

API key on stdin exceeds the 8 KiB limit

Error message

API key on stdin exceeds the 8 KiB limit

What it means

The stdin API-key reader caps input at MAX_STDIN_API_KEY_BYTES (8 KiB). It deliberately reads one extra byte via take(limit + 1) so an over-long input is detected exactly, then bails rather than truncating or accepting an oversized key.

Solutions

  1. Trim the input to just the API key — only the bare token, ≤ 8 KiB: `head -c 8192` no; instead extract the correct field.
  2. If the credential genuinely exceeds 8 KiB, use the alternative non-stdin key configuration path (config/provider key store) rather than stdin.
  3. Verify with `wc -c` that the key input is under 8193 bytes: `wc -c key.txt`.

Example fix

// before
cat full-credential-bundle.json | codewhale providers set-key --stdin
// after
jq -r .api_key full-credential-bundle.json | codewhale providers set-key --stdin
Defensive patterns

Strategy: validation

Validate before calling

let key = std::fs::read_to_string("key.txt")?;
if key.trim().is_empty() || key.len() > 8 * 1024 {
    eprintln!("api key must be non-empty and at most 8 KiB");
}

Try / catch

match read_api_key_from_stdin() {
    Err(e) if e.to_string().contains("exceeds the 8 KiB limit") => {
        eprintln!("input too large — extract the bare key token, not a whole credential file");
    }
    Err(e) => return Err(e),
    Ok(k) => use_key(k),
}

Prevention

When it happens

Trigger: Piping or typing an API key into the stdin-reading subcommand whose total length exceeds 8192 bytes (8 KiB), e.g. `cat huge-key.txt | codewhale ... api-key-from-stdin`.

Common situations: Pasting a whole JSON credential blob or PEM instead of the bare key; accidentally piping a file of keys; concatenated env output including newlines and multiple secrets.

Understand the failure class

Background: payload too large / request exceeds maximum size: why libraries cap bytes and how to fix oversize payloads — this error's family across 50 libraries.

Related errors


AI-assisted analysis of Hmbown/CodeWhale@73e0f67d83 (2026-09-22). Data as JSON: /api/errors/16f1cc17c9aa0af6. Report an issue: GitHub.

Appendix: source

Thrown at crates/cli/src/lib.rs:5532

    };
    metrics::run(metrics::MetricsArgs {
        json: args.json,
        since,
    })
}

/// Maximum bytes read for an API key on stdin. Keys are short; anything
/// larger is a piped file, not a key.
const MAX_STDIN_API_KEY_BYTES: u64 = 8 * 1024;

fn read_api_key_from_stdin() -> Result<String> {
    let mut input = String::new();
    io::stdin()
        .take(MAX_STDIN_API_KEY_BYTES + 1)
        .read_to_string(&mut input)
        .context("failed to read api key from stdin")?;
    if input.len() as u64 > MAX_STDIN_API_KEY_BYTES {
        bail!("API key on stdin exceeds the 8 KiB limit");
    }
    let key = input.trim().to_string();
    if key.is_empty() {
        bail!("empty API key provided");
    }
    Ok(key)
}

#[cfg(test)]
mod tests {
    use super::*;
    use clap::error::ErrorKind;
    use codewhale_config::{ModelSource, ProviderSource};
    use std::ffi::OsString;
    use std::sync::{Mutex, OnceLock};

    fn parse_ok(argv: &[&str]) -> Cli {
        Cli::try_parse_from(argv).unwrap_or_else(|err| panic!("parse failed for {argv:?}: {err}"))

View on GitHub (pinned to 73e0f67d83)