Hmbown/CodeWhale · error
API key on stdin exceeds the 8 KiB limit
Error message
API key on stdin exceeds the 8 KiB limit
What it means
The stdin API-key reader caps input at MAX_STDIN_API_KEY_BYTES (8 KiB). It deliberately reads one extra byte via take(limit + 1) so an over-long input is detected exactly, then bails rather than truncating or accepting an oversized key.
Solutions
- Trim the input to just the API key — only the bare token, ≤ 8 KiB: `head -c 8192` no; instead extract the correct field.
- If the credential genuinely exceeds 8 KiB, use the alternative non-stdin key configuration path (config/provider key store) rather than stdin.
- Verify with `wc -c` that the key input is under 8193 bytes: `wc -c key.txt`.
Example fix
// before cat full-credential-bundle.json | codewhale providers set-key --stdin // after jq -r .api_key full-credential-bundle.json | codewhale providers set-key --stdin
Defensive patterns
Strategy: validation
Validate before calling
let key = std::fs::read_to_string("key.txt")?;
if key.trim().is_empty() || key.len() > 8 * 1024 {
eprintln!("api key must be non-empty and at most 8 KiB");
} Try / catch
match read_api_key_from_stdin() {
Err(e) if e.to_string().contains("exceeds the 8 KiB limit") => {
eprintln!("input too large — extract the bare key token, not a whole credential file");
}
Err(e) => return Err(e),
Ok(k) => use_key(k),
} Prevention
- Pipe only the bare key token; never a JSON bundle, PEM, or multi-key file.
- Check `wc -c` on the source before piping.
- Use the config/provider key store for oversized credentials instead of stdin.
When it happens
Trigger: Piping or typing an API key into the stdin-reading subcommand whose total length exceeds 8192 bytes (8 KiB), e.g. `cat huge-key.txt | codewhale ... api-key-from-stdin`.
Common situations: Pasting a whole JSON credential blob or PEM instead of the bare key; accidentally piping a file of keys; concatenated env output including newlines and multiple secrets.
Understand the failure class
Background: payload too large / request exceeds maximum size: why libraries cap bytes and how to fix oversize payloads — this error's family across 50 libraries.
Related errors
- API key input is unexpectedly large
- A positive pull request number is required
- API key contains invalid control characters
- API key id must be lowercase hex characters — the part…
- API key must be - UTF-8 bytes
AI-assisted analysis of Hmbown/CodeWhale@73e0f67d83 (2026-09-22).
Data as JSON: /api/errors/16f1cc17c9aa0af6.
Report an issue: GitHub.
Appendix: source
Thrown at crates/cli/src/lib.rs:5532
};
metrics::run(metrics::MetricsArgs {
json: args.json,
since,
})
}
/// Maximum bytes read for an API key on stdin. Keys are short; anything
/// larger is a piped file, not a key.
const MAX_STDIN_API_KEY_BYTES: u64 = 8 * 1024;
fn read_api_key_from_stdin() -> Result<String> {
let mut input = String::new();
io::stdin()
.take(MAX_STDIN_API_KEY_BYTES + 1)
.read_to_string(&mut input)
.context("failed to read api key from stdin")?;
if input.len() as u64 > MAX_STDIN_API_KEY_BYTES {
bail!("API key on stdin exceeds the 8 KiB limit");
}
let key = input.trim().to_string();
if key.is_empty() {
bail!("empty API key provided");
}
Ok(key)
}
#[cfg(test)]
mod tests {
use super::*;
use clap::error::ErrorKind;
use codewhale_config::{ModelSource, ProviderSource};
use std::ffi::OsString;
use std::sync::{Mutex, OnceLock};
fn parse_ok(argv: &[&str]) -> Cli {
Cli::try_parse_from(argv).unwrap_or_else(|err| panic!("parse failed for {argv:?}: {err}"))View on GitHub (pinned to 73e0f67d83)