dify/api
yungle246 be6612f454 feat: allow knowledge base API keys to be scoped to a single dataset
Reintroduce the nullable api_tokens.dataset_id column (dropped in 2e9819ca5b28)
so dataset API keys can opt into per-knowledge-base scoping:

- NULL dataset_id keeps today's workspace-wide behavior, so every existing key
  and the existing /datasets/api-keys create route are unchanged.
- validate_dataset_token rejects a bound key for any other dataset, and for
  endpoints that carry no dataset id (e.g. list-all), with 403.
- CachedApiToken carries dataset_id with a None default so cache entries
  written before deploy keep deserializing.
- The per-dataset console routes in apikey.py (previously dead code that 500ed
  on a missing ApiToken.dataset_id) now create bound keys; their list returns
  bound keys plus workspace keys so the dataset page shows the full access
  picture.
- Frontend: the knowledge base API access popover gains an API keys entry; the
  secret key modal accepts datasetId, shows a scope column, and offers a
  workspace / this-knowledge-base scope choice on create. New strings are
  localized for all 23 locales.
2026-06-11 11:41:47 +09:00
..
.idea
.vscode feat: collaboration (#30781) 2026-04-16 02:21:04 +00:00
clients feat(agent): Sandbox / CLI Agent (dify.shell) + read-only sandbox file inspector (#36984) 2026-06-03 22:37:31 +00:00
commands feat: add cross-environment app migration workflow (#36765) 2026-05-28 07:30:33 +00:00
configs fix(api): expose device-flow approve rate limit as env var (#37083) 2026-06-05 02:56:23 +00:00
constants feat(api): Agent App type S1 — AppMode.AGENT + create flow + binding (#36829) 2026-06-02 03:50:10 +00:00
context chore(api): convert AppContext from ABC to Protocol (#37203) 2026-06-09 03:16:39 +00:00
contexts chore(api): align Python support with 3.12 (#34419) 2026-04-02 05:07:32 +00:00
controllers feat: allow knowledge base API keys to be scoped to a single dataset 2026-06-11 11:41:47 +09:00
core feat: agent slash menu backend (#37268) 2026-06-10 10:40:03 +00:00
dev chore(api): Suppress unknown contract checks by default (#36969) 2026-06-09 08:32:34 +00:00
docker fix: add miss celery queue (#35282) 2026-04-16 02:40:14 +00:00
enterprise ci: add flag for linter (#37018) 2026-06-08 04:53:12 +00:00
enums refactor: quota v3 integration (#35436) 2026-04-27 01:49:40 +00:00
events feat: add cross-environment app migration workflow (#36765) 2026-05-28 07:30:33 +00:00
extensions chore: [Refactor/Chore] if isinstance to match case #35902 (#37087) 2026-06-09 09:54:04 +00:00
factories fix: validate conversation variable description length to prevent varchar(255) truncation error (#33038) 2026-06-10 07:28:12 +00:00
fields feat: agent slash menu backend (#37268) 2026-06-10 10:40:03 +00:00
libs feat(api,cli): strict UUID validation for app-id and workspace-id (#37212) 2026-06-09 07:35:18 +00:00
migrations feat: allow knowledge base API keys to be scoped to a single dataset 2026-06-11 11:41:47 +09:00
models feat: allow knowledge base API keys to be scoped to a single dataset 2026-06-11 11:41:47 +09:00
openapi/markdown feat: agent slash menu backend (#37268) 2026-06-10 10:40:03 +00:00
providers ci: add flag for linter (#37018) 2026-06-08 04:53:12 +00:00
repositories chore(api): convert RecommendAppRetrievalBase and WorkflowPauseEntity from ABC to Protocol (#37182) 2026-06-08 14:17:07 +00:00
schedule chore(api): Fix several typing errors (#37119) 2026-06-06 01:44:32 +00:00
services feat: allow knowledge base API keys to be scoped to a single dataset 2026-06-11 11:41:47 +09:00
tasks ci: add flag for linter (#37018) 2026-06-08 04:53:12 +00:00
templates feat: collaboration (#30781) 2026-04-16 02:21:04 +00:00
tests feat: allow knowledge base API keys to be scoped to a single dataset 2026-06-11 11:41:47 +09:00
.dockerignore
.env.example feat(plugin): cache plugin model providers by tenant (#36449) 2026-05-23 09:12:09 +00:00
.importlinter refactor(api): use standalone graphon package (#34209) 2026-03-27 21:05:32 +00:00
.ruff.toml chore: reorg imports (#35308) 2026-04-16 08:50:02 +00:00
AGENTS.md feat(api): Flask-RESTX response() vs actual return value checker (#36488) 2026-05-21 15:05:06 +00:00
app_factory.py feat(api): introduce model-type migration script (#36520) 2026-05-27 02:12:11 +00:00
app.py feat: collaboration (#30781) 2026-04-16 02:21:04 +00:00
celery_entrypoint.py chore(api): adjust monkey patching in gunicorn.conf.py (#26056) 2025-09-22 18:23:01 +08:00
celery_healthcheck.py fix: lighten the health checks for the Worker and Worker Beat services, and disable them by default (#34572) 2026-04-06 02:26:26 +00:00
cnt_base.sh add cnt script and one more example (#28272) 2025-11-18 16:44:14 +09:00
conftest.py test(api): manage backend pytest services natively (#36235) 2026-05-19 07:52:15 +00:00
dify_app.py refactor(api): tighten login and wrapper typing (#34447) 2026-04-02 09:36:58 +00:00
Dockerfile feat(api): introduce select, file and file list form input types to Human Input node (#36322) 2026-06-04 01:54:28 +00:00
Dockerfile.dockerignore build: fix api docker build (#36423) 2026-05-20 03:48:18 +00:00
gunicorn.conf.py docs(api): update docs about gevent setup in app.py (#27611) 2025-10-30 15:43:08 +08:00
pyproject.toml chore(deps): bump the storage group across 1 directory with 5 updates (#37153) 2026-06-09 14:43:22 +08:00
pyrefly-local-excludes.txt chore(api): Fix several typing errors (#37119) 2026-06-06 01:44:32 +00:00
pytest.ini chore: add pytest XML and branch coverage reports (#33730) 2026-03-19 17:08:34 +08:00
README.md chore: Remove pyright in favor of pyrefly (#36154) 2026-05-14 05:49:08 +00:00
uv.lock feat(dify-agent): sync shell and back proxy updates (#37159) 2026-06-10 03:04:32 +00:00

Dify Backend API

Setup and Run

Important

In the v1.3.0 release, poetry has been replaced with uv as the package manager for Dify API backend service.

uv and pnpm are required to run the setup and development commands below.

The scripts resolve paths relative to their location, so you can run them from anywhere.

  1. Run setup (copies env files and installs dependencies).

    ./dev/setup
    
  2. Review api/.env, web/.env.local, and docker/middleware.env values (see the SECRET_KEY note below).

  3. Start middleware (PostgreSQL/Redis/Weaviate).

    ./dev/start-docker-compose
    
  4. Start backend (runs migrations first).

    ./dev/start-api
    
  5. Start Dify web service.

    ./dev/start-web
    

    ./dev/setup and ./dev/start-web install JavaScript dependencies through the repository root workspace, so you do not need a separate cd web && pnpm install step.

  6. Set up your application by visiting http://localhost:3000.

  7. Start the worker service (async and scheduler tasks, runs from api).

    ./dev/start-worker
    
  8. Optional: start Celery Beat (scheduled tasks).

    ./dev/start-beat
    

Environment notes

Important

When the frontend and backend run on different subdomains, set COOKIE_DOMAIN to the sites top-level domain (e.g., example.com). The frontend and backend must be under the same top-level domain in order to share authentication cookies.

  • Generate a SECRET_KEY in the .env file.

    bash for Linux

    sed -i "/^SECRET_KEY=/c\\SECRET_KEY=$(openssl rand -base64 42)" .env
    

    bash for Mac

    secret_key=$(openssl rand -base64 42)
    sed -i '' "/^SECRET_KEY=/c\\
    SECRET_KEY=${secret_key}" .env
    

Testing

  1. Install dependencies for both the backend and the test environment

    cd api
    uv sync --group dev
    
  2. Run the tests locally with mocked system environment variables in tool.pytest_env section in pyproject.toml, more can check Claude.md

    cd api
    uv run pytest                           # Run all tests
    uv run pytest tests/unit_tests/         # Unit tests only
    uv run pytest tests/integration_tests/  # Integration tests
    
    # Code quality
    ./dev/reformat               # Run all formatters and linters
    uv run ruff check --fix ./   # Fix linting issues
    uv run ruff format ./        # Format code
    uv run pyrefly check         # Type checking
    

Generate TS stub

uv run dev/generate_swagger_specs.py --output-dir openapi

use https://jsontotable.org/openapi-to-typescript to convert to typescript