The idea is to have a code-monkey API authorization module. This module should have a way to: a) generate API keys + store the API keys (or their hashes) - ex: database ex: 1 API key for each Runtime project b) validate API keys