Provider keys never enter the agent
Workloads call a proxy that authenticates them and attaches the real key upstream.
WhereConsole
Introduced Mar 24, 2026
How it works
The key stays upstream.
Workloads call the proxy; it authenticates them and attaches the real provider key on the way out.
Two API shapes, one endpoint.
The proxy serves both Anthropic- and OpenAI-shaped APIs — which is what makes agent CLIs interchangeable.
Metered in passing.
Every call is counted as it goes through — usage needs no separate integration.
See it on your own cluster.
Thirty minutes, your infrastructure, your stack. Or skip the call — it is one Helm release onto a cluster you already run.