Overview
What Sluiceline is, and how a request flows through the gateway.
Sluiceline sits between your app and the AI providers you already use. You keep
the real provider key here and your app calls the gateway with an opaque safe-key
(sk-safe-…) instead. The gateway enforces quotas and per-visitor limits, then
forwards to the provider with the real key.
Request flow
- Your app sends the provider's normal request to the gateway, authenticated with a safe-key.
- The gateway resolves that safe-key: which platform it targets, which mode it runs in, which quotas apply.
- Safe mode decrypts the real key, swaps the credential, and streams the provider's response back unchanged.
- Mock mode returns a provider-shaped response and never contacts the provider.
The response envelope, the streaming format and the error shapes are the provider's own, so an SDK cannot tell that a gateway is in the path.
Modes
| Safe | Mock | |
|---|---|---|
| Forwards to the provider | Yes | No |
| Uses the encrypted upstream key | Yes | No |
| Consumes PV / UV quota | Yes | No |
| Fires alerts and the circuit breaker | Yes | No |
| Intended for | Production | Development and demos |
The mode is a property of the key, not of the URL. The prefix selects the platform; the credential selects the mode. See Safe vs Mock.
What changes in your code
Two values:
| Before | After | |
|---|---|---|
| Base URL | https://api.openai.com/v1 | https://sluiceline.com/openai |
| Credential | your provider key | your safe-key |
Request bodies, streaming, retries and error handling stay as they are. One-click switching lists the base URL and the credential header for every platform.
Next
- Quickstart — your first request through the gateway.
- Credentials — the header each platform uses.
- Quotas & limits — how PV and UV protect the real key.
- Errors — every status code the gateway returns.