Security
What the safe-key and the encrypted upstream key protect, and what they do not.
The safe-key
| Property | Value |
|---|---|
| Format | sk-safe- followed by 43 base64url characters: 51 in total, the length of an OpenAI key |
| Contents | 32 random bytes. No user, platform or mode is encoded into it |
| At rest | Looked up by sha256(key), so the plaintext is never a stored identifier |
| If it leaks | It reveals nothing about you or your provider key. The exposure is limited to your quota until you revoke it |
The upstream key
| Property | Value |
|---|---|
| At rest | AES-256-GCM encrypted, keyed with HKDF-derived material |
| Decryption | Inside the gateway, only at the moment a request is forwarded |
| Exposure | Never sent to the browser and never included in an API response |
Revocation
Revoking or pausing a key in the dashboard takes effect on the next request, wherever it arrives from. Nothing has to expire.
Limitations
Visitor identity is derived from the caller's user-agent and IP, both of which the client controls. That stops careless leaks and low-cost scripts; it does not stop an attacker who rotates addresses. Per-key revocation, the PV fuse and the alert email are the tools for that case.