Browse docs · Concepts
Get started
Concepts
Guides
Security
Reference
Docs / Concepts
Proxies
A transparent bridge to a REST API: the agent calls your proxy URL with its proxy key and the broker forwards the request to the real upstream with the real credential injected.
A proxy is the drop-in form of the bridge. Where a published endpoint exposes one fixed operation, a proxy forwards the caller's own HTTP request -- method, path, query and body -- straight through to a pinned upstream, injecting the real credential broker-side. The agent points an ordinary HTTP client (or an existing SDK) at the proxy and never holds the upstream key.
How a call flows
agent → GET https://your-broker/p/px_ab12/v1/charges (Authorization: Bearer pk_px_...)
broker → authenticates the proxy key, checks method + path + guardrails
→ forwards to https://api.stripe.com/v1/charges (Authorization: Bearer <real key>)
→ returns the upstream response to the agent
The agent sees only the response. The upstream secret is injected inside the broker and is never logged or returned.
Create one
In Proxies, choose New proxy and set:
- Upstream base URL, e.g.
https://api.stripe.com. The host is pinned here; callers control only the path beneath it. - Credential: the sealed credential whose secret is injected. Store the API key first in Credentials (provider
httpis the usual choice for a static key). - Auth header and scheme: how the secret is sent. Default
Authorization: Bearer <secret>. For a raw API-key header, set the header name (e.g.X-Api-Key) and schemenone. - Allowed methods: only these HTTP methods are forwarded; everything else is refused.
- Allowed path prefixes (optional): if set, only paths under them are forwarded. Leave blank to allow any path under the base.
The key is shown once. Call it by appending the upstream path:
curl -H "Authorization: Bearer pk_px_..." \ https://your-broker/p/px_ab12/v1/charges?limit=3
Least privilege and safety
- Pinned host. The upstream host comes from the proxy config, never the caller, and the broker refuses to follow a redirect to another host, so a proxy cannot be bent into a request against an internal service.
- Method and path allowlists. A read-only proxy can allow just
GETunder/v1/charges; a write proxy is a separate row with its own key. - Account guardrails and lockdown apply. An account-wide deny (policy agent
*) or a lockdown stops proxy traffic too. - Per-request audit. Every forwarded call writes one record (method, upstream host and path, outcome), with no secret.
Proxy or endpoint?
Use a proxy when you want an existing SDK or many routes to work with a single base-URL change. Use an endpoint when you want to expose exactly one operation with fixed parameters and nothing else. Proxy and endpoint keys are long-lived by nature; for agents that can use workload identity, that is the stronger option.