Local selective proxy
Intercept only sensitive API traffic while normal browsing and low-risk calls stay direct.
KeyRelay
KeyRelay routes sensitive API calls through a secure relay so agents can take action without ever touching real provider keys.
No raw keys on endpoints
100%
Typical added latency
20–100ms
Approval channels
Email · SMS · WhatsApp
curl -fsSL https://get.keyrelay.dev/install.sh | bash keyrelay login keyrelay proxy start --mode enforce keyrelay policy apply default-supabase.yml
Intercept only sensitive API traffic while normal browsing and low-risk calls stay direct.
Real provider keys stay in a remote vault. Your agent never sees raw credentials.
Apply allow, deny, or approval rules by host, path, method, and process identity.
High-risk actions can require one-tap human approval before execution.
Correlation IDs and immutable events give full visibility over who did what and when.
Self-hostable architecture with optional managed hosting for teams that want less ops.
Run KeyRelay on your own infrastructure, or use managed hosting as soon as it lands. Either way, the architecture keeps real secrets off endpoints.