API credentials
Full project API keys are shown once and are not stored. Authentication headers and upstream credentials are not logged.
Legal
The hosted preview minimises sensitive data and separates identity, project credentials and upstream secrets.
Full project API keys are shown once and are not stored. Authentication headers and upstream credentials are not logged.
The hosted proxy records project, key, chain, method, status, latency and byte counts. Sensitive request payloads are excluded by default.
Sensitive administrative actions are recorded with actor, target, before/after state, timestamp and request identifier.