<!-- https://zerolog.ch/docs/keyproxy · Docs / Keys and privacy -->
# Key proxy for third-party keys

> Store an API key for a third-party provider (Cloudflare, Tailscale, Stripe, and others) and agents in your chats can use it without ever seeing the real value.

Store an API key for a third-party provider (Cloudflare, Tailscale, Stripe, and others) and agents in your chats can use it without ever seeing the real value. Only a placeholder reaches an agent; the real key stays in a separate, dedicated key service and is swapped in only on the way out to the provider.

- You register a passkey before your first key — it's what guarantees that access can only ever be widened with your confirmation, never by the app alone.
- New keys start **read-only**. Pick a template (for example "DNS for one zone") to grant more, or switch on **full access** with a passkey confirmation. Outside full access, payments and orders always wait for your approval; under full access they go through without asking.
- You can bring your own AI provider key (OpenAI and others). Requests with it go straight to that provider, so its data retention applies to them — not ZeroLog's zero-data-retention promise.
- Any new secret a provider hands back — a freshly created token, for example — is caught and stored the same way. An agent only ever sees a placeholder for it too.
- Lock a key instantly from the panel. A locked key stops working everywhere at once.
- Containers with their own VPN access do not go through the key service and cannot use keys stored here — this is enforced technically, not just documented: such a workspace never receives key-service trust or secrets in the first place.
- A site hosted elsewhere reads its own code, including anything embedded in it — prefer a key limited to what that site actually needs.
