<!-- https://zerolog.ch/news/key-proxy-agents-never-see-your-keys -->
# Key proxy: your agents use your API keys without ever seeing them

2026-10-06 · Product

> Keys for Cloudflare, Stripe, GitHub and other services now live in a separate key service, and agents in your workspace only ever get a placeholder.

An agent that deploys your site needs your Cloudflare token. Until now that meant putting the token where the agent could read it, and anything an agent can read it can also copy or send elsewhere.

Now you add a key under *Settings → Keys (third-party APIs)*. It goes to a key service on its own machine, which the rest of ZeroLog can't read keys back from. The agent sees a placeholder. When its request leaves the workspace, the key service checks it, swaps in the real key and blacks out any secret in the answer.

- **Passkey first.** You register a passkey before your first key. A new passkey can't widen anything for 24 hours.
- **Read-only to start.** Anything more waits for you, and allowing more needs your passkey.
- **Payments ask first**, unless you give a key full access, which takes a passkey and a warning.
- **Lock instantly.** A locked key is refused everywhere.

Profiles cover Cloudflare, Tailscale, Stripe, GitHub, Vercel, Netlify, Hetzner, Porkbun, Infomaniak and OpenAI. `zl_` keys let tools outside ZeroLog use the same rules.

Before switching it on we ran it against the real Cloudflare API with a narrow test token, attacks included: duplicate JSON keys, path tricks, a placeholder hidden in a DNS record, another account's placeholder, replayed signatures, expired approvals, widening without a passkey. All were refused. The run also found five bugs that mock-ups had missed; they were fixed first.

Two limits. Requests with your own AI provider key follow that provider's data rules, not our zero-data-retention promise. And a workspace gets either the key proxy or its own VPN, never both.

The key service logs decisions, not content: who allowed or locked what, and when. That log is kept until you delete your account, which clears the key service first. More in the [key proxy docs](https://zerolog.ch/docs/keyproxy.html).
