Identity & keys
API requests use a Bearer key. Keep keys server-side. Available sign-in and second-factor methods depend on current system configuration.
From API keys and request routing to provider processing, logs, and incident response, this page describes the service's current security boundaries.
API requests use a Bearer key. Keep keys server-side. Available sign-in and second-factor methods depend on current system configuration.
The gateway sends the request content required for the selected model call to the corresponding upstream provider. Changing models may also change the data processor.
The console can expose request, usage, and error diagnostics. Retention depends on data type, account status, legal duties, and security needs.
The public status page shows only configured monitors. Diagnose account-level failures with a Request ID and request logs.
Do not submit personal data, credentials, or sensitive business content unless required. The privacy policy and terms govern information handling.
Separate and rotate API keys by application. Available 2FA, passkey, and permission controls depend on current account configuration. Do not share privileged accounts.
Submit only what a task requires. Remove, redact, or de-identify personal data, credentials, regulated data, and sensitive business information before use.
Logs and billing records serve different purposes. Data that is no longer needed is deleted, anonymized, or restricted as applicable.
Security certifications and assurances are displayed only when supported by publishable evidence. Report suspected issues through support or the published support email.
POLICY & STATUS