Skip to content
GridRouterhome

Search

Search providers, capabilities and pages

Bring your own keys: how GridRouter verifies vendor billing

When you call vendors with your own keys, GridRouter checks each call against the vendor's published billing rules and flags charges that don't match.

The GridRouter team2 min read

During launch every call on GridRouter runs on your own vendor keys. The vendor bills you directly, at your own rate, and GridRouter adds nothing. That raises a fair question: if we're not the ones charging you, how do you know the vendor charged you correctly?

Every call in your logs now answers it. GridRouter reads what the vendor says it charged, works out what the vendor's own published rules say it should have charged, and shows you whether the two match.

Your keys stay sealed

Keys you add are stored in a vault with envelope encryption and are only decrypted inside the call path. They never reach an agent's machine, and structured logs never contain them. Stored request and response bodies are redacted, the resolved key values are scrubbed out, and the result is encrypted with a key derived for your workspace alone.

Rules come from the vendor's own docs

For each vendor we research how it bills and write that down as a rule, with a link to the page it came from and the date we read it. A rule answers a few questions:

  • When is a call charged? On every call, on any success, only when a result is found, per group of records returned, or whatever the response says it cost.
  • How many credits? For example, a quarter of a credit for an email validation.
  • Is anything free? A record the vendor says you already bought, or a repeat inside a window.
  • Are retries and duplicates charged again?

Then, on every call, GridRouter reads the usage the vendor reports in its response headers or body, applies the rule to what actually happened (a hit, a miss or a failure, and how many records came back), and compares the two numbers.

The verdicts

What each billing verdict in your call log means.
VerdictWhen
Billed rightWhat the vendor reported matches what its rules say
Charged for a missThe vendor reported a charge for a call that found nothing or failed
Charged twice for a retryA repeat of a request the vendor already billed was billed again inside its window
Price mismatchThe reported charge differs from the rule on a hit or a record count
Can't verifyNo rule yet, or the vendor didn't report usage

In the log viewer you can filter to mismatches, open a call to see the vendor's rule in plain English next to the response, and see per vendor how many calls were billed right and how many credits were overbilled. Mismatches export as a CSV you can send the vendor with a dispute.

What's covered today

  • Vendors that report usage per call, in response headers or the body, can be checked on every call. A typical rule: an email find costs one credit when the address is valid, and a validation costs a fraction of a credit for a definitive answer.
  • Hunter publishes its rules, but it doesn't report usage per call, so its calls show the expected charge and read "Can't verify". Checking them needs a before-and-after balance check, which we haven't built because it costs an extra call per call.
  • Prospeo marks records you already bought as free and doesn't charge repeats within 90 days. It has no public per-credit price, so dollar amounts are left empty.

Refunds for results later proven invalid happen outside the API, so we show whether a vendor offers them but don't track them per call.

Why this is free

Checking a vendor's bill is part of keeping your keys safe, so it's on every plan, including Free. Paid plans will charge for storage and operations at scale, never for checking what you were charged.

Sources

  1. Hunter API credits
  2. Prospeo enrich person API
  3. GridRouter security

The router is free

Free while we launch. Keep your vendor accounts and bring their keys.