Skip to content
GridRouterhome

Search

Search providers, capabilities and pages

Security and governance

Security and governance built into every call

Your vendor keys, data and spend stay inside your workspace, and every change is on the record.

See it working

Scoped API keysDemo dataOpen in the demo

API keys

Keys call the API and MCP server for this workspace. Keep a backup key so rotating or revoking the primary never causes downtime.

NameKeyScopesCreatedLast usedExpiresCredit limitActions
Acme outbound (production)primary
grid_live_demo7Hq2…call, run, catalog:read, balance:read2026-08-203 min agoNever$12.48 of $50.00 per month
Research agent
grid_live_demoK81x…call, run, catalog:read2026-09-189 min agoNever$1.21 of $5.00 per day
CI smoke testsci
grid_test_demo4f2a…call, catalog:read2026-08-315 h agoNeverNone
1 revoked key
  • grid_live_demo0a9d… Old laptop (created 2026-07-12)

Lost every key? Owner recovery codes are in Sessions and recovery.

Each key with its scopes, spend limit and last use, from the example workspace. Secrets are shown once, at creation.

What you get

  • Envelope-encrypted vault

    Vendor keys are sealed per workspace, write-only, and injected server-side; they never reach your code or your agents.

  • Workspace isolation

    Forced Postgres row-level security on every tenant table, and per-workspace keys for the cache and stored bodies.

  • Scoped API keys

    Scopes, spend limits, expiry dates, IP allowlists and zero-downtime rotation with a grace period.

  • Roles

    Owner, admin, developer, billing and viewer, mapped to what each can read and change.

  • Hash-chained audit log

    Member, role, key, recovery-code and billing changes, each with who did it. A changed or deleted entry breaks the chain.

  • Security events

    A key used from a new IP raises an alert; sign-ins are rate-limited with account lockout; owners hold one-time recovery codes.

How it works

  1. Add vendor keys; they're sealed in your workspace's vault and never shown again.

  2. Create an API key per app or agent with only the scopes and budget it needs.

  3. Review sessions, roles and the audit log; rotate keys without downtime.

POST /v1/keys
curl https://api.gridrouter.io/v1/keys \
  -H "Authorization: Bearer $GRID_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
    "name": "Research agent",
    "scopes": ["call", "catalog:read"],
    "limit_micro": 5000000,
    "limit_reset": "day",
    "allowed_ips": ["203.0.113.0/24"]
  }'

Questions

Can GridRouter staff read my vendor keys?

No. Keys are encrypted under your workspace's key, write-only through the API, and decrypted only inside the worker that makes the call.

Is GridRouter SOC 2 certified?

Not yet. Our controls and the latest audit are published on the security page, and we'll say so when a report exists.

How do I report a vulnerability?

See /.well-known/security.txt and the security page for the disclosure process.

Try it on your own data

Free while we launch. Bring your vendor keys; no card needed.