Gateway & virtual keys
Route supported provider calls through a hosted, centrally metered gateway without distributing a provider key.
On this page
Choose where provider traffic travels
In local or shared-device mode, your machine calls the provider directly. In gateway mode, request and response content passes through the gateway's memory. The gateway authenticates a scoped virtual key and uses the same atomic budget ledger as shared devices.
Configure a provider credential in Settings → Gateway & shared budgets, or select BYOK passthrough. Stored provider keys use envelope encryption. Create a virtual key, assign its user/project and provider/model scopes, then copy its lsh_ value once. Only its hash and prefix persist.
Connect your local proxy
Use a fresh LEASH_HOME. Device enrollment and gateway enrollment are separate transport modes. Save the one-time key in a private file, connect, and restart the proxy. The local proxy still provides local caps, hooks and panic.
chmod 600 ./leash-key.txt
export LEASH_HOME="$HOME/.leash-hosted"
leash gateway connect \
--url https://YOUR_DOMAIN/gateway \
--key-file ./leash-key.txt
leash start
# Another terminal, with the same LEASH_HOME:
leash run --cap 5 -- claudeConnect an existing SDK
Use a fresh session UUID for each agent run. Without x-leash-session, the key uses its persistent default session. Anthropic's baseURL is https://YOUR_DOMAIN/gateway/anthropic. A passthrough key also requires x-leash-provider-key on each request.
import OpenAI from "openai";
import { randomUUID } from "node:crypto";
const client = new OpenAI({
apiKey: process.env.LEASH_VIRTUAL_KEY,
baseURL: "https://YOUR_DOMAIN/gateway/openai/v1",
defaultHeaders: { "x-leash-session": randomUUID() },
});Revoke and disconnect
Revoking a virtual key blocks new calls and stops active gateway streams on their next safety poll. Revoking a stored provider credential wipes its encrypted payload and revokes bound keys. Removing the assigned workspace membership denies further admission.
To return a local proxy to direct provider mode, run leash gateway disconnect and restart it. Your provider credentials are then needed locally again.