Short version: your API calls go directly to providers (OpenAI, Stripe, Resend…).
Elding is never in the request path. We store and serve the secret values, like any
secret manager, but your traffic never passes through us.
The common misconception
Elding is not a hosted MITM proxy. A lot of secret tooling routes your production traffic through a vendor gateway. Elding does not. This is the core of our design.In development
127.0.0.1). It injects the real key
and forwards the request directly to the provider. Elding’s servers only ever see
metadata (the names of the keys referenced), never the request body, query, or response.
In production
The honest trust model
Like Doppler, Infisical, Vault, or AWS Secrets Manager, Elding stores and serves your secret values. To serve them, our servers can decrypt them (envelope encryption, AES‑256‑GCM, KEK in KMS). This is the standard, accepted model for secret management.| We say ✅ | We never claim ❌ |
|---|---|
| Your API requests never transit our servers | ”We never see your secrets” |
| Local proxy, direct calls | ”Zero-knowledge” |
| We store and serve your secrets, never your traffic | ”We never touch your keys” |