Skip to content
OrbAPI

Security

Last updated 1 October 2026

A marketplace that holds other people's API keys has one job above all others. This is how the gateway is designed to do it.

Seller keys

  • Encrypted on arrival with a key held in a managed key service, never written to logs.
  • Decrypted only in the gateway process, only for the lifetime of a request.
  • Never returned by any API, never visible to buyers or shown again in the dashboard.
  • Deleted when a listing is revoked.

Spend caps

Every listing has a hard cap set by the seller. The gateway reserves capacity against the cap before it sends a request and stops at the limit, including under concurrent load. Sellers can pause a listing at any time.

Buyer keys

  • Stored hashed. The full key is shown once, at creation.
  • Can be scoped to markets, given a spend limit and rotated without downtime.
  • Carry a recognisable prefix so secret scanners can catch leaks.

Request data

Traffic is encrypted in transit. Request and response bodies pass through the gateway and are not stored, unless a buyer turns on logging for their own key.

Status of these controls

The gateway is in private preview. The controls above describe its design. Independent audit reports will be linked here when they exist. We do not claim a certification we do not hold.

Report a vulnerability

Write to security@orbapi.dev. Please include steps to reproduce, and give us reasonable time to fix the issue before you publish. We will not take legal action against research done in good faith that avoids privacy violations, data destruction and service disruption. A machine-readable contact is at /.well-known/security.txt.