{"repo":"behind24proxies/keycontrol","free":true,"listed":false,"github":"https://github.com/behind24proxies/keycontrol","clone":"git clone https://github.com/behind24proxies/keycontrol.git","description":"Hide your master keys behind \"virtual keys\" with limited permissions","language":"TypeScript","stars":15,"topics":["api","authentication","key","proxy","rate-limiter","rate-limiting","redis-cache","virtual"],"license":null,"category":"networking-infra","readme_excerpt":"Open-Source API Gateway & Key Management Protect your secret API keys by splitting them into scoped, rate-limited virtual keys — without ever exposing the originals. 🚀 Quick Start · ⚙️ How It Works · 📖 API Docs · 🛠️ Dev Setup --- Overview KeyControl is a self-hosted API gateway that sits between your clients and upstream API providers (Bunny.net, Vercel, Anthropic, Twilio, etc.). It takes a single \"secret\" API key and lets you create multiple virtual keys (prefixed um- ), each with its own rate limits, IP rules, method restrictions, and endpoint access controls. When a request comes in with a virtual key, KeyControl validates all the rules, swaps the virtual key for the real one, and forwards the request — all transparently. If a virtual key is compromised, revoke it instantly without rotating your actual secret. Features 🔑 Virtual Key Splitting — One secret key → many scoped virtual keys limited to certain endpoints/methods (prefixed um- ) 🎛️ Presets — Reusable access policies that bundle resources, methods, rate limits, and IP rules 🚦 Rate Limiting — Multi-window sliding limits (e.g., 10/sec + 100/min) per key 🛡️ IP Allowlists & Blocklists — IP rules with wildcard patterns and CIDR notation 🔒 Endpoint Groups — Restrict keys to specific URL patterns and HTTP methods 📊 Request Logging — Full request audit trail with filtering, togglable logging and IP logging 🌐 Transparent Proxying — Automatic key replacement and request forwarding 🔐 2FA Support — Optional TOTP two","default_branch":null,"files":null,"tree":[],"storefront":"/r/behind24proxies","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/behind24proxies/keycontrol/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}