v0.29
14 September 2026
Backup provider keys: a refused key no longer cuts the service
- The x-provider-key header takes up to five keys separated by commas. When the provider refuses a key for itself, the request restarts on the next one with the same model, before the first byte is written to your client.
- Never on a limit the provider imposes. A rate limit or a tier's monthly ceiling does not change key: OpenAI's terms forbid working around its limits, and a refused request still counts against the per-minute limit.
- Keys are still neither logged nor stored. To remember a refusal, the proxy keeps a fingerprint computed with a secret drawn at startup, erased at most 61 minutes after the key was last used.
- A memory reorders, it never removes. A key that is invalid, out of credit or at the ceiling you set is tried last for 15 minutes, and its first success clears the memory.
- No capacity promised: keys from the same organisation share its limits and its credit. The phrase load balancing was cut from the design before the first line of code, along with the mode that would have spread your prompts across several accounts.
Our mistake
Our own texts promised more than the code. They said a refused key was tried last for 15 minutes whatever the refusal. That is only true of a key that is invalid, out of credit or at the ceiling you set, and at OpenAI of a key without access to the model, for that model. The texts say it now.