Service data flow
The gateway processes an authenticated request so it can validate access, select a configured upstream path, and return an API response. Request content is used to perform the requested inference operation. Client bearer tokens are used for gateway authentication and are not forwarded upstream. The gateway uses server-side upstream credentials for configured providers instead. Clients should treat prompts, model inputs, and outputs as data that may be processed by the configured service path needed to complete the request.
Do not submit passwords, raw bearer tokens, private keys, unredacted credentials, or other secrets in a prompt. Do not put tokens in URLs, source control, screenshots, or agent transcripts. Use the developer portal to learn the required authentication header and use the authorized operator channel when you need a credential, revocation, or support.
Operational records
The service may return request identifiers, route warnings, and status information that help an authorized operator diagnose an integration. Share only redacted diagnostic details. This page describes the current technical service boundary and does not replace a legal agreement, a customer-specific data-processing agreement, or a retention commitment. Product owners must provide those terms before relying on the service for a use case that requires them.