What it watches
OpenRouter is read only when one of its keys is found in an app’s public code: which key it is, whether it is off, its credit limit and what it spent. It feeds no budget or spike alert.
What Keelnest reads
- Credential: Management key.
- Reads: your key list (names, the start and end of each key, whether it's on, its credit limit) and a leaked key's daily spend.
OpenRouter has no read-only key, so a management key could also create or delete keys; Keelnest only reads with it. Only your default workspace is read, and the list only while a key from your site is leaked. It does not feed Cost Guard.
Read-only, like every connection: Keelnest never refunds, charges, changes a price, edits a setting or an environment variable, merges on its own or runs a migration. The credential is checked with one read call before it is stored, encrypted at rest, and can be revoked at the provider at any time. Security says the whole of it.
How to connect
- Create the management key. openrouter.ai > Settings > Management keys > Create. Keelnest only reads your key list and a leaked key's spend. Open OpenRouter.
- Paste it into Keelnest. In your workspace, open Integrations, find OpenRouter and press Connect. Keelnest makes one read call to confirm the credential works and stores it encrypted.
- Link the apps. Under Manage, pick the applications whose keys this account holds. Nothing is read until a key from one of them is found in public code.
Connect OpenRouter in a few minutes.
Create a workspace, free for your first app, and connect it from Integrations — or run the free health check on any public address first.