FAQ

Do I need to know how to program?

No. Installation comes down to starting a container, and all configuration happens in an ordinary web interface: create a model, issue an access key, look at the log and the spending. Programs connect with an address they already know — nothing needs programming on their side. The only technical string is the database connection in the startup file, and even that is easiest to copy once from the installation guide.

How is this different from the proxy server built into Xedant Agent?

They are different things, and the names make them easy to confuse. The built-in proxy server lives inside Xedant Agent, serves only that agent and is switched on in the agent’s settings — nothing external can connect to it. Proxy Agent is a standalone application on your server: all your programs talk to it at once, with any models and any vendors, and it adds access keys, limits, a log, analytics, secret hiding and a proxy for ordinary traffic. Details about the built-in one are on the Proxy Server page, about the standalone one — in the Getting Started section.

Which programs will work?

Any that can talk to an OpenAI- or Anthropic-format address: in such a program’s settings you simply change the server address and the key. That covers programmer assistants (Claude Code included), your own scripts, internal services and everything else that calls models over these formats. Programs with no AI connection at all — a browser, a download manager, any proxy-capable client — can also go through this same server, but as ordinary traffic. Details are in the Connecting Applications and Tunnel Service sections.

Is a separate database mandatory?

Yes, we will say it honestly: the product runs only on PostgreSQL, and that is the single mandatory setting. There is no database inside the container — without a connection string the app will not start. The good news is that a separate database server is not required: it comes up next to the app in the same startup file, as one service. The setup is described in the Installation section.

Is an activation key required?

Yes, a key is required — let’s be direct about it. Proxy Agent checks the license: without a valid key, your programs’ requests to the models do not pass, and the proxy service refuses connections. The product itself still starts and works as usual: sign-in, settings, models, access keys, logs, analytics, secret hiding and management over the API are all available without a key. The key is set on the server with the AGENT_LICENSE variable and is read when the container starts. What exactly is closed, how to set the key and how to check its state — on the Licensing page. Prices are the same as the neighboring products: personal $197, company $497, service $970.

How do I limit a contractor’s spending?

Every person or contractor gets their own access key. A key carries four spending limits — per day, week, month and in total — and they are set in money, not in “portions of text” (tokens), so they are understandable without conversion. As soon as the first one is reached, the key stops passing requests, and the log shows how much was spent and on what. On top of that, a key can be allowed only part of the models: then nobody will use an expensive model through it. Details are in the Access Keys and Costs & Limits sections.

Are request texts stored?

No, and that is deliberate. Only service information remains in the log: the time, the model, the key, the token volume, the duration, the cost and the error text. The requests and responses themselves are never written — your conversations with the models do not pile up anywhere, not even with you. If for some reason you need to keep the content too, that has to be done outside the product. Details are in the Request Log section.

How does secret hiding work, and is it safe?

The feature is off by default — you enable it yourself in the settings. Then you create a rule: a name, a search pattern and a list of secrets (keys, passwords, document numbers). Before a request is sent to the model, the product finds only the values you listed in the text and replaces them with conventional placeholders; in the model’s reply those placeholders are put back where they were. The placeholders are the same for the same value, so the request keeps its meaning. If the check cannot be completed, the request does not go to the vendor at all — the product chooses the safe refusal. Leak events are recorded, but the secrets themselves are masked in them. One honest caveat: the mappings live in the working-state volume; if the volume is not mounted, after recreating the container the placeholders already sent cannot be restored. Details are in the Anonymization section.

Can ordinary traffic go through it?

Yes. Besides models, the product can act as an ordinary proxy server: every channel of yours can get its own port that accepts both HTTP and SOCKS5, with its own access-key check. By default nothing listens — a channel starts accepting connections only after you give it a port. Connections on that port reach the internet only through that channel. The important difference from model traffic: ordinary traffic is counted in volume and shown in a separate log, but is never counted in money and does not consume the key’s limits. Details are in the Tunnel Service section.

Where does the data go?

Only where you send it yourself: to the model vendors you choose, or through your own channels. Vendor keys, access keys, logs, analytics and secret-hiding rules live on your server — you do not need an account with us, and nothing is sent to anyone else’s cloud. The only exception is if you enable statistics delivery to your own ClickHouse address yourself. One thing to keep in mind: the administrator of your server sees the settings and logs in full. Details are in the Access & Security section.

Did not find your answer — look into the documentation or start with the installation.

← Back to the Proxy Agent section home