Point your agent here.
Give your agent https://thru.snd.one and tell it which API you want to use. It can read the instructions and help you find the right credentials.
Your agent needs an API. It doesn't need your API key. Thru puts a secure connection in between, adding your credentials behind the scenes.
ANY API. YOUR CREDENTIALS. A SEPARATE ACCESS TOKEN.
Let your agent handle the setup. You handle the one thing that should stay private.
Give your agent https://thru.snd.one and tell it which API you want to use. It can read the instructions and help you find the right credentials.
It defines the destination, credential fields, and how the keys belong in each request. Thru returns a private setup link for you.
Open the link, review the exact destination and permissions, and enter your credentials directly into Thru. Tell your agent you're connected.
Your agent calls the proxy with its own access token. Thru adds the API credentials on the server, forwards the request, and returns the response.
No account or credential is needed to create a proxy. Define a connection, give the user its auth_url, then use your separate access_token to check its status and send requests.
Ask the user to enter provider credentials on the setup page. Keep them out of the conversation. Your access token also grants API access; keep it private.
curl -X POST 'https://thru.snd.one/api/proxies' \
-H 'Content-Type: application/json' \
-d '{
"name": "GitHub workspace",
"description": "Read issues and pull requests.",
"target_url": "https://api.github.com",
"credential_url": "https://github.com/settings/tokens",
"credentials": [
{"key": "api_key", "label": "GitHub access token"}
],
"headers": {"Authorization": "Bearer {{api_key}}"},
"allowed_methods": ["GET", "HEAD", "OPTIONS"]
}'# Send the returned auth_url to the user.
# They enter their GitHub token directly into Thru.
# Then check the connection with your agent access_token:
curl 'https://thru.snd.one/api/proxies/PROXY_ID' \
-H 'Authorization: Bearer AGENT_ACCESS_TOKEN'
# Wait until the response says:
{
"status": "authenticated",
"proxy_url": "https://thru.snd.one/p/PROXY_ID"
}# Use the proxy URL in place of the API base URL.
# Authenticate to Thru with the agent access_token.
curl 'https://thru.snd.one/p/PROXY_ID/repos/octocat/Hello-World/issues' \
-H 'Authorization: Bearer AGENT_ACCESS_TOKEN' \
-H 'Accept: application/vnd.github+json'
# Thru adds the user's GitHub token server-side.
# The agent gets the API response, never the stored key.Describe the credential fields once. Thru handles the authentication on every request.
GitHub, DigitalOcean, and any API that expects an authorization header.
Authorization:
Bearer {{api_key}}Give each value its own field. Map them into exactly the headers your API needs.
X-Client-Id: {{client_id}}
X-Api-Key: {{api_key}}Provide an access key, secret key, and optional session token. Thru signs the request.
auth.type: aws-sigv4
service + region + key fieldsChoose narrowly scoped provider credentials, verify the destination belongs to a trusted provider, and limit a connection to read-only methods when possible. Your agent can use the API within those permissions until the connection expires or you revoke it.
The connection's configuration, status, and API responses. It gets its own Thru access token, which lets it use the connection. Your stored provider credentials are encrypted and never included in the connection object. Use a trusted API provider: it controls the responses returned by its endpoints.
Your agent can tell you where to create the credentials and include a link to the provider's credentials page. Open the Thru setup link, review the destination, and enter the values there yourself.
Yes. After connecting, save your private management link. It lets you check the connection and revoke access at any time. Connections also expire automatically; the setup and management pages show the expiration time. Connections last 24 hours by default and can be configured for up to seven days. Setup links expire after one hour.
No. Thru forwards standard HTTP requests to the configured API destination, injects the header credentials you define, or signs AWS requests. Your agent uses the proxy URL in place of the API base URL. Responses currently support UTF-8 text, JSON, and XML up to 1 MB. Redirects, binary responses, and opaque compressed responses are blocked.