AI agent? The same documentation as one plain-markdown file is at https://apiblaze.com/docs.md (also rendered at /docs/machine). It is generated from `npx apiblaze skills` and `npx apiblaze --help`.
Ship an API in one command
APIblaze sits between your callers and your backend. People, apps and AI agents all come through it, and only clean traffic reaches your code.
Don’t like reading docs?
Type this in your agent:
❯ Show me what apiblaze can do using npx apiblaze skillsClaude Code or Codex installs the skill and does the work. Browsing as an agent? Use the machine docs (/docs.md).
What is APIblaze?
APIblaze is a serverless MCP & API gateway. Instead of sending your traffic directly from frontend to backend and letting LLM agents do whatever they want to your backend, you configure your frontend and agents to send their traffic to APIblaze (a simple URL) before APIblaze forwards that traffic to your backend. APIblaze secures that traffic (throttling, authentication, authorization policies, role based access management, transformations, ...). This helps you go from having your business logic coded to being production-ready in seconds rather than weeks.
Quickstart
Point APIblaze at your API's OpenAPI spec, or at its base URL. No account needed.
$ npx apiblaze create --target https://ninopizzas.com/openapi.yamlWhat happens next
The command asks two questions, then prints everything you need. This is a real run, logged out:
$ npx apiblaze create --target https://ninopizzas.com/openapi.yaml
--target is an OpenAPI document (https://ninopizzas.com/openapi.yaml) — creating FROM the spec.
Create an API proxy
Not logged in — creating an anonymous proxy. You can claim it to your account within 30 days.
? Should only creators of a resource in the API be able to amend that resource?
❯◉ restaurants — only the person who created a restaurant, or an admin, can view or change it
◉ restaurants/{restaurantId}/reservations — only the person who created a reservation, or an admin, can view, change or delete it
◉ restaurants/{restaurantId}/tables — only the person who created a table, or an admin, can change or delete it
? Who is the admin? Their email address (Enter to skip): admin@ninopizzas.com
✔ API proxy created!
✓ https://daringfox2395.tryabz.run/1.0.0/prod — your backend and widget use the API key; people and agents use an APIblaze login (with GitHub)
✓ restaurants, reservations + tables locked to their creator
API key (backend key — for your backend and widget; shown once, save it now):
sk_prod_D4vp7X1PRT_…
Send it as X-API-Key and say who is calling with X-End-User-Id.
(Separate keys were also created for: dev, test.)
Try it — copy/paste:
curl https://daringfox2395.tryabz.run/1.0.0/prod/restaurants -H "X-API-Key: sk_prod_D4vp7X1PRT_…" -H "X-End-User-Id: you"
X-End-User-Id = who your server is acting for; the rules check that person (any handle works for a test).
Keys you ship to users (browser, app, widget) must not name anyone: npx apiblaze apikeys mint --client --tenant victorymeadow1963
MCP URL (for agents): https://daringfox2395-victorymeadow1963.mcp.tryabz.run/1.0.0/prod
? Connect an agent to it now? Not now
Later: npx apiblaze apichat daringfox2395 --install-mcp claude
✓ admin: admin@ninopizzas.com — active now
Try saying to your agent:
✓ "List the restaurants." → allowed (lists stay open)
✓ "Create a reservation, then show it to me." → allowed: you created it
✗ "Delete a reservation you didn't create." → refused: not yours, and you're not an admin
✓ "Now do that again as an admin." → allowed: admin@ninopizzas.com is an active admin
⚠ Anonymous — claim within 30 days or it expires. To claim these proxies:
npx apiblaze login && npx apiblaze claim 7XQ7-…
? Do you want to chat with your API now? No
Later: npx apiblaze apichat daringfox2395- • You get a proxy at
{name}.tryabz.run, an MCP server for agents, a hosted dev portal, and one API key per environment (dev, test, prod). - • Logged out, it lives in an anonymous workspace for 30 days. Claim it to keep it; it then moves to
abz.run. - • Every curl on this page that changes a proxy sends a control-plane key as
X-API-Key: thecp_keyabove, or one from the dashboard. Add--verboseto any CLI command to print the exact calls it made.
The create request
One call, no auth header: POST https://api.apiblaze.com/proxy. Give it one source; everything else has a default.
$ npx apiblaze create --target https://pokeapi.co --name pokeproxy --tenant acme- • One source:
target(your API's base URL),openapi(a spec URL or the spec text), orgithub. A spec URL intargetis refused with a hint to useopenapi; the CLI's--targetsorts that out for you. - • Names are optional. Leave out
name,tenantorproduct_slugand they are generated. - • One default differs. The raw call opens only the API-key door. The CLI opens both doors: key and GitHub sign-in. The quickstart's curl tab shows the body that matches the CLI.
Your target backend is run locally, not hosted yet?
$ npx apiblaze dev
one of your proxies has an openapi.yaml file with a target set to localhost:3000
Tunnel:
https://myapp.abz.run/1.0.0/dev -> localhost:3000
# --openapi ./openapi.yaml is optional: dev finds /openapi.json (and friends) on your serverConfig file based setup
Everything a proxy starts with can live in one JSON file: keep it in your repo, review it like code, and create the same proxy again anywhere. The CLI and the HTTP call take the same object.
a) Create a proxy from a config file
$ npx apiblaze create --config apiblaze.json --name myapi
# flags still work and override the file's fields (--name, --tenant, --apikey, …)b) A config that sets up the things most proxies need
This is the file used for the runs below. Save it as apiblaze.json:
{
"openapi": "https://ninopizzas.com/openapi.yaml",
"environments": {
"dev": { "target": "https://backend.resiresi.com" },
"prod": { "target": "https://backend.resiresi.com" }
},
"requests_auth": {
"mode": "authenticate",
"methods": ["api_key", "jwt"],
"identified_traffic_only": true
},
"login": { "providers": [{ "type": "github", "managed": true }] },
"secure": {
"families": ["/restaurants", "/restaurants/{restaurantId}/reservations", "/restaurants/{restaurantId}/tables"]
},
"throttling": { "userRateLimit": 5, "proxyQuota": 5000, "quotaPeriod": "daily" },
"cors": {
"allow_all_origins": false,
"allowed_origins": ["https://ninopizzas.com", "http://localhost:3000"],
"allow_methods": ["GET", "POST", "PATCH", "DELETE", "OPTIONS"],
"allow_headers": ["Content-Type", "Authorization", "X-API-Key", "X-End-User-Id"],
"expose_headers": [],
"allow_credentials": true,
"max_age": 600
}
}- •
openapi: your spec, as a URL or the text itself. It gives the MCP server its tools and tells the ownership rules which routes create what. - •
environments: one backend per stage, each with its own keys. Pointdevat staging in real life. - •
requests_auth: both doors (an API key, or a sign-in token), andidentified_traffic_onlyso every call must name its user. - •
login: the GitHub sign-in APIblaze hosts for people and agents. Swap in your own OAuth app here (see Dev-portal login). - •
secure.families: the resources only their creator, or an admin, can read, change or delete. - •
throttling: 5 requests per second per person and 5,000 a day for the whole proxy. - •
cors: only your site and your local dev server may call it from a browser. - • Not in the file: the admin, which is one more command:
npx apiblaze admins add you@example.com --tenant <tenant>. Add"tenant"to name the workspace yourself; tenant names are global, so pick one that is yours.
What that file creates
$ npx apiblaze create --config apiblaze.json --name cfgnino7261 --auto
✔ API proxy created!
✓ https://cfgnino7261.tryabz.run/1.0.0/prod — your backend and widget use the API key; people and agents use an APIblaze login (with GitHub)
✓ restaurants, reservations + tables locked to their creator
API key (backend key — for your backend and widget; shown once, save it now):
sk_prod_c0HfMJdqR0_…
(Separate keys were also created for: dev.)
MCP URL (for agents): https://cfgnino7261-happytower2425.mcp.tryabz.run/1.0.0/prod
# checked on the live proxy:
# the key with no X-End-User-Id → 403 identity_required
# no key → 401 (sign in, or send a key)
# 12 calls at once as one person → 5 through, 7 × 429
# preflight from https://ninopizzas.com → Access-Control-Allow-Origin: https://ninopizzas.com
# preflight from https://evil.example → no Access-Control-Allow-OriginAuthentication
Who may call the proxy is one scale with four stops. create starts you on the second.
| Who can call | CLI | Request field |
|---|---|---|
| Anyone | create --config (mode passthrough) | requests_auth.mode: "passthrough" |
| Anyone with valid credentials | create (the default) | requests_auth.mode: "authenticate" |
| Identified end users | create --identified | identified_traffic_only: true |
| Pre-approved end users | preapprove <email> (logged in) | preapproved_users_only: true |
Require a named user on every call
$ npx apiblaze create --target https://ninopizzas.com/openapi.yaml --identified
# a key alone, with no X-End-User-Id, now gets:
# 403 {"error":{"code":"identity_required","message":"Tenant requires every request to carry a resolved x-end-user-id"}}
# the same key with X-End-User-Id: ana → 200
# already created? turn it on (or off) later:
$ npx apiblaze identified daringfox2395 require # allow-anon turns it offOne door only
# API key, no sign-in:
$ npx apiblaze create --target https://api.example.com --apikey
# GitHub sign-in (APIblaze-hosted), no API key:
$ npx apiblaze create --target https://api.example.com --oauthKeys for your tenants: backend, client, or one person
# a person-bound key: every call made with it counts as that person
$ npx apiblaze apikeys mint --tenant victorymeadow1963 --for ana@ninopizzas.com
✔ Key minted for ana@ninopizzas.com.
key: sk_dev_avnEC8yPFZ_… (shown once — store it now)
tenant: victorymeadow1963 env: dev
issued to: ana@ninopizzas.com — calls made with this key count as this person; an X-End-User-Id naming anyone else is refused
# a client key: safe in a browser or app, cannot name a user
$ npx apiblaze apikeys mint --tenant victorymeadow1963 --client
✔ Client key minted.
# no flag (or --backend): a server key that names the user with X-End-User-IdYour own login: trust your JWT issuer
$ npx apiblaze create --target https://api.example.com \
--oauth '{"iss":"https://login.acme.com/","aud":"acme-api","jwks":"https://login.acme.com/.well-known/jwks.json"}'The end user is the token's sub. Add --apikey to keep the key door open too. Your own OAuth app on the APIblaze login page is in Dev-portal login.
Opaque tokens, and no auth at all
$ cat opaque.json
{ "target": "https://api.example.com",
"requests_auth": { "mode": "authenticate", "methods": ["opaque"],
"opaque": { "endpoint": "https://auth.example.com/introspect", "method": "POST", "body": "token={token}" } } }
$ npx apiblaze create --config opaque.json
# open to anyone: the same file with "requests_auth": { "mode": "passthrough" }Authorization: Prevents users and agents taking unauthorized actions
Give create a spec and it asks one question. Keep every box ticked, and only the person who created a record, or an admin, can read, change or delete it. Your backend does not change.
1. How you got there
$ npx apiblaze create --target https://ninopizzas.com/openapi.yaml
? Should only creators of a resource in the API be able to amend that resource?
❯◉ restaurants — only the person who created a restaurant, or an admin, can view or change it
◉ restaurants/{restaurantId}/reservations — only the person who created a reservation, or an admin, can view, change or delete it
◉ restaurants/{restaurantId}/tables — only the person who created a table, or an admin, can change or delete it
? Who is the admin? Their email address (Enter to skip): admin@ninopizzas.com
✓ restaurants, reservations + tables locked to their creator2. What it does: Ana books a table, Ben tries to read it
$ npx apiblaze apichat daringfox2395 --xenduserid ana -p "book a table for 2 at Nino's Pizza tomorrow at 8pm for Ana, ana@ninopizzas.com"
Acting as: ana
✓ createReservation (ok, 1624ms)
assistant › Your reservation for 2 at Nino's Pizza tomorrow, September 25th, 2026, at 8:00 PM for Ana (ana@ninopizzas.com)
has been confirmed. The reservation ID is `aae4fd94-d498-401f-8fd5-d8cff044485c`.
$ npx apiblaze apichat daringfox2395 --xenduserid ben -p "show me Ana's reservation aae4fd94-d498-401f-8fd5-d8cff044485c at Nino's Pizza"
Acting as: ben
✗ getReservation (error, 884ms)
response:
Not allowed for your credential.
assistant › I am sorry, I cannot fulfill this request. The API returned a "Forbidden" error, meaning I am not allowed to access this information.- • Locked: reading, changing or deleting one record by the
idits create returned. Open: listing a collection and creating. Lists are not filtered by owner, so filter them in your backend with thex-abz-user-idheader. - • Who the person is: the signed-in user, the person a key is bound to, or the
X-End-User-Idyour server sends with its key. A call that names nobody can still create a record nobody owns;create --identifiedrefuses those (see Authentication). - • Admins bypass the rules:
npx apiblaze admins add you@example.com --tenant victorymeadow1963works logged out. Reviewing the ticks later withnpx apiblaze rule daringfox2395needs a login.
Authorization one-line rules
For rules the checkbox can't express, write a sentence. It starts in watch-only mode: it reports what it would block, until you enforce it. Needs a login; each sentence is billed as one agent turn.
$ npx apiblaze rule daringfox2395 "users see only their own reservations; managers see all"
# happy with what it reports? enforce it:
$ npx apiblaze rule daringfox2395 "users see only their own reservations; managers see all" --enforce
# a longer design session over many routes:
$ npx apiblaze agent authz daringfox2395- •
managersis an ordinary group from Users & Groups. Tenant admins are the built-inapiblaze_adminsgroup. - • Enforcement fails closed: if the policy engine can't be reached, the request is denied.
Throttling
Every new proxy already allows 10 requests per second per consumer key and 3,000 requests a day. Change either at any time, logged in or not.
$ npx apiblaze limits set daringfox2395 --rate 10 --quota 3000 --period daily
✔ Limits updated — daringfox2395 v1.0.0.
daringfox2395 v1.0.0 (anonymous workspace)
mode standard per consumer key, approximate per location
rate limit 10/s (100 per 10 s) per consumer key
end-user rate 10/s (100 per 10 s) per X-End-User-Id
ceiling 100/s (1000 per 10 s) whole proxy · read-only, self-serve up to 1000/s
quota 3,000 per day (daily) fixed UTC windows
spend cap (none)
credential quota (none)
config version 1 · edits bind within 30 s, no reset on edit
# see the current values without changing anything:
$ npx apiblaze limits get daringfox2395- •
--ratecounts per consumer key;--end-user-ratecounts per person named inX-End-User-Id.--spend-capstops the proxy at a monthly dollar amount, and--credential-quotagives each key its own quota. - • Over a rate a caller gets
429; over the quota,402. Up to 1,000 requests per second is self-serve; above that,limits request-maxasks an operator. An anonymous workspace is capped lower until you claim it.
Transformation
Change requests on their way to your backend without touching either side. A common case: callers send one value, your backend wants another. Here callers send a country code and the backend needs a currency, so the proxy looks it up in a mapping table.
# 1. the table: from=to pairs
$ npx apiblaze transform mapping daringfox2395 currencies FR=EUR US=USD GB=GBP
✔ Create mapping table "currencies" (3 entries) — daringfox2395 v1.0.0.
FR → EUR
US → USD
GB → GBP
# 2. the rule: read X-Country, write X-Currency through that table
$ npx apiblaze transform map daringfox2395 header:X-Country header:X-Currency --table currencies
✔ Add transform: header:X-Country → header:X-Currency through "currencies" — daringfox2395 v1.0.0.
A value not in the table: nothing is written.
# a caller sends X-Country: FR → your backend receives X-Currency: EUR as well
# (--on-no-match fail refuses unknown values; passthrough copies them as-is)Sources and destinations can be headers, query parameters or body fields (header:, query:, bodyvar:).transform list daringfox2395 shows every rule; --secret on transform mapping stores the values encrypted.
Only the proxy reaches your backend
Have the proxy add a secret header to every call it forwards, and make your backend refuse calls without it. Then nobody can go around the gateway.
$ export TARGET_SERVER_SECRET=$(openssl rand -hex 24) # give the same value to your backend
$ npx apiblaze transform set-header daringfox2395 x-target-api-key --value-env TARGET_SERVER_SECRET --secret
✔ Add transform: send x-target-api-key to the upstream — daringfox2395 v1.0.0 (stored encrypted).
Every call the proxy forwards now carries x-target-api-key. Your backend can reject calls without it.
$ npx apiblaze transform list daringfox2395
● set header x-target-api-key [request] 66574aa7-…
set header:x-target-api-key = (secret)transform remove daringfox2395 x-target-api-key takes it off. The same rules can rewrite other headers and body fields.
Dev-portal login
Every proxy gets a hosted developer portal with GitHub sign-in already set up. Swap in your own OAuth app, and choose which token reaches your API.
$ npx apiblaze create --target https://api.example.com \
--oauth '{"provider":"google","clientId":"xxxx.apps.googleusercontent.com","clientSecret":"GOCSPX-xxxx"}'
# providers: github · google · microsoft · facebook · auth0
# token types, scopes, callback URLs: put the curl tab's body in a file and use --configtoken_type is what the browser receives; target_server_token is what your API receives. Add --apikey next to --oauth to keep both doors, with your app in place of hosted GitHub, so your users don't get a second login.
Chat with your API
Ask your API questions in plain English. The chat calls it live, through the same rules as everyone else.
$ npx apiblaze apichat daringfox2395
Chat with your API · daringfox2395-victorymeadow1963.mcp.tryabz.run
Ask a question in plain English. /exit to quit · /login for more free chats · /claim to keep this workspace
you › which restaurants are there?
✓ listRestaurants (ok, 971ms)
assistant › There are 5 restaurants: Gino's Pizza, Joe's Pizza, Le Bernardin, Nino's Pizza, and Zingerman's Roadhouse.
9 free chats left · /login to get more
# someone else's API, no login: npx apiblaze apichat --target https://pokeapi.co/openapi.yaml
# one question, no prompt: npx apiblaze apichat daringfox2395 -p "which restaurants are there?"- •
--xenduserid anamakes the chat act as Ana. Add--verboseto see each call. - •
npx apiblaze llm set-keyuses your own model key instead of the free chats.
Publish an MCP server
Every proxy already is one. create prints its address; agents sign in with GitHub, and scripts can send the API key.
# connect Claude Code (or codex) to it:
$ npx apiblaze apichat daringfox2395 --install-mcp claude
$ claude mcp add --transport http daringfox2395 https://daringfox2395-victorymeadow1963.mcp.tryabz.run/1.0.0/prod --header "X-API-Key: sk_prod_D4…" …
✔ MCP daringfox2395 added to Claude CLI (local scope — this directory).
# choose which routes become tools (logged in, billed per turn), then /publish:
$ npx apiblaze agent mcp daringfox2395The address is {project}-{tenant}.mcp.tryabz.run/{version}/{environment}, or .mcp.abz.run once claimed. The same server also answers at {project}-{tenant}.mcpblaze.com, and npx mcpblaze is this same CLI under the MCPblaze name. A tenant is the workspace for one group of your users, such as one customer company.
Manage APIblaze from an agent
Just type Use APIblaze (npx apiblaze skill) to proxy the {backend, frontend} in the current directory in your agent. It installs the skill, reads your code, and runs the commands on this page for you. Clients without a shell (Claude Desktop, ChatGPT, web agents) do the same through one MCP server: add it, sign in with GitHub once, and the agent works on your team.
# ask a chatbot that acts on your account, from the terminal:
$ npx apiblaze docs
# or give any MCP client the same powers:
$ claude mcp add --transport http apiblaze https://mcp.apiblaze.com
# then /mcp and sign in once. Tools, in order: describe_server, propose_rules, create_server,
# apply_rules, add_admin, issue_key, set_rate_limit, integration_kit, explain_access
# MCPblaze: https://mcp.mcpblaze.comOpened in a browser, the same address brings you to these docs. Everything the tools do is also a CLI command, which is the path when a localhost tunnel is involved: only a process on your machine can run one.
Builder agents
Some setup is easier to describe than to write. The builder agents are chat sessions in your terminal that read your proxy (its spec, and real traffic when there is some) and propose the configuration for you. Nothing changes until you say so: each one shows its proposal, you ask for changes in plain English, then /publish applies it. openapi writes the spec your API never had, from the calls it has seen. authz turns rules like “managers see every reservation” into policies and runs them watch-only on real traffic before you enforce them. mcp chooses which routes agents get as tools, with names and descriptions they can understand. Plain agent takes any request and makes the calls. They need a login and are billed per turn.
$ npx apiblaze agent # describe what you want; it makes the calls
$ npx apiblaze agent openapi daringfox2395 # drafts a spec from real traffic, or opens a PR
$ npx apiblaze agent authz daringfox2395 # drafts access rules, watch-only until /enable
$ npx apiblaze agent mcp daringfox2395 # picks the routes that become MCP toolsUI: Drop-in widgets
Three React components give your users APIblaze features on your own site. Each one talks only to a route on your server, which holds the secret and says who is signed in, so the browser never sees a key. npx apiblaze integration daringfox2395 --stack nextjs prints the code for your proxy.
Chat: your users talk to your API
A chat bubble on your site. Users ask in plain English (“book me a table for Friday”); the chat calls your API as that user, through the same rules, and streams the answer.
Nino’s Pizza
Wood-fired. Neapolitan. Midtown.
▲ the drop-in <ChatWidget/> — tools run live behind your proxy, white-labelled to your brand
$ npx apiblaze integration daringfox2395 --stack nextjs
app/account/page.tsx
import { ChatWidget } from 'apiblaze/react';
<ChatWidget endpoint="/api/apiblaze/chat" title="Chat with daringfox2395" suggestions={['What can I do here?']} />
app/api/apiblaze/chat/route.ts
import { createApiblazeChat } from 'apiblaze/server';
import { auth } from '@/auth';
const chat = createApiblazeChat({
project: 'daringfox2395',
apiKey: process.env.APIBLAZE_SERVER_KEY!, // the server key — server only
getUser: async () => {
const s = await auth();
if (!s?.user) return null;
return { userId: s.user.id }; // the chat acts as this person
},
});
export const POST = chat.handler;API keys: your users manage their own keys
Each signed-in user sees their keys for your API, and can create, rotate and revoke them. Keys land in that customer's tenant, so every customer only sees their own.
Developer
API access
Create a key to call the Acme API from your app or CI.
Your API keys
▲ the drop-in <ApiKeyWidget/>, white-labelled to your brand
# the widget's server key: a control-plane key (no --tenant)
$ npx apiblaze apikeys mint --desc "keys widget" # → APIBLAZE_CP_KEY
$ npx apiblaze integration daringfox2395 --stack nextjs
app/account/page.tsx
import { ApiKeyWidget } from 'apiblaze/react';
<ApiKeyWidget endpoint="/api/apiblaze/keys" title="Your API keys" />
app/api/apiblaze/keys/route.ts
import { createApiblazeKeys } from 'apiblaze/server';
const keys = createApiblazeKeys({
cpKey: process.env.APIBLAZE_CP_KEY!, // control-plane key — server only
getUser: async () => {
const s = await auth();
if (!s?.user) return null;
return { tenant: 'victorymeadow1963', userId: s.user.id, email: s.user.email ?? undefined };
},
});
export const GET = keys.handler;
export const POST = keys.handler;Users & groups: your customers' admins manage their team
A tenant's admin adds people, puts them in groups like reservationists, and your authorization rules use those groups. The route is the keys route with one word changed, and it uses the same widget key. For each signed-in admin it mints a short-lived key issued to that person and acts with it, so APIblaze always knows which admin made a change. Someone who isn't an admin sees “admin access required”.
Workspace
Team access
Your customer’s admins manage their own users & groups — on your site.
Users & groups
▲ the drop-in <UsersGroupsWidget/>, white-labelled to your brand
$ npx apiblaze admins add boss@ninopizzas.com --tenant victorymeadow1963
✔ boss@ninopizzas.com is now a tenant admin of victorymeadow1963.
Reload the Users & Groups widget — access flips from “pending” to ready.
The widget uses your widget key (APIBLAZE_CP_KEY) and mints this admin a short-lived personal key itself.
app/team/page.tsx
import { UsersGroupsWidget } from 'apiblaze/react';
<UsersGroupsWidget endpoint="/api/apiblaze/groups" />
app/api/apiblaze/groups/route.ts
import { createApiblazeGroups } from 'apiblaze/server'; // the only change vs. the keys route
const groups = createApiblazeGroups({ cpKey: process.env.APIBLAZE_CP_KEY!, getUser });
export const GET = groups.handler;
export const POST = groups.handler;
# APIBLAZE_CP_KEY: `npx apiblaze apikeys mint --desc "widget key"`, run by a team admin or ownerThe Next.js sidecar
Route the calls your Next.js app makes to other APIs through APIblaze, one origin at a time, without changing code.
$ npx apiblaze init # in your Next.js app: wires the sidecar and a dev inspector
$ npm run dev
[apiblaze/sidecar] direct (not approved) → https://api.stripe.com · approve to route it: npx apiblaze sidecar approve api.stripe.com
$ npx apiblaze sidecar approve api.stripe.com
✔ Approved api.stripe.com → proxy scapistripecom23c0af. Routing within ~5 min.
$ npx apiblaze sidecar # what is routed, and what is still a candidate
Routed through APIblaze (1)
● https://api.stripe.com → scapistripecom23c0af
$ npx apiblaze sidecar deny analytics.example.com # stop suggesting it
$ npx apiblaze sidecar remove api.stripe.com # go direct again (deletes the proxy)APIBLAZE_SIDECAR=off in .env.local turns it all off without removing anything.
Versions & environments
Point dev, test and prod at different backends, and run API versions side by side. Each environment has its own keys.
$ npx apiblaze target daringfox2395 --env dev --url https://backend.resiresi.com
✔ Set target for env dev → https://backend.resiresi.com — daringfox2395 v1.0.0.
# a 2.0.0 next to 1.0.0, served at /2.0.0/…
$ npx apiblaze create --name daringfox2395 --target https://api-v2.example.com --apiversion 2.0.0
# which version and environment the bare domain serves
$ npx apiblaze domain set-base daringfox2395Custom domains
Serve your API, MCP server, portal or login page from your own domain. APIblaze issues the certificate. Needs a login; billed monthly.
$ npx apiblaze domain add daringfox2395 --domain api.ninopizzas.com # prints the DNS records to set
$ npx apiblaze domain status daringfox2395
$ npx apiblaze domain add daringfox2395 --domain mcp.ninopizzas.com --kind mcp
$ npx apiblaze domain add --tenant victorymeadow1963 --kind portal --domain developers.ninopizzas.com
$ npx apiblaze domain list daringfox2395
$ npx apiblaze domain rm daringfox2395 --id <domain id from list>Claim a proxy you created anonymously
A proxy made logged out is deleted after 72 hours with no traffic, or 30 days without any. Claiming it makes it yours, with everything else you made while logged out.
⚠ Anonymous — claim within 30 days or it expires. To claim these proxies:
npx apiblaze login && npx apiblaze claim 7XQ7-…
# on the machine that created them, the code is remembered:
$ npx apiblaze login && npx apiblaze claim
# into a team you already have:
$ npx apiblaze claim 7XQ7-… --team my-teamClaimed proxies move from tryabz.run to abz.run, and their MCP servers with them. Inside apichat, /claim does the same. Deleting a proxy needs a login, so claim first if you want to delete one.
The CLI
npx apiblaze needs Node 18 and no install. This is its help, verbatim.
$ npx apiblaze --help
Usage: apiblaze [options] [command]
APIblaze CLI — create & manage API proxies and run dev tunnels
Options:
-V, --version output the version number
-v, --verbose Print the exact series of API calls each command makes
(curl-equivalent you could run yourself)
-h, --help display help for command
Don't like reading docs? Run npx apiblaze docs — ask an AI chatbot about APIblaze, and let it act on your account.
Chat
docs Ask an AI chatbot about APIblaze — and let it act on your account (it's the real API, not a docs search)
apichat Turn any API into a chat: point at an OpenAPI spec — or chat an EXISTING proxy by name (no login needed)
agent Chat with an assistant that builds and runs your APIs (billed per turn)
llm Manage a local LLM provider key for chat (optional — lifts model quality, bills your key)
Setup
dev Put the app running on THIS machine on the internet: a public URL and an MCP address for AI agents, tunnelled to localhost. Included: API keys, sign-in, ownership rules, rate limits. No login needed. (Deployed app? Use `create`.)
create Put an app that is already DEPLOYED behind APIblaze: a public URL and an MCP address for AI agents in front of your URL or OpenAPI spec. Included: API keys, sign-in, ownership rules, rate limits. No login needed. (App on this machine? Use `dev`.)
integration What to add to your frontend and frontend-server for a proxy — the same kit the APIblaze MCP hands an agent: widgets, the call-through with the key + X-End-User-Id, what your backend must trust, env vars, what stays open
skill|skills What APIblaze does, for you or your AI assistant: checks this folder for a backend and offers the next step (put it on the internet, or a sample app)
login Authenticate with APIblaze
init Set up the APIblaze sidecar in a Next.js app (shortcut for `apiblaze sidecar setup`)
sidecar The APIblaze sidecar — set it up, then approve which origins route through APIblaze
claim Claim your anonymous workspace into your account (requires login)
team Switch the active team, or create a new one
whoami Show who you are — both API Producer and API Consumer
logout Sign out (asks whether to drop the Producer or Consumer login)
flush Log out and wipe every local trace: login, workspace keys, apichats, DP keys, secrets, and the MCP servers + CLAUDE.md/AGENTS.md blocks apichat installed elsewhere
Recipes — install a working setup, or publish yours
search Find a published recipe — a whole working proxy someone else set up
show Read a recipe before you install it (upstreams, questions, transforms, spec)
install Create a proxy from a recipe, with your own credentials
publish Publish one of your proxies as a recipe others can install
withdraw Permanently delete one published recipe revision
Control plane commands
config Browse and change every proxy setting & feature (interactive; git-config-style get/set)
projects List the projects in your team
logs API Producer view — stream this proxy's requests from EVERY caller live (see `apiblaze logs list` to browse past days)
tenant Manage tenants — bare command opens the interactive picker (settings, app clients, providers)
group Manage a tenant's users & groups — bare command lists groups
admins Manage who can administer a tenant's users & groups (the first-admin bootstrap the widget needs)
apikeys API keys — for your team (control plane), or with `mint --tenant` for your API's callers: a backend key, a client key (--client) or a key bound to one person (--for)
iam Turn users & groups on/off for a proxy's tenant (identified calls get their user's groups applied)
identified Require calls to identify their end user (X-End-User-Id from a backend key, or a login token — a client key alone cannot) — or allow unattributed calls again
preapprove Allow an email or company domain to sign in to an access-restricted API (--list, --remove)
allowoauthregistration Approve the next OAuth client that registers against your tenant (Claude Code, Codex, any MCP client) — single use
rule Lock resources to the person who created them — or describe any access rule in plain English (that one is billed per turn)
mcp Optional tweaks to a proxy's MCP server: prompts, per-tool behavior (read-only / destructive / confirm / always-async), UI resource
domain Use your own domain for your API, MCP server, developer portal or login pages (billed monthly)
delete Delete a proxy and everything under it (asks first)
job Check a background delete job (from a delete that ran with --no-wait)
target Change where a proxy forwards requests
limits Rate limits, quota and spend cap for a proxy (10-second figure shown beside each rate)
billing Your wallet: balance (available · in use · grace), top up, usage history, auto-rebuy
transform Change requests on their way to your backend — e.g. send it a secret header so it only answers to the proxy
rename Change a proxy's display name
spec View or update a proxy's OpenAPI spec (or build one by chatting: apiblaze agent openapi)
export Export config and data for migration out of APIblaze (Kong, ...)
Data plane commands
consumer login Log in to a tenant's portal as a consumer (device flow)
consumer apikeys List your consumer API keys (reveals expiring ones), then offer to create one
consumer logs API Consumer view — stream YOUR OWN requests on this tenant live (see `consumer logs list` for past days)
Tips:
• `apiblaze config <project>` browses EVERY setting & feature (works logged-out to explore).
• Add --verbose to any command to see the equivalent API calls.
• Add --auto to `dev` or `create` for a scriptable run: no prompts, no TTY needed, proxy name generated.
• Full API reference: https://api.apiblaze.com/openapi.json
• Run `apiblaze <command> --help` (e.g. `apiblaze consumer --help`) for sub-commands.
Examples:
$ npx apiblaze dev --port 3000 --openapi ./openapi.yaml # your local code, shipped safely: both doors, rules, admin, agent — through a tunnel
$ npx apiblaze integration myapi --stack nextjs # what to add to your frontend + frontend-server
$ npx apiblaze apichat --target https://pokeapi.co/openapi.yaml # chat with any API
$ npx apiblaze agent # just chat
$ npx apiblaze create --target https://api.example.com # one-line API proxy — API key for your code, GitHub sign-in for agents
$ npx apiblaze create --target ./openapi.yaml --auto # zero prompts: both doors + every resource locked to its creator
$ npx apiblaze create --target https://api.example.com --apikey # API-key door only
$ npx apiblaze rule myapi # pick what to lock, then turn enforcement on
$ npx apiblaze admins add you@example.com --tenant acme # make someone an admin (bypasses the ownership rules)
$ npx apiblaze skill --install # teach Claude Code to ship your API safely with APIblaze
$ npx apiblaze search gmail # find a recipe (no login needed)
$ npx apiblaze install @julien/gmail # someone's whole working setup, your credentials
$ npx apiblaze publish mygmail # share yours back, as @yourgithubhandle/mygmail
$ npx apiblaze limits set myapi --rate 50 --verbose # rate limit (500 per 10 s) + show the API call
$ npx apiblaze billing balance # available · in use · grace
$ npx apiblaze consumer login # act as a consumer of your API
$ npx apiblaze team --new "Acme Corp" # new team, and switch to itA CLI also for the consumers of your API
The people who call your API get a hosted portal (sign-in, their own keys, a live console) and their own CLI commands.
# the portal: https://{tenant}.portal.apiblaze.com/{version}
# e.g. https://victorymeadow1963.portal.apiblaze.com/1.0.0
$ npx apiblaze consumer login --tenant victorymeadow1963 # device-flow sign-in
$ npx apiblaze consumer apikeys # list keys, offer to create one
$ npx apiblaze consumer logs # your own requests, liveField reference
The create body at a glance. Types and defaults live in api.apiblaze.com/openapi.json.
| target / openapi / github | The source, exactly one. A spec URL goes in openapi. |
| name / tenant / product_slug / display_name | Naming. All optional and generated when missing. |
| auth_type | none / api_key / oauth. The HTTP call defaults to api_key; the CLI opens both doors. |
| requests_auth.mode | passthrough (anyone) or authenticate |
| requests_auth.methods | api_key / jwt / opaque |
| requests_auth.identified_traffic_only | Every call must name an end user |
| requests_auth.preapproved_users_only | Only end users on the tenant allowlist |
| requests_auth.jwt.allowed_pairs | Accepted (iss, aud, jwks_url) of your own login |
| requests_auth.opaque | Introspection endpoint, method, params, body |
| secure.families | Resource paths to lock to their creator, e.g. "/restaurants" |
| login.providers[] | Portal sign-in providers, managed or your own app |
| environments | Per-environment targets. On update, the whole object is replaced. |
| throttling | userRateLimit (per person, or per key) · proxyQuota · quotaPeriod |
Full API reference
Every control-plane endpoint, with schemas and a live console.