AI agent? The same documentation as one plain-markdown file is at https://apiblaze.com/docs.md (also rendered at /docs/machine). It is generated from `npx apiblaze skills` and `npx apiblaze --help`.

Documentation

Ship an API in one command

APIblaze sits between your callers and your backend. People, apps and AI agents all come through it, and only clean traffic reaches your code.

Don’t like reading docs?

Type this in your agent:

❯ Show me what apiblaze can do using npx apiblaze skills

Claude Code or Codex installs the skill and does the work. Browsing as an agent? Use the machine docs (/docs.md).

What is APIblaze?

APIblaze is a serverless MCP & API gateway. Instead of sending your traffic directly from frontend to backend and letting LLM agents do whatever they want to your backend, you configure your frontend and agents to send their traffic to APIblaze (a simple URL) before APIblaze forwards that traffic to your backend. APIblaze secures that traffic (throttling, authentication, authorization policies, role based access management, transformations, ...). This helps you go from having your business logic coded to being production-ready in seconds rather than weeks.

Quickstart

Point APIblaze at your API's OpenAPI spec, or at its base URL. No account needed.

$ npx apiblaze create --target https://ninopizzas.com/openapi.yaml

What happens next

The command asks two questions, then prints everything you need. This is a real run, logged out:

npx apiblaze create — the full run
$ npx apiblaze create --target https://ninopizzas.com/openapi.yaml
  --target is an OpenAPI document (https://ninopizzas.com/openapi.yaml) — creating FROM the spec.

Create an API proxy
Not logged in — creating an anonymous proxy. You can claim it to your account within 30 days.

? Should only creators of a resource in the API be able to amend that resource?
❯◉ restaurants — only the person who created a restaurant, or an admin, can view or change it
 ◉ restaurants/{restaurantId}/reservations — only the person who created a reservation, or an admin, can view, change or delete it
 ◉ restaurants/{restaurantId}/tables — only the person who created a table, or an admin, can change or delete it
? Who is the admin? Their email address (Enter to skip): admin@ninopizzas.com
✔ API proxy created!

  ✓ https://daringfox2395.tryabz.run/1.0.0/prod — your backend and widget use the API key; people and agents use an APIblaze login (with GitHub)
  ✓ restaurants, reservations + tables locked to their creator

  API key (backend key — for your backend and widget; shown once, save it now):
    sk_prod_D4vp7X1PRT_…
  Send it as X-API-Key and say who is calling with X-End-User-Id.
  (Separate keys were also created for: dev, test.)

  Try it — copy/paste:
    curl https://daringfox2395.tryabz.run/1.0.0/prod/restaurants -H "X-API-Key: sk_prod_D4vp7X1PRT_…" -H "X-End-User-Id: you"
    X-End-User-Id = who your server is acting for; the rules check that person (any handle works for a test).
    Keys you ship to users (browser, app, widget) must not name anyone:  npx apiblaze apikeys mint --client --tenant victorymeadow1963

  MCP URL (for agents):  https://daringfox2395-victorymeadow1963.mcp.tryabz.run/1.0.0/prod

? Connect an agent to it now? Not now
  Later:  npx apiblaze apichat daringfox2395 --install-mcp claude
  ✓ admin: admin@ninopizzas.com — active now

  Try saying to your agent:
    ✓ "List the restaurants."                       → allowed (lists stay open)
    ✓ "Create a reservation, then show it to me."   → allowed: you created it
    ✗ "Delete a reservation you didn't create."     → refused: not yours, and you're not an admin
    ✓ "Now do that again as an admin."              → allowed: admin@ninopizzas.com is an active admin

  ⚠ Anonymous — claim within 30 days or it expires. To claim these proxies:
      npx apiblaze login && npx apiblaze claim 7XQ7-…

? Do you want to chat with your API now? No
  Later:  npx apiblaze apichat daringfox2395
  • • You get a proxy at {name}.tryabz.run, an MCP server for agents, a hosted dev portal, and one API key per environment (dev, test, prod).
  • • Logged out, it lives in an anonymous workspace for 30 days. Claim it to keep it; it then moves to abz.run.
  • • Every curl on this page that changes a proxy sends a control-plane key as X-API-Key: the cp_key above, or one from the dashboard. Add --verbose to any CLI command to print the exact calls it made.

The create request

One call, no auth header: POST https://api.apiblaze.com/proxy. Give it one source; everything else has a default.

$ npx apiblaze create --target https://pokeapi.co --name pokeproxy --tenant acme
  • • One source: target (your API's base URL), openapi (a spec URL or the spec text), or github. A spec URL in target is refused with a hint to use openapi; the CLI's --target sorts that out for you.
  • • Names are optional. Leave out name, tenant or product_slug and they are generated.
  • • One default differs. The raw call opens only the API-key door. The CLI opens both doors: key and GitHub sign-in. The quickstart's curl tab shows the body that matches the CLI.

Your target backend is run locally, not hosted yet?

$ npx apiblaze dev
one of your proxies has an openapi.yaml file with a target set to localhost:3000
Tunnel:
https://myapp.abz.run/1.0.0/dev  -> localhost:3000
# --openapi ./openapi.yaml is optional: dev finds /openapi.json (and friends) on your server

Config file based setup

Everything a proxy starts with can live in one JSON file: keep it in your repo, review it like code, and create the same proxy again anywhere. The CLI and the HTTP call take the same object.

a) Create a proxy from a config file

$ npx apiblaze create --config apiblaze.json --name myapi

# flags still work and override the file's fields (--name, --tenant, --apikey, …)

b) A config that sets up the things most proxies need

This is the file used for the runs below. Save it as apiblaze.json:

apiblaze.json — Copy gives you the file
{
  "openapi": "https://ninopizzas.com/openapi.yaml",
  "environments": {
    "dev":  { "target": "https://backend.resiresi.com" },
    "prod": { "target": "https://backend.resiresi.com" }
  },
  "requests_auth": {
    "mode": "authenticate",
    "methods": ["api_key", "jwt"],
    "identified_traffic_only": true
  },
  "login": { "providers": [{ "type": "github", "managed": true }] },
  "secure": {
    "families": ["/restaurants", "/restaurants/{restaurantId}/reservations", "/restaurants/{restaurantId}/tables"]
  },
  "throttling": { "userRateLimit": 5, "proxyQuota": 5000, "quotaPeriod": "daily" },
  "cors": {
    "allow_all_origins": false,
    "allowed_origins": ["https://ninopizzas.com", "http://localhost:3000"],
    "allow_methods": ["GET", "POST", "PATCH", "DELETE", "OPTIONS"],
    "allow_headers": ["Content-Type", "Authorization", "X-API-Key", "X-End-User-Id"],
    "expose_headers": [],
    "allow_credentials": true,
    "max_age": 600
  }
}
  • • openapi: your spec, as a URL or the text itself. It gives the MCP server its tools and tells the ownership rules which routes create what.
  • • environments: one backend per stage, each with its own keys. Point dev at staging in real life.
  • • requests_auth: both doors (an API key, or a sign-in token), and identified_traffic_only so every call must name its user.
  • • login: the GitHub sign-in APIblaze hosts for people and agents. Swap in your own OAuth app here (see Dev-portal login).
  • • secure.families: the resources only their creator, or an admin, can read, change or delete.
  • • throttling: 5 requests per second per person and 5,000 a day for the whole proxy.
  • • cors: only your site and your local dev server may call it from a browser.
  • • Not in the file: the admin, which is one more command: npx apiblaze admins add you@example.com --tenant <tenant>. Add "tenant" to name the workspace yourself; tenant names are global, so pick one that is yours.

What that file creates

npx apiblaze create --config apiblaze.json --auto — a real run
$ npx apiblaze create --config apiblaze.json --name cfgnino7261 --auto
✔ API proxy created!
  ✓ https://cfgnino7261.tryabz.run/1.0.0/prod — your backend and widget use the API key; people and agents use an APIblaze login (with GitHub)
  ✓ restaurants, reservations + tables locked to their creator
  API key (backend key — for your backend and widget; shown once, save it now):
    sk_prod_c0HfMJdqR0_…
  (Separate keys were also created for: dev.)
  MCP URL (for agents):  https://cfgnino7261-happytower2425.mcp.tryabz.run/1.0.0/prod

# checked on the live proxy:
#   the key with no X-End-User-Id          → 403 identity_required
#   no key                                 → 401 (sign in, or send a key)
#   12 calls at once as one person         → 5 through, 7 × 429
#   preflight from https://ninopizzas.com  → Access-Control-Allow-Origin: https://ninopizzas.com
#   preflight from https://evil.example    → no Access-Control-Allow-Origin

Authentication

Who may call the proxy is one scale with four stops. create starts you on the second.

Who can callCLIRequest field
Anyonecreate --config (mode passthrough)requests_auth.mode: "passthrough"
Anyone with valid credentialscreate (the default)requests_auth.mode: "authenticate"
Identified end userscreate --identifiedidentified_traffic_only: true
Pre-approved end userspreapprove <email> (logged in)preapproved_users_only: true

Require a named user on every call

$ npx apiblaze create --target https://ninopizzas.com/openapi.yaml --identified

# a key alone, with no X-End-User-Id, now gets:
# 403 {"error":{"code":"identity_required","message":"Tenant requires every request to carry a resolved x-end-user-id"}}
# the same key with X-End-User-Id: ana → 200

# already created? turn it on (or off) later:
$ npx apiblaze identified daringfox2395 require        # allow-anon turns it off

One door only

# API key, no sign-in:
$ npx apiblaze create --target https://api.example.com --apikey

# GitHub sign-in (APIblaze-hosted), no API key:
$ npx apiblaze create --target https://api.example.com --oauth

Keys for your tenants: backend, client, or one person

# a person-bound key: every call made with it counts as that person
$ npx apiblaze apikeys mint --tenant victorymeadow1963 --for ana@ninopizzas.com
✔ Key minted for ana@ninopizzas.com.
  key:     sk_dev_avnEC8yPFZ_…  (shown once — store it now)
  tenant:  victorymeadow1963   env: dev
  issued to: ana@ninopizzas.com — calls made with this key count as this person; an X-End-User-Id naming anyone else is refused

# a client key: safe in a browser or app, cannot name a user
$ npx apiblaze apikeys mint --tenant victorymeadow1963 --client
✔ Client key minted.

# no flag (or --backend): a server key that names the user with X-End-User-Id

Your own login: trust your JWT issuer

$ npx apiblaze create --target https://api.example.com \
    --oauth '{"iss":"https://login.acme.com/","aud":"acme-api","jwks":"https://login.acme.com/.well-known/jwks.json"}'

The end user is the token's sub. Add --apikey to keep the key door open too. Your own OAuth app on the APIblaze login page is in Dev-portal login.

Opaque tokens, and no auth at all

$ cat opaque.json
{ "target": "https://api.example.com",
  "requests_auth": { "mode": "authenticate", "methods": ["opaque"],
    "opaque": { "endpoint": "https://auth.example.com/introspect", "method": "POST", "body": "token={token}" } } }
$ npx apiblaze create --config opaque.json

# open to anyone: the same file with "requests_auth": { "mode": "passthrough" }

Authorization: Prevents users and agents taking unauthorized actions

Give create a spec and it asks one question. Keep every box ticked, and only the person who created a record, or an admin, can read, change or delete it. Your backend does not change.

1. How you got there

the question create asks — enter keeps every resource locked
$ npx apiblaze create --target https://ninopizzas.com/openapi.yaml
? Should only creators of a resource in the API be able to amend that resource?
❯◉ restaurants — only the person who created a restaurant, or an admin, can view or change it
 ◉ restaurants/{restaurantId}/reservations — only the person who created a reservation, or an admin, can view, change or delete it
 ◉ restaurants/{restaurantId}/tables — only the person who created a table, or an admin, can change or delete it
? Who is the admin? Their email address (Enter to skip): admin@ninopizzas.com
  ✓ restaurants, reservations + tables locked to their creator

2. What it does: Ana books a table, Ben tries to read it

the same chat, acting as Ana, then as Ben
$ npx apiblaze apichat daringfox2395 --xenduserid ana -p "book a table for 2 at Nino's Pizza tomorrow at 8pm for Ana, ana@ninopizzas.com"
  Acting as: ana
  ✓ createReservation (ok, 1624ms)
assistant › Your reservation for 2 at Nino's Pizza tomorrow, September 25th, 2026, at 8:00 PM for Ana (ana@ninopizzas.com)
            has been confirmed. The reservation ID is `aae4fd94-d498-401f-8fd5-d8cff044485c`.

$ npx apiblaze apichat daringfox2395 --xenduserid ben -p "show me Ana's reservation aae4fd94-d498-401f-8fd5-d8cff044485c at Nino's Pizza"
  Acting as: ben
  ✗ getReservation (error, 884ms)
      response:
        Not allowed for your credential.
assistant › I am sorry, I cannot fulfill this request. The API returned a "Forbidden" error, meaning I am not allowed to access this information.
  • • Locked: reading, changing or deleting one record by the id its create returned. Open: listing a collection and creating. Lists are not filtered by owner, so filter them in your backend with the x-abz-user-id header.
  • • Who the person is: the signed-in user, the person a key is bound to, or the X-End-User-Id your server sends with its key. A call that names nobody can still create a record nobody owns; create --identified refuses those (see Authentication).
  • • Admins bypass the rules: npx apiblaze admins add you@example.com --tenant victorymeadow1963 works logged out. Reviewing the ticks later with npx apiblaze rule daringfox2395 needs a login.

Authorization one-line rules

For rules the checkbox can't express, write a sentence. It starts in watch-only mode: it reports what it would block, until you enforce it. Needs a login; each sentence is billed as one agent turn.

$ npx apiblaze rule daringfox2395 "users see only their own reservations; managers see all"
# happy with what it reports? enforce it:
$ npx apiblaze rule daringfox2395 "users see only their own reservations; managers see all" --enforce

# a longer design session over many routes:
$ npx apiblaze agent authz daringfox2395
  • • managers is an ordinary group from Users & Groups. Tenant admins are the built-in apiblaze_admins group.
  • • Enforcement fails closed: if the policy engine can't be reached, the request is denied.

Throttling

Every new proxy already allows 10 requests per second per consumer key and 3,000 requests a day. Change either at any time, logged in or not.

$ npx apiblaze limits set daringfox2395 --rate 10 --quota 3000 --period daily
✔ Limits updated — daringfox2395 v1.0.0.
daringfox2395 v1.0.0  (anonymous workspace)
  mode               standard  per consumer key, approximate per location
  rate limit         10/s (100 per 10 s)  per consumer key
  end-user rate      10/s (100 per 10 s)  per X-End-User-Id
  ceiling            100/s (1000 per 10 s)  whole proxy · read-only, self-serve up to 1000/s
  quota              3,000 per day (daily)  fixed UTC windows
  spend cap          (none)
  credential quota   (none)
  config version 1 · edits bind within 30 s, no reset on edit

# see the current values without changing anything:
$ npx apiblaze limits get daringfox2395
  • • --rate counts per consumer key; --end-user-rate counts per person named in X-End-User-Id. --spend-cap stops the proxy at a monthly dollar amount, and --credential-quota gives each key its own quota.
  • • Over a rate a caller gets 429; over the quota, 402. Up to 1,000 requests per second is self-serve; above that, limits request-max asks an operator. An anonymous workspace is capped lower until you claim it.

Transformation

Change requests on their way to your backend without touching either side. A common case: callers send one value, your backend wants another. Here callers send a country code and the backend needs a currency, so the proxy looks it up in a mapping table.

# 1. the table: from=to pairs
$ npx apiblaze transform mapping daringfox2395 currencies FR=EUR US=USD GB=GBP
✔ Create mapping table "currencies" (3 entries) — daringfox2395 v1.0.0.
    FR → EUR
    US → USD
    GB → GBP

# 2. the rule: read X-Country, write X-Currency through that table
$ npx apiblaze transform map daringfox2395 header:X-Country header:X-Currency --table currencies
✔ Add transform: header:X-Country → header:X-Currency through "currencies" — daringfox2395 v1.0.0.
  A value not in the table: nothing is written.

# a caller sends  X-Country: FR  →  your backend receives  X-Currency: EUR  as well
# (--on-no-match fail refuses unknown values; passthrough copies them as-is)

Sources and destinations can be headers, query parameters or body fields (header:, query:, bodyvar:).transform list daringfox2395 shows every rule; --secret on transform mapping stores the values encrypted.

Only the proxy reaches your backend

Have the proxy add a secret header to every call it forwards, and make your backend refuse calls without it. Then nobody can go around the gateway.

$ export TARGET_SERVER_SECRET=$(openssl rand -hex 24)     # give the same value to your backend
$ npx apiblaze transform set-header daringfox2395 x-target-api-key --value-env TARGET_SERVER_SECRET --secret
✔ Add transform: send x-target-api-key to the upstream — daringfox2395 v1.0.0 (stored encrypted).
  Every call the proxy forwards now carries x-target-api-key. Your backend can reject calls without it.

$ npx apiblaze transform list daringfox2395
● set header x-target-api-key [request] 66574aa7-…
    set header:x-target-api-key = (secret)

transform remove daringfox2395 x-target-api-key takes it off. The same rules can rewrite other headers and body fields.

Dev-portal login

Every proxy gets a hosted developer portal with GitHub sign-in already set up. Swap in your own OAuth app, and choose which token reaches your API.

npx apiblaze create --oauth — the APIblaze login page with YOUR app
$ npx apiblaze create --target https://api.example.com \
    --oauth '{"provider":"google","clientId":"xxxx.apps.googleusercontent.com","clientSecret":"GOCSPX-xxxx"}'

# providers: github · google · microsoft · facebook · auth0
# token types, scopes, callback URLs: put the curl tab's body in a file and use --config

token_type is what the browser receives; target_server_token is what your API receives. Add --apikey next to --oauth to keep both doors, with your app in place of hosted GitHub, so your users don't get a second login.

Chat with your API

Ask your API questions in plain English. The chat calls it live, through the same rules as everyone else.

$ npx apiblaze apichat daringfox2395

Chat with your API  · daringfox2395-victorymeadow1963.mcp.tryabz.run
Ask a question in plain English. /exit to quit · /login for more free chats · /claim to keep this workspace

you › which restaurants are there?
  ✓ listRestaurants (ok, 971ms)
assistant › There are 5 restaurants: Gino's Pizza, Joe's Pizza, Le Bernardin, Nino's Pizza, and Zingerman's Roadhouse.
  9 free chats left · /login to get more

# someone else's API, no login:     npx apiblaze apichat --target https://pokeapi.co/openapi.yaml
# one question, no prompt:          npx apiblaze apichat daringfox2395 -p "which restaurants are there?"
  • • --xenduserid ana makes the chat act as Ana. Add --verbose to see each call.
  • • npx apiblaze llm set-key uses your own model key instead of the free chats.

Publish an MCP server

Every proxy already is one. create prints its address; agents sign in with GitHub, and scripts can send the API key.

# connect Claude Code (or codex) to it:
$ npx apiblaze apichat daringfox2395 --install-mcp claude
  $ claude mcp add --transport http daringfox2395 https://daringfox2395-victorymeadow1963.mcp.tryabz.run/1.0.0/prod --header "X-API-Key: sk_prod_D4…" …
  ✔ MCP daringfox2395 added to Claude CLI (local scope — this directory).

# choose which routes become tools (logged in, billed per turn), then /publish:
$ npx apiblaze agent mcp daringfox2395

The address is {project}-{tenant}.mcp.tryabz.run/{version}/{environment}, or .mcp.abz.run once claimed. The same server also answers at {project}-{tenant}.mcpblaze.com, and npx mcpblaze is this same CLI under the MCPblaze name. A tenant is the workspace for one group of your users, such as one customer company.

Manage APIblaze from an agent

Just type Use APIblaze (npx apiblaze skill) to proxy the {backend, frontend} in the current directory in your agent. It installs the skill, reads your code, and runs the commands on this page for you. Clients without a shell (Claude Desktop, ChatGPT, web agents) do the same through one MCP server: add it, sign in with GitHub once, and the agent works on your team.

# ask a chatbot that acts on your account, from the terminal:
$ npx apiblaze docs

# or give any MCP client the same powers:
$ claude mcp add --transport http apiblaze https://mcp.apiblaze.com
# then /mcp and sign in once. Tools, in order: describe_server, propose_rules, create_server,
# apply_rules, add_admin, issue_key, set_rate_limit, integration_kit, explain_access
# MCPblaze: https://mcp.mcpblaze.com

Opened in a browser, the same address brings you to these docs. Everything the tools do is also a CLI command, which is the path when a localhost tunnel is involved: only a process on your machine can run one.

Builder agents

Some setup is easier to describe than to write. The builder agents are chat sessions in your terminal that read your proxy (its spec, and real traffic when there is some) and propose the configuration for you. Nothing changes until you say so: each one shows its proposal, you ask for changes in plain English, then /publish applies it. openapi writes the spec your API never had, from the calls it has seen. authz turns rules like “managers see every reservation” into policies and runs them watch-only on real traffic before you enforce them. mcp chooses which routes agents get as tools, with names and descriptions they can understand. Plain agent takes any request and makes the calls. They need a login and are billed per turn.

$ npx apiblaze agent                        # describe what you want; it makes the calls
$ npx apiblaze agent openapi daringfox2395   # drafts a spec from real traffic, or opens a PR
$ npx apiblaze agent authz daringfox2395     # drafts access rules, watch-only until /enable
$ npx apiblaze agent mcp daringfox2395       # picks the routes that become MCP tools

UI: Drop-in widgets

Three React components give your users APIblaze features on your own site. Each one talks only to a route on your server, which holds the secret and says who is signed in, so the browser never sees a key. npx apiblaze integration daringfox2395 --stack nextjs prints the code for your proxy.

Chat: your users talk to your API

A chat bubble on your site. Users ask in plain English (“book me a table for Friday”); the chat calls your API as that user, through the same rules, and streams the answer.

ninopizzas.com

Nino’s Pizza

Wood-fired. Neapolitan. Midtown.

Margherita
Diavola
Quattro
Chat with Nino✕
Book a table for 2 tomorrow at 8pm
Checking availability
Creating reservation
Done! Table for 2, tomorrow 8:00 pm — see you at Nino's 🍕
Ask something…
➤

▲ the drop-in <ChatWidget/> — tools run live behind your proxy, white-labelled to your brand

What your users see: the chat on your site, calling your API as them.
npx apiblaze integration — the chat part
$ npx apiblaze integration daringfox2395 --stack nextjs

   app/account/page.tsx
     import { ChatWidget } from 'apiblaze/react';
     <ChatWidget endpoint="/api/apiblaze/chat" title="Chat with daringfox2395" suggestions={['What can I do here?']} />

   app/api/apiblaze/chat/route.ts
     import { createApiblazeChat } from 'apiblaze/server';
     import { auth } from '@/auth';

     const chat = createApiblazeChat({
       project: 'daringfox2395',
       apiKey: process.env.APIBLAZE_SERVER_KEY!,       // the server key — server only
       getUser: async () => {
         const s = await auth();
         if (!s?.user) return null;
         return { userId: s.user.id };                 // the chat acts as this person
       },
     });
     export const POST = chat.handler;

API keys: your users manage their own keys

Each signed-in user sees their keys for your API, and can create, rotate and revoke them. Keys land in that customer's tenant, so every customer only sees their own.

acme.dev/developers

Developer

API access

Create a key to call the Acme API from your app or CI.

Your API keys
yJt••••••z7r
Created 7/13/2026 · Never used
prod
Aq0••••••tbX
Created 7/13/2026 · Never used
prod
6Cl••••••E5z
Created 7/13/2026 · Never used
prod

▲ the drop-in <ApiKeyWidget/>, white-labelled to your brand

What your users see: their own keys, on your developer page.
npx apiblaze integration — the keys part, and the widget's key
# the widget's server key: a control-plane key (no --tenant)
$ npx apiblaze apikeys mint --desc "keys widget"          # → APIBLAZE_CP_KEY

$ npx apiblaze integration daringfox2395 --stack nextjs
   app/account/page.tsx
     import { ApiKeyWidget } from 'apiblaze/react';
     <ApiKeyWidget endpoint="/api/apiblaze/keys" title="Your API keys" />

   app/api/apiblaze/keys/route.ts
     import { createApiblazeKeys } from 'apiblaze/server';
     const keys = createApiblazeKeys({
       cpKey: process.env.APIBLAZE_CP_KEY!,           // control-plane key — server only
       getUser: async () => {
         const s = await auth();
         if (!s?.user) return null;
         return { tenant: 'victorymeadow1963', userId: s.user.id, email: s.user.email ?? undefined };
       },
     });
     export const GET = keys.handler;
     export const POST = keys.handler;

Users & groups: your customers' admins manage their team

A tenant's admin adds people, puts them in groups like reservationists, and your authorization rules use those groups. The route is the keys route with one word changed, and it uses the same widget key. For each signed-in admin it mints a short-lived key issued to that person and acts with it, so APIblaze always knows which admin made a change. Someone who isn't an admin sees “admin access required”.

ninopizzas.com/team

Workspace

Team access

Your customer’s admins manage their own users & groups — on your site.

Users & groups
Users 3Groups 2Admins 2
+ Add user
AM
Ana Moretti
ana@ninopizzas.com
BR
Ben Russo
ben@ninopizzas.com
CE
Chiara Esposito
chiara@ninopizzas.com
3 people have called your API but aren’t users yet.Review and add →

▲ the drop-in <UsersGroupsWidget/>, white-labelled to your brand

What your customers' admins see: their users and groups, on your site.
make someone an admin, then wire the route
$ npx apiblaze admins add boss@ninopizzas.com --tenant victorymeadow1963
✔ boss@ninopizzas.com is now a tenant admin of victorymeadow1963.
  Reload the Users & Groups widget — access flips from “pending” to ready.
  The widget uses your widget key (APIBLAZE_CP_KEY) and mints this admin a short-lived personal key itself.

   app/team/page.tsx
     import { UsersGroupsWidget } from 'apiblaze/react';
     <UsersGroupsWidget endpoint="/api/apiblaze/groups" />

   app/api/apiblaze/groups/route.ts
     import { createApiblazeGroups } from 'apiblaze/server';   // the only change vs. the keys route
     const groups = createApiblazeGroups({ cpKey: process.env.APIBLAZE_CP_KEY!, getUser });
     export const GET = groups.handler;
     export const POST = groups.handler;

# APIBLAZE_CP_KEY: `npx apiblaze apikeys mint --desc "widget key"`, run by a team admin or owner
The widgets guide, with NextAuth, Clerk, Auth0 and Supabase tabs

The Next.js sidecar

Route the calls your Next.js app makes to other APIs through APIblaze, one origin at a time, without changing code.

$ npx apiblaze init            # in your Next.js app: wires the sidecar and a dev inspector
$ npm run dev
[apiblaze/sidecar] direct (not approved) → https://api.stripe.com · approve to route it: npx apiblaze sidecar approve api.stripe.com

$ npx apiblaze sidecar approve api.stripe.com
✔ Approved api.stripe.com → proxy scapistripecom23c0af. Routing within ~5 min.

$ npx apiblaze sidecar          # what is routed, and what is still a candidate
Routed through APIblaze (1)
  ● https://api.stripe.com  → scapistripecom23c0af
$ npx apiblaze sidecar deny analytics.example.com     # stop suggesting it
$ npx apiblaze sidecar remove api.stripe.com          # go direct again (deletes the proxy)

APIBLAZE_SIDECAR=off in .env.local turns it all off without removing anything.

Versions & environments

Point dev, test and prod at different backends, and run API versions side by side. Each environment has its own keys.

$ npx apiblaze target daringfox2395 --env dev --url https://backend.resiresi.com
✔ Set target for env dev → https://backend.resiresi.com — daringfox2395 v1.0.0.

# a 2.0.0 next to 1.0.0, served at /2.0.0/…
$ npx apiblaze create --name daringfox2395 --target https://api-v2.example.com --apiversion 2.0.0

# which version and environment the bare domain serves
$ npx apiblaze domain set-base daringfox2395

Custom domains

Serve your API, MCP server, portal or login page from your own domain. APIblaze issues the certificate. Needs a login; billed monthly.

$ npx apiblaze domain add daringfox2395 --domain api.ninopizzas.com        # prints the DNS records to set
$ npx apiblaze domain status daringfox2395
$ npx apiblaze domain add daringfox2395 --domain mcp.ninopizzas.com --kind mcp
$ npx apiblaze domain add --tenant victorymeadow1963 --kind portal --domain developers.ninopizzas.com
$ npx apiblaze domain list daringfox2395
$ npx apiblaze domain rm daringfox2395 --id <domain id from list>

Claim a proxy you created anonymously

A proxy made logged out is deleted after 72 hours with no traffic, or 30 days without any. Claiming it makes it yours, with everything else you made while logged out.

  ⚠ Anonymous — claim within 30 days or it expires. To claim these proxies:
      npx apiblaze login && npx apiblaze claim 7XQ7-…

# on the machine that created them, the code is remembered:
$ npx apiblaze login && npx apiblaze claim

# into a team you already have:
$ npx apiblaze claim 7XQ7-… --team my-team

Claimed proxies move from tryabz.run to abz.run, and their MCP servers with them. Inside apichat, /claim does the same. Deleting a proxy needs a login, so claim first if you want to delete one.

The CLI

npx apiblaze needs Node 18 and no install. This is its help, verbatim.

npx apiblaze --help
$ npx apiblaze --help
Usage: apiblaze [options] [command]

APIblaze CLI — create & manage API proxies and run dev tunnels

Options:
  -V, --version  output the version number
  -v, --verbose  Print the exact series of API calls each command makes
                 (curl-equivalent you could run yourself)
  -h, --help     display help for command

Don't like reading docs? Run  npx apiblaze docs  — ask an AI chatbot about APIblaze, and let it act on your account.

Chat
  docs                    Ask an AI chatbot about APIblaze — and let it act on your account (it's the real API, not a docs search)
  apichat                 Turn any API into a chat: point at an OpenAPI spec — or chat an EXISTING proxy by name (no login needed)
  agent                   Chat with an assistant that builds and runs your APIs (billed per turn)
  llm                     Manage a local LLM provider key for chat (optional — lifts model quality, bills your key)

Setup
  dev                     Put the app running on THIS machine on the internet: a public URL and an MCP address for AI agents, tunnelled to localhost. Included: API keys, sign-in, ownership rules, rate limits. No login needed. (Deployed app? Use `create`.)
  create                  Put an app that is already DEPLOYED behind APIblaze: a public URL and an MCP address for AI agents in front of your URL or OpenAPI spec. Included: API keys, sign-in, ownership rules, rate limits. No login needed. (App on this machine? Use `dev`.)
  integration             What to add to your frontend and frontend-server for a proxy — the same kit the APIblaze MCP hands an agent: widgets, the call-through with the key + X-End-User-Id, what your backend must trust, env vars, what stays open
  skill|skills            What APIblaze does, for you or your AI assistant: checks this folder for a backend and offers the next step (put it on the internet, or a sample app)
  login                   Authenticate with APIblaze
  init                    Set up the APIblaze sidecar in a Next.js app (shortcut for `apiblaze sidecar setup`)
  sidecar                 The APIblaze sidecar — set it up, then approve which origins route through APIblaze
  claim                   Claim your anonymous workspace into your account (requires login)
  team                    Switch the active team, or create a new one
  whoami                  Show who you are — both API Producer and API Consumer
  logout                  Sign out (asks whether to drop the Producer or Consumer login)
  flush                   Log out and wipe every local trace: login, workspace keys, apichats, DP keys, secrets, and the MCP servers + CLAUDE.md/AGENTS.md blocks apichat installed elsewhere

Recipes — install a working setup, or publish yours
  search                  Find a published recipe — a whole working proxy someone else set up
  show                    Read a recipe before you install it (upstreams, questions, transforms, spec)
  install                 Create a proxy from a recipe, with your own credentials
  publish                 Publish one of your proxies as a recipe others can install
  withdraw                Permanently delete one published recipe revision

Control plane commands
  config                  Browse and change every proxy setting & feature (interactive; git-config-style get/set)
  projects                List the projects in your team
  logs                    API Producer view — stream this proxy's requests from EVERY caller live (see `apiblaze logs list` to browse past days)
  tenant                  Manage tenants — bare command opens the interactive picker (settings, app clients, providers)
  group                   Manage a tenant's users & groups — bare command lists groups
  admins                  Manage who can administer a tenant's users & groups (the first-admin bootstrap the widget needs)
  apikeys                 API keys — for your team (control plane), or with `mint --tenant` for your API's callers: a backend key, a client key (--client) or a key bound to one person (--for)
  iam                     Turn users & groups on/off for a proxy's tenant (identified calls get their user's groups applied)
  identified              Require calls to identify their end user (X-End-User-Id from a backend key, or a login token — a client key alone cannot) — or allow unattributed calls again
  preapprove              Allow an email or company domain to sign in to an access-restricted API (--list, --remove)
  allowoauthregistration  Approve the next OAuth client that registers against your tenant (Claude Code, Codex, any MCP client) — single use
  rule                    Lock resources to the person who created them — or describe any access rule in plain English (that one is billed per turn)
  mcp                     Optional tweaks to a proxy's MCP server: prompts, per-tool behavior (read-only / destructive / confirm / always-async), UI resource
  domain                  Use your own domain for your API, MCP server, developer portal or login pages (billed monthly)
  delete                  Delete a proxy and everything under it (asks first)
  job                     Check a background delete job (from a delete that ran with --no-wait)
  target                  Change where a proxy forwards requests
  limits                  Rate limits, quota and spend cap for a proxy (10-second figure shown beside each rate)
  billing                 Your wallet: balance (available · in use · grace), top up, usage history, auto-rebuy
  transform               Change requests on their way to your backend — e.g. send it a secret header so it only answers to the proxy
  rename                  Change a proxy's display name
  spec                    View or update a proxy's OpenAPI spec (or build one by chatting: apiblaze agent openapi)
  export                  Export config and data for migration out of APIblaze (Kong, ...)

Data plane commands
  consumer login          Log in to a tenant's portal as a consumer (device flow)
  consumer apikeys        List your consumer API keys (reveals expiring ones), then offer to create one
  consumer logs           API Consumer view — stream YOUR OWN requests on this tenant live (see `consumer logs list` for past days)

Tips:
  • `apiblaze config <project>` browses EVERY setting & feature (works logged-out to explore).
  • Add --verbose to any command to see the equivalent API calls.
  • Add --auto to `dev` or `create` for a scriptable run: no prompts, no TTY needed, proxy name generated.
  • Full API reference: https://api.apiblaze.com/openapi.json
  • Run `apiblaze <command> --help` (e.g. `apiblaze consumer --help`) for sub-commands.

Examples:
  $ npx apiblaze dev --port 3000 --openapi ./openapi.yaml   # your local code, shipped safely: both doors, rules, admin, agent — through a tunnel
  $ npx apiblaze integration myapi --stack nextjs          # what to add to your frontend + frontend-server
  $ npx apiblaze apichat --target https://pokeapi.co/openapi.yaml  # chat with any API
  $ npx apiblaze agent                                   # just chat
  $ npx apiblaze create --target https://api.example.com # one-line API proxy — API key for your code, GitHub sign-in for agents
  $ npx apiblaze create --target ./openapi.yaml --auto    # zero prompts: both doors + every resource locked to its creator
  $ npx apiblaze create --target https://api.example.com --apikey  # API-key door only
  $ npx apiblaze rule myapi                              # pick what to lock, then turn enforcement on
  $ npx apiblaze admins add you@example.com --tenant acme # make someone an admin (bypasses the ownership rules)
  $ npx apiblaze skill --install                         # teach Claude Code to ship your API safely with APIblaze
  $ npx apiblaze search gmail                            # find a recipe (no login needed)
  $ npx apiblaze install @julien/gmail                   # someone's whole working setup, your credentials
  $ npx apiblaze publish mygmail                         # share yours back, as @yourgithubhandle/mygmail
  $ npx apiblaze limits set myapi --rate 50 --verbose    # rate limit (500 per 10 s) + show the API call
  $ npx apiblaze billing balance                         # available · in use · grace
  $ npx apiblaze consumer login                          # act as a consumer of your API
  $ npx apiblaze team --new "Acme Corp"                  # new team, and switch to it

A CLI also for the consumers of your API

The people who call your API get a hosted portal (sign-in, their own keys, a live console) and their own CLI commands.

# the portal: https://{tenant}.portal.apiblaze.com/{version}
#   e.g. https://victorymeadow1963.portal.apiblaze.com/1.0.0

$ npx apiblaze consumer login --tenant victorymeadow1963   # device-flow sign-in
$ npx apiblaze consumer apikeys                           # list keys, offer to create one
$ npx apiblaze consumer logs                              # your own requests, live

Field reference

The create body at a glance. Types and defaults live in api.apiblaze.com/openapi.json.

target / openapi / githubThe source, exactly one. A spec URL goes in openapi.
name / tenant / product_slug / display_nameNaming. All optional and generated when missing.
auth_typenone / api_key / oauth. The HTTP call defaults to api_key; the CLI opens both doors.
requests_auth.modepassthrough (anyone) or authenticate
requests_auth.methodsapi_key / jwt / opaque
requests_auth.identified_traffic_onlyEvery call must name an end user
requests_auth.preapproved_users_onlyOnly end users on the tenant allowlist
requests_auth.jwt.allowed_pairsAccepted (iss, aud, jwks_url) of your own login
requests_auth.opaqueIntrospection endpoint, method, params, body
secure.familiesResource paths to lock to their creator, e.g. "/restaurants"
login.providers[]Portal sign-in providers, managed or your own app
environmentsPer-environment targets. On update, the whole object is replaced.
throttlinguserRateLimit (per person, or per key) · proxyQuota · quotaPeriod

Full API reference

Every control-plane endpoint, with schemas and a live console.